Back to the episode map

Research Note

Fintech Regulatory Perimeter Research Note

Which current sources can illustrate AI governance in financial services without implying that every fintech startup is governed by the same regulator or rule set?

Aug 4, 20262 min readBy Dalton Anderson

Fintech Regulatory Perimeter Research Note

Question

Which current sources can illustrate AI governance in financial services without implying that every fintech startup is governed by the same regulator or rule set?

What the sources establish

FINRA's 2026 GenAI report says FINRA rules and securities laws continue to apply when member firms use GenAI. It identifies possible implications for supervision, communications, recordkeeping, and fair dealing and discusses testing, monitoring, documentation, privacy, model versions, human review, and agent authority.

The SEC's 2017 robo-adviser guidance says registered robo-advisers are subject to the substantive and fiduciary obligations of the Advisers Act. The SEC's care-obligations bulletin addresses broker-dealer and investment-adviser recommendations to retail investors.

The Federal Reserve's SR 26-2, issued with the OCC and FDIC, supersedes SR 11-7 and revises model-risk guidance. It is expected to be most relevant to banking organizations with more than $30 billion in assets regulated by the Federal Reserve. The underlying guidance excludes generative and agentic AI from direct scope while noting that governance practices should inform controls for tools outside it.

The NIST AI Risk Management Framework is voluntary and cross-sector. It can support governance and evaluation language, but it is not a regulator-specific compliance standard.

Disagreement and uncertainty

The exact perimeter depends on the legal entity, activity, customer, jurisdiction, data, recommendation or transaction, role of the system, and contractual relationships. Brokerage, advisory, banking, payments, lending, insurance, tax, identity, and internal administrative tools can differ materially.

Compliance with one framework does not establish compliance with another law or regulation. A vendor used by a regulated firm does not necessarily become the regulated firm, but contracts and third-party oversight can still impose requirements.

Editorial use

Every public reference must name the source's direct scope. Use these examples to show that technology does not erase the obligations of the underlying activity.

Do not present FINRA guidance as a universal startup rule, SEC robo-adviser guidance as governing all automation, banking model-risk guidance as directly covering every generative system, or NIST alignment as regulatory approval.

Sources

Follow the evidence.

  1. adviserinfo.sec.gov: 292690adviserinfo.sec.gov
  2. nber.org: w28990nber.org
  3. nber.org: w28417nber.org
  4. hbs.edu: itemhbs.edu
  5. finra.org: gen aifinra.org
  6. NIST AI Risk Management Frameworknist.gov
  7. socialleverage.com: how we actually use ai at social leveragesocialleverage.com
  8. mattober.comattober.co
  9. linkedin.com: obermattjlinkedin.com
  10. steveblank.com: consultants don’t pivot founders dosteveblank.com
  11. steveblank.com: ampsteveblank.com
  12. socialleverage.com: teamsocialleverage.com
  13. socialleverage.comsocialleverage.com
  14. sba.gov: close or sell your businesssba.gov
  15. socialleverage.com: approachsocialleverage.com
  16. sec.gov: 2017 52sec.gov
  17. federalreserve.gov: SR2602federalreserve.gov
  18. sociology.stanford.edu: strength weak tiessociology.stanford.edu
  19. science.org: science.abl4476science.org
  20. socialleverage.com: moats make the g o a t s lunch learn recap with matt obersocialleverage.com
  21. steveblank.com: customer development manifestosteveblank.com
  22. sec.gov: staff bulletin standards conduct broker dealers investment advisers care obligationssec.gov
Fintech Regulatory Perimeter Research Note