FINRA AI recordkeeping: there is no carve-out.
Published July 26, 2026 · OmniStrat AI
FINRA Regulatory Notice 24-09 makes explicit that existing books-and-records, supervision (Rule 3110), and communications rules apply fully to AI tools. Firm-built or third-party. A firm adopting AI must keep records of AI-assisted activity to the same standard as any other business record.
What Notice 24-09 actually says
FINRA's rules are technology-neutral: Rule 2210 governs AI-generated communications, Rule 3110 requires supervisory systems that account for AI reliability and accuracy, and books-and-records obligations attach to AI-assisted workflows with no exemption for new technology.
The $625 million lesson
Roughly 70 firms paid over $625M in penalties for off-channel communications, records that existed but could not be produced or trusted. AI decisioning is the next unrecorded surface: screening, scoring, research, and execution assisted by models that most recordkeeping stacks never capture.
What a firm must be able to produce
What the AI was asked, what it decided or produced, when, under whose supervision. And evidence the record was not altered. Exportable logs a vendor or the firm can rewrite do not meet the evidentiary bar an examiner applies.
Satisfying it with a proof layer
Route AI through a gateway that signs every decision to a hash-chained, externally timestamped ledger (how it works). OmniStrat produces regulator-verifiable receipts by construction, decisions via Foundry, executions via Terminal. (General information, not legal advice.)
The three questions an examiner will ask
Strip away the citation numbers and a books-and-records exam of an AI-assisted workflow reduces to three questions. First: can you produce the record at all — the recommendation, the model output that shaped it, the order that followed? Second: can you show the record has not been altered since it was created — not assert it, show it? Third: can you demonstrate supervision — that a person with authority could have seen this activity at the time, not only after the request letter arrived?
Conventional logging answers the first question on a good day and neither of the others. A log line is a row somebody with database access could have edited, and most AI logging was built by engineers for debugging, not by compliance for production to an examiner. The gap between “we log everything” and “we can produce evidence” is exactly where firms get hurt.
Why hash-chained records answer differently
A record written into a hash chain carries its own integrity argument. Each entry commits to the one before it, so removing, editing or reordering any entry breaks every entry after it — detectably, by arithmetic anyone can run. The examiner does not have to trust your change-management controls, your vendor, or you. Re-hash, check the Ed25519 signature, confirm the chain position. The demonstration takes seconds and requires nothing from us, which is the point: evidence that depends on the goodwill of the party under examination is not evidence.
That maps directly onto the WORM intent of the recordkeeping rules: not merely stored, but stored in a form whose alteration is evident. You can test the mechanism yourself against a live record at the public verifier, with no account.
Where to start without boiling the ocean
No firm converts its recordkeeping in a quarter, and an examiner does not expect it. What is achievable now: route the AI-assisted decisions with the highest supervision exposure — recommendations, suitability determinations, trade rationale — through a layer that writes each one to the chain as it happens. The rest of the estate can follow. When the request letter comes, the firm that can produce even one class of decisions as independently verifiable records is having a different conversation than the firm explaining its logging roadmap.
A 30-day pilot on one workflow produces the audit artifact your compliance team can judge directly.
Join the list →