The word is doing two jobs, and both of them are legitimate. That is what makes this hard to see and impossible to unsee.
Start with the workflow, because the abstraction is what gets this dismissed.
A wealth advisor at a mid-sized dual-registrant opens an account for a new client. The firm has put an agentic workflow in front of the custodian's digital account-opening rails. An intake agent assembles what the firm already holds about the client — meeting notes, email threads, CRM records, uploaded documents. A profile agent prefills the application: registration type, investment objectives, stated risk tolerance, funding source, beneficiary designations. A validation agent sweeps the draft for the defects that would come back not-in-good-order and clears them. The advisor opens the draft, reads it, and clicks approve. The application is submitted.
This is not a speculative architecture. In August 2026 a vendor announced general availability, after pilots, of exactly this workflow on a major custodian's advisor platform: an agent that assembles client data from meetings, email, CRM and documents, completes the custodian's digital account-opening workflow, and returns a draft for advisor review. I am citing that announcement as the publicly announced template for an agent executing a regulated workflow on a custodian's rails with a human review step — not as evidence about how any firm's identity layer behaves, which I have not inspected and cannot see.
Now the supervision question, asked in the register a firm's compliance department actually uses:
Which registered principal reviewed this, and where is the writing?
The record answers immediately, and its answer is a service identity. Call it svc-wealthplatform-prod. Every hop executed under it. It holds an entitlement to the custodian's submission endpoint. It was provisioned through a change record with a named requester and a named approver. It has an owner in the configuration management database. All of that is real, and none of it is responsive.
Here is the part that makes this different from an ordinary logging complaint. The record does not fail to name a principal. It names one. In the vocabulary of every identity system in the estate — the directory, the token service, the cloud provider's authorisation layer, the agent framework's own documentation — a principal is any authenticated subject: a person, a service, a workload. svc-wealthplatform-prod is a principal. The sentence "a principal performed this action" is true, checkable, and emitted automatically.
In FINRA's rulebook, a principal is something else entirely: a person, associated with the member, registered in a principal capacity after passing a principal qualification examination, carrying supervisory authority for a named type of business. The two definitions share a word and share nothing else. One is a property of an authenticated session. The other is a licensing status held by a human being who can be sanctioned.
The advisor, the firm, the four-hop chain, the service principal name and the review sequence above are a constructed illustration, assembled from patterns documented in public vendor announcements, published regulatory material and platform documentation. It is not a report of any real firm, client, account, incident or deployment, and no part of this piece describes client work. The vendor announcement referred to is cited only for what it announces.
The objection, stated properly
Two responses land immediately, and they come from different rooms. The first comes from the firm's own compliance function and it is the better one. The second comes from the regulatory reading and it is the more comfortable one. Both deserve to be put at their strongest before either is answered.
The compliance response goes like this. There is a human in this loop. The advisor read the draft and approved it before anything was submitted. Nothing was executed autonomously. The firm's written supervisory procedures already describe how new accounts are opened, who reviews them, and on what cycle; the agents changed how the draft got assembled, not who signs off. Adding machinery to a step that already has a human control is solving a problem the firm does not have, and there is a version of this argument that reduces to consultants inventing work.
The regulatory response is shorter and harder to dismiss. FINRA has not made a rule about agents. Regulatory Notice 24-09 is guidance and says on its face that it creates no new legal or regulatory requirements. The GenAI section of the annual oversight report is a description of examination findings and effective practices, written in the language of things firms may want to consider. The January 2026 piece on AI agents is a blog post — it is filed as one, it reads as one, and it carries a disclaimer stating it creates no new obligations and relieves firms of none. Three documents in nineteen months, none of them binding, none of them specifying a control. Build the workflow, keep the human review, revisit when someone writes a rule.
I want to concede both at full strength, because each is right about something, and in each case the thing it is right about is not the thing at issue.
The advisor is real, and the advisor is the wrong category of person. Rule 3110 is built on a distinction between two kinds of associated person. Registered representatives conduct the business. Registered principals supervise it. The whole point of the second category is that it is not the first: supervision that consists of the person doing the work approving their own work is the arrangement the regime exists to prevent. In the illustration, the one human act in the chain is performed by a registered representative on their own client's application. That is a real control and it is a first-line control. It is not principal review, and describing it as though it were is where the record and the rulebook quietly part company.
The writing is required to be a writing, and a click is not one. Rule 3110(b)(2) asks for review by a registered principal, evidenced in writing, of transactions relating to the member's investment banking or securities business. Three elements, not one: a reviewer of a specified category, an item reviewed, and evidence in written form. An approval event in an application carries the item and a timestamp. It does not carry a reviewer of the required category, and it does not carry a writing in any sense the word is used in that rule — it carries the fact that a button was pressed. A firm can of course produce a writing afterwards, and firms do. That writing is composed by a person about a system, after the fact, and the system cannot contradict it.
"No rule yet" is a true statement that points the opposite way. It is entirely correct that none of the three FINRA documents is a rule. It does not follow that no rule applies. Rule 3110 is a rule, it is in force, it is technology-agnostic on its face, and it attaches to the types of business in which the member engages rather than to the tools used to conduct them. The absence of agent-specific guidance does not suspend the supervision requirement; it removes the description of what satisfying it looks like when part of the business is conducted by a chain. That is a specification gap, not an obligation gap, and the two have opposite consequences for what a firm should do now.
Which is the argument compressed into one paragraph. The rule that binds is old, general and person-shaped. The material that describes agents is new, specific and non-binding. Nothing in between tells a firm how to make the second satisfy the first, and the interval in which that is true is the interval a firm is operating in.
What FINRA has actually said, characterised precisely
Being wrong about the status of these documents is expensive, because the people this argument is aimed at know exactly what they are. So: three objects, three kinds, in publication order.
Regulatory Notice 24-09, 27 June 2024 — a notice. It reminds firms that FINRA's rules are, in its phrasing, intended to be technology neutral, and that they continue to apply when a firm uses generative AI. It addresses what a firm using generative AI inside its supervisory system needs to attend to: technology governance, model risk, data integrity, and the reliability and accuracy of the AI model. And it says, in terms, that it does not create new legal or regulatory requirements. A notice is FINRA telling firms how existing obligations land on a new fact pattern. It is authoritative as an interpretation and it is not itself a rule.
The 2026 Annual Regulatory Oversight Report, GenAI section, published 9 December 2025 — an examination-program report. This is the document that tells firms what FINRA's examiners have been finding and what effective practices look like across the membership. Its GenAI section is where agent-shaped risks first enter FINRA's examination vocabulary, and its register is discretionary throughout: firms may want to consider, some firms have found it effective to. That register is not a hedge, it is the genre. An oversight report describes the examination programme; it does not create the standard the programme measures against.
"Emerging Trend in GenAI: Observations on AI Agents," 27 January 2026, with a companion "Types of AI Agents" reference — a blog post. This is the one that matters most and carries the least formal weight, and both halves of that sentence are true. It is a regulator writing about agents specifically, defining them as systems that perform and complete tasks autonomously, without human intervention, and setting out the risk areas it sees: autonomy, scope and authority, auditability, data sensitivity, and domain knowledge. It also carries the plainest disclaimer of the three — that it creates no new legal or regulatory requirements and relieves firms of no existing obligations. Anyone who presents this to a compliance officer as a requirement will be corrected inside a minute, and rightly.
The figure draws four of the five risk areas rather than all of them, and the omission is deliberate: autonomy, scope and authority, auditability and data sensitivity are properties of what the system is permitted to do, which is what this piece is about. Domain knowledge is a property of who is competent to judge the output, which is a different problem — and, as it happens, the one place where FINRA's existing architecture already has an answer, because designation under Rule 3110(a)(2) is precisely a mapping from a type of business to a person qualified to supervise it.
Read the three documents as a sequence and the shape is unmistakable. Each is more specific than the last about the technology. None is more specific than the last about the control. The agents note describes, in supervisory vocabulary, a system acting beyond the user's actual or intended scope and authority — and never names Rule 3110, never names the registered principal, and never says what a reasonably designed supervisory system looks like when part of the business is conducted by a chain of agents. That is not a criticism of the note. A blog post is not where a control specification goes. It is an observation about where the specification currently is, which is nowhere.
One boundary marker, because a large share of the firms this describes are inside bank holding companies. For a bank-affiliated broker-dealer, the April 2026 revised interagency model risk management guidance — OCC Bulletin 2026-13, the Federal Reserve's SR 26-2, the FDIC's parallel issuance, one shared text — places generative and agentic AI models expressly outside its scope in footnote 3, while the same footnote returns the determination of appropriate governance and controls to the institution. That is a deferral rather than an exemption, and it points the same way this argument does: the framework that would have specified the controls has been withdrawn and the responsibility for determining them has not. It also has nothing to say about FINRA supervision, which is a separate regime with a separate reviewing officer, and conflating the two is a mistake a supervisory reader will catch.
The mechanism: the designation has no target
Everything above is framing. This section is the claim, and it is a claim about what exists in the record rather than about what anyone neglected to write down.
Rule 3110 has three moving parts and they are meant to interlock. The member designates an appropriately registered principal with supervisory authority for each type of business in which it engages. The member establishes and maintains written supervisory procedures covering those types of business and the activities of its associated persons. And the member's system provides for review by a registered principal, evidenced in writing, of the transactions its business produces. Designation, procedure, review. Each of the three refers to the other two.
Now push an agent chain through it, one part at a time.
Designation assumes a target that can be designated. Firms have designated principals for branch offices, for options business, for municipal securities, for research, for advertising review. The designation attaches to a type of business and a person who is qualified to supervise it. There is no designated principal for the intake agent, and the reason is not oversight — it is that the intake agent is not a type of business, and the type of business it participates in already has a designated principal who has never been told that part of that business is now conducted by a chain running as a service account. The designation exists; the map from the designation to what actually happens has a hole in it.
The procedures cover the types of business, and the types of business have quietly changed shape. Rule 3110(b)(1) asks for procedures covering the types of business in which the member engages. When a firm introduces an agentic workflow, it does not usually think of itself as engaging in a new type of business, and in the ordinary sense it has not. But the procedures are supposed to describe how the work is supervised, and the work is now assembled by software that reads client communications, populates a customer profile, and clears defects before a human ever sees the draft. If the procedures still describe a process in which an operations associate assembles the application, the procedures now describe something that does not happen.
Review is meant to be review of an item by a person of a category, and only the item survives. Take the approval event apart. It has an item — the draft application. It has a timestamp. It has an actor, and the actor is a registered representative. It has no writing beyond its own existence. Compare that against what the rule asks for and exactly one of the three required elements is present. This is worth stating flatly because it is the most checkable claim in this piece: the record produced by the workflow can populate the item, and cannot populate the reviewer category or the writing, and no configuration of the workflow as described changes that.
There is a deeper version of the same point, and it is the one that survives every attempt to fix the surface. FINRA's own framing of agent risk is action beyond the user's actual or intended scope and authority. To test that proposition against a record, you need two things: what the agent did, and what its scope and authority were. The first is recoverable — it is a sequence of invocations, and each invocation is an event that the code causing it can observe as it happens. The second is not recoverable, because in the prevailing pattern nothing ever constructed it. Authority moves between the agents as ambient context: one session authenticated at the boundary, one credential built at start-up, one system prompt carried forward. Nothing is passed at any handoff that says what the receiving agent may do, narrower than what the sending agent could. So the scope the note asks you to compare against was never written down anywhere, and it was never written down because it never existed.
This is why it is not a missing field. A missing field implies a value that nobody recorded. Here there is no value. The only principal identifier it would be correct to attach to the submission span is the same one attached to every other span in the chain, which therefore distinguishes nothing. Writing it at four hops does not produce four facts. It produces one fact copied four times, and the copies are silent about everything that happened in between them.
And it is why the fix is not more telemetry. Turn sampling off, retain at full fidelity, keep every tool argument and every intermediate. The chain is now perfectly recorded and the supervision question is exactly as unanswerable, because the fidelity is fidelity to a call graph. Call graphs are recoverable because their edges are invocations. An authority graph is not recoverable, because its edges would be grants, and no grant was created at any hop.
The supervision question, asked against the record that exists
Three files, in the order a compliance examiner would meet them. The first transcribes the shape of the record an agentic account-opening workflow actually produces. The second asks the supervision question against it, and the type system makes the honest answer unavoidable — the return type has no variant carrying a registered principal, because no field on the record could ever produce one. The third writes the three elements Rule 3110(b)(2) asks for as a type, and shows which of them the record can populate. Nothing here is a proposed design; the third file is a requirement read back as a data structure.
Written from the shape of a conventional agent trace plus the approval event the application emits alongside it. Note where the principal sits: on the run rather than on the hop, because every hop executes under the identical value. Modelling it per hop would invite a reader to believe four facts were recorded where one was.
/** An identity-layer principal. In every directory, token service and agent framework
* in the estate, this word covers services as readily as people. That is not a bug in
* those systems; it is what the word means there. */
export interface ServicePrincipal {
readonly kind: "service";
readonly id: string; // e.g. "svc-wealthplatform-prod"
/** Owner of record in the CMDB. An owner is not a reviewer of any given item. */
readonly ownerOfRecord: string;
readonly entitlements: readonly string[]; // standing capability, not per-action grant
}
/** An associated person conducting the business. The supervised category. */
export interface RegisteredRepresentative {
readonly kind: "registered-representative";
readonly crdId: string;
readonly displayName: string;
}
/** An associated person registered in a principal capacity, carrying supervisory
* authority for a designated type of business. The supervisory category. Declared
* here so the absence of any value of this type below is visible rather than implied. */
export interface RegisteredPrincipal {
readonly kind: "registered-principal";
readonly crdId: string;
readonly displayName: string;
/** The type of business for which this person is designated. */
readonly designatedFor: string;
}
/** One hop. Every field is an observation of an invocation that happened. */
export interface Hop {
readonly spanId: string;
readonly parentSpanId: string | null;
readonly component: "intake" | "profile" | "validation" | "submission";
readonly startedIso: string;
readonly durationMs: number;
/** Present only where the hop reached a system outside the firm. */
readonly effect?: { readonly endpoint: string; readonly method: "POST" | "PATCH" };
}
/** The human act in the chain. Note the actor's type. */
export interface ApprovalEvent {
readonly draftId: string;
readonly actor: RegisteredRepresentative;
readonly approvedIso: string;
/** What the application stored. There is no narrative field, because the interface
* did not ask for one and the workflow did not produce one. */
readonly uiAction: "approve";
}
export interface AccountOpeningRun {
readonly correlationId: string;
/** One value, for the whole run. This is the record's answer to "which principal". */
readonly principal: ServicePrincipal;
readonly hops: readonly Hop[];
readonly approval: ApprovalEvent;
readonly boundarySession: { readonly sessionId: string; readonly authenticatedIso: string };
}All three files are written to be read rather than deployed. The first two describe a constructed illustration. The third paraphrases a requirement into a type and is a reading aid, not a compliance artefact; anyone building against Rule 3110 should read the rule text rather than this transcription of it.
Three jurisdictions, approaching the same hole from different ends
The gap is not a peculiarity of United States supervision. What differs across jurisdictions is which half of the structure the regulator has already specified, and the pattern is almost neat enough to be suspicious.
In the United States, FINRA has the reviewing officer and not the AI assignment. The registered principal exists as a category in binding rule; the designation, the written procedures and the review-evidenced-in-writing requirement are all in force. What is missing is any statement of how that architecture is meant to close over a chain of agents — which is the specification gap the three documents above leave open.
In India, SEBI has the AI assignment and not the reviewing officer. Regulation 16C, notified on 10 February 2025, places responsibility for the output of artificial intelligence and machine learning tools on the regulated entity itself — whether the tools are built in-house or obtained from a third party — and extends the same responsibility to investor data handled by those tools. That is a binding assignment of responsibility for AI output, which the United States securities regime does not have in equivalent terms. What it assigns responsibility to is the entity, not an officer. The consultation paper of 20 June 2025 proposes governance guidelines that would go further, including designated senior management oversight with technical competence; as a consultation it proposes rather than requires, and no final instrument had issued as of the date on this piece.
In the GCC, neither half is specified, and the honest thing to say is that there is nothing to cite. I could not verify a securities-specific AI instrument in any Gulf jurisdiction. What exists is posture rather than instrument: the Dubai Financial Services Authority publicising the integration of agentic AI across its own supervisory operations, and the DIFC's stated ambition to become an AI-native financial centre. Those are wire-reported positions, not consultations with numbers on them. The absence is the finding, and I would rather report it as an absence than dress a policy speech up as an anchor.
That last point is worth making carefully, because it is the commercially convenient one and convenience is a reason to distrust it. The three regimes are not equivalent and nothing built for one automatically satisfies another. What is true is narrower: the object each of them is missing is the same object — a record of who authorised what, bounded, at the moment the authority passed — and a firm that builds it once has the material each regime asks for in its own vocabulary. That is an argument about the shape of the artefact, not a claim about legal sufficiency anywhere.
The limits of the argument, and what would falsify it
Four things could be wrong here. They are worth naming at full strength rather than in the weakened forms that are easy to answer.
The claim is about a prevailing pattern, not about every deployment. I am describing how authority propagates in the agent frameworks and reference architectures currently in general use. A firm that mints a distinct credential at each hop, bounded to the operation at hand and naming its parent, already holds the object and this piece does not describe it. I have not found such a deployment described in any primary source, and I have not surveyed the industry. One public, checkable counterexample would confine this piece to a description of what the rest of the field is doing, which is a fair outcome.
The announced workflow is an announcement, and I have not seen inside it. The August 2026 account-opening launch is cited as a template because it is publicly described and because a custodian accepting an agent on its own regulated rails is a genuine platform-risk signal. It is a vendor press release: general availability after pilots, with no named production firms and with the efficiency figures — a large reduction in not-in-good-order rates, hours returned per advisor per week — reported by the vendor rather than measured by anyone independent. I do not know how its identity layer works. If it mints per-action authority naming a human reviewer, then it is an existence proof against my claim rather than an illustration of it, and I would want to know.
FINRA may specify the control, and reasonably soon. A regulator that publishes a dedicated note on AI agents thirteen months after its generative AI notice is not a regulator that has stopped thinking about it. If FINRA issues guidance describing what a reasonably designed supervisory system looks like over agentic workflows, a firm that built the evidence layer early merely built it early — the cheapest of the ways to be wrong. The asymmetry is the whole practical argument: building early is a design constraint absorbed while the workflow is small; building late is retrofitting attribution into chains already carrying client business, which is the same problem as reconstructing it from logs.
The strongest falsifier is behavioural, and I cannot close it. If examiners in practice accept the advisor's approval plus a written procedure describing the workflow as satisfying principal review, then the gap has no supervisory consequence and this reduces to a preference about the quality of evidence. I have no basis for asserting that examiners reject it and I am not going to invent one. What I can point at is the text: three elements in the rule, one of them present in the record; a designation requirement whose target is unclear; and a regulator that has now named action beyond intended scope and authority as a risk it is watching for.
One further limit, because it cuts against how this argument is usually deployed commercially. Nothing above shows that a firm should stop building agentic workflows, and nothing above establishes that the absence of an authority object has caused a loss anywhere in this sector. I am not aware of a published enforcement action or incident turning on this failure; if I were, it would be in the sources rather than in a paragraph like this one. The claim is about what a firm can demonstrate when asked, which is narrower and more testable than a claim about what will go wrong.
What an answer would have to be
This is the teardown. Building the answer here would fold two pieces into a worse one, so I will name the properties and stop.
- The grant is an object created at the handoff. Not a condition inherited from the process environment, and not an identifier stamped onto a span afterwards. Something is constructed at the moment authority passes, or there is nothing for a reviewer to review.
- It is bounded more tightly than its parent, and it names its parent. A grant identical to its parent is the same grant and carries no information. If the chain does not narrow, the chain is decorative.
- It is reviewable before it is exercisable, for the classes the firm designates. This is the property the securities regime forces and no other sector does as sharply. A record produced after the fact is evidence of what happened. A gate is evidence that a person decided, and the rule asks for the second.
- It terminates in a person of the right regulatory category, and the terminal link is the load-bearing one. Every other property can be satisfied by service identities delegating to one another indefinitely. The regime does not want a well-formed chain; it wants the chain to end in someone who is registered, designated, and answerable — and for the classes that require principal review, a registered representative at the root is not the right terminal.
It also has to survive two conditions a clean-room design tends to assume away. Part of the chain runs on someone else's rails — a custodian's platform, a vendor's hosted agent — so the record has to cross a boundary the firm cannot see inside. And review has to be practical at production volume, which means the design has to specify what gets reviewed item by item and what gets sampled, or the gate becomes a rubber stamp and the firm has bought worse evidence at higher cost.
None of that is exotic, and the securities regime is unusual in already containing the human category the design has to terminate in. What has not been done is the assembly: grants that are objects, review that is a gate, and a mapping from a firm's written supervisory procedures onto both, in a form a firm can operate and an examiner can walk through. That construction is the subject of the companion to this piece, "Per-action grants a registered principal can review."
The reason to do it before the specification arrives is the same reason the absence of a rule is a weaker comfort than it sounds. Whatever eventually gets written will be written by people reading what the industry built while nothing was written. That interval is open now, and it is the only period in which what a firm builds influences what it is later measured against.