Overview
Watch
In this Red Oak Insights webinar, former SEC and NASD (now FINRA) enforcement attorney Brian Rubin, Manulife | John Hancock’s Head of Global Distribution Compliance Derek Stern, and MirrorWeb VP of Product Jamie Hoyle join moderator James Cella to tackle how firms should govern AI while the rulebook is still being written. They explore everything from why existing supervision, communications, and recordkeeping rules already apply to how firms should handle AI records, explainability, and model versioning ahead of an exam.
Critical Questions Powered by Red Oak
No. As former SEC and NASD (now FINRA) enforcement attorney Brian Rubin put it during Red Oak’s July 16 Insights panel, “there are no existing AI rules,” but regulators are not waiting for them before examining firms or bringing cases. The SEC and FINRA have been consistent that existing, technology-neutral rules already apply, including supervision, communications, recordkeeping, conflicts of interest, Reg BI, and fiduciary obligations, whether AI touched the work or not. FINRA’s Regulatory Notice 24-09 used Rule 3110 as an example, and the 2026 Regulatory Oversight Report elevates generative AI to a standalone focus area. Enforcement is already underway, and Rubin described it as back to basics: the SEC has charged firms for overstating AI capabilities, the practice now known as AI washing, and FINRA brought an AML case involving a flawed automated identity-verification process. Neither required a new rule, because a firm remains responsible for the outcomes produced by the technology it chooses to rely on.
There are no AI-specific retention periods, so the practical starting point is determining whether you have a record that has to be retained at all, since not everything an AI system produces carries the same regulatory weight. Once something is sent to a client, used in a recommendation, or built into marketing, existing retention periods apply regardless of whether a person or a model created it. In practice, some firms apply full regulatory retention to AI records tied to communications, recommendations, and supervisory review, and shorter windows to lower-risk operational data.
The deeper issue is explainability: firms need to reconstruct how a decision was made, what role AI played, and where human oversight came in. Model versioning is a specific challenge, because a model may be updated or retired between a decision and an exam. Rubin’s advice was to test reconstruction now, taking a decision from six or twelve months ago and trying to rebuild it. If you cannot, that is a gap worth closing before a regulator asks.
For years, firms have leaned on lexicons and keyword lists to flag risky communications, an approach with a well-known flaw: it generates an enormous volume of false positives. The alternative is context. MirrorWeb’s Jamie Hoyle described systems that read a firm’s own supervisory policies and generate tailored review logic from them, so if a firm has a $250 gift limit, the system can recognize that a dinner at a three-Michelin-star restaurant likely exceeds it without anyone writing a keyword for the restaurant’s name. That is the shift from matching words to understanding context, and it lets compliance teams focus attention on the small slice of activity that carries real risk rather than running blanket samples. The key is that every flag stays explainable enough to show a regulator exactly why it was raised.
Transcript
0:06Good afternoon everyone. This is James Cella. We’ll give uh from Red Oak. We’ll give everybody a few minutes to uh a
0:12minute or two to make sure that they join in. But we’re grateful to have you uh joining us here. Uh we can see as uh
0:19we hit the top of the hour, have a lot of folks who signed up for our uh AI panel today and excited to have uh have
0:26you join us. So, we’ll just give a few minutes uh knowing how many backtobacks many of our wonderful clients, friends,
0:32and customers uh uh experience. So, we’ll just give another minute or so and
0:39then when I get word from our folks in the control room that we’re ready to
0:44proceed, uh if you can just give me a little message there, we will we will move forward and start an introduction
0:50for our webinar. But again, thank you very much for joining. James Cell from Red Oak here. We’ll be doing introductions uh once we get the queue
0:58to move forward.
1:06All right, looks like we’re all ready and set to go. Good afternoon everybody. Again, uh thank you again for joining us
1:12here today and for being with us. Again, my name is James Cella uh with Red Oak.
1:17Really excited to be the moderator for our panel here today. Wanted to start off by just giving a little bit of background information here about Red
1:24Oak. Uh Red Oak is the only modern compliance connectivity engine where content review, distribution and and
1:30supervision work as one in an intelligent uh and integrated system.
1:36Marketing content is reviewed, approved, and then content flows seamlessly through for you for distribution,
1:42engagement, and analytics. And for those of you who’ve been following the Red Oak story uh over the years, we’ve uh Red
1:49Oak has been built by compliance experts uh and we serve 17 of the top 20 uh
1:54global asset managers. And we’re really glad today to have not only our our uh all of you joining us here on our
2:00webinar. Super grateful uh for our uh speakers today as we’re going to be talking about uh what everybody loves to
2:07talk about uh AI. and we’re going to take a look at AI from several different perspectives as we jump into our subject
2:13today. Uh we’re really honored and grateful to have a former regulator and current legal counsel joining us and
2:18we’ll have him introduce himself here in a moment. Uh we’re excited to have an enterprise practitioner who’s
2:24implemented AI through the compliance lens join us and we’ll have him introduce us here in a moment. And then
2:30we have a technology and supervision uh the technology and supervision perspective as well from our partners
2:36and I like to call our sister company uh Mir Web joining us here as well today.
2:42So I’m going to let them introduce themselves. Brian uh if you wouldn’t mind starting us off today. Could you tell us a little bit about your
2:47background and the firm that you’re at? Sure. Thanks James and hi everybody. I’m in Washington DC as you can tell
2:54floating above the title basin. I am a partner at Evershed Southerntherland in
3:00DC. I’m co-head of the securities enforcement practice and I was
3:05previously with the SEC’s enforcement staff and also deputy chief counsel of enforcement at NASD.
3:12So you spent quite a few years inside NS uh NASD and the SSC before moving into
3:17advising firms on on on uh uh advising uh firms that they regulate. uh can you
3:24can you share with us or how does that knowledge and perspective help you prepare for exams and enforcement
3:29especially now on something very new like AI? Sure. So yeah, as you said, my
3:35perspective is shaped by seeing these issues on both sides of the table. I
3:40spent more than a decade as a regulator first at the SEC and then at NASD now
3:47FINRA. So, I learned how regulators build cases, how they develop theories
3:53of liability, what kind of evidence they find persuasive, and ultimately what drives enforcement decisions. And just
4:01as importantly, I saw what kinds of explan explanations
4:07and remediation efforts actually resonate with the staff. Um, and then
4:12which ones don’t. And because I’ve been on both sides, I can often anticipate the questions the regulators are going
4:19to ask and the concerns behind those questions, which then in my role now
4:25helps prepare firms more effectively and address issues before they become bigger problems. And I’ve had the opportunity
4:32to apply those lessons in the real world on this side of the table for the past two decades in private practice. is I’ve
4:38probably handled more than a couple hundred exams and investigations involving the SEC, FINRA, and state
4:44regulators. I’ve negotiated more than 60 settlements with FINRA and dozens with the SEC and states. And I’ve also
4:52successfully litigated against both the SEC and FINRA. So I think that
4:57background helps me assess matters realistically from the start identifying
5:02strengths, weaknesses, potential exposure. And the way that I think about
5:09AI is really no different. The technology is new and exciting and
5:15sometimes scary frankly, but the regulatory questions are familiar and we’ll be talking about all of those
5:21types of things. supervision, disclosure, you know, recordkeeping, customer communications, books, records,
5:28uh, privacy, governance, cyber security, everything. Basically, the key though is
5:33understanding both the emerging technology and the
5:38regulatory framework um that the examiners and the enforcement staff are using to evaluate
5:45it. So that combination helps firms prepare for the questions the regulators
5:51are asking right now and also frankly the ones they’re likely going to ask a
5:57year or two or three from now especially as we expect rules to be you know growing modifying and and uh I
6:05shouldn’t say growing modifying but adjusting to this new AI world that we live in right Brian so excellent well
6:11thank you so much glad to have your wealth of experience here with us we also have Jamie Jamie Hy. Uh Jamie, can
6:16you introduce yourself uh as well? Sure. Yeah. Hi, I am Jamie Hy. I am the
6:23head of product at Mir Webb. We are a communications supervision platform. Um
6:29and don’t let the accent fool you. I do live in America. I’m here in very well
6:34usually sunny but rainy Austin, Texas. Um alongside James. So yeah, super excited to speak
6:42boots here just so you know. Uh that’s a Texas accent. Jamie,
6:47I can throw in a few howdies if people want. Um but yeah, no uh Mir Webb. Um yeah, we we really we started out as a
6:54website archiving firm as an area employs, but we’ve really built a really strong business in sort of AI native
7:00communication supervision across social media, across mobile channels, uh team communications, email, all the things
7:06that you’ve come to expect um from a modern communications supervision platform.
7:12And uh you know just and for our uh for those of you who are joining us uh Red Oak and Mir share a unique partnership.
7:21We’ve sometimes refer to each other as sister companies. Uh our uh our uh
7:27chairman of the board at Red Oak is also the CEO of Mir Webb. We’re also own owned uh primarily by the same private
7:33equity firm main sale. Uh and so we work extremely closely together uh in this
7:38partnership. So glad to have you here with us Jamie. you know, you’ve spent a a decade building in this space. You’ve seen a real shift and a lot of changes
7:46that have happened not only in that decade, but just, you know, in the last two or three years. Um, can you talk
7:51about, you know, you know, what where where it came when it came to AI, you know, what is that inflection point like
7:56from where you’re sitting, uh, you know, watching thousands of clients kind of go through this sort of, uh, experience of
8:02of of adjusting to a new world with AI? Can you kind of talk about what that’s been like from your perspective?
8:08Yeah, for sure. But I think it’s really important to go even a bit further back um where every single person that we
8:15spoke to, you know, 15 years ago, people using, you know, lexicons and keywords to try and do communication supervision.
8:22And you’ll hear the example, you know, I use the phrase guarantee all the time as examples.
8:28You know, a bunch of people on this call will have guarantee inside their lexiccoms for communication supervision.
8:33But if I guarantee that Spain’s going to win the World Cup on Sunday, that’s not something that you should be uh
8:38concerned about as a supervisory um professional. So I believe you guaranteed England earlier
8:45in the week if I recall. I apologize. Yeah, yeah, that’s okay. Uh yeah, I’m
8:50over it. Right. Um so and really now as we sort of the industry then went into sort of what we call lowerase AI. So
8:57more of the machine learning and trying to do pattern recognition. And what we found broadly across the industry is
9:03that it didn’t do a great job of cutting down on the the false positives that you know people really suffer from when
9:08they’re trying to do communications review. Um where we see the big unlock and the big advantage particularly
9:14inside our client base has been from this new generation of AI and sort of LM
9:20powered systems that are able to actually provide defensibility but also crucially explanability to the
9:25regulator. being able to show chain of thought and chain of custody, being able to say this is what we think happened.
9:31This is why it’s been flagged and this is why this requires your attention. Um, so I think we sort of sit at this
9:37inflection point now where for the first time sort of as as compliance professionals like we’re able to take a
9:45look at this software, take a look at the technology and meaningfully adjust the way that we’re able to do communications review, you know, focus
9:50on the core workflow and being able to demonstrate to the regulator that you have a clean, safe, and efficient
9:56program that is really catching the things that matter. And we’re able to now build these systems that don’t just reduce the number of false positives,
10:02but really do a good job of highlighting things that you may not have seen previously with Lexicon or these sort of these these prior lowercase AI systems.
10:10Excellent. Thank you so much, Jamie. Glad to have you here with us. And and finally, our good friend Derek Stern, if
10:16you wouldn’t mind introducing yourself uh uh from the client and compliance side. Yeah, sure. Hi, everybody. And and thank
10:22you, James, and everyone for having me. So, uh my name is Derek Stern. I’m the head of global distribution compliance
10:28at Manual Life, John Hancock, working in our wealth and asset management business. So in my role, I lead our
10:34compliance program that supports our marketing and distribution activities across the wealth and asset management
10:39business and includes products from our mutual funds to ETFs, retirement insurance, institutional products,
10:45including private markets. So our primary role is really to help ensure that materials and our communications
10:51that we use to market our our products across the globe. And we’re working in North America, Europe, and Asia. And we
10:58partner very closely with crossf functional business partners to help our business grow in a compliant way.
11:04Oh, thank you, Derek. And and so you’ve you’ve had three uh decades in in your career, a compliance career. Uh meaning
11:11you started when you’re about uh nine or 10 years old, right? That’s right. Uh so how have things
11:18changed in the last year or two? What’s changed the most when it comes to your role? uh specifically around you know
11:24the question or subject of AI. Yeah, I think more has changed in the last year or two than probably in the
11:30previous years in my career combined. So I I think at least in my experience historically compliance teams we always
11:36operated in a very fairly traditional style when we’re reviewing marketing materials. Um, today we’re dealing with
11:43different types of content, whether it’s social media, digital content, AI created content, and I think the
11:49expectation from our business partners for for speed to market has changed
11:54rapidly in the last couple years. Our volume of information is increasing, but the times that we get to review these
12:00materials always seems to shrink. So, that’s certainly been a big change. Things are moving faster. we need to
12:06have, you know, continue to evolve our governance processes to make sure we’re still meeting regulatory adherence even
12:13though we’re moving quicker. So, I think that’s one of the biggest shifts that I’ve seen is that we’re becoming
12:18compliance is becoming more integrated into the business. We’re being asked to partner with them earlier on in the
12:24process um and try and help shape solutions and provide guidance rather than just reviewing the product is which
12:32is what we used to be doing. we get something at the end stage look for compliance review and by the time
12:38something had to change it might have been too late but technology has had a major impact I think over the last even
12:456 months to a year so here at man life John Hancock our leadership from the top has made AI a priority for us and it’s
12:52also creating opportunities for us to rethink how compliance operates so I think we’ve seen some of the most
12:58meaningful change in in the recent years and what we’re trying to do is embrace it and find ways that it can help us
13:04improve but still manage efficiencies and regulatory risk. So I think in the
13:10past we’re kind of moving away from adapting from change that happened maybe periodically to an environment where
13:17change is happening all the time right now. Yeah. And and and that seat at the table uh that compliance has had over the
13:23years or has been fighting to get it seems like that maybe that seat’s getting bigger. There are more seats at the table and and more people coming
13:29together when it comes to these questions I would imagine. Yes. they they now view us more as a partner than one of these roadblocks if
13:35you will. Yes, absolutely. Uh all right, so uh thank you for the introduction. So Brian, let’s let’s kind of start off
13:42with you. So as outside council working with financial services firms who are navigating AI adoption, you know, tell
13:48us kind of what that current regulatory landscape looks like right now.
13:53Yeah. So there are no existing AI rules and the easiest way to think about it is
14:01that the regulators are not waiting for specific AI rules before examining firms
14:08or even bringing enforcement actions. Instead the SEC and FINRA have
14:13emphasized that existing technology neutral rules already apply. Okay. So if
14:19somebody asks what’s the AI rule, the practical answer is that the rules governing things like supervision,
14:26communications, conflicts, recordkeeping, fiduciary obligations are
14:31already the starting point. So first point is existing rules already apply to
14:37AI. FINRA and the SEC have consistently taken the position that firms remain
14:44responsible for their conduct, their decisions, their communications, whatever it is that’s generated by AI
14:51tools. FIN regulatory notice 2409 specifically observed that generative AI
14:58affects virtually every core compliance function including supervision, communications, and recordkeeping. So
15:04just as some examples, REGGBI and fiduciary duty obligations would require
15:10firms to exercise independent judgment rather than relying solely on a model’s
15:16output. Supervision requirements 3110 and 20647
15:22require controls tailored to how AI tools actually operate, including
15:27testing, validation, and appropriate human oversight. The communications
15:32rules 2210 under FINRA and the SEC’s marketing rule apply to AI generated
15:38content just as they would apply to traditional communications. And then books and records and we’ll talk about
15:43that in more detail in a bit. 1783 and 4 and then 2042 under the advisers act
15:49apply to certain AI related records, inputs, outputs, supervisory documentation. And then as a side note,
15:57the SEC’s 2023 predictive data analytics proposal,
16:03which wasn’t adopted, remains important because it reflects continued regulatory
16:09concern about conflicts, optimization algorithms, and AIdriven investor
16:14interactions. The second point I want to make is that enforcement is already happening and
16:21it’s sort of back to basics. The SEC has brought a few enforcement actions
16:27involving AI washing, you know, charging firms for overstating AI capabilities.
16:34And then not directly in the AI space, but FINRA brought an AML case involving
16:41a flawed automated identity verification algorithm, which really underscores a
16:48broader point that reliance on automated technology
16:53not reasonably designed for a firm’s business model or its risks creates
16:58liabilities. So the regulators are not waiting for AI specific rules to act.
17:04And then third, there’s broader regulatory expectations beyond the securities laws and beyond my knowledge.
17:10Uh FTC, CFPB, CFTC, and some states have some
17:17regulatory interest and have made statements and have some specific rules on some of the things that we’re talking
17:23about. Um and then regarding FINRA specifically where it’s been the most
17:29active um FINRA has been translating its regulatory principles into
17:36operational expectations I would call it. The 2026 annual regulatory oversight
17:42report elevates Gen AI to a standalone
17:48focus area. So exams are focusing on how
17:53AI is actually being used, not just what the WSPs say. So they’re acting they’re
17:59asking practical questions like who approved the tool, what data does it
18:05use, how are outputs validated, what the WSPs are saying in terms of reflecting
18:13realworld usage. So I I think there’s sort of four themes here. One is
18:20governance and accountability structures. They’re looking at that. Second, vendor oversight including
18:28access controls and incident management. Third, supervision of AI generated
18:34communications and outputs. And then fourth, emerging risks from autonomous
18:40agents um and you know making sure humans are in the loop. So the bottom line is really this is more sort of a
18:48show your work environment and that means documenting governance, real
18:53supervision, human accountability and the records that let you explain to the
18:59regulators what was going on after the fact. And I think firms that can clearly
19:06tell their story will be in the strongest position when it comes to
19:11exams and enforcement investigations. That’s excellent, Brian. In fact, uh you
19:17know, you know, one of the questions I I had thought in my mind is is is uh as you you were answering the question is
19:23is is these examiners asking about AI right throughout the
19:28entire process? I’m sure uh asking you know at each point of the examination where AI is is being uh utilized who’s
19:37utilizing it how is it being utilized uh and uh without all that documentation in governments I’m sure that is a very
19:43difficult question to ask if it’s just Joemo who’s running chat GBT on a few things here and there
19:49you used uh AI to read your mind so that’s why I was able to anticipate that
19:54question so I appreciate that I appreciate that thank Uh, hey Derek. So, uh, your firm
20:00has, uh, has made AI adoption a real top priority, uh, enterprisewide, and it’s really been driven down by the CEO of
20:07your organization. So, what, um, what has it been like to have that, you know, have that, uh, directive handed to you
20:13from your leadership, and how’s that really changed how your compliance team, uh, not only uh, sees its role in the
20:19organization, but, you know, how has it how’s it changed your role um, you know, over the past 12 to 18 months?
20:26Yeah, I think having that buy in from the top, if you will, literally from our CEO down has made a big difference for
20:32us. You know, all of our leadership has been very clear that AI and and other technology platforms is the strategic
20:39partner, a priority for our firm and it’s something that we all need to embrace whether we’re doing it on our
20:44own or doing it as part of a project. Um, it all is helping us work smarter and a little bit more efficiently. So
20:50that commitment from the top creates that confidence and that culture for innovation and we’re seeing that happen
20:56throughout the organization. Uh I think we’ve been pursuing pretty aggressively different AI partnerships and
21:02capabilities. Um we’re using AI almost every day whether it’s to research
21:07issues, summarize information, identify potential risks, or even automate some routine tasks. Um we’re starting to
21:14build our own AI agents to help us improve our workflows and our efficiencies. and also helping to
21:20support businesses and the compliance processes. So if leadership is making AI
21:26a priority, it’s changing the conversation. It’s not any longer is compliance being asked whether we can
21:33use AI. It’s we should be and then how do we do it responsibly, safely and effectively. So for my team, I think
21:40what’s changed a lot is that it shifted our mindset. We are I mentioned earlier that we’ve often been brought in towards
21:46the end of our process to review activities. Now we’re partnering much earlier with our
21:52business partners. We’re working alongside our technology teams, our legal teams, marketing teams,
21:58operational teams really to help build new technology and tools and we’re
22:03giving them guidance on new governance, training them how to use AI where human
22:09uh insight comes in and we’re doing that from the start. So we’re not being reactive to something that maybe in the
22:15past we’ve done. So you know I mentioned earlier that we’re trying to position ourselves as not the department of no or
22:22sales prevention. We’re partnering with the business now because we have this buyin from the top and really trying to
22:28find ways to use AI responsibly. So we’re ensuring we have the right
22:33controls that go into AI related tools. We’re also looking into areas around privacy and recordkeeping. Brian, some
22:39things that you mentioned before and ensuring that we have transparency, we understand risks involved with certain
22:45models and I think most importantly we still maintain that human oversight. So
22:51James you asked about the biggest change for the team. So I think it’s the opportunity for us to become a little bit more strategic. So instead of
22:57spending all of our times doing manual reviews and activities, we’re focusing on technology and how that can help us
23:04spend more time on higher risk issues and give the business better guidance and build a better compliance program as
23:11as we go into the future. So it’s different, you know, than we’ve been in the past. Um, but I think it’s one of
23:17the most significant shifts that we’ve seen over the last couple years. Would
23:23you say that uh you know that the uh the sh there’s shared responsibility within
23:30IT and compliance and marketing in maintaining those AI processes or are
23:36those sitting with specific individual contributors within teams? How can you talk a little bit about like how
23:41structurally some of those things work? Uh I I think if you asked me this even a month ago I would have a very different
23:47answer. That’s how fast this is changing, right? I think over the last even the last couple weeks several of us in the
23:53compliance organization have sat in in meetings uh with our technology people
23:58as we’re looking to build new AI type of tools and they’re coming to us and say
24:03we need your help you know what should we be doing what should we consider um and that hasn’t happened before so yeah
24:10we are uh sitting at the table from the start I I can’t remember a time when
24:15compliance has been brought in to so many meetings asked us technical questions that sometimes we can and
24:22can’t answer. Um, but it it’s been a great partnership and I think that’ll just get us to an area where we’ll have
24:29more compliant technology going forward that’s going to help us all, you know, stay out of trouble from the regulators
24:35and having a call Brian um but do the right thing. If I could sort of supplement that, um,
24:41the tone at the top is critical and the regulators always talk about it from a compliance and legal perspective. It’s
24:48critical and it’s great hearing the things that Derek is talking about that the top of his company want AI but also
24:55want compliance involved with it. That’s very important. It is. It is. And uh no it it it allows
25:03at least from a regulatory point of view uh folks like Derek and yourself to like educate everybody kind of along the
25:09entire process of here’s what regulators are going to be asking for and we can’t be operating in a bubble I would assume.
25:14Right. So uh so Jamie let’s let’s turn over turn over some time to you. So you know when a lot of people hear about AI for
25:21compliance. Sometimes they think about you know AI from a a pre-approval point of view running uh content through uh AI
25:29to try and spot check or find some things prior to it being formally uh submitted for review. Can you talk about
25:35maybe more on the post review side of things when it comes to like supervision especially on the e ecoms uh side of the
25:41business? Yeah, for sure. Um and I think really the the two lenses to frame this through
25:47um are through really the differences in the volume of the number of items that
25:52need to be reviewed and really the differing shapes of these these these content items. So if you are doing free
25:59review um of content uh of PDFs of of presentations of marketing materials you
26:05know it varies from firm to firm but often you’ve got hundreds to thousands to maybe tens of thousands of
26:10submissions inside your firm in any given month. I think if you look at any reasonable sized firm um inside our
26:17system we are seeing tens to hundreds of thousands to millions of messages a day per organization. So that really changes
26:25the way that we actually have to go away and try and super supervise those capabilities. Um the we already have
26:31sampling as a as an industry to try and select content that that should be reviewed. And it’s really our view that
26:37you know we should be letting people uh review content that is materially more relevant to them. You shouldn’t be doing
26:44a 1% sample of every single thing in the organization. you should be looking at the half a percent or the 1% of things
26:50that really do matter the most that may cause material risk to your organization. I think the other thing here is really around the shape of the
26:57kinds of content that comes through communication supervision but also the context of what has been said
27:03previously. So when we you know we submit a document through pre-review from PDF you know PDF that it contains
27:09is usually self- encapsulated. It may be a clone of a different submission. and it may have a history of changes, of
27:15facts, of figures that have changed. When we look at a an iMessage, what we need to take into account isn’t just the
27:22contents of that message. It’s also the attachments of that that are on that message. It’s also the the Fred and the
27:28history. So, if I say to you James that, you know, that sounds great, let’s go away and do that. That might not be a
27:35problem from supervisor perspective. But if we look three or four messages back and you’ve said, I’ve got this
27:40great insight. What is that? Yeah. Yeah. Exactly. right? Like I’ve got this great inside tip. You need to jump on
27:45this right now. Suddenly that message that was previously innocuous gets an awful lot harder. So when we’re thinking
27:51about AI, you know, in in in communication supervision specifically, we’ve got to have systems that are built
27:57for the scale of dealing with millions of messages a day. You’ve got to have systems that are built for the the context and the different shapes of that
28:04data. Um and it’s really around making sure that we’re able to give compliance officers time back to do more of that
28:10stuff. and we don’t want to do these 1% samples. What we want to do is put people in a position where they are
28:16looking at the most materially risky things to their organization. Um I think Derek you spoke a lot about you know the
28:22increased value and positioning of of compliance having a seat at the table in these conversations. I think you know
28:28part of the where the unlock for AI supervision is a let’s have more time to go and do more of those activities that
28:35drive the business forward but also be in the sheer value unlock of the data. you know, if it’s your data and you you
28:41own it and you’re able to do more interesting and more interesting things from a supervisory perspective, what can we now do with your systems architect is
28:47such that you can give those insights back to the business. So, I do think this is a a really incredibly exciting
28:53time for AI and compliance generally, but just specifically for for communication supervision. There is
28:59we’re really starting scratching the surface of what becomes possible. Absolutely. Thank you. So, so Derek,
29:04you’ve had a chance to evaluate AI tools uh for your compliance uh department and and needs. Can you tell us like, you
29:10know, what that process is like? What’s it like testing that sort of under the hood and and and what do platforms kind of need to prove to you, I guess, and
29:17and prove to your organization before you would maybe onboard them and consider them uh things that not only
29:22your your uh direct reports can use and your teams can use, but also perhaps things that are touching the the uh the
29:29field that you’re monitoring as well. Yeah. And James, I’ll I’ll first say that the way I look at things is
29:35different than the rest of the firm. So, we have a whole model risk committee that’s involved with reviewing AI tools.
29:42So, I’m not going to speak to that. I’m going to focus on what my team and I would be looking for. And to be quite
29:47honest, we’re not looking for a perfect solution. So, we want something that’s going to give us some predictability,
29:52transparency, and the right controls that we need for our business. So, we’re looking at a couple things. We want to
29:58understand first and foremost how the tool would would evaluate data and how it will handle our data. How’s it being
30:04collected? Where is it being stored? Who has access to it? I think those are some questions we all have to look at um
30:09right from the start. Um more importantly, I think something that Brian was saying before, we need to look
30:15at explanability. So if we’re using AI to reach a conclusion or to give us an
30:20example or give us a recommendation, we need to understand how that tool got to
30:25that answer u and be able to document that. So you know being in our regulated environment, it’s not just enough for
30:32the tool to give us an answer and say we got this from AI. We need to feel confident that we can explain and defend
30:38the process that went on behind the scenes to get to that answer. Um we also look at governance and
30:44oversight. We want to know what the tool’s going to do around model updates, testing, monitoring, and what’s change
30:51of management. I think everything that we’re looking at today is is changing so fast that what a tool can do today, it
30:57may perform differently 6 months down the road. So, we want to make sure a tool can adapt to that. And then lastly,
31:03we want to figure out how the tool fits in with our human review process. Um, James, you mentioned the tone from the
31:09top. Um the tone from the top has been that AI isn’t meant to replace people. It’s meant to augment what we’re doing.
31:16So we’re looking at tools that are an enhancement, not a replacement for human judgment. So I think some of the most
31:22successful implementations that we would work with are often the ones that help people work more efficiently um while
31:29still keeping human accountability. Um and I think one thing I I should
31:34probably add on is is we need to test this out. So a vendor can promise us the
31:39world and say our tool can do X, Y, and Z. But until we sit down, test it out and see how it performs, we’re not going
31:46to be comfortable to make sure it’s fitting in with our own risk uh set scenarios. So at the end of the day, you
31:53know, before we place an AI tool into a compliance workflow or adopt it, we need to be confident that the tool is going
31:59to be reliable. it understands what our risk metrics are and know what the controls are, what the controls are in
32:06our regulated environment. Um, if we can do all of that, uh, then we’re in good shape to move forward with, you know,
32:12implementing tools. Awesome. So, uh, Brian and Jamie, can we can we like jump in a little bit or
32:18double click it was some like to say into a couple things that Derrick said. So one of them is uh talking about you
32:26know all of the sort of related data associated with you know running content
32:31through AI. So we’re talking about probably prompts, we’re talking about responses and requests. We’re talking
32:37about uh you know some potentially decently technical sorts of things. Um,
32:43Brian, maybe first with you and maybe follow up with Jamie a little bit more on the technical side, but can you talk
32:48about like what uh how firms should maybe be thinking about and handling
32:53basically all that sort of AI metadata and data associated with just just
32:59running things through a model? It’s a great question. It’s a tough
33:04issue. As we said, there aren’t specific AI rules and there aren’t specific AI
33:11retention periods. So, the goal is having a framework that you can explain
33:18and defend. And here’s a way to think about it and not legal advice as Matt
33:23Lavine says. Um, so you first want to determine whether you have a record that
33:30has to be retained. So what’s the data? You have to figure out what the data is
33:36before you decide how long to keep it. AI tools, as you said, generate, you know, prompts, intermediate outputs,
33:43decision logs, operational data, all kinds of stuff. And not all of that has
33:48the same regulatory significance. So the threshold is
33:53whether the information constitutes a required record. Clearly once it’s sent
34:00to a client or used in a recommendation or cited marketing then we’re talking about a different story and FINRA has
34:06made clear again in 2409 but also there was I think 257 and then the 2026 annual
34:14report that existing recordkeeping rules apply regardless of whether AI generates
34:21it. The second thing to think about is off channel risk just like off-ch
34:27communications. If employees are using unapproved AI platforms for client
34:33related work generating records outside the firm that that’s an issue. Third
34:38once you have identified a required record then you have to apply existing
34:45retention periods. So for broker dealers you know communications three years
34:50under 17 A4B4 while other books and records they have
34:55six-year requirement. RAS generally [snorts] under for their books and records have
35:00the 5-year requirement under 2042. So the bottom line is that existing
35:06recordkeeping requirements apply regardless of whether the content is
35:11created by me or somebody else at a firm or by an AI tool. And the FINRA 2026
35:18report emphasized that point. So a as a practical matter, some firms end up
35:23applying the full regulatory retention periods to AI related records that
35:28support things like client communications, recommendations, disclosures, supervisor review, or other
35:35regulated activities, but they have shorter periods for lower risk
35:42operational or system preference data. So for agentic AI systems, FINR has
35:49emphasized audibility, transparency, and governance
35:54considerations suggesting that firms may want to maintain sufficient records to
35:59reconstruct significant actions, decision pathways, key inputs, things like that to explain or to supervise an
36:07outcome. The fourth issue, and Derek touched on this, I think is vendors,
36:13right? So much of this data lives with third-party AI providers and in other
36:19contexts firms have been cited for failing to verify vendors recordkeeping capabilities and for contracts that
36:26don’t address retention obligations. So the lessons that we’ve learned on the
36:32cyber security front apply here. And then the last thing I want to emphasize
36:37is you have to build it for explainability
36:42and if there’s litigation or regulatory issues. So the goal isn’t retaining
36:49everything forever. It’s retaining what’s regulatory required and then
36:55enough to reconstruct and defend the process. And then separately, if there’s
37:02litigation or regulatory inquiries, there’s going to be holds. So the system
37:08has to be designed to override any scheduled deletions. So the framework
37:15has to take that stuff into account from the start. Um, so those are sort of the
37:20basic principles that I that I think about. And Brian Dur, isn’t there a risk
37:27maybe of keeping too much information that might be subject to a regulatory exam? Yeah. Yeah, that’s always an issue. And
37:33and a lot of firms think they have an automatic uh deletion or retention policy, but it turns out they’re keeping
37:39everything forever. Same thing with AI. You don’t want to keep what you don’t need to keep, but on the other hand, you
37:44do have to balance it because you do want to be able to tell the story.
37:50And and Jamie, could you jump in and talk about um just what that kind of looks like from a not only a volume of
37:57data that we’re you know, it’s almost like a a brand new volume of data that we’re now ingesting and archiving and storing. Uh but also can you talk about
38:05like what that means from a a UI point of view or a usability point of view when it comes to that sort of
38:11transparency that Brian was talking about? 100%. And I think there’s there’s two ways to break that down, right? there is
38:17the increase in generated communication. So things like from a core from a co-pilot from from a a chat GPT
38:24enterprise um you know firms have different views on this. I think we are seeing increasingly across our customer
38:29base that people are choosing to on the side of caution and retain those
38:35communications because they may contain client relevant information or business relevant information or the decisioning
38:41process required to reach a to tell the full story around a given communication because eventually
38:48it gets used in an email it gets used in social media they want to be able to tell the journey end to end. Um I think from an actual sort of decisioning
38:54perspective. So why we say a given email is potentially a risk and should be
39:00reviewed or how we select a social media post um appear in a compliance review
39:06cube. You’ve got to have compliance grade AI. You’ve got to be in a position where we have explainability and we’re
39:13able to say exactly this is the version of the prompts that cause this to happen. This is the reason why we
39:19thought this was a thing. these are specific keywords and flags and messages and this is what happens as a result like because ultimately you know I think
39:25as as Derek and Brian spent a lot of time talking about today like the human is still responsible for the output of
39:32that system and you’ll hear people talk about putting compliance on autopilot and you should run for the hills like
39:38you cannot be in a position where you are entrusting the system to just do things and figure it out and then you
39:44know if something goes wrong it’s still the responsibility of the organization it’s still the responsibility of the So
39:50vendors and AI vendors should be very very transparent around exactly what they’re doing and why they’re doing it
39:56and that should be available inside the UIs of these systems. Um I think it’s so so important. It’s a fundamental
40:02principle of of what we’ve done. Absolutely. Thank you so much. So uh
40:07Jamie kind of back to you on a a diff maybe different topic. So uh for many
40:12years across um not only from the uh supervising e communications and and
40:19also from an ad review point of view and and other um uh sorts of compliance review processes, lexicons and keywords
40:26have been a a key part of how uh firms have tried to identify things that need
40:32their attention. Uh random sampling is also kind of in that mix. Uh, and I and you know, someone who’s been in the
40:38space for um, uh, you know, I used to have hair like Jamie back in the day. I mean, they maybe not too long, but been
40:46in the space for, you know, coming up on 20 years or so. You know, we’ve been waiting for AI to help us replace these
40:52things that we that we knew were problematic, that we knew that, you know, the word guarantee is is hard to
40:57use in uh to to trigger based upon a variety of uses of of contextes and and
41:03manners. Uh so uh so with you know the sort of the what I would kind of call the the legacy or the old way of doing
41:09things from a lex le uh lexicon point of view. Uh can you talk about like you
41:14know that has often generated a lot of false positives and can you talk about how AI has helped is helping to kind of
41:22turn the tide and really allow uh customers and clients to be able to like really spot where where the issues are.
41:30Yeah. And I think as well it’s worth first starting on how AI is going to make this work. So you know if we’re not
41:37careful around the the choice of vendors that you’ve got there’s like an obvious way and then a non-obvious way around
41:42how AI can lead to an increase in false posters. So the obvious way is if a
41:49vendor implements AI as an app before. So if you have the same lexicons, you have the same review processes, the same
41:56review cues, and they add a little button in saying review with AI, you end up with the worst of both worlds, right?
42:01Because that takes 20 30 seconds to go away and generate an output and you’ve not actually reduced any of the noise
42:08whatsoever. So it’s an AI workflow, right? But it actually takes longer to clear those alerts and clear those cues.
42:14The non-obvious way is actually what we are seeing generally is an increase in the individual number of communications
42:20per rep and per employee because now like you can go in you can use cord you
42:25can send more emails you can go away and generate more content as an end user and
42:30the net impact that then has is that your review cues get busier and busier there’s more and more content if you’re
42:36using Wexcon using random sampling either way more input in leads to more
42:42messages to review so I think what we are going to see over the next sort of certainly we’re seeing it now but
42:47particularly over the next 18 months is that each individual inside an organization will generate more more and
42:54more client communications over a bunch of you know different formats and different platforms which leads to more
43:00work for these communications supervisory teams because there’s she know there’s much more data being
43:06generated per person as a result of AI. So how do we cut through that noise? How
43:11do we be in a position where we’re able to actually turn that from, you know, a potential issue for supervisory routines
43:18into something that is a force multiplier? And I think you you’ve got to design the systems around the human
43:24in the loop. You got to make sure that there is still human aware and accountable for for the reasoning and
43:29judgment, but you’ve also you got to make sure that we’re actually taking a new approach to the way that these review cues are built. So the way that
43:37we have handled this is really through starting with written supervisory policies and with training manuals. So
43:43people upload their WSPs uh to our platform, we automatically then go away and generate tailored supervisory uh
43:49prompts and systems based on their actual compliance handbook. So, if we
43:54have something like $250 uh annual gift limit, for example, what we’re able to
44:00do is then really harness the power of the, you know, the the LLM and the AI systems goes go and say, “Hey, okay,
44:05well, you sent you to went with a client to the French Laundry. The LM knows that the French Laundry is a free star
44:12restaurant in Napa Valley. We’re able to start finding content like that based on context, not on the keywords. So if you
44:18have the right UI and the right layout and you’re able to apply that logical reasoning whilst making sure that all of
44:24this is explainable, it’s very very clear what is happening and why, that’s how we end up with a reduction in the
44:30number of overall alert words and the things that you’re actually looking at are suddenly an awful lot more relevant because we’re not just doing keywords or
44:37random sampling. We’re able to very precisely say this is why we’re reviewing this and this is why we think this matters.
44:43Awesome. Thank you so much. So So Brian, couple questions for you. Um,
44:48so we’re kind of in an interesting period of time right now where uh,
44:54you know, our our clients, firms, clients that you’re working with are
44:59making making a lot of decisions about AI with a lot with limited regulatory guidance that’s specific about it. I
45:06mean, you you went through it, but uh, earlier on as far as like returning to basics, which is absolutely the right
45:11way to go about it. Um, but is there a precedent in your experience uh where
45:18something new has come out like this before and there wasn’t a lot of guidance along the way and like does
45:23this remind you of anything that you’ve seen you know kind of in your experience in the past when it comes to you know kind of an expansion of of capabilities
45:31that technology has provided? Yeah. So electronic communications
45:36right? So the books and records rules were written when people used paper and
45:41I think three of us here remember all that stuff before emails. Um but three
45:47of us yeah but then uh you know people started emailing so then there were a
45:53number of regulatory actions 20 years ago on email retention and then more recently we saw the SEC bring all of the
46:00off channel cases dealing with texting, WhatsApp, that sort of thing. no changes in the rules or regulations. The
46:07regulators said, “These are the rules and this is how we’re applying it.” The more recent commission has sort of been
46:13rethinking that, and I think we will be seeing changes in the books and records rules. But that’s a perfect example of
46:21new technology, old rules, and if regulators see an issue or a concern
46:27about it, they’re going to apply the existing rules to the new situation.
46:32So, so let’s kind of maybe dive into that a little bit deeper just from a scenario point of view. So, so let’s say a firm uh runs AI as part of its its
46:40review processes uh and it keeps the final decisions on the record. But once the retention window lapses and the
46:46underlying AI generated data gets deleted, uh then there’s like a two or
46:51three year sort of gap uh in between that period of time and a regular comes in, starts poking around and looks for
46:58them to explain their decisions. uh if a firm can’t uh you know if those if those
47:03AI records are gone uh uh you know I guess from where you sit how should
47:09firms be preparing for such scenarios and it sounds like some of those scenarios might already be occurring but
47:14you know the future may be do do you envision more of that in the future potentially?
47:20Yeah. So, it’s it’s an explanability issue rather than a pure retention
47:27issue. And again, not legal advice. Everything’s based on facts and circumstances. But I in general, firms
47:34need to explain how a decision was reached and not just the final outcome.
47:41Nobody’s expecting any firm to preserve every prompt forever, but they do need
47:47to show how a decision was reached, what role AI played, what role human
47:53oversight played. So you do need that and if you don’t have that, that’s a
47:59supervision gap really. So you have to build a documented decision trail for
48:06higher risk AI use cases. So if you’re talking about you know recommendations
48:14or communications you want the key things to be within that that you are
48:21retaining. And one thing which people may not even think about is model
48:26versioning that can be important if a model has been updated or retired. I was
48:33involved with one case not AI but CRM related and the CRM tool had changed and
48:40that became very relevant for the regulators. So you have to focus on that
48:46and as I mentioned before the FINRA 2026 report highlighted auditability,
48:52transparency and supervisory concerns. So firms should really be thinking about
48:58that. And then third, you have to recognize that that’s where the
49:03regulators are looking. They’re looking at the monitoring of prompts and
49:09outputs. And then the last advice that that I would give and that some firms are doing is you should be testing now.
49:17As you mentioned, a regulator may come in a year, two years, 3 years from now. It probably makes sense for firms to
49:23look at decisions they made six months ago or a year ago and see whether they
49:30could reconstruct it. And if you have problems reconstructing it now, you should probably be looking at what
49:35you’re doing for the future exams that come about. Awesome. Awesome. Thanks so much, Brian.
49:40So, Derek, a question for you. You said it said it to me before personally, you know, as we’ve we’ve uh talked about
49:47this uh uh subject quite a bit over the last several months. Um but but you’ve you’ve mentioned that in your own view
49:53on AI that you know things could look differently even six months from now maybe even a month from now you you kind
50:00of alluded to earlier on because the technology is changing and improving moving really quickly. So what’s one
50:05thing you’re watching really closely uh either a development or a decision uh that you think will most uh change how
50:11your team uh uses AI between now and then? Yeah. And let me just start off by by
50:17something that I experienced just a few hours ago and Brian just relates to what you said is we’re going through a
50:23wireframe uh you know PowerPoint presentation on how an AI tool that we’re working on
50:29right now could work and someone did this very basic it was an AI generated
50:35outline of different steps and one of our heads of marketing said that’s great
50:40but it’s not good enough to have on paper you got to document this and we got to keep it. So the fact that marketing people are saying this like to
50:47me that was like that’s brand new. So you know that’s a good first step. But I think for me these days the biggest
50:54thing that we’re really looking at is is how are agents going to help us? How’s AI going to help us be more efficient
51:00and maybe automate some of our workflows today. So you know we all know that AI
51:05is generating content for us. It’s summarizing content and it’s been really valuable, but we’re looking to help it,
51:13you know, change how we’re doing our work. Um, and there’s enormous potential for us in the compliance team. So, we’re
51:20not just dealing with policies and regulations and disclosures anymore. We’re using AI to become a little bit
51:26more capable and navigating some of the complexities that we’ve experienced that comes along with new products and new
51:32tools. But we’re making sure that we have the right governance process and practices in place that are going
51:39alongside this new technology. So for our teams, the capabilities are advancing really quickly. Our
51:45organization seems to be advancing just as quickly, which is a good thing. But, you know, being being at the table with
51:52our marketing people that says we need to make sure we’re doing the right thing is great. It makes our jobs easier and
51:58ensures that the governance that we have in place hopefully works. I know it’s a work in progress, but it’s a good start.
52:04So, what we’re trying to do is balance everything. Um, take advantage of the innovation, but manage that
52:10accountability, ensure that we can provide that regulatory um, defensibility, if you will, and and
52:17we can prove what we’re doing and document all that stuff, but but James, if you ask me this, I know we talked
52:23about six months before, six months later. I think our answer is going to be different. you know, we want to make
52:29sure that the tools we’re using today, and I touched about this earlier, are still going to work six months from now.
52:34I know things are going to change, maybe we’ll get some rule guidance. Um, but I think the the organizations that are
52:41going to succeed and hopefully we’re working towards that are ones that combine a lot of these capabilities that
52:46we’ve talked about here with strong governance, oversight and and hopefully well-trained employees that know how to
52:53do this and having compliance be um have a seat at the table. And I think all of
52:59that could lead to successful outcomes. Excellent. Excellent. So Jamie, let’s tie on to that a little bit. uh you know
53:06we we’ve we’ve talked a lot about how uh AI is is is uh you know we’re no longer
53:11having the conversations about is AI here to stay or not. I mean I think I think we’ve kind of all sort of moved on from that. That that seems so I don’t
53:17know like 1995 in reference uh to how long ago or that that seems like we we’ve kind of all accepted that.
53:23However, um sounds like 2024 I think actually 2024. Yes. No, I know what I’m saying.
53:28But like that feels like a decade or two ago uh that we’re having those sorts of conversations. I think I think it’s here
53:34and it’s it’s not only here to stay, but it’s here to stay and evolve quite a bit. So, you know, kind of on that that
53:39vein, Jamie, you know, we talked about compliance and supervision when it comes to AI. Can you talk about like what are
53:45some other things that you see AI playing a role in especially for our
53:50compliance and supervision uh friends if you will uh that are on the line that
53:55that aren’t necessarily about supervision and compliance that maybe AI allows us to unlock a little bit.
54:02Yeah. And I think really one of the the really interesting unlocks that we start to get from from all of this is
54:11what else can we do because the historic challenge that firms have
54:18had is that all of this data gets sold inside a platform. And you know we
54:23talked about it today. Compliance hasn’t necessarily always had a seat at the table. you’ve had this piece of compliance software that has been built
54:29for a purpose that um you know it sits and it goes away it does that job. I
54:35think one of the things that has been really transformational in concept both to this industry and the world generally
54:41has been the way that people are starting to use connectors between all of these different systems. So now you
54:47can go into claude, you can write a prompt and if you’ve got Salesforce set up via MCP server and you’ve got your
54:54Outlook set up via MCP server, you can suddenly start to do these crossplatform
55:00workflows that are very very you know important. Now there is regulatory and there is a compliance and data security
55:06challenge here, right? You need to make sure that all of this is accountable that we have the this explanability
55:12through the system. you know exactly who and what is where um what is being used. Um, and so where I think we’ll see over
55:20the next six to 12 months and maybe to Derek’s point like we are moving so quickly to get some of these things into
55:25place that like what I say today will change completely in six months as we have more and more emerging technology.
55:31But I think this idea of compliance connectivity where we’re able to start bridging these gaps between these
55:36platforms and really allow this end toend workflow of content gets reviewed and then it gets you can track that all
55:43the way through all these different systems. the engagement and how and why it’s been used. Like I just think there
55:48is so much opportunity ahead of us and now that requires you to use vendors who
55:53are who want to be open who want to be in a position where they can enable these kind of behaviors and it requires
55:59you to to you know really evaluate every single part of your stack and your
56:04people. So, do we have the right software to be able to go away and and have that openness and that
56:09interconnectivity to unlock these new workflows and business experiences and
56:15how are we do we have well-trained staff who know how they can use these systems and start thinking about the inter links. So, I just think this is an
56:22incredibly exciting time for for for the industry generally. Um, I think there is
56:27an awful lot of value that we can start to unlock particularly as firms start to work close together. So, yeah, we’re we’re super super excited about the
56:33journey ahead. Absolutely. Thank you. Well, we we’re coming to a close uh on our time. Uh
56:38just wanted to first of all not only thank our panelists, but maybe give each of you a final word, final sort of 30
56:43seconds or so of of of something that maybe to a little golden nugget or a
56:49little whatever that you’d like to share uh you know with folks that maybe we didn’t get to cover or something that is maybe on your mind. Maybe you want to
56:55get a little crazy, make some predictions about what you see coming in the next six to 12 to 18 months on this. Uh it’s being recorded so we will maybe
57:02hold you to it. But u let’s start with uh Derek if you’re if you’re cool with that you know maybe what’s sort of final
57:07word on on the subject that we’ve had here at today. Yeah I’m cool with that but I’m not going to make any predictions. We’re in
57:13compliance anything right? So do you want it? No. Um no but thank you again for having
57:19us. I I think for from my standpoint you know everything that I’ve said before you know having the tone from the top
57:25has really given compliance a voice. You know we have a seat at the table that were being brought in earlier. I think
57:31all of that is important if you’re going to be using AI and technology, using the right platforms, understanding how it
57:37works. Um, having the right governance, um, and again, I can’t repeat this enough, but ensuring the human in the
57:43loop stays front and center, uh, you know, to me is one of the most important things. So, uh, those are the things
57:50that I’ve seen that really have changed over the last couple months. I don’t expect it to. I think it should get
57:55better in the future. Um, and if we can do all that, then I think firms will start to be able to leverage these tools
58:01a little bit a little bit more successfully and create that efficiency that AI is supposed to help us out with.
58:08Thank you, Derek. Thank you, Derek. Thank you for being here with us, Brian. Final word from you.
58:13Also, I don’t make predictions. Um, firms are adapting to this new
58:19technology and you have to realize that the regulators are as well. So they’re
58:25thinking through the same sorts of issues that everyone on this webinar is thinking through. So I would suggest
58:33reading the regulatory guidance, reading speeches that come out and looking at
58:38exam findings to the extent they’re out there or enforcement actions. I think initially the regulators will bring
58:45cases dealing with lowhanging fruit, firms not having adequate policies and procedures, not keeping anything
58:52relevant, that sort of thing. At some point though, they may push the
58:57envelope. Um, we’re in sort of a regulatorite environment now. So, there
59:02may not be a lot of pushing the envelope, but it is important that firms
59:08do listen to what the regulators are saying and try to read the tea leaves as much as you can.
59:13Thank you very much. So, Jamie, it’s on you if you have predictions. If not, we won’t hold you to it. But, I’ll uh I think I’ll I’ll stay with the
59:20panel. I think there is so much moving so fast that, you know, I can make a prediction now and I think in six months
59:25time that we’ll be even further ahead of what I say. So uh and I think you know really you know I think as Brian said
59:31you know you know it’s the same regulations it’s the same standards you got to have got to have humans in the loop but I think if you’ve got that
59:38explanability that compliance grade AI as the baseline for what is possible
59:44then you know there is a whole world of opportunity that is being opened up now and
59:50I think you know as I walk towards our road map for the rest of year as I walk towards the the the art of the possible
59:56with all of this stuff where we can start to bring these systems closer together and get better and better and better at the uh the supervisory and the
1:00:03the agentic workflows here like there is just so much opportunity. Um so if there’s one thing that you know you want
1:00:09to take away from this panel and this session there is so much opportunity inside your organizations inside your
1:00:14functions from the vendors that you choose to use like it’s a new world and you know there’s some amazing things
1:00:21that we’re we’re we’re going to do um together over the next next few months. So, super exciting.
1:00:26Thank you. Thank you, Jamie. So, again, thank you, Derek, Brian, and Jamie. Thank you so much for lending your
1:00:32expertise and your voice uh and your time. And thank you for everybody who’s joined our webinar today. Again, my name
1:00:38is James Cell from Red Oak. Uh we will also be sending out a recording in the
1:00:43coming days and ask uh and wish everybody a wonderful day and and take care. Thank you so much for joining us.
1:00:49 And again, Brian, Jamie, and Derek, thank you again. Appreciate it. Thank you. Thanks.
Read the Blog Post
On July 16, Red Oak brought together three people who see artificial intelligence in financial services from very different vantage points. Brian Rubin is a former SEC and NASD (now FINRA) enforcement attorney, now a partner at Eversheds Sutherland. Derek Stern is Head of Global Distribution Compliance at Manulife | John Hancock. Jamie Hoyle is VP of Product at MirrorWeb. James Cella, Red Oak’s Chief Supervision Evangelist, moderated a conversation about how firms should be thinking about governing AI.
Firms are making significant AI decisions right now, ahead of any AI-specific rulebook. The panelists agreed that the absence of new rules is not the absence of expectations.
Existing Rules Already Apply
“There are no existing AI rules,” Rubin said early on. However, regulators are not waiting for AI-specific rules before they examine firms or bring cases.
The SEC and FINRA have been consistent that existing, technology-neutral rules already apply: supervision, communications, recordkeeping, conflicts of interest, Reg BI, and fiduciary obligations are the starting point, whether AI touched the work or not. FINRA’s Regulatory Notice 24-09 used Rule 3110 as an example. In it, FINRA stated: “If a firm is using Gen AI tools as part of its supervisory system—for the review of electronic correspondence, for instance—its policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model.” 1 The 2026 Regulatory Oversight Report goes further and elevates generative AI to a standalone focus area.
Enforcement is already underway, and Rubin described it as back to basics. The SEC has charged firms for overstating AI capabilities, the practice now known as “AI washing.” FINRA has brought an AML case involving a flawed automated identity-verification process. Neither required a new rule. Both rested on the same principle: a firm remains responsible for outcomes produced by the technology it chooses to rely on.
Rubin said this is a “show your work” environment. Exams are increasingly focused on how AI is being used, not on what the written supervisory procedures claim. Who approved the tool, what data it touches, how outputs are validated, and where a human stayed accountable.
A Familiar Pattern
If the pattern feels familiar, that is because it is. Rubin drew the parallel to electronic communications. The books-and-records rules were written for paper. Then email arrived, and roughly two decades ago a wave of enforcement actions followed on email retention. More recently came the off-channel cases: texting, WhatsApp, personal devices. No rule changed. Regulators applied the existing framework to a new medium.
When employees run client-related work through unapproved AI platforms, they generate records outside the firm’s control. It’s a familiar problem the industry spent years addressing with messaging apps.
The Unsettled Recordkeeping Question
Should firms keep AI prompts, intermediate outputs, decision logs, and operational data at volume? For how long? There are no AI-specific retention periods. No settled answer to what a firm must keep.
Rubin suggested that firms start by asking whether they have a record that has to be retained at all, because not everything an AI system produces carries the same regulatory weight. Once something is sent to a client, used in a recommendation, or built into marketing, existing retention periods apply regardless of whether a person or a model created it. In practice, some firms apply full regulatory retention to AI records tied to communications, recommendations, and supervisory review, and shorter windows to lower-risk operational data.
The deeper issue is explainability. Firms need to reconstruct how a decision was made, what role AI played, and where human oversight came in. Rubin flagged model versioning as a specific challenge. Firms need to think about how to handle models that have been updated or retired between a decision and an exam.
The group walked through an example. A firm runs AI in its review process, keeps the final decisions, and lets the underlying AI data age out on schedule. Two or three years later, a regulator asks the firm to explain those decisions, and the material needed to do so is gone. Rubin’s advice was practical: test reconstruction now. Take a decision from six or twelve months ago and try to rebuild it. If you can’t, that is a gap that needs to be addressed.
The Compliance Role Is Changing
The most optimistic thread came from Stern, who has spent three decades in compliance and said more has changed in the last year or two than in all the years before it combined. At Manulife | John Hancock, AI adoption is a priority set from the top, by the CEO, and the mandate arrived with a requirement that compliance be involved from the start.
That has changed what his team does day to day. The question inside the firm is no longer whether compliance can use AI. It is how to do so responsibly. Compliance is brought in earlier, sitting with technology, legal, and marketing teams while systems are still being designed. Stern said that compliance is no longer the “department of no” or “sales prevention.” It’s seen as a partner.
Vetting an AI System Before It Goes Live
Stern walked through how his team vets AI before it enters a compliance workflow, and the criteria double as a due-diligence checklist for any firm. He starts with the data: how the system handles it, where it is stored, and who can access it. Then comes explainability. If a system reaches a conclusion, the firm has to understand and defend how it got there. As Stern put it, it is not enough for a system to give you an answer and say it came from AI. Governance comes next. A firm needs to know how a vendor handles model updates, testing, and change management, because a system that performs well today may behave differently in six months. And finally, fit with human review. Stern warned that a vendor can promise anything, so test it against your own risk scenarios before you believe it.
Hoyle added on, saying “you’ll hear [vendors] talk about putting compliance on autopilot and you should run for the hills.” The organization remains responsible for the output of the system.
From Keywords to Context
Hoyle spent years watching firms rely on lexicons and keyword lists to flag risky communications, and the approach has a well-known flaw: it generates an enormous volume of false positives.
The alternative is context. Hoyle described systems that read a firm’s own supervisory policies and generate tailored review logic from them. If a firm has a $250 gift limit, the system can recognize that a dinner at a three-Michelin-star restaurant likely exceeds it, without anyone writing a keyword for the restaurant’s name. That is the shift: from matching words to understanding context, with every flag explainable enough to show a regulator why it was raised.
The Takeaway
Every panelist recognized that technology is outpacing regulatory guidance, and that any prediction they made about the next six months would likely be out of date by then. But the rules that matter already exist. So does the discipline: documentation, explainability, and human accountability are things compliance teams have practiced for decades. AI is a new medium for an old obligation.
The views expressed by Brian Rubin and Derek Stern in this conversation are their own and do not constitute an endorsement of Red Oak or any of its products. MirrorWeb is a partner company of Red Oak.
Contributors
Brian Rubin is a partner at Eversheds Sutherland and Co-Head of the Securities Enforcement Group. He previously served in SEC Enforcement and as Deputy Chief Counsel of Enforcement at NASD (now FINRA), and now represents firms in examinations and investigations by the SEC, FINRA, and state regulators. Connect with Brian on LinkedIn. The views expressed by Brian Rubin in this conversation are his own and do not constitute an endorsement of Red Oak or any of its products.
Derek Stern is the Head of Global Distribution Compliance at Manulife Wealth & Asset Management. He leads the global compliance program supporting marketing and distribution activities across mutual fund, retirement, insurance, and institutional businesses. Derek partners closely with sales, marketing, and product teams to manage regulatory risk across jurisdictions, including digital and social media. He is an advocate for using technology and AI to streamline compliance processes while maintaining strong regulatory standards. Connect with Derek on LinkedIn.
Jamie Hoyle is a product leader at MirrorWeb, a leading web archiving and communications supervision provider trusted by the world’s largest financial services institutions. MirrorWeb helps compliance teams monitor, capture, and archive activity across digital channels, from WhatsApp to websites, enabling supervision of off-channel risk and evolving record-keeping needs. Connect with Jamie on LinkedIn.
James Cella is Chief Supervision Evangelist at Red Oak, bringing more than 20 years of experience building compliance and supervision technology for financial institutions. Connect with James on LinkedIn.



