NewSolo / Entrepreneur access, by invitation.Redeem invite →

FINRA Generative AI Recordkeeping Requirements: What Is Actually a Record

By Ernest Provo, founderLast reviewed: 2026-08-28

FINRA has no AI-specific recordkeeping rule — its rules are technology-neutral, so the existing obligations reach generative AI use exactly as far as they reach everything else. Two things follow: interactions that produce required records must be made, preserved, and producible under the same instruments as always (FINRA Rule 4511; 17 CFR 240.17a-3 and 240.17a-4), and — the part competing summaries get wrong — not every AI interaction is automatically a required record. As of 2026-08-28, this guide draws that line and turns it into a deployable log design with an examiner checklist.

The obligation stack

Four instruments do all the work, and they layer cleanly: a general duty, an enumerated list of records to make, the preservation mechanics, and the notice that closes the "but it's AI" argument.

  1. 01FINRA Rule 4511 — the general duty

    What it says:
    Members shall make and preserve books and records as required under the FINRA rules, the Exchange Act and the applicable Exchange Act rules; records with no specified period are kept at least six years; everything is preserved in a format and media that complies with SEA Rule 17a-4.
    What it means for AI use:
    The duty attaches to the record, not the tool. Nothing in 4511 names AI — and nothing in it exempts AI. If an AI-assisted workflow produces something the rules treat as a record, 4511's make-and-preserve duty already covers it.
  2. 0217 CFR 240.17a-3 — records to be made

    What it says:
    Enumerates the records firms must create: blotters (a)(1), order memoranda (a)(6)–(7), confirmations (a)(8), associated-person records (a)(12), customer complaint records (a)(18), and evidence that advertisements, sales literature and other communications received principal approval (a)(20), among others.
    What it means for AI use:
    This is a list, not a net. It does not require making a record of every internal draft or every tool interaction — but if an AI workflow creates or modifies something on the list, that record must be made and must be complete, whatever produced it.
  3. 0317 CFR 240.17a-4 — records to be preserved, and how

    What it says:
    Sets the preservation classes and periods — six years for (a)-class records, three years for (b)-class, the first two in an easily accessible place — including (b)(4): originals of all communications received and copies of all communications sent (and any approvals thereof), including inter-office memoranda and communications, relating to its business as such. Paragraph (f) governs electronic systems: either a complete time-stamped audit trail permitting re-creation of an original record if it is modified or deleted, or a non-rewriteable, non-erasable format — plus filed undertakings, backup arrangements, readiness to immediately produce any record on request, and, where the non-rewriteable, non-erasable alternative is used, an audit system for accountability over inputting and modification.
    What it means for AI use:
    Two consequences. First, the communications class turns on 'relating to its business as such', not on the medium — an AI-drafted message that is sent is squarely in it. Second, whatever you classify as a record has to live in a system meeting (f); an application log is not automatically that system.
  4. 04FINRA Regulatory Notice 24-09 — the technology-neutral frame

    What it says:
    Reminds member firms that FINRA's rules — intended to be technology neutral — and the securities laws more generally continue to apply when firms use generative AI or similar technologies, and that a firm using such tools in its supervisory system should address technology governance, including model risk management, data privacy and integrity, and reliability and accuracy of the model, in its policies and procedures.
    What it means for AI use:
    The notice creates no new recordkeeping rule and names no new record category. What it removes is the hope that AI use sits outside the existing ones — depending on how a firm uses the technology, virtually every area of its regulatory obligations can be implicated.

Not every interaction is a required record

This is the line competing pages blur, in both directions. One camp implies every prompt is a regulated record — which drives firms toward keeping everything forever, drowning review teams and colliding with every minimisation duty they hold elsewhere. The other camp treats AI tools as outside the rules entirely — which Regulatory Notice 24-09 exists to refute. The accurate position sits between: the recordkeeping rules enumerate categories, and an AI interaction is a required record when, and only when, it produces or constitutes something in one of them. The five tests below make that determination per use case — and the determination itself, written and signed, is the artifact an examiner most wants to see.

  1. T1Does the AI interaction produce, or itself constitute, a communication sent or received relating to the firm's business as such?

    Yes →
    The communication is in the 17a-4(b)(4) preserved class — and note the class expressly includes inter-office memoranda and communications, so 'internal' alone is not an exit. An AI-drafted message that is sent to a client, or circulated internally as a business communication, is preserved with any approvals of it.
    No →
    Continue. Drafting scratch work that never becomes a communication is not automatically captured by (b)(4) — the next tests decide what else could reach it.
  2. T2Does the workflow create or modify a record 17a-3 requires the firm to make — an order memorandum, a complaint record, an approval record?

    Yes →
    The resulting record is required regardless of the tool that produced it, and it must be complete and accurate. If an AI system populates an order memorandum, the memorandum is the record; the obligation did not move into the chat window, but it did not weaken either.
    No →
    Continue. The 17a-3 list is enumerated, not open-ended — a use case that touches none of its categories creates no 17a-3 record.
  3. T3Is the AI tool itself part of the firm's supervisory or review process — for example, screening correspondence?

    Yes →
    Then the use sits inside the supervision obligations Regulatory Notice 24-09 discusses: policies and procedures addressing technology governance, model risk management, data privacy and integrity, and accuracy. Evidence of how the review operated belongs in the firm's books-and-records program.
    No →
    Continue. Most drafting and research assistance is not itself a supervisory function.
  4. T4Is the interaction none of the above — internal ideation, code assistance, research scratch work that never becomes a communication or a required record?

    Yes →
    Then no enumerated category automatically captures the interaction, and retention of it is the firm's own policy decision. Make that decision deliberately, write it down, and remember that a litigation hold can still reach material no retention rule ever required you to keep.
    No →
    Then one of the earlier tests fired — treat the output as the record it is.
  5. T5For everything you did classify as a record: does it land in a system that meets 17a-4(f)?

    Yes →
    The design is coherent: required records in a conformant store — audit-trail alternative permitting re-creation, or non-rewriteable, non-erasable format — with the undertakings, backup arrangements, and immediate-production readiness paragraph (f)(3) requires.
    No →
    The classification work is undone by the storage. A required record in a general-purpose application log is a finding waiting to be written.

From obligation to log design

The tests produce a two-plane design. Interactions classified as records get full-content capture into a store that meets 17a-4(f), on the retention clock their class sets — that is the "full" logging mode, chosen deliberately for exactly the workspaces that need it, as the zero retention and audit logs guide maps. Everything else runs as minimal as policy allows, with the audit plane recording that requests happened. The record shape is the audit log schema template — attribution, model identity, content mode, hashes — and the clocks are named retention classes per record type, built with the prompt log retention crosswalk and its worksheet. This page owns the classification step; those pages own the fields, the periods, and the modes.

The examiner checklist

Nine asks, phrased the way they arrive: as evidence to produce. Each carries the build note that makes producing it a query instead of a project.

  1. 01Where does generative AI touch your business?

    Evidence to produce:
    A current inventory naming each AI surface, the routes into it (chat interface, API, integrations), and the business processes it serves.
    How to build it:
    The access_path and model_id fields of the audit log schema, aggregated — coverage across every route is what makes the inventory credible.
  2. 02Which AI interactions do you treat as records, and who decided?

    Evidence to produce:
    A written determination applying the record tests above per use case, with the date, the owner who signed it, and its review cycle. This single document is what separates a considered program from an accidental one.
    How to build it:
    The five record tests on this page are the template; the recordkeeping owner signs the output.
  3. 03Show me a sample record with full attribution.

    Evidence to produce:
    A produced record carrying the authenticated identity that made the request, the timestamp, the model that served it, and the content — not a shared API key that makes every request look identical.
    How to build it:
    actor_id, timestamp, model_id, and the content fields of the schema template.
  4. 04How does your storage meet 17a-4(f)?

    Evidence to produce:
    A description of the electronic recordkeeping system naming which (f)(2) alternative it uses — complete time-stamped audit trail permitting re-creation of the original record, or non-rewriteable, non-erasable format — plus the filed undertakings, the backup arrangements, and, where the non-rewriteable, non-erasable alternative is used, the audit system for accountability over inputting and modification.
    How to build it:
    This is the record store, not the activity log. The audit plane records that requests happened; the designated store preserves the records themselves. Keep the two distinct on purpose.
  5. 05What is your retention schedule, per record class?

    Evidence to produce:
    A schedule citing the applicable 17a-4 period per class — six years for (a)-class, three for (b)-class, first two easily accessible — and the FINRA Rule 4511 six-year default where no period is specified.
    How to build it:
    These become named retention_class values; the retention crosswalk's worksheet builds the schedule row by row.
  6. 06Show me AI-drafted communications that were actually sent.

    Evidence to produce:
    The sent communications, preserved in the designated store with any approvals of them — including evidence of principal approval where 17a-3(a)(20) requires it.
    How to build it:
    Capture the final artifact regardless of logging mode: whatever the drafting exchange's classification, the sent communication is unambiguous.
  7. 07How is AI use supervised?

    Evidence to produce:
    Written supervisory procedures addressing generative AI in the terms Regulatory Notice 24-09 uses — technology governance, model risk management, data privacy and integrity, reliability and accuracy — plus the review records showing the procedures operate.
    How to build it:
    policy_decision events (allowed / blocked / flagged) land in the same trail as everything else, so supervision evidence is a query, not a project.
  8. 08Produce all AI activity for a date range. Now.

    Evidence to produce:
    A timed, date-ranged, machine-readable export — the rule's own standard is being ready at all times to provide, and immediately provide, any record on request.
    How to build it:
    export_batch_id records that the production happened. Run the drill before an examiner runs it for you.
  9. 09What stops disposal when a hold lands?

    Evidence to produce:
    A documented hold procedure naming who declares it and how scheduled disposal mechanically stops for the records in scope, plus one test showing it worked.
    How to build it:
    The retention crosswalk's worksheet includes the hold-suspension test; a hold that is only an email does not stop a cron job.

How PrivateStack fits this program

A PrivateStack workspace records each request with user identity, timestamp, model identity, and request context; audit logs export date-ranged and machine-readable, and exportable audit records support a customer's FINRA/SEC books-and-records program — they inform it, they do not replace the firm's designated record store or its own recordkeeping determinations. The honest limits, stated plainly: the record/non-record classification is the firm's decision, made with its counsel and recordkeeping owner, and no platform can make it; nor does any product feature by itself satisfy a recordkeeping obligation. What a platform owes you is the mechanics — attribution on every request, coverage across every access path, separate clocks, clean export. The full control set is on the security page, and the audit trail requirements checklist covers the ten controls examiners ask about across every framework.

Questions people actually ask

Is every generative AI chat automatically a FINRA record?
No — and pages that claim otherwise are overreaching. The recordkeeping rules enumerate categories: communications relating to the firm's business as such (17a-4(b)(4)), the records 17a-3 requires firms to make, and the preservation classes of 17a-4. An AI interaction is a required record when it produces or constitutes one of those things — an internal brainstorm that never becomes a communication is not automatically captured. What every firm does need is a written determination of which of its AI uses fall where, because the classification, not the tool, is what an examiner will probe.
Does FINRA have AI-specific recordkeeping rules?
No. Regulatory Notice 24-09 says the existing rules — intended to be technology neutral — and the securities laws generally continue to apply when firms use generative AI in the course of business. The notice creates no new record category and cites no new retention period; its effect is to close the argument that AI use sits outside the rules that already exist.
An associated person drafts a client email with AI. What must be kept?
The sent communication, unambiguously — it is in the 17a-4(b)(4) preserved class, with any approvals of it, and with principal-approval evidence where 17a-3(a)(20) applies. Whether the drafting exchange itself is also retained is the firm's documented determination: (b)(4) reaches communications relating to the firm's business, including inter-office ones, but a private drafting session with a tool is not self-evidently a communication sent or received. Decide it, write it down, and apply it consistently.
Can our required AI records live in the same log as everything else?
They can only if that system meets 17a-4(f), and most application logs do not: paragraph (f) demands either a complete time-stamped audit trail that permits re-creation of an original record if it is modified or deleted, or a non-rewriteable, non-erasable format — plus filed undertakings, backup arrangements, immediate production on request, and, for firms on the non-rewriteable alternative, an audit system over inputting and modification. The cleaner design is two planes: required records in a conformant store, and the activity log recording that requests happened across everything else.
Can we run zero-retention AI tools and still meet books-and-records duties?
Yes, and the separation is the design: route what the rules require into the designated record store on its full retention clock, and keep every other plane — provider, gateway, scratch conversations — as minimal as you like. Zero retention is a statement about content planes; the books-and-records duty is a statement about specific records. The zero-retention-and-audit-logs guide maps that split in detail.

Comparing how a governed workspace and a direct model API each handle these obligations? The closed-API comparison covers both honestly.

Primary sources

Every statement above traces to one of these publications. Read the instrument before any vendor's interpretation — including ours.

  • FINRA Rule 4511General requirements — books and records: make and preserve; six-year default where no period is specified; format and media that complies with SEA Rule 17a-4.
  • FINRA Regulatory Notice 24-09Reminds member firms that FINRA's technology-neutral rules and the securities laws continue to apply when firms use generative AI, and discusses supervision, technology governance, and model risk when such tools are used.
  • 17 CFR 240.17a-3Records to be made by certain exchange members, brokers and dealers — the enumerated categories, including blotters, order memoranda, confirmations, complaint records, and communications-approval records.
  • 17 CFR 240.17a-4Records to be preserved — the six- and three-year classes, the (b)(4) communications class including inter-office memoranda relating to the firm's business as such, and the paragraph (f) electronic recordkeeping requirements with their undertakings, backup, and immediate-production duties.