Red Oak and MirrorWeb are combining. Read the press release | What it means for you

We are combining with MirrorWeb. Learn more

Red Oak Insights | AI in Financial Services: A Legal, Regulatory, and Enterprise View

Overview

Watch

In this Red Oak Insights webinar, former SEC and NASD (now FINRA) enforcement attorney Brian Rubin, Manulife | John Hancock’s Head of Global Distribution Compliance Derek Stern, and MirrorWeb VP of Product Jamie Hoyle join moderator James Cella to tackle how firms should govern AI while the rulebook is still being written. They explore everything from why existing supervision, communications, and recordkeeping rules already apply to how firms should handle AI records, explainability, and model versioning ahead of an exam.

Critical Questions Powered by Red Oak

No. As former SEC and NASD (now FINRA) enforcement attorney Brian Rubin put it during Red Oak’s July 16 Insights panel, “there are no existing AI rules,” but regulators are not waiting for them before examining firms or bringing cases. The SEC and FINRA have been consistent that existing, technology-neutral rules already apply, including supervision, communications, recordkeeping, conflicts of interest, Reg BI, and fiduciary obligations, whether AI touched the work or not. FINRA’s Regulatory Notice 24-09 used Rule 3110 as an example, and the 2026 Regulatory Oversight Report elevates generative AI to a standalone focus area. Enforcement is already underway, and Rubin described it as back to basics: the SEC has charged firms for overstating AI capabilities, the practice now known as AI washing, and FINRA brought an AML case involving a flawed automated identity-verification process. Neither required a new rule, because a firm remains responsible for the outcomes produced by the technology it chooses to rely on.

There are no AI-specific retention periods, so the practical starting point is determining whether you have a record that has to be retained at all, since not everything an AI system produces carries the same regulatory weight. Once something is sent to a client, used in a recommendation, or built into marketing, existing retention periods apply regardless of whether a person or a model created it. In practice, some firms apply full regulatory retention to AI records tied to communications, recommendations, and supervisory review, and shorter windows to lower-risk operational data.

The deeper issue is explainability: firms need to reconstruct how a decision was made, what role AI played, and where human oversight came in. Model versioning is a specific challenge, because a model may be updated or retired between a decision and an exam. Rubin’s advice was to test reconstruction now, taking a decision from six or twelve months ago and trying to rebuild it. If you cannot, that is a gap worth closing before a regulator asks.

For years, firms have leaned on lexicons and keyword lists to flag risky communications, an approach with a well-known flaw: it generates an enormous volume of false positives. The alternative is context. MirrorWeb’s Jamie Hoyle described systems that read a firm’s own supervisory policies and generate tailored review logic from them, so if a firm has a $250 gift limit, the system can recognize that a dinner at a three-Michelin-star restaurant likely exceeds it without anyone writing a keyword for the restaurant’s name. That is the shift from matching words to understanding context, and it lets compliance teams focus attention on the small slice of activity that carries real risk rather than running blanket samples. The key is that every flag stays explainable enough to show a regulator exactly why it was raised.

Transcript

0:06Good afternoon everyone. This is James Cella. We’ll give uh from Red Oak. We’ll give everybody a few minutes to uh a

0:12minute or two to make sure that they join in. But we’re grateful to have you uh joining us here. Uh we can see as uh

0:19we hit the top of the hour, have a lot of folks who signed up for our uh AI panel today and excited to have uh have

0:26you join us. So, we’ll just give a few minutes uh knowing how many backtobacks many of our wonderful clients, friends,

0:32and customers uh uh experience. So, we’ll just give another minute or so and

0:39then when I get word from our folks in the control room that we’re ready to

0:44proceed, uh if you can just give me a little message there, we will we will move forward and start an introduction

0:50for our webinar. But again, thank you very much for joining. James Cell from Red Oak here. We’ll be doing introductions uh once we get the queue

0:58to move forward.

1:06All right, looks like we’re all ready and set to go. Good afternoon everybody. Again, uh thank you again for joining us

1:12here today and for being with us. Again, my name is James Cella uh with Red Oak.

1:17Really excited to be the moderator for our panel here today. Wanted to start off by just giving a little bit of background information here about Red

1:24Oak. Uh Red Oak is the only modern compliance connectivity engine where content review, distribution and and

1:30supervision work as one in an intelligent uh and integrated system.

1:36Marketing content is reviewed, approved, and then content flows seamlessly through for you for distribution,

1:42engagement, and analytics. And for those of you who’ve been following the Red Oak story uh over the years, we’ve uh Red

1:49Oak has been built by compliance experts uh and we serve 17 of the top 20 uh

1:54global asset managers. And we’re really glad today to have not only our our uh all of you joining us here on our

2:00webinar. Super grateful uh for our uh speakers today as we’re going to be talking about uh what everybody loves to

2:07talk about uh AI. and we’re going to take a look at AI from several different perspectives as we jump into our subject

2:13today. Uh we’re really honored and grateful to have a former regulator and current legal counsel joining us and

2:18we’ll have him introduce himself here in a moment. Uh we’re excited to have an enterprise practitioner who’s

2:24implemented AI through the compliance lens join us and we’ll have him introduce us here in a moment. And then

2:30we have a technology and supervision uh the technology and supervision perspective as well from our partners

2:36and I like to call our sister company uh Mir Web joining us here as well today.

2:42So I’m going to let them introduce themselves. Brian uh if you wouldn’t mind starting us off today. Could you tell us a little bit about your

2:47background and the firm that you’re at? Sure. Thanks James and hi everybody. I’m in Washington DC as you can tell

2:54floating above the title basin. I am a partner at Evershed Southerntherland in

3:00DC. I’m co-head of the securities enforcement practice and I was

3:05previously with the SEC’s enforcement staff and also deputy chief counsel of enforcement at NASD.

3:12So you spent quite a few years inside NS uh NASD and the SSC before moving into

3:17advising firms on on on uh uh advising uh firms that they regulate. uh can you

3:24can you share with us or how does that knowledge and perspective help you prepare for exams and enforcement

3:29especially now on something very new like AI? Sure. So yeah, as you said, my

3:35perspective is shaped by seeing these issues on both sides of the table. I

3:40spent more than a decade as a regulator first at the SEC and then at NASD now

3:47FINRA. So, I learned how regulators build cases, how they develop theories

3:53of liability, what kind of evidence they find persuasive, and ultimately what drives enforcement decisions. And just

4:01as importantly, I saw what kinds of explan explanations

4:07and remediation efforts actually resonate with the staff. Um, and then

4:12which ones don’t. And because I’ve been on both sides, I can often anticipate the questions the regulators are going

4:19to ask and the concerns behind those questions, which then in my role now

4:25helps prepare firms more effectively and address issues before they become bigger problems. And I’ve had the opportunity

4:32to apply those lessons in the real world on this side of the table for the past two decades in private practice. is I’ve

4:38probably handled more than a couple hundred exams and investigations involving the SEC, FINRA, and state

4:44regulators. I’ve negotiated more than 60 settlements with FINRA and dozens with the SEC and states. And I’ve also

4:52successfully litigated against both the SEC and FINRA. So I think that

4:57background helps me assess matters realistically from the start identifying

5:02strengths, weaknesses, potential exposure. And the way that I think about

5:09AI is really no different. The technology is new and exciting and

5:15sometimes scary frankly, but the regulatory questions are familiar and we’ll be talking about all of those

5:21types of things. supervision, disclosure, you know, recordkeeping, customer communications, books, records,

5:28uh, privacy, governance, cyber security, everything. Basically, the key though is

5:33understanding both the emerging technology and the

5:38regulatory framework um that the examiners and the enforcement staff are using to evaluate

5:45it. So that combination helps firms prepare for the questions the regulators

5:51are asking right now and also frankly the ones they’re likely going to ask a

5:57year or two or three from now especially as we expect rules to be you know growing modifying and and uh I

6:05shouldn’t say growing modifying but adjusting to this new AI world that we live in right Brian so excellent well

6:11thank you so much glad to have your wealth of experience here with us we also have Jamie Jamie Hy. Uh Jamie, can

6:16you introduce yourself uh as well? Sure. Yeah. Hi, I am Jamie Hy. I am the

6:23head of product at Mir Webb. We are a communications supervision platform. Um

6:29and don’t let the accent fool you. I do live in America. I’m here in very well

6:34usually sunny but rainy Austin, Texas. Um alongside James. So yeah, super excited to speak

6:42boots here just so you know. Uh that’s a Texas accent. Jamie,

6:47I can throw in a few howdies if people want. Um but yeah, no uh Mir Webb. Um yeah, we we really we started out as a

6:54website archiving firm as an area employs, but we’ve really built a really strong business in sort of AI native

7:00communication supervision across social media, across mobile channels, uh team communications, email, all the things

7:06that you’ve come to expect um from a modern communications supervision platform.

7:12And uh you know just and for our uh for those of you who are joining us uh Red Oak and Mir share a unique partnership.

7:21We’ve sometimes refer to each other as sister companies. Uh our uh our uh

7:27chairman of the board at Red Oak is also the CEO of Mir Webb. We’re also own owned uh primarily by the same private

7:33equity firm main sale. Uh and so we work extremely closely together uh in this

7:38partnership. So glad to have you here with us Jamie. you know, you’ve spent a a decade building in this space. You’ve seen a real shift and a lot of changes

7:46that have happened not only in that decade, but just, you know, in the last two or three years. Um, can you talk

7:51about, you know, you know, what where where it came when it came to AI, you know, what is that inflection point like

7:56from where you’re sitting, uh, you know, watching thousands of clients kind of go through this sort of, uh, experience of

8:02of of adjusting to a new world with AI? Can you kind of talk about what that’s been like from your perspective?

8:08Yeah, for sure. But I think it’s really important to go even a bit further back um where every single person that we

8:15spoke to, you know, 15 years ago, people using, you know, lexicons and keywords to try and do communication supervision.

8:22And you’ll hear the example, you know, I use the phrase guarantee all the time as examples.

8:28You know, a bunch of people on this call will have guarantee inside their lexiccoms for communication supervision.

8:33But if I guarantee that Spain’s going to win the World Cup on Sunday, that’s not something that you should be uh

8:38concerned about as a supervisory um professional. So I believe you guaranteed England earlier

8:45in the week if I recall. I apologize. Yeah, yeah, that’s okay. Uh yeah, I’m

8:50over it. Right. Um so and really now as we sort of the industry then went into sort of what we call lowerase AI. So

8:57more of the machine learning and trying to do pattern recognition. And what we found broadly across the industry is

9:03that it didn’t do a great job of cutting down on the the false positives that you know people really suffer from when

9:08they’re trying to do communications review. Um where we see the big unlock and the big advantage particularly

9:14inside our client base has been from this new generation of AI and sort of LM

9:20powered systems that are able to actually provide defensibility but also crucially explanability to the

9:25regulator. being able to show chain of thought and chain of custody, being able to say this is what we think happened.

9:31This is why it’s been flagged and this is why this requires your attention. Um, so I think we sort of sit at this

9:37inflection point now where for the first time sort of as as compliance professionals like we’re able to take a

9:45look at this software, take a look at the technology and meaningfully adjust the way that we’re able to do communications review, you know, focus

9:50on the core workflow and being able to demonstrate to the regulator that you have a clean, safe, and efficient

9:56program that is really catching the things that matter. And we’re able to now build these systems that don’t just reduce the number of false positives,

10:02but really do a good job of highlighting things that you may not have seen previously with Lexicon or these sort of these these prior lowercase AI systems.

10:10Excellent. Thank you so much, Jamie. Glad to have you here with us. And and finally, our good friend Derek Stern, if

10:16you wouldn’t mind introducing yourself uh uh from the client and compliance side. Yeah, sure. Hi, everybody. And and thank

10:22you, James, and everyone for having me. So, uh my name is Derek Stern. I’m the head of global distribution compliance

10:28at Manual Life, John Hancock, working in our wealth and asset management business. So in my role, I lead our

10:34compliance program that supports our marketing and distribution activities across the wealth and asset management

10:39business and includes products from our mutual funds to ETFs, retirement insurance, institutional products,

10:45including private markets. So our primary role is really to help ensure that materials and our communications

10:51that we use to market our our products across the globe. And we’re working in North America, Europe, and Asia. And we

10:58partner very closely with crossf functional business partners to help our business grow in a compliant way.

11:04Oh, thank you, Derek. And and so you’ve you’ve had three uh decades in in your career, a compliance career. Uh meaning

11:11you started when you’re about uh nine or 10 years old, right? That’s right. Uh so how have things

11:18changed in the last year or two? What’s changed the most when it comes to your role? uh specifically around you know

11:24the question or subject of AI. Yeah, I think more has changed in the last year or two than probably in the

11:30previous years in my career combined. So I I think at least in my experience historically compliance teams we always

11:36operated in a very fairly traditional style when we’re reviewing marketing materials. Um, today we’re dealing with

11:43different types of content, whether it’s social media, digital content, AI created content, and I think the

11:49expectation from our business partners for for speed to market has changed

11:54rapidly in the last couple years. Our volume of information is increasing, but the times that we get to review these

12:00materials always seems to shrink. So, that’s certainly been a big change. Things are moving faster. we need to

12:06have, you know, continue to evolve our governance processes to make sure we’re still meeting regulatory adherence even

12:13though we’re moving quicker. So, I think that’s one of the biggest shifts that I’ve seen is that we’re becoming

12:18compliance is becoming more integrated into the business. We’re being asked to partner with them earlier on in the

12:24process um and try and help shape solutions and provide guidance rather than just reviewing the product is which

12:32is what we used to be doing. we get something at the end stage look for compliance review and by the time

12:38something had to change it might have been too late but technology has had a major impact I think over the last even

12:456 months to a year so here at man life John Hancock our leadership from the top has made AI a priority for us and it’s

12:52also creating opportunities for us to rethink how compliance operates so I think we’ve seen some of the most

12:58meaningful change in in the recent years and what we’re trying to do is embrace it and find ways that it can help us

13:04improve but still manage efficiencies and regulatory risk. So I think in the

13:10past we’re kind of moving away from adapting from change that happened maybe periodically to an environment where

13:17change is happening all the time right now. Yeah. And and and that seat at the table uh that compliance has had over the

13:23years or has been fighting to get it seems like that maybe that seat’s getting bigger. There are more seats at the table and and more people coming

13:29together when it comes to these questions I would imagine. Yes. they they now view us more as a partner than one of these roadblocks if

13:35you will. Yes, absolutely. Uh all right, so uh thank you for the introduction. So Brian, let’s let’s kind of start off

13:42with you. So as outside council working with financial services firms who are navigating AI adoption, you know, tell

13:48us kind of what that current regulatory landscape looks like right now.

13:53Yeah. So there are no existing AI rules and the easiest way to think about it is

14:01that the regulators are not waiting for specific AI rules before examining firms

14:08or even bringing enforcement actions. Instead the SEC and FINRA have

14:13emphasized that existing technology neutral rules already apply. Okay. So if

14:19somebody asks what’s the AI rule, the practical answer is that the rules governing things like supervision,

14:26communications, conflicts, recordkeeping, fiduciary obligations are

14:31already the starting point. So first point is existing rules already apply to

14:37AI. FINRA and the SEC have consistently taken the position that firms remain

14:44responsible for their conduct, their decisions, their communications, whatever it is that’s generated by AI

14:51tools. FIN regulatory notice 2409 specifically observed that generative AI

14:58affects virtually every core compliance function including supervision, communications, and recordkeeping. So

15:04just as some examples, REGGBI and fiduciary duty obligations would require

15:10firms to exercise independent judgment rather than relying solely on a model’s

15:16output. Supervision requirements 3110 and 20647

15:22require controls tailored to how AI tools actually operate, including

15:27testing, validation, and appropriate human oversight. The communications

15:32rules 2210 under FINRA and the SEC’s marketing rule apply to AI generated

15:38content just as they would apply to traditional communications. And then books and records and we’ll talk about

15:43that in more detail in a bit. 1783 and 4 and then 2042 under the advisers act

15:49apply to certain AI related records, inputs, outputs, supervisory documentation. And then as a side note,

15:57the SEC’s 2023 predictive data analytics proposal,

16:03which wasn’t adopted, remains important because it reflects continued regulatory

16:09concern about conflicts, optimization algorithms, and AIdriven investor

16:14interactions. The second point I want to make is that enforcement is already happening and

16:21it’s sort of back to basics. The SEC has brought a few enforcement actions

16:27involving AI washing, you know, charging firms for overstating AI capabilities.

16:34And then not directly in the AI space, but FINRA brought an AML case involving

16:41a flawed automated identity verification algorithm, which really underscores a

16:48broader point that reliance on automated technology

16:53not reasonably designed for a firm’s business model or its risks creates

16:58liabilities. So the regulators are not waiting for AI specific rules to act.

17:04And then third, there’s broader regulatory expectations beyond the securities laws and beyond my knowledge.

17:10Uh FTC, CFPB, CFTC, and some states have some

17:17regulatory interest and have made statements and have some specific rules on some of the things that we’re talking

17:23about. Um and then regarding FINRA specifically where it’s been the most

17:29active um FINRA has been translating its regulatory principles into

17:36operational expectations I would call it. The 2026 annual regulatory oversight

17:42report elevates Gen AI to a standalone

17:48focus area. So exams are focusing on how

17:53AI is actually being used, not just what the WSPs say. So they’re acting they’re

17:59asking practical questions like who approved the tool, what data does it

18:05use, how are outputs validated, what the WSPs are saying in terms of reflecting

18:13realworld usage. So I I think there’s sort of four themes here. One is

18:20governance and accountability structures. They’re looking at that. Second, vendor oversight including

18:28access controls and incident management. Third, supervision of AI generated

18:34communications and outputs. And then fourth, emerging risks from autonomous

18:40agents um and you know making sure humans are in the loop. So the bottom line is really this is more sort of a

18:48show your work environment and that means documenting governance, real

18:53supervision, human accountability and the records that let you explain to the

18:59regulators what was going on after the fact. And I think firms that can clearly

19:06tell their story will be in the strongest position when it comes to

19:11exams and enforcement investigations. That’s excellent, Brian. In fact, uh you

19:17know, you know, one of the questions I I had thought in my mind is is is uh as you you were answering the question is

19:23is is these examiners asking about AI right throughout the

19:28entire process? I’m sure uh asking you know at each point of the examination where AI is is being uh utilized who’s

19:37utilizing it how is it being utilized uh and uh without all that documentation in governments I’m sure that is a very

19:43difficult question to ask if it’s just Joemo who’s running chat GBT on a few things here and there

19:49you used uh AI to read your mind so that’s why I was able to anticipate that

19:54question so I appreciate that I appreciate that thank Uh, hey Derek. So, uh, your firm

20:00has, uh, has made AI adoption a real top priority, uh, enterprisewide, and it’s really been driven down by the CEO of

20:07your organization. So, what, um, what has it been like to have that, you know, have that, uh, directive handed to you

20:13from your leadership, and how’s that really changed how your compliance team, uh, not only uh, sees its role in the

20:19organization, but, you know, how has it how’s it changed your role um, you know, over the past 12 to 18 months?

20:26Yeah, I think having that buy in from the top, if you will, literally from our CEO down has made a big difference for

20:32us. You know, all of our leadership has been very clear that AI and and other technology platforms is the strategic

20:39partner, a priority for our firm and it’s something that we all need to embrace whether we’re doing it on our

20:44own or doing it as part of a project. Um, it all is helping us work smarter and a little bit more efficiently. So

20:50that commitment from the top creates that confidence and that culture for innovation and we’re seeing that happen

20:56throughout the organization. Uh I think we’ve been pursuing pretty aggressively different AI partnerships and

21:02capabilities. Um we’re using AI almost every day whether it’s to research

21:07issues, summarize information, identify potential risks, or even automate some routine tasks. Um we’re starting to

21:14build our own AI agents to help us improve our workflows and our efficiencies. and also helping to

21:20support businesses and the compliance processes. So if leadership is making AI

21:26a priority, it’s changing the conversation. It’s not any longer is compliance being asked whether we can

21:33use AI. It’s we should be and then how do we do it responsibly, safely and effectively. So for my team, I think

21:40what’s changed a lot is that it shifted our mindset. We are I mentioned earlier that we’ve often been brought in towards

21:46the end of our process to review activities. Now we’re partnering much earlier with our

21:52business partners. We’re working alongside our technology teams, our legal teams, marketing teams,

21:58operational teams really to help build new technology and tools and we’re

22:03giving them guidance on new governance, training them how to use AI where human

22:09uh insight comes in and we’re doing that from the start. So we’re not being reactive to something that maybe in the

22:15past we’ve done. So you know I mentioned earlier that we’re trying to position ourselves as not the department of no or

22:22sales prevention. We’re partnering with the business now because we have this buyin from the top and really trying to

22:28find ways to use AI responsibly. So we’re ensuring we have the right

22:33controls that go into AI related tools. We’re also looking into areas around privacy and recordkeeping. Brian, some

22:39things that you mentioned before and ensuring that we have transparency, we understand risks involved with certain

22:45models and I think most importantly we still maintain that human oversight. So

22:51James you asked about the biggest change for the team. So I think it’s the opportunity for us to become a little bit more strategic. So instead of

22:57spending all of our times doing manual reviews and activities, we’re focusing on technology and how that can help us

23:04spend more time on higher risk issues and give the business better guidance and build a better compliance program as

23:11as we go into the future. So it’s different, you know, than we’ve been in the past. Um, but I think it’s one of

23:17the most significant shifts that we’ve seen over the last couple years. Would

23:23you say that uh you know that the uh the sh there’s shared responsibility within

23:30IT and compliance and marketing in maintaining those AI processes or are

23:36those sitting with specific individual contributors within teams? How can you talk a little bit about like how

23:41structurally some of those things work? Uh I I think if you asked me this even a month ago I would have a very different

23:47answer. That’s how fast this is changing, right? I think over the last even the last couple weeks several of us in the

23:53compliance organization have sat in in meetings uh with our technology people

23:58as we’re looking to build new AI type of tools and they’re coming to us and say

24:03we need your help you know what should we be doing what should we consider um and that hasn’t happened before so yeah

24:10we are uh sitting at the table from the start I I can’t remember a time when

24:15compliance has been brought in to so many meetings asked us technical questions that sometimes we can and

24:22can’t answer. Um, but it it’s been a great partnership and I think that’ll just get us to an area where we’ll have

24:29more compliant technology going forward that’s going to help us all, you know, stay out of trouble from the regulators

24:35and having a call Brian um but do the right thing. If I could sort of supplement that, um,

24:41the tone at the top is critical and the regulators always talk about it from a compliance and legal perspective. It’s

24:48critical and it’s great hearing the things that Derek is talking about that the top of his company want AI but also

24:55want compliance involved with it. That’s very important. It is. It is. And uh no it it it allows

25:03at least from a regulatory point of view uh folks like Derek and yourself to like educate everybody kind of along the

25:09entire process of here’s what regulators are going to be asking for and we can’t be operating in a bubble I would assume.

25:14Right. So uh so Jamie let’s let’s turn over turn over some time to you. So you know when a lot of people hear about AI for

25:21compliance. Sometimes they think about you know AI from a a pre-approval point of view running uh content through uh AI

25:29to try and spot check or find some things prior to it being formally uh submitted for review. Can you talk about

25:35maybe more on the post review side of things when it comes to like supervision especially on the e ecoms uh side of the

25:41business? Yeah, for sure. Um and I think really the the two lenses to frame this through

25:47um are through really the differences in the volume of the number of items that

25:52need to be reviewed and really the differing shapes of these these these content items. So if you are doing free

25:59review um of content uh of PDFs of of presentations of marketing materials you

26:05know it varies from firm to firm but often you’ve got hundreds to thousands to maybe tens of thousands of

26:10submissions inside your firm in any given month. I think if you look at any reasonable sized firm um inside our

26:17system we are seeing tens to hundreds of thousands to millions of messages a day per organization. So that really changes

26:25the way that we actually have to go away and try and super supervise those capabilities. Um the we already have

26:31sampling as a as an industry to try and select content that that should be reviewed. And it’s really our view that

26:37you know we should be letting people uh review content that is materially more relevant to them. You shouldn’t be doing

26:44a 1% sample of every single thing in the organization. you should be looking at the half a percent or the 1% of things

26:50that really do matter the most that may cause material risk to your organization. I think the other thing here is really around the shape of the

26:57kinds of content that comes through communication supervision but also the context of what has been said

27:03previously. So when we you know we submit a document through pre-review from PDF you know PDF that it contains

27:09is usually self- encapsulated. It may be a clone of a different submission. and it may have a history of changes, of

27:15facts, of figures that have changed. When we look at a an iMessage, what we need to take into account isn’t just the

27:22contents of that message. It’s also the attachments of that that are on that message. It’s also the the Fred and the

27:28history. So, if I say to you James that, you know, that sounds great, let’s go away and do that. That might not be a

27:35problem from supervisor perspective. But if we look three or four messages back and you’ve said, I’ve got this

27:40great insight. What is that? Yeah. Yeah. Exactly. right? Like I’ve got this great inside tip. You need to jump on

27:45this right now. Suddenly that message that was previously innocuous gets an awful lot harder. So when we’re thinking

27:51about AI, you know, in in in communication supervision specifically, we’ve got to have systems that are built

27:57for the scale of dealing with millions of messages a day. You’ve got to have systems that are built for the the context and the different shapes of that

28:04data. Um and it’s really around making sure that we’re able to give compliance officers time back to do more of that

28:10stuff. and we don’t want to do these 1% samples. What we want to do is put people in a position where they are

28:16looking at the most materially risky things to their organization. Um I think Derek you spoke a lot about you know the

28:22increased value and positioning of of compliance having a seat at the table in these conversations. I think you know

28:28part of the where the unlock for AI supervision is a let’s have more time to go and do more of those activities that

28:35drive the business forward but also be in the sheer value unlock of the data. you know, if it’s your data and you you

28:41own it and you’re able to do more interesting and more interesting things from a supervisory perspective, what can we now do with your systems architect is

28:47such that you can give those insights back to the business. So, I do think this is a a really incredibly exciting

28:53time for AI and compliance generally, but just specifically for for communication supervision. There is

28:59we’re really starting scratching the surface of what becomes possible. Absolutely. Thank you. So, so Derek,

29:04you’ve had a chance to evaluate AI tools uh for your compliance uh department and and needs. Can you tell us like, you

29:10know, what that process is like? What’s it like testing that sort of under the hood and and and what do platforms kind of need to prove to you, I guess, and

29:17and prove to your organization before you would maybe onboard them and consider them uh things that not only

29:22your your uh direct reports can use and your teams can use, but also perhaps things that are touching the the uh the

29:29field that you’re monitoring as well. Yeah. And James, I’ll I’ll first say that the way I look at things is

29:35different than the rest of the firm. So, we have a whole model risk committee that’s involved with reviewing AI tools.

29:42So, I’m not going to speak to that. I’m going to focus on what my team and I would be looking for. And to be quite

29:47honest, we’re not looking for a perfect solution. So, we want something that’s going to give us some predictability,

29:52transparency, and the right controls that we need for our business. So, we’re looking at a couple things. We want to

29:58understand first and foremost how the tool would would evaluate data and how it will handle our data. How’s it being

30:04collected? Where is it being stored? Who has access to it? I think those are some questions we all have to look at um

30:09right from the start. Um more importantly, I think something that Brian was saying before, we need to look

30:15at explanability. So if we’re using AI to reach a conclusion or to give us an

30:20example or give us a recommendation, we need to understand how that tool got to

30:25that answer u and be able to document that. So you know being in our regulated environment, it’s not just enough for

30:32the tool to give us an answer and say we got this from AI. We need to feel confident that we can explain and defend

30:38the process that went on behind the scenes to get to that answer. Um we also look at governance and

30:44oversight. We want to know what the tool’s going to do around model updates, testing, monitoring, and what’s change

30:51of management. I think everything that we’re looking at today is is changing so fast that what a tool can do today, it

30:57may perform differently 6 months down the road. So, we want to make sure a tool can adapt to that. And then lastly,

31:03we want to figure out how the tool fits in with our human review process. Um, James, you mentioned the tone from the

31:09top. Um the tone from the top has been that AI isn’t meant to replace people. It’s meant to augment what we’re doing.

31:16So we’re looking at tools that are an enhancement, not a replacement for human judgment. So I think some of the most

31:22successful implementations that we would work with are often the ones that help people work more efficiently um while

31:29still keeping human accountability. Um and I think one thing I I should

31:34probably add on is is we need to test this out. So a vendor can promise us the

31:39world and say our tool can do X, Y, and Z. But until we sit down, test it out and see how it performs, we’re not going

31:46to be comfortable to make sure it’s fitting in with our own risk uh set scenarios. So at the end of the day, you

31:53know, before we place an AI tool into a compliance workflow or adopt it, we need to be confident that the tool is going

31:59to be reliable. it understands what our risk metrics are and know what the controls are, what the controls are in

32:06our regulated environment. Um, if we can do all of that, uh, then we’re in good shape to move forward with, you know,

32:12implementing tools. Awesome. So, uh, Brian and Jamie, can we can we like jump in a little bit or

32:18double click it was some like to say into a couple things that Derrick said. So one of them is uh talking about you

32:26know all of the sort of related data associated with you know running content

32:31through AI. So we’re talking about probably prompts, we’re talking about responses and requests. We’re talking

32:37about uh you know some potentially decently technical sorts of things. Um,

32:43Brian, maybe first with you and maybe follow up with Jamie a little bit more on the technical side, but can you talk

32:48about like what uh how firms should maybe be thinking about and handling

32:53basically all that sort of AI metadata and data associated with just just

32:59running things through a model? It’s a great question. It’s a tough

33:04issue. As we said, there aren’t specific AI rules and there aren’t specific AI

33:11retention periods. So, the goal is having a framework that you can explain

33:18and defend. And here’s a way to think about it and not legal advice as Matt

33:23Lavine says. Um, so you first want to determine whether you have a record that

33:30has to be retained. So what’s the data? You have to figure out what the data is

33:36before you decide how long to keep it. AI tools, as you said, generate, you know, prompts, intermediate outputs,

33:43decision logs, operational data, all kinds of stuff. And not all of that has

33:48the same regulatory significance. So the threshold is

33:53whether the information constitutes a required record. Clearly once it’s sent

34:00to a client or used in a recommendation or cited marketing then we’re talking about a different story and FINRA has

34:06made clear again in 2409 but also there was I think 257 and then the 2026 annual

34:14report that existing recordkeeping rules apply regardless of whether AI generates

34:21it. The second thing to think about is off channel risk just like off-ch

34:27communications. If employees are using unapproved AI platforms for client

34:33related work generating records outside the firm that that’s an issue. Third

34:38once you have identified a required record then you have to apply existing

34:45retention periods. So for broker dealers you know communications three years

34:50under 17 A4B4 while other books and records they have

34:55six-year requirement. RAS generally [snorts] under for their books and records have

35:00the 5-year requirement under 2042. So the bottom line is that existing

35:06recordkeeping requirements apply regardless of whether the content is

35:11created by me or somebody else at a firm or by an AI tool. And the FINRA 2026

35:18report emphasized that point. So a as a practical matter, some firms end up

35:23applying the full regulatory retention periods to AI related records that

35:28support things like client communications, recommendations, disclosures, supervisor review, or other

35:35regulated activities, but they have shorter periods for lower risk

35:42operational or system preference data. So for agentic AI systems, FINR has

35:49emphasized audibility, transparency, and governance

35:54considerations suggesting that firms may want to maintain sufficient records to

35:59reconstruct significant actions, decision pathways, key inputs, things like that to explain or to supervise an

36:07outcome. The fourth issue, and Derek touched on this, I think is vendors,

36:13right? So much of this data lives with third-party AI providers and in other

36:19contexts firms have been cited for failing to verify vendors recordkeeping capabilities and for contracts that

36:26don’t address retention obligations. So the lessons that we’ve learned on the

36:32cyber security front apply here. And then the last thing I want to emphasize

36:37is you have to build it for explainability

36:42and if there’s litigation or regulatory issues. So the goal isn’t retaining

36:49everything forever. It’s retaining what’s regulatory required and then

36:55enough to reconstruct and defend the process. And then separately, if there’s

37:02litigation or regulatory inquiries, there’s going to be holds. So the system

37:08has to be designed to override any scheduled deletions. So the framework

37:15has to take that stuff into account from the start. Um, so those are sort of the

37:20basic principles that I that I think about. And Brian Dur, isn’t there a risk

37:27maybe of keeping too much information that might be subject to a regulatory exam? Yeah. Yeah, that’s always an issue. And

37:33and a lot of firms think they have an automatic uh deletion or retention policy, but it turns out they’re keeping

37:39everything forever. Same thing with AI. You don’t want to keep what you don’t need to keep, but on the other hand, you

37:44do have to balance it because you do want to be able to tell the story.

37:50And and Jamie, could you jump in and talk about um just what that kind of looks like from a not only a volume of

37:57data that we’re you know, it’s almost like a a brand new volume of data that we’re now ingesting and archiving and storing. Uh but also can you talk about

38:05like what that means from a a UI point of view or a usability point of view when it comes to that sort of

38:11transparency that Brian was talking about? 100%. And I think there’s there’s two ways to break that down, right? there is

38:17the increase in generated communication. So things like from a core from a co-pilot from from a a chat GPT

38:24enterprise um you know firms have different views on this. I think we are seeing increasingly across our customer

38:29base that people are choosing to on the side of caution and retain those

38:35communications because they may contain client relevant information or business relevant information or the decisioning

38:41process required to reach a to tell the full story around a given communication because eventually

38:48it gets used in an email it gets used in social media they want to be able to tell the journey end to end. Um I think from an actual sort of decisioning

38:54perspective. So why we say a given email is potentially a risk and should be

39:00reviewed or how we select a social media post um appear in a compliance review

39:06cube. You’ve got to have compliance grade AI. You’ve got to be in a position where we have explainability and we’re

39:13able to say exactly this is the version of the prompts that cause this to happen. This is the reason why we

39:19thought this was a thing. these are specific keywords and flags and messages and this is what happens as a result like because ultimately you know I think

39:25as as Derek and Brian spent a lot of time talking about today like the human is still responsible for the output of

39:32that system and you’ll hear people talk about putting compliance on autopilot and you should run for the hills like

39:38you cannot be in a position where you are entrusting the system to just do things and figure it out and then you

39:44know if something goes wrong it’s still the responsibility of the organization it’s still the responsibility of the So

39:50vendors and AI vendors should be very very transparent around exactly what they’re doing and why they’re doing it

39:56and that should be available inside the UIs of these systems. Um I think it’s so so important. It’s a fundamental

40:02principle of of what we’ve done. Absolutely. Thank you so much. So uh

40:07Jamie kind of back to you on a a diff maybe different topic. So uh for many

40:12years across um not only from the uh supervising e communications and and

40:19also from an ad review point of view and and other um uh sorts of compliance review processes, lexicons and keywords

40:26have been a a key part of how uh firms have tried to identify things that need

40:32their attention. Uh random sampling is also kind of in that mix. Uh, and I and you know, someone who’s been in the

40:38space for um, uh, you know, I used to have hair like Jamie back in the day. I mean, they maybe not too long, but been

40:46in the space for, you know, coming up on 20 years or so. You know, we’ve been waiting for AI to help us replace these

40:52things that we that we knew were problematic, that we knew that, you know, the word guarantee is is hard to

40:57use in uh to to trigger based upon a variety of uses of of contextes and and

41:03manners. Uh so uh so with you know the sort of the what I would kind of call the the legacy or the old way of doing

41:09things from a lex le uh lexicon point of view. Uh can you talk about like you

41:14know that has often generated a lot of false positives and can you talk about how AI has helped is helping to kind of

41:22turn the tide and really allow uh customers and clients to be able to like really spot where where the issues are.

41:30Yeah. And I think as well it’s worth first starting on how AI is going to make this work. So you know if we’re not

41:37careful around the the choice of vendors that you’ve got there’s like an obvious way and then a non-obvious way around

41:42how AI can lead to an increase in false posters. So the obvious way is if a

41:49vendor implements AI as an app before. So if you have the same lexicons, you have the same review processes, the same

41:56review cues, and they add a little button in saying review with AI, you end up with the worst of both worlds, right?

42:01Because that takes 20 30 seconds to go away and generate an output and you’ve not actually reduced any of the noise

42:08whatsoever. So it’s an AI workflow, right? But it actually takes longer to clear those alerts and clear those cues.

42:14The non-obvious way is actually what we are seeing generally is an increase in the individual number of communications

42:20per rep and per employee because now like you can go in you can use cord you

42:25can send more emails you can go away and generate more content as an end user and

42:30the net impact that then has is that your review cues get busier and busier there’s more and more content if you’re

42:36using Wexcon using random sampling either way more input in leads to more

42:42messages to review so I think what we are going to see over the next sort of certainly we’re seeing it now but

42:47particularly over the next 18 months is that each individual inside an organization will generate more more and

42:54more client communications over a bunch of you know different formats and different platforms which leads to more

43:00work for these communications supervisory teams because there’s she know there’s much more data being

43:06generated per person as a result of AI. So how do we cut through that noise? How

43:11do we be in a position where we’re able to actually turn that from, you know, a potential issue for supervisory routines

43:18into something that is a force multiplier? And I think you you’ve got to design the systems around the human

43:24in the loop. You got to make sure that there is still human aware and accountable for for the reasoning and

43:29judgment, but you’ve also you got to make sure that we’re actually taking a new approach to the way that these review cues are built. So the way that

43:37we have handled this is really through starting with written supervisory policies and with training manuals. So

43:43people upload their WSPs uh to our platform, we automatically then go away and generate tailored supervisory uh

43:49prompts and systems based on their actual compliance handbook. So, if we

43:54have something like $250 uh annual gift limit, for example, what we’re able to

44:00do is then really harness the power of the, you know, the the LLM and the AI systems goes go and say, “Hey, okay,

44:05well, you sent you to went with a client to the French Laundry. The LM knows that the French Laundry is a free star

44:12restaurant in Napa Valley. We’re able to start finding content like that based on context, not on the keywords. So if you

44:18have the right UI and the right layout and you’re able to apply that logical reasoning whilst making sure that all of

44:24this is explainable, it’s very very clear what is happening and why, that’s how we end up with a reduction in the

44:30number of overall alert words and the things that you’re actually looking at are suddenly an awful lot more relevant because we’re not just doing keywords or

44:37random sampling. We’re able to very precisely say this is why we’re reviewing this and this is why we think this matters.

44:43Awesome. Thank you so much. So So Brian, couple questions for you. Um,

44:48so we’re kind of in an interesting period of time right now where uh,

44:54you know, our our clients, firms, clients that you’re working with are

44:59making making a lot of decisions about AI with a lot with limited regulatory guidance that’s specific about it. I

45:06mean, you you went through it, but uh, earlier on as far as like returning to basics, which is absolutely the right

45:11way to go about it. Um, but is there a precedent in your experience uh where

45:18something new has come out like this before and there wasn’t a lot of guidance along the way and like does

45:23this remind you of anything that you’ve seen you know kind of in your experience in the past when it comes to you know kind of an expansion of of capabilities

45:31that technology has provided? Yeah. So electronic communications

45:36right? So the books and records rules were written when people used paper and

45:41I think three of us here remember all that stuff before emails. Um but three

45:47of us yeah but then uh you know people started emailing so then there were a

45:53number of regulatory actions 20 years ago on email retention and then more recently we saw the SEC bring all of the

46:00off channel cases dealing with texting, WhatsApp, that sort of thing. no changes in the rules or regulations. The

46:07regulators said, “These are the rules and this is how we’re applying it.” The more recent commission has sort of been

46:13rethinking that, and I think we will be seeing changes in the books and records rules. But that’s a perfect example of

46:21new technology, old rules, and if regulators see an issue or a concern

46:27about it, they’re going to apply the existing rules to the new situation.

46:32So, so let’s kind of maybe dive into that a little bit deeper just from a scenario point of view. So, so let’s say a firm uh runs AI as part of its its

46:40review processes uh and it keeps the final decisions on the record. But once the retention window lapses and the

46:46underlying AI generated data gets deleted, uh then there’s like a two or

46:51three year sort of gap uh in between that period of time and a regular comes in, starts poking around and looks for

46:58them to explain their decisions. uh if a firm can’t uh you know if those if those

47:03AI records are gone uh uh you know I guess from where you sit how should

47:09firms be preparing for such scenarios and it sounds like some of those scenarios might already be occurring but

47:14you know the future may be do do you envision more of that in the future potentially?

47:20Yeah. So, it’s it’s an explanability issue rather than a pure retention

47:27issue. And again, not legal advice. Everything’s based on facts and circumstances. But I in general, firms

47:34need to explain how a decision was reached and not just the final outcome.

47:41Nobody’s expecting any firm to preserve every prompt forever, but they do need

47:47to show how a decision was reached, what role AI played, what role human

47:53oversight played. So you do need that and if you don’t have that, that’s a

47:59supervision gap really. So you have to build a documented decision trail for

48:06higher risk AI use cases. So if you’re talking about you know recommendations

48:14or communications you want the key things to be within that that you are

48:21retaining. And one thing which people may not even think about is model

48:26versioning that can be important if a model has been updated or retired. I was

48:33involved with one case not AI but CRM related and the CRM tool had changed and

48:40that became very relevant for the regulators. So you have to focus on that

48:46and as I mentioned before the FINRA 2026 report highlighted auditability,

48:52transparency and supervisory concerns. So firms should really be thinking about

48:58that. And then third, you have to recognize that that’s where the

49:03regulators are looking. They’re looking at the monitoring of prompts and

49:09outputs. And then the last advice that that I would give and that some firms are doing is you should be testing now.

49:17As you mentioned, a regulator may come in a year, two years, 3 years from now. It probably makes sense for firms to

49:23look at decisions they made six months ago or a year ago and see whether they

49:30could reconstruct it. And if you have problems reconstructing it now, you should probably be looking at what

49:35you’re doing for the future exams that come about. Awesome. Awesome. Thanks so much, Brian.

49:40So, Derek, a question for you. You said it said it to me before personally, you know, as we’ve we’ve uh talked about

49:47this uh uh subject quite a bit over the last several months. Um but but you’ve you’ve mentioned that in your own view

49:53on AI that you know things could look differently even six months from now maybe even a month from now you you kind

50:00of alluded to earlier on because the technology is changing and improving moving really quickly. So what’s one

50:05thing you’re watching really closely uh either a development or a decision uh that you think will most uh change how

50:11your team uh uses AI between now and then? Yeah. And let me just start off by by

50:17something that I experienced just a few hours ago and Brian just relates to what you said is we’re going through a

50:23wireframe uh you know PowerPoint presentation on how an AI tool that we’re working on

50:29right now could work and someone did this very basic it was an AI generated

50:35outline of different steps and one of our heads of marketing said that’s great

50:40but it’s not good enough to have on paper you got to document this and we got to keep it. So the fact that marketing people are saying this like to

50:47me that was like that’s brand new. So you know that’s a good first step. But I think for me these days the biggest

50:54thing that we’re really looking at is is how are agents going to help us? How’s AI going to help us be more efficient

51:00and maybe automate some of our workflows today. So you know we all know that AI

51:05is generating content for us. It’s summarizing content and it’s been really valuable, but we’re looking to help it,

51:13you know, change how we’re doing our work. Um, and there’s enormous potential for us in the compliance team. So, we’re

51:20not just dealing with policies and regulations and disclosures anymore. We’re using AI to become a little bit

51:26more capable and navigating some of the complexities that we’ve experienced that comes along with new products and new

51:32tools. But we’re making sure that we have the right governance process and practices in place that are going

51:39alongside this new technology. So for our teams, the capabilities are advancing really quickly. Our

51:45organization seems to be advancing just as quickly, which is a good thing. But, you know, being being at the table with

51:52our marketing people that says we need to make sure we’re doing the right thing is great. It makes our jobs easier and

51:58ensures that the governance that we have in place hopefully works. I know it’s a work in progress, but it’s a good start.

52:04So, what we’re trying to do is balance everything. Um, take advantage of the innovation, but manage that

52:10accountability, ensure that we can provide that regulatory um, defensibility, if you will, and and

52:17we can prove what we’re doing and document all that stuff, but but James, if you ask me this, I know we talked

52:23about six months before, six months later. I think our answer is going to be different. you know, we want to make

52:29sure that the tools we’re using today, and I touched about this earlier, are still going to work six months from now.

52:34I know things are going to change, maybe we’ll get some rule guidance. Um, but I think the the organizations that are

52:41going to succeed and hopefully we’re working towards that are ones that combine a lot of these capabilities that

52:46we’ve talked about here with strong governance, oversight and and hopefully well-trained employees that know how to

52:53do this and having compliance be um have a seat at the table. And I think all of

52:59that could lead to successful outcomes. Excellent. Excellent. So Jamie, let’s tie on to that a little bit. uh you know

53:06we we’ve we’ve talked a lot about how uh AI is is is uh you know we’re no longer

53:11having the conversations about is AI here to stay or not. I mean I think I think we’ve kind of all sort of moved on from that. That that seems so I don’t

53:17know like 1995 in reference uh to how long ago or that that seems like we we’ve kind of all accepted that.

53:23However, um sounds like 2024 I think actually 2024. Yes. No, I know what I’m saying.

53:28But like that feels like a decade or two ago uh that we’re having those sorts of conversations. I think I think it’s here

53:34and it’s it’s not only here to stay, but it’s here to stay and evolve quite a bit. So, you know, kind of on that that

53:39vein, Jamie, you know, we talked about compliance and supervision when it comes to AI. Can you talk about like what are

53:45some other things that you see AI playing a role in especially for our

53:50compliance and supervision uh friends if you will uh that are on the line that

53:55that aren’t necessarily about supervision and compliance that maybe AI allows us to unlock a little bit.

54:02Yeah. And I think really one of the the really interesting unlocks that we start to get from from all of this is

54:11what else can we do because the historic challenge that firms have

54:18had is that all of this data gets sold inside a platform. And you know we

54:23talked about it today. Compliance hasn’t necessarily always had a seat at the table. you’ve had this piece of compliance software that has been built

54:29for a purpose that um you know it sits and it goes away it does that job. I

54:35think one of the things that has been really transformational in concept both to this industry and the world generally

54:41has been the way that people are starting to use connectors between all of these different systems. So now you

54:47can go into claude, you can write a prompt and if you’ve got Salesforce set up via MCP server and you’ve got your

54:54Outlook set up via MCP server, you can suddenly start to do these crossplatform

55:00workflows that are very very you know important. Now there is regulatory and there is a compliance and data security

55:06challenge here, right? You need to make sure that all of this is accountable that we have the this explanability

55:12through the system. you know exactly who and what is where um what is being used. Um, and so where I think we’ll see over

55:20the next six to 12 months and maybe to Derek’s point like we are moving so quickly to get some of these things into

55:25place that like what I say today will change completely in six months as we have more and more emerging technology.

55:31But I think this idea of compliance connectivity where we’re able to start bridging these gaps between these

55:36platforms and really allow this end toend workflow of content gets reviewed and then it gets you can track that all

55:43the way through all these different systems. the engagement and how and why it’s been used. Like I just think there

55:48is so much opportunity ahead of us and now that requires you to use vendors who

55:53are who want to be open who want to be in a position where they can enable these kind of behaviors and it requires

55:59you to to you know really evaluate every single part of your stack and your

56:04people. So, do we have the right software to be able to go away and and have that openness and that

56:09interconnectivity to unlock these new workflows and business experiences and

56:15how are we do we have well-trained staff who know how they can use these systems and start thinking about the inter links. So, I just think this is an

56:22incredibly exciting time for for for the industry generally. Um, I think there is

56:27an awful lot of value that we can start to unlock particularly as firms start to work close together. So, yeah, we’re we’re super super excited about the

56:33journey ahead. Absolutely. Thank you. Well, we we’re coming to a close uh on our time. Uh

56:38just wanted to first of all not only thank our panelists, but maybe give each of you a final word, final sort of 30

56:43seconds or so of of of something that maybe to a little golden nugget or a

56:49little whatever that you’d like to share uh you know with folks that maybe we didn’t get to cover or something that is maybe on your mind. Maybe you want to

56:55get a little crazy, make some predictions about what you see coming in the next six to 12 to 18 months on this. Uh it’s being recorded so we will maybe

57:02hold you to it. But u let’s start with uh Derek if you’re if you’re cool with that you know maybe what’s sort of final

57:07word on on the subject that we’ve had here at today. Yeah I’m cool with that but I’m not going to make any predictions. We’re in

57:13compliance anything right? So do you want it? No. Um no but thank you again for having

57:19us. I I think for from my standpoint you know everything that I’ve said before you know having the tone from the top

57:25has really given compliance a voice. You know we have a seat at the table that were being brought in earlier. I think

57:31all of that is important if you’re going to be using AI and technology, using the right platforms, understanding how it

57:37works. Um, having the right governance, um, and again, I can’t repeat this enough, but ensuring the human in the

57:43loop stays front and center, uh, you know, to me is one of the most important things. So, uh, those are the things

57:50that I’ve seen that really have changed over the last couple months. I don’t expect it to. I think it should get

57:55better in the future. Um, and if we can do all that, then I think firms will start to be able to leverage these tools

58:01a little bit a little bit more successfully and create that efficiency that AI is supposed to help us out with.

58:08Thank you, Derek. Thank you, Derek. Thank you for being here with us, Brian. Final word from you.

58:13Also, I don’t make predictions. Um, firms are adapting to this new

58:19technology and you have to realize that the regulators are as well. So they’re

58:25thinking through the same sorts of issues that everyone on this webinar is thinking through. So I would suggest

58:33reading the regulatory guidance, reading speeches that come out and looking at

58:38exam findings to the extent they’re out there or enforcement actions. I think initially the regulators will bring

58:45cases dealing with lowhanging fruit, firms not having adequate policies and procedures, not keeping anything

58:52relevant, that sort of thing. At some point though, they may push the

58:57envelope. Um, we’re in sort of a regulatorite environment now. So, there

59:02may not be a lot of pushing the envelope, but it is important that firms

59:08do listen to what the regulators are saying and try to read the tea leaves as much as you can.

59:13Thank you very much. So, Jamie, it’s on you if you have predictions. If not, we won’t hold you to it. But, I’ll uh I think I’ll I’ll stay with the

59:20panel. I think there is so much moving so fast that, you know, I can make a prediction now and I think in six months

59:25time that we’ll be even further ahead of what I say. So uh and I think you know really you know I think as Brian said

59:31you know you know it’s the same regulations it’s the same standards you got to have got to have humans in the loop but I think if you’ve got that

59:38explanability that compliance grade AI as the baseline for what is possible

59:44then you know there is a whole world of opportunity that is being opened up now and

59:50I think you know as I walk towards our road map for the rest of year as I walk towards the the the art of the possible

59:56with all of this stuff where we can start to bring these systems closer together and get better and better and better at the uh the supervisory and the

1:00:03the agentic workflows here like there is just so much opportunity. Um so if there’s one thing that you know you want

1:00:09to take away from this panel and this session there is so much opportunity inside your organizations inside your

1:00:14functions from the vendors that you choose to use like it’s a new world and you know there’s some amazing things

1:00:21that we’re we’re we’re going to do um together over the next next few months. So, super exciting.

1:00:26Thank you. Thank you, Jamie. So, again, thank you, Derek, Brian, and Jamie. Thank you so much for lending your

1:00:32expertise and your voice uh and your time. And thank you for everybody who’s joined our webinar today. Again, my name

1:00:38is James Cell from Red Oak. Uh we will also be sending out a recording in the

1:00:43coming days and ask uh and wish everybody a wonderful day and and take care. Thank you so much for joining us.

1:00:49 And again, Brian, Jamie, and Derek, thank you again. Appreciate it. Thank you. Thanks.

Read the Blog Post

On July 16, Red Oak brought together three people who see artificial intelligence in financial services from very different vantage points. Brian Rubin is a former SEC and NASD (now FINRA) enforcement attorney, now a partner at Eversheds Sutherland. Derek Stern is Head of Global Distribution Compliance at Manulife | John Hancock. Jamie Hoyle is VP of Product at MirrorWeb. James Cella, Red Oak’s Chief Supervision Evangelist, moderated a conversation about how firms should be thinking about governing AI. 

Firms are making significant AI decisions right now, ahead of any AI-specific rulebook. The panelists agreed that the absence of new rules is not the absence of expectations. 

Existing Rules Already Apply 

“There are no existing AI rules,” Rubin said early on.  However, regulators are not waiting for AI-specific rules before they examine firms or bring cases.  

The SEC and FINRA have been consistent that existing, technology-neutral rules already apply: supervision, communications, recordkeeping, conflicts of interest, Reg BI, and fiduciary obligations are the starting point, whether AI touched the work or not. FINRA’s Regulatory Notice 24-09 used Rule 3110 as an example. In it, FINRA stated: “If a firm is using Gen AI tools as part of its supervisory system—for the review of electronic correspondence, for instance—its policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model.” 1 The 2026 Regulatory Oversight Report goes further and elevates generative AI to a standalone focus area. 

Enforcement is already underway, and Rubin described it as back to basics. The SEC has charged firms for overstating AI capabilities, the practice now known as “AI washing.” FINRA has brought an AML case involving a flawed automated identity-verification process. Neither required a new rule. Both rested on the same principle: a firm remains responsible for outcomes produced by the technology it chooses to rely on. 

Rubin said this is a “show your work” environment. Exams are increasingly focused on how AI is being used, not on what the written supervisory procedures claim. Who approved the tool, what data it touches, how outputs are validated, and where a human stayed accountable.   

A Familiar Pattern 

If the pattern feels familiar, that is because it is. Rubin drew the parallel to electronic communications. The books-and-records rules were written for paper. Then email arrived, and roughly two decades ago a wave of enforcement actions followed on email retention. More recently came the off-channel cases: texting, WhatsApp, personal devices. No rule changed. Regulators applied the existing framework to a new medium. 

When employees run client-related work through unapproved AI platforms, they generate records outside the firm’s control. It’s a familiar problem the industry spent years addressing with messaging apps. 

The Unsettled Recordkeeping Question 

Should firms keep AI prompts, intermediate outputs, decision logs, and operational data at volume? For how long? There are no AI-specific retention periods. No settled answer to what a firm must keep. 

Rubin suggested that firms start by asking whether they have a record that has to be retained at all, because not everything an AI system produces carries the same regulatory weight. Once something is sent to a client, used in a recommendation, or built into marketing, existing retention periods apply regardless of whether a person or a model created it. In practice, some firms apply full regulatory retention to AI records tied to communications, recommendations, and supervisory review, and shorter windows to lower-risk operational data. 

The deeper issue is explainability. Firms need to reconstruct how a decision was made, what role AI played, and where human oversight came in. Rubin flagged model versioning as a specific challenge. Firms need to think about how to handle models that have been updated or retired between a decision and an exam. 

The group walked through an example. A firm runs AI in its review process, keeps the final decisions, and lets the underlying AI data age out on schedule. Two or three years later, a regulator asks the firm to explain those decisions, and the material needed to do so is gone. Rubin’s advice was practical: test reconstruction now. Take a decision from six or twelve months ago and try to rebuild it. If you can’t, that is a gap that needs to be addressed. 

The Compliance Role Is Changing 

The most optimistic thread came from Stern, who has spent three decades in compliance and said more has changed in the last year or two than in all the years before it combined. At Manulife | John Hancock, AI adoption is a priority set from the top, by the CEO, and the mandate arrived with a requirement that compliance be involved from the start. 

That has changed what his team does day to day. The question inside the firm is no longer whether compliance can use AI. It is how to do so responsibly. Compliance is brought in earlier, sitting with technology, legal, and marketing teams while systems are still being designed. Stern said that compliance is no longer the “department of no” or “sales prevention.” It’s seen as a partner. 

Vetting an AI System Before It Goes Live 

Stern walked through how his team vets AI before it enters a compliance workflow, and the criteria double as a due-diligence checklist for any firm. He starts with the data: how the system handles it, where it is stored, and who can access it. Then comes explainability. If a system reaches a conclusion, the firm has to understand and defend how it got there. As Stern put it, it is not enough for a system to give you an answer and say it came from AI. Governance comes next. A firm needs to know how a vendor handles model updates, testing, and change management, because a system that performs well today may behave differently in six months. And finally, fit with human review. Stern warned that a vendor can promise anything, so test it against your own risk scenarios before you believe it. 

Hoyle added on, saying “you’ll hear [vendors] talk about putting compliance on autopilot and you should run for the hills.” The organization remains responsible for the output of the system. 

From Keywords to Context 

Hoyle spent years watching firms rely on lexicons and keyword lists to flag risky communications, and the approach has a well-known flaw: it generates an enormous volume of false positives. 

The alternative is context. Hoyle described systems that read a firm’s own supervisory policies and generate tailored review logic from them. If a firm has a $250 gift limit, the system can recognize that a dinner at a three-Michelin-star restaurant likely exceeds it, without anyone writing a keyword for the restaurant’s name. That is the shift: from matching words to understanding context, with every flag explainable enough to show a regulator why it was raised. 

The Takeaway 

Every panelist recognized that technology is outpacing regulatory guidance, and that any prediction they made about the next six months would likely be out of date by then. But the rules that matter already exist. So does the discipline: documentation, explainability, and human accountability are things compliance teams have practiced for decades. AI is a new medium for an old obligation.  

The views expressed by Brian Rubin and Derek Stern in this conversation are their own and do not constitute an endorsement of Red Oak or any of its products. MirrorWeb is a partner company of Red Oak 

Contributors

Brian Rubin is a partner at Eversheds Sutherland and Co-Head of the Securities Enforcement Group. He previously served in SEC Enforcement and as Deputy Chief Counsel of Enforcement at NASD (now FINRA), and now represents firms in examinations and investigations by the SEC, FINRA, and state regulators. Connect with Brian on LinkedIn. The views expressed by Brian Rubin in this conversation are his own and do not constitute an endorsement of Red Oak or any of its products.

Derek Stern is the Head of Global Distribution Compliance at Manulife Wealth & Asset Management. He leads the global compliance program supporting marketing and distribution activities across mutual fund, retirement, insurance, and institutional businesses. Derek partners closely with sales, marketing, and product teams to manage regulatory risk across jurisdictions, including digital and social media. He is an advocate for using technology and AI to streamline compliance processes while maintaining strong regulatory standards. Connect with Derek on LinkedIn.

Jamie Hoyle is a product leader at MirrorWeb, a leading web archiving and communications supervision provider trusted by the world’s largest financial services institutions. MirrorWeb helps compliance teams monitor, capture, and archive activity across digital channels, from WhatsApp to websites, enabling supervision of off-channel risk and evolving record-keeping needs. Connect with Jamie on LinkedIn.

James Cella is Chief Supervision Evangelist at Red Oak, bringing more than 20 years of experience building compliance and supervision technology for financial institutions. Connect with James on LinkedIn.

Red Oak and MirrorWeb

Red Oak and MirrorWeb are combining

Red Oak and MirrorWeb are combining to deliver one platform for governing the full regulated communication lifecycle — from content creation and review through distribution, supervision, archiving, and the analytics that turn a complete record into a clear picture of how your firm communicates, complies, and grows.

Nothing changes for your team today. Your platform, your contacts, and your support stay as they are.