AI Governance for Capital Markets Needs a Use-Case Control Map
AI governance for capital markets should classify each use by business function, information type, customer impact, and regulatory owner. Research summarization, investment banking work, communications review, surveillance, and trading support need different permissions, testing, supervision, and evidence even when they call the same LLM provider.

An investment banking associate selects two paragraphs from a confidential committee memo and asks an approved LLM to shorten them. The same provider also serves a research assistant that summarizes public filings. AI governance capital markets firms can defend must distinguish those requests before either reaches the model. The authenticated person and desk, business purpose and information class, provider route, plus review obligation all change the decision. A firm-wide approval for one vendor hides the mechanism the supervisory system needs to control.
TL;DR
- Govern capital-markets AI by use case and information class, plus customer or market effect and accountable regulatory owner.
- Give public research and MNPI-bearing banking work separate policies and evidence tests. Apply distinct controls to client communications, surveillance, and trading support.
- FINRA's technology-neutral rules apply to internally developed tools and third-party generative AI, including AI that is embedded in products used by member firms.
- An authenticated HTTP enforcement point can control routed LLM calls; books and records plus trading controls, model validation, and human supervision remain adjacent systems.
The control map starts with the business function
Capital markets firms already separate research and investment banking, sales and trading, plus operations and compliance because their information and conduct risks differ. AI permissions should preserve those boundaries. A research analyst summarizing a filed annual report presents a different risk from a banker drafting merger materials or a surveillance team asking a model to group alerts.
The FINRA artificial intelligence topic page states that FINRA rules and securities laws continue to apply when member firms use generative AI. That applies to internally developed tools and third-party technology, including technology that is embedded in existing products. The technology label adds no general exemption. Build the register at use-case resolution.
Each entry should name the business owner and regulatory owner; users and data classes; model and route; customer or market impact; required testing and human review; retained records plus the change trigger. My view is blunt: an inventory row called "enterprise chatbot" should fail governance review. It says nothing about the decision being made or the information crossing the boundary.
MNPI policy needs transaction and desk context
Material non-public information rarely arrives in a prompt with an MNPI label. It appears inside draft offering documents and deal code names; unpublished estimates; wall-crossing notes; or a committee memo photographed as a clean block of black text on a white browser pane. Prompt classification can identify sensitive patterns, but business context determines the policy.
An approved research assistant may summarize public SEC filings. An investment banking role can require a deny rule for external model routes when deal context appears. A restricted-list match can add another signal. Controls should also distinguish redaction from blocking. Removing one issuer name may leave dates and transaction structure, plus financial terms that still identify the deal.
AI security for financial analysts owns the narrower problem of analyst prompts carrying MNPI and client information. Firm-wide capital-markets governance adds information barriers and transaction context, model-change approval and vendor ownership, plus evidence testing across desks. The policy record should show the originating principal and effective desk role rather than only the shared application credential.
Supervision follows each deployed use
FINRA Regulatory Notice 24-09 reminds member firms that existing obligations apply to generative AI use. Under Rule 3110, a supervisory system using generative AI should address technology governance and model risk management; data privacy and integrity; reliability; plus model accuracy. FINRA also states that firms should evaluate tools before deployment and continue complying with the rules relevant to the specific business use.
That produces different completion tests. A client-communication assistant needs content review and approval controls mapped to Rule 2210. A surveillance summarizer needs tests showing that analysts receive reliable source references and retain responsibility for disposition. An internal policy assistant needs access restrictions so a user receives only material permitted for that role.
Trading support requires pre-trade controls and model validation, plus kill mechanisms and market-access controls outside the LLM request layer. The evidence packet should connect the use approval to executed samples. A passing public-filings request and a denied banking prompt, plus an output with a fabricated citation caught in review and a model-route change, tell a reviewer far more than a signed policy PDF.
Records should reconstruct the model-assisted event
A capital-markets record has to match the regulated activity. The prompt and response are part of a business communication, a supervisory review, or support for another retained decision. The AI decision record should capture the person or agent behind the call; role and desk; data classification and use-case identifier; model route and policy version; plus outcome and timestamp.
Content retention should follow legal and privacy rules, plus records-management rules for the underlying activity.
A gateway record supplies one part of that chain. The books-and-records system preserves the covered communication and approval. The order management system preserves trading activity. The surveillance platform keeps alert disposition. Model risk files hold validation and limitations, plus performance review. AI governance audit covers the difference between policy artifacts and operating evidence.
Do not claim that request logs prove regulatory compliance. They prove a bounded event at the AI traffic layer. A Rule 3110 assessment also depends on the supervisory design and reviewer actions; business facts and exceptions; training; plus remediation.
Third-party and embedded AI need route-specific treatment
FINRA's notice expressly includes third-party and embedded technology. A firm may route its own research assistant through a customer-controlled model endpoint while a communications platform invokes an embedded model behind the vendor's service. The first path can cross an external policy point. The second is opaque to the firm.
Record both in the inventory, but assign different controls. Customer-controlled routes can carry firm identity and use-case context into per-request policy. Embedded routes need contract terms and entitlements; product configuration and vendor testing; records exports and incident duties; model-change notice; plus an exit plan. A provider assurance report supports diligence. Ongoing samples and evidence retrieval demonstrate operation.
Pre-announcement earnings exposure through AI addresses issuer-side leakage during the close. Capital-markets governance applies a related information-control method across banking and research, plus sales and trading and surveillance while preserving each function's regulatory owner. When AI is embedded in a vendor product and has inadequate event evidence, the firm can restrict permitted content or keep the use out of regulated workflows.
The operating cadence should follow material changes
Governance should run on events as well as scheduled review. Trigger reassessment when a provider changes the model; an application adds retrieval over internal sources; a desk expands the user group; a workflow begins producing client-facing content; or an agent gains permission to take an action. A model-name update can alter behavior while the user interface stays unchanged.
Quarterly review can test access and denied data classes, evidence retrieval and exceptions, plus inventory reconciliation. Higher-impact uses need monitoring tied to their own risk and supervisory procedures. The committee should receive unresolved exceptions and material changes, along with named owners and deadlines. Avoid a single risk score that compresses a banking MNPI route and a public research summarizer into adjacent rows.
The AI model inventory management guide provides the route register. The capital-markets layer adds business function and information barrier, rule owner and retained record, plus customer or market impact. Those fields let compliance trace an approved use to its actual traffic and adjacent controls.
DeepInspect
DeepInspect supports capital-markets workflows whose LLM traffic uses customer-controlled HTTP routes. It runs inline as a stateless proxy between authenticated users or agents and model endpoints. The application supplies the originating identity and role, plus desk and use-case context. DeepInspect classifies prompt content, checks the model destination and versioned policy, then permits, redacts, or blocks before an allowed request reaches the provider.
Each routed decision produces a signed, tamper-evident record. Books and records plus communications approval, model validation and information barriers, trading controls, plus vendor-managed embedded inference are adjacent responsibilities. The request record gives those programs a reliable link between an authenticated principal and a specific model call. Book a technical deep dive at deepinspect.ai.
Frequently asked questions
- Can capital-markets staff use generative AI for public research?
A firm can approve public-source research as a defined use with source verification and role limits, plus approved routes and review requirements. FINRA's Notice 24-09 lists potential uses such as summaries derived from research reports and issuer information drawn from SEC filings and earnings-call transcripts. Staff remain responsible for accuracy and applicable research controls. The policy should block restricted internal material and retain evidence appropriate to the resulting business record.
- Does FINRA require a separate generative AI rulebook?
FINRA says its rules are technology neutral, and Notice 24-09 creates no new legal or regulatory requirements. The existing obligation attaches according to the use. Rule 3110 supervision and Rule 2210 communications standards, books and records, privacy, plus other duties can apply. Firms still need AI-specific procedures because the model route and prompt content, output behavior, plus embedded vendor path introduce operating facts that older procedures may omit.
- What should a capital-markets AI inventory contain?
Include the business function and use-case owner; regulatory owner; users and agents; calling application; provider and model; route and data classes; information-barrier status; customer or market impact; review requirement and testing; retained records and vendor terms; plus change triggers. Separate customer-controlled HTTP routes from opaque embedded AI. Link each entry to executed access tests and the policy version so a reviewer can verify that the listed control actually operated.
- Can an AI gateway supervise trading activity?
An AI gateway can govern routed HTTP calls to an LLM, including role and content class, plus destination and per-request policy. Order entry and market access, algorithm limits and trade surveillance, restricted-list controls, plus kill mechanisms sit in trading and compliance systems. If a trading-support workflow calls an LLM, the gateway can control that call and record it. The firm still needs the established controls around the order and market activity.
- How should a firm govern AI that is embedded in a vendor product?
Start by documenting the vendor's actual data path and model use; entitlements and retention; training terms and subprocessors; event exports and change notices; plus incident duties. Test user access and the evidence export. If the AI is embedded in a vendor product, restrict it to approved information classes when requests cannot cross the firm's policy point. Keep vendor-managed inference in the inventory as a distinct route and require the business owner to accept any residual visibility limit.