Research Note
Fintech Regulatory Perimeter Research Note
Which current sources can illustrate AI governance in financial services without implying that every fintech startup is governed by the same regulator or rule set?
Fintech Regulatory Perimeter Research Note
Question
Which current sources can illustrate AI governance in financial services without implying that every fintech startup is governed by the same regulator or rule set?
What the sources establish
FINRA's 2026 GenAI report says FINRA rules and securities laws continue to apply when member firms use GenAI. It identifies possible implications for supervision, communications, recordkeeping, and fair dealing and discusses testing, monitoring, documentation, privacy, model versions, human review, and agent authority.
The SEC's 2017 robo-adviser guidance says registered robo-advisers are subject to the substantive and fiduciary obligations of the Advisers Act. The SEC's care-obligations bulletin addresses broker-dealer and investment-adviser recommendations to retail investors.
The Federal Reserve's SR 26-2, issued with the OCC and FDIC, supersedes SR 11-7 and revises model-risk guidance. It is expected to be most relevant to banking organizations with more than $30 billion in assets regulated by the Federal Reserve. The underlying guidance excludes generative and agentic AI from direct scope while noting that governance practices should inform controls for tools outside it.
The NIST AI Risk Management Framework is voluntary and cross-sector. It can support governance and evaluation language, but it is not a regulator-specific compliance standard.
Disagreement and uncertainty
The exact perimeter depends on the legal entity, activity, customer, jurisdiction, data, recommendation or transaction, role of the system, and contractual relationships. Brokerage, advisory, banking, payments, lending, insurance, tax, identity, and internal administrative tools can differ materially.
Compliance with one framework does not establish compliance with another law or regulation. A vendor used by a regulated firm does not necessarily become the regulated firm, but contracts and third-party oversight can still impose requirements.
Editorial use
Every public reference must name the source's direct scope. Use these examples to show that technology does not erase the obligations of the underlying activity.
Do not present FINRA guidance as a universal startup rule, SEC robo-adviser guidance as governing all automation, banking model-risk guidance as directly covering every generative system, or NIST alignment as regulatory approval.
Sources
Follow the evidence.
- adviserinfo.sec.gov: 292690adviserinfo.sec.gov
- nber.org: w28990nber.org
- nber.org: w28417nber.org
- hbs.edu: itemhbs.edu
- finra.org: gen aifinra.org
- NIST AI Risk Management Frameworknist.gov
- socialleverage.com: how we actually use ai at social leveragesocialleverage.com
- mattober.comattober.co
- linkedin.com: obermattjlinkedin.com
- steveblank.com: consultants don’t pivot founders dosteveblank.com
- steveblank.com: ampsteveblank.com
- socialleverage.com: teamsocialleverage.com
- socialleverage.comsocialleverage.com
- sba.gov: close or sell your businesssba.gov
- socialleverage.com: approachsocialleverage.com
- sec.gov: 2017 52sec.gov
- federalreserve.gov: SR2602federalreserve.gov
- sociology.stanford.edu: strength weak tiessociology.stanford.edu
- science.org: science.abl4476science.org
- socialleverage.com: moats make the g o a t s lunch learn recap with matt obersocialleverage.com
- steveblank.com: customer development manifestosteveblank.com
- sec.gov: staff bulletin standards conduct broker dealers investment advisers care obligationssec.gov