Regulated marketing has often treated approval as a destination. A communication enters a queue, an authorised principal reviews it and a timestamp shows that it passed through control.

FINRA is asking whether that model still matches how communications are produced.

On 9 July 2026, the US broker-dealer self-regulatory organisation published a proposal to modernise Rule 2210, which governs communications with the public. Its central change would replace the prescriptive requirement for a registered principal to approve most retail communications before use with a supervisory model that allows firms to determine which communications require pre-use approval according to risk. The comment period closes on 11 September 2026.

The proposal responds directly to social media, generative AI and the growing volume and variety of communications firms produce. Yet its significance extends beyond technology. It would shift the centre of control from an approval attached to every asset towards the design and operation of the supervisory system surrounding it.

Under that model, firms would need to show more than who approved a communication. They would need to explain why it followed that review route, which factors informed the decision and whether the wider system was implemented as written.

The proposal changes the control model, not the communications standard

Rule 2210 currently divides written communications into retail communications, correspondence and institutional communications. A retail communication is one distributed or made available to more than 25 retail customers within a 30-day period.

Subject to specified exceptions, an appropriately qualified registered principal must approve each retail communication before the earlier of its use or filing with FINRA’s Advertising Regulation Department. Correspondence and institutional communications can already be supervised through more flexible written procedures.

FINRA’s proposal would bring retail communications closer to that risk-based model. Member firms would establish written procedures appropriate to their business, size and structure to determine which categories of retail communication require principal pre-use approval.

Those procedures would still have to be reasonably designed to ensure compliance. Where a firm did not require every communication to be approved before use, its system would need to cover staff education and training, documentation of that training, surveillance and follow-up. The firm would also have to retain evidence that its procedures had been implemented and carried out.

The substantive standard would remain. Communications must still be fair and balanced and cannot contain false, exaggerated, unwarranted, promissory or misleading claims. A risk-based route would not relieve the firm of responsibility for the eventual communication.

Notice 26-14 contains other proposed changes. It would remove the regulatory distinction between static and interactive social media, modify filing requirements for new firms and certain performance comparisons, and replace detailed provisions concerning past specific recommendations with a broader fair-and-balanced standard. This Note concentrates on the supervisory change because it has the widest implications for how marketing and compliance teams organise their work.

Once review routes differ, routing becomes a compliance judgement

A universal approval queue is blunt, but it is relatively easy to describe. Everything within scope goes to a principal before publication.

A risk-based system is more discriminating and more demanding. The organisation must define what changes the level of scrutiny.

FINRA proposes eight non-exhaustive factors. They include the nature and complexity of the product or service, the experience of the communication’s preparer, whether it makes a recommendation, whether it promotes a third-party or affiliate product, whether it is tailored to a particular audience, the use of performance data or comparisons, the distribution method and the firm’s previous history of communication concerns.

The factors describe a judgement that cannot be made from the final copy alone.

A routine communication based on an established template may involve a familiar product, trained employees, no recommendation and no performance claim. A finfluencer-led campaign promoting a complex product to a defined audience may involve compensation, limited subject expertise, performance comparisons and a distribution channel with significant reach. Both may be retail communications, but their supervisory profiles are materially different.

Once every communication no longer follows the same checkpoint, the route itself becomes part of the decision record.

That route cannot depend entirely on an individual marketer recognising an issue or an experienced compliance officer recalling a similar case. The firm needs a shared method for identifying the relevant facts, applying its thresholds and escalating matters that require principal review.

This makes classification an important part of the marketing brief. Product, audience, channel, preparer, claims, evidence, distribution and previous concerns must be known early enough to determine the correct path. Sending a finished asset to compliance without that context would leave the reviewer reconstructing the same information the supervisory system is supposed to use.

FINRA’s data supports a more differentiated model

FINRA’s economic assessment shows the scale of the current process. Between 1 January 2023 and 31 December 2025, its Advertising Regulation Department reviewed 4,501 retail communications filed before first use and 172,898 filed after first use.

Twenty-four per cent of the pre-use filings were found to be non-compliant, compared with 10 per cent of post-use filings. These categories are not a like-for-like sample: communications subject to pre-use filing can carry different risks from those filed afterwards. The figures nevertheless support FINRA’s broader premise that communications do not present a uniform level of risk.

The variation is particularly visible among new firms. FINRA identified 1,295 first-year filings from 153 new members during the same period and found approximately 69 per cent to be non-compliant. Its proposal would therefore strengthen rather than relax the new-member filing period, beginning the one-year period when a firm makes its first filing rather than when its membership becomes effective.

Risk-based supervision should not mean sending less work through review because the queue is inconvenient. It should direct attention according to evidence about where harm and non-compliance are more likely.

That requires a feedback mechanism. The firm’s experience of corrections, complaints, regulatory findings, unreliable preparers and recurring product issues should change how later communications are classified. Without that connection, risk-based review becomes a static policy applied to a changing business.

Social media has outgrown the static-versus-interactive test

The current framework distinguishes between static social media content and interactive content. Static material has generally attracted pre-use approval, while real-time interactive communications may be supervised more flexibly.

FINRA acknowledges that this line has become difficult to apply. A post can remain on a profile like static content while also allowing immediate comments, sharing and engagement. The platform format says relatively little about the communication’s actual risk.

The proposal would remove that distinction and bring social media into the same risk-based assessment as other communications.

This is particularly relevant to finfluencer content. FINRA notes that the risks associated with an influencer can arise from their qualifications or conflicts of interest and persist regardless of whether the post is classified as static or interactive. Under the proposed factors, firms would consider the preparer’s experience, anyone paid to produce or endorse the content, the intended audience, distribution method and substance of the communication.

That is a more useful model for modern marketing. The same substantive claim can travel through a video, livestream, social post, email or app notification. A control system organised mainly around platform categories can miss the common risk running through them.

A system organised around the product, claim, audience and source of influence can follow the communication as its format changes.

AI sits on both sides of the supervisory system

Generative AI creates the practical problem that helped prompt the proposal. It can produce and adapt communications quickly, while the appropriate review treatment may depend on how those communications are distributed, whether they recommend or promote something and which customers receive them.

FINRA is clear that member firms remain responsible for communications regardless of whether they were generated by a person or an AI system. The substantive requirements are technologically neutral.

AI may also form part of the response. Notice 26-14 says generative AI tools can support a reasonably designed supervisory system provided they are vetted, tested and monitored. FINRA’s earlier AI guidance says firms should address technology governance, model risk, data privacy and integrity, reliability and accuracy when using AI within supervision. Those expectations apply whether a firm develops the technology itself or uses a third-party system.

For firms, this creates two distinct objects of control.

The first is the communication produced or adapted with AI. Its claims, evidence, audience and overall meaning still require appropriate assessment.

The second is the AI system used to classify, review or route that communication. A tool can make a fluent but incorrect assessment, apply generic rules without firm-specific context or fail to recognise that a model, product or internal policy has changed. An apparently consistent automated process can reproduce the same error across a large volume of work.

Governance therefore needs to cover which sources the system may use, which risk factors it evaluates, how its performance is tested, which decisions require human authority and what happens when a reviewer disagrees with its output. Model or configuration changes should trigger reassessment where they could affect the supervisory result.

AI should help assemble the evidence needed for judgement, resolve repeatable questions and direct genuine exceptions to the right specialist. Treating it as an invisible approver would weaken the very evidence-based system FINRA’s proposal requires.

Risk-based supervision depends on organisational memory

One of FINRA’s proposed factors is the firm’s or associated person’s history of communication concerns involving particular products, services or methods.

That turns previous experience into a supervisory input. A problem identified in one campaign should inform the treatment of the next comparable communication. A repeated correction may justify stronger pre-use review, revised training or a change to the approved claim set. A long record of dependable use may support a more efficient route for genuinely routine material.

Most firms hold some of this knowledge already, but not necessarily in a reusable form.

Policies contain formal requirements. Approval systems show that an asset passed. Emails may contain the reasoning. Monitoring tools capture later issues. Experienced reviewers remember which products, representatives and claims tend to create difficulty. When those sources remain disconnected, the next decision-maker cannot reliably apply what the organisation has learned.

A useful supervisory record should preserve the communication’s risk factors, the route selected, the reason for that route, any evidence or previous decisions relied on, the people responsible and the outcome of subsequent surveillance. It should also identify what would invalidate the conclusion.

That last point matters because precedent without context can create false confidence. An earlier approval may have depended on a different audience, product feature, evidence base or distribution method. Reusable judgement should give the next reviewer a better starting point without converting an old decision into a permanent permission.

This is organisational intelligence in practical form: connecting formal requirements, company-specific interpretations, previous decisions and observed outcomes so that they can inform the work taking place now.

What marketing and compliance teams should prepare now

Notice 26-14 remains a proposal, and the final approach may change. Firms do not need to behave as though the amendments have already taken effect. They can, however, use the consultation to examine whether their current processes could support a credible risk-based model.

Define the risk taxonomy and decision rights

A firm should be able to describe which communication characteristics change the review route, who may make that classification and which combinations require principal pre-use approval.

The categories need enough precision to guide real decisions. Labels such as low, medium and high risk are of limited value unless teams know what evidence moves a communication between them.

Decision rights matter equally. Marketing may provide the product, audience and channel information, but should not be expected to resolve an unfamiliar regulatory interpretation. Compliance may set thresholds and approve exceptions, while an appropriately qualified principal retains authority for categories requiring principal review.

Put supervisory information into the brief

The proposal’s risk factors should be available before the work reaches final approval.

The brief or workflow can capture the product and service, intended audience, distribution method, presence of a recommendation, performance information, third-party involvement and identity of anyone preparing or endorsing the communication. Relevant evidence and previous decisions should travel with the asset.

This improves both speed and decision quality. Routine work can follow an established path, while reviewers receive enough context to concentrate on the issues that genuinely require judgement.

Record the reason for the route and feed outcomes back

An approval stamp shows the result of a process. A risk-based system also needs evidence of how the process selected that result.

The record should show why pre-use approval was required, why a lower-risk route was permitted or why an exception was escalated. Surveillance findings, customer complaints, regulatory feedback and recurring corrections should then inform future classifications, procedures and training.

Without that feedback loop, the firm can demonstrate that it designed a supervisory system but not that the system learns from its performance.

Govern AI as part of the system

Firms considering AI for generation, review or supervision should separate automation of routine activity from delegation of regulatory judgement.

Testing should reflect the actual products, claims, audiences and policies the system will encounter. Firms need a defined route for disagreement, correction and escalation, with changes to the model, data sources or configuration assessed for their effect on supervisory outcomes.

The objective is not an AI tool that produces more approvals. It is a better-informed supervisory process that directs human expertise towards the decisions where it carries the greatest value.

Less pre-use approval would demand better supervision

FINRA’s proposal may reduce the number of communications requiring principal approval before use. That does not make it a deregulatory shortcut.

A firm relying on a risk-based model would need to define its categories, train its people, monitor adherence, preserve evidence and show that its controls responded to experience. FINRA acknowledges that this could involve significant implementation and ongoing costs, even where it later reduces operational burden. Firms would also remain free to retain universal pre-use approval where they consider that approach more appropriate.

The current model asks whether a communication passed through the prescribed checkpoint. The proposed model would ask a broader question: was the supervisory system reasonably designed, was the communication treated according to that system and can the firm prove both?

For marketing leaders, the opportunity is to stop treating every asset as though it presents the same regulatory problem. For compliance leaders, the responsibility is to make the distinctions dependable rather than informal.

The strongest firms will not simply review fewer communications. They will know which work requires deeper scrutiny, make the supporting reasoning visible and retain what each decision teaches the organisation.

What teams need to know

What is FINRA Regulatory Notice 26-14?

Regulatory Notice 26-14 is a request for comment published by FINRA on 9 July 2026. It proposes changes to Rule 2210 covering the supervision, filing and content standards for communications with the public. The comment period closes on 11 September 2026.

Has FINRA Rule 2210 changed?

No. Notice 26-14 is a proposal, not an adopted amendment. Firms remain subject to the current version of Rule 2210 unless and until changes are completed through the applicable rulemaking process.

Who does FINRA Rule 2210 apply to?

Rule 2210 applies to FINRA member firms and their associated persons, principally US broker-dealers. It should not be treated as a general rule for every investment adviser or financial services company, although dually registered firms may operate under overlapping broker-dealer and investment adviser requirements.

Would principal pre-use approval disappear?

Not entirely. Firms would establish written procedures determining which categories require principal approval before use, based on their business and relevant risk factors. The proposal would preserve mandatory pre-use principal review for retail research reports, while firms could retain broader pre-use approval where appropriate.

How would the proposal affect social media?

FINRA proposes removing the distinction between static and interactive social media content. Firms would instead apply the wider risk-based factors, including the channel, audience, substance of the communication and qualifications or conflicts of people who prepare or endorse it.

Can AI be used to review FINRA communications?

Potentially. FINRA says generative AI tools may form part of a reasonably designed supervisory system when they are appropriately vetted, tested and monitored. The member firm remains responsible for compliance and should address matters including accuracy, reliability, data governance and human oversight.