FINRA has decided to apply the rulebook it already has, covering supervision, communications, recordkeeping, Reg BI and AML, to artificial intelligence rather than write AI-specific rules. In an article published August 12, 2026, Robert Heim of Tarter Krinsky & Drogin and Stephen Zak of Three Mile Advisors argue that this sounds like clarity and is nothing of the kind.
There is no AI rule, so there is no phase-in date and no regulator-issued checklist. As the article states, “It means the burden is on firms to map a fast-moving technology onto a rulebook that wasn’t written with it in mind, and to do it before an examiner asks how.”
One line in their checklist is the one we would put in front of every compliance officer. Under recordkeeping, they tell firms to retain logs of prompts and outputs, “not just the final deliverables,” so the firm can reconstruct how an output was produced.
That is the argument we have been making for months. Under FINRA Rule 4511 and SEC Rule 17a-4, the relevant record is not necessarily just the answer an employee pasted into a client email. It can include the prompts, outputs and other records needed to reconstruct how that answer was produced.
Recordkeeping assumed the document was the activity
An employee wrote the email, so the email was the record of what the employee did. That equivalence is gone. An employee now writes one sentence and the AI retrieves four documents, calls three tools, sends an email, and updates a client record. The sentence is the caption. The actions are the business activity.
FINRA’s agent guidance is about actions, not text
The authors’ own agent section makes this point without naming it. The 2026 Annual Regulatory Oversight Report is FINRA’s first explicit guidance on autonomous agents, meaning systems that act without a human approving each step, and every control the authors list is a control on an action: an approval gate before the agent executes a transaction, sends a communication, or modifies a record.
Those are tool calls. They are not necessarily captured in the conversation transcript. A firm that archived the chat and nothing else cannot show that the transaction was attempted, who authorized it, or whether the gate held.
The same problem already exists in off-channel communications: the fact that a firm prohibits a channel does not mean the communication disappeared.
What the record of AI use has to include
So the record of AI use cannot be just the conversation. It has to include the captured events that let someone reconstruct what happened: the prompt, the response, the documents retrieved into context, every tool call with its arguments and result, every action an agent took, and every policy decision the system made before the call ran, including calls it blocked. A denied attempt is a record too, and it is often the one an examiner most wants to see.
This is what we mean by AI activity retention, as distinct from capturing AI chat. We have written the longer version of this argument in Are LLM tool calls business records?, and the narrower question about chat platforms in Are ChatGPT conversations business records?
The half almost nobody is keeping
The captured events show what the AI did. They do not show what it was allowed to do: which tools were on the table, which were explicitly denied, what standing instructions were in place, which model and which software handled the call. That is the execution context, and without it “our AI could not have done that” is an assertion a firm cannot prove. With it, the answer is a record.
Together the two halves are what an examiner is actually asking for: enough to reconstruct not just what happened, but what was possible.
What to do this quarter
None of this requires waiting for a rule that is not coming. Five things a records-focused compliance function can start on now:
- Inventory every AI use case, including AI embedded in software you already license. You cannot retain what nobody has written down.
- Confirm your retention covers prompts and outputs, not only the finished document. For higher-risk use cases, keep enough to reconstruct how an output was produced.
- Address unsanctioned AI use in both policy and training. An employee pasting client data into a personal ChatGPT account is the off-channel problem your firm already knows, on a new surface.
- Record which model and which version produced each output. An answer given in March has to be explainable in March’s terms, not against whatever the vendor shipped since.
- Confirm your obligations survive the vendor. Outsourcing the tool does not outsource the recordkeeping, and that includes data return when the contract ends.
Comma captures tool calls with full request, response, timing and identity in production today through Arc Relay, which is open source and self-hostable. Capture from ChatGPT Enterprise, Microsoft 365 Copilot and Claude Enterprise is demo available, and we deploy those with you.


