← Blog

Shadow AI in Capital Markets: MNPI, Supervision, and Books and Records

Parminder Singh
Parminder Singh··8 min read
Summarize with AI

Shadow AI in capital markets can move MNPI and draft research into unapproved model services while leaving the firm without a supervisory record. This article maps the traffic to FINRA''s technology-neutral rules and SEC books-and-records duties, then defines the controls required at the managed HTTP AI boundary.

Industry Verticalsshadow-aiai-securityai-governancecompliancepolicy-enforcementaudit
Shadow AI in Capital Markets: MNPI, Supervision, and Books and Records

At 6:42 a.m., an equity analyst has a draft initiation report open beside an AI chat window. The prompt contains an unpublished price target and channel-check notes. One line describes a management call. The request may travel to an unapproved model before the firm's research approval workflow or communications archive sees any of it.

That sequence makes shadow AI in capital markets a supervision problem with an HTTP data channel at its center. Broker-dealers and other market firms already record communications and supervise associated persons. They protect material nonpublic information and preserve business records. AI prompts create a separate machine-facing communication stream. The controls need to meet it where the request leaves.

TL;DR

  • Capital-markets shadow AI can expose MNPI and draft research before supervisory review, along with order context and client communications.
  • FINRA says its rules remain technology neutral when firms use generative AI, including third-party and embedded tools.
  • Books-and-records archives need the AI request and its policy decision joined to the response and the human-review trail.
  • DeepInspect governs authenticated HTTP AI traffic routed through it; consumer browser use outside that route needs separate controls.

MNPI can fit inside a small prompt

A capital-markets prompt rarely looks like a complete deal room. It may contain six lines from a research draft or a proposed syndicate allocation. Another prompt carries a client's block-trade interest or a summarized conversation with an issuer. Each fragment can carry meaning because the user supplies context the model needs. The destination receives that context even when the employee omits the source document.

The broader shadow AI for finance article covers financial-services exposure. Capital markets adds regulated communications and information barriers. It also adds public-facing content standards and market-abuse surveillance. The relevant identity includes firm and legal entity, desk and registration, supervisory chain and wall status. An IP address or shared API key gives compliance a poor substitute.

My view is blunt: a firm that archives the final research report while discarding the AI prompt that shaped it has preserved the cleanest artifact and lost the interesting one. The request shows what unpublished information entered the tool and which policy governed the exchange.

FINRA applies existing rules to generative AI

FINRA Regulatory Notice 24-09, published June 27, 2024, reminds member firms that FINRA rules and federal securities laws continue to apply when firms use generative AI and large language models. The notice says the rules are technology neutral. It also covers firm-built tools and third-party technology, including technology that is embedded in existing products.

FINRA points directly to Rule 3110 supervision. A firm using generative AI in its supervisory system needs policies addressing technology governance and model risk management. Those policies also cover data privacy and integrity, plus reliability and accuracy. Notice 24-09 also explains that the applicable obligations depend on the use case and that generative AI can implicate virtually every area of a member firm's duties.

That framing matters for shadow use. An unregistered AI assistant still operates inside the firm's business when an associated person uses it for research or for sales and trading support. Lack of approval creates an internal control failure; it does not erase the underlying obligation.

SEC recordkeeping follows the business record

Broker-dealer recordkeeping under Exchange Act Rule 17a-4 covers specified records and communications relating to the firm's business. The SEC's electronic recordkeeping framework sets preservation and accessibility requirements for covered records, along with production requirements. Firms need counsel and compliance to determine which AI prompts and responses fall within their precise record schedule.

The architectural point is narrower. If an AI exchange becomes part of a recommendation or a customer communication, or feeds a research publication or supervisory review, the firm needs enough linkage to preserve and retrieve the relevant record. A provider's account history gives the provider's view. A local application log gives the application's view. Neither inherently captures the firm's identity and wall status, or the policy version and approval chain at request time.

An independent policy record can join the AI exchange to the firm's archive. That connection turns a loose prompt into evidence tied to a named user and business process.

Four capital-markets workflows require different policy

Each workflow below sends a different kind of content to a model, so each needs its own rule set rather than one firm-wide allowance.

Research production

Research staff can use models for summarization and drafting, or for document comparison and code assistance. Prompts may carry unpublished ratings and target prices, or issuer communications and assumptions awaiting supervisory approval. Policy should bind the request to the analyst and coverage group, plus the publication state and destination model. A public filing belongs in a different class from notes taken during a restricted management call.

Sales and trading

A salesperson may summarize client color. A trader may ask for code that analyzes a current order blotter. The prompt can reveal customer identity and trading interest. It can also reveal positions or order timing. Inline classification should detect those fields and apply desk-specific policy before transmission. Surveillance can ingest the decision record alongside chat and order events.

Investment banking

Bankers work with codenames and valuation ranges. Draft announcements and bidder lists move through the same tools, as do diligence findings. Information-barrier context is decisive. A model route approved for public pitch materials may stay prohibited for live-deal content. The request must inherit wall and deal-team attributes supplied by the originating workflow.

Compliance and supervision

Compliance teams also create sensitive prompts. A request summarizing an alert can expose the subject and the investigative theory. FINRA Notice 24-09 specifically discusses AI used within supervision. The control path needs to preserve confidentiality and evidence while keeping the supervisor responsible for the conclusion.

Information barriers belong in request context

Capital-markets IAM establishes who the user is. AI authorization needs to answer what that person may send to this model for this business purpose. Useful context can include desk and branch, legal entity and restricted-list relationship, wall-crossing state and deal code, communication type and supervisory owner.

The application or managed access layer must supply those attributes. A stateless enforcement proxy can evaluate them without becoming the source of the firm's restricted list. If the caller presents a shared service credential, the decision reflects that shared role. Weak upstream identity produces weak downstream evidence.

Prompt classification then adds content signals such as issuer names and security identifiers, price targets and order fields, deal codenames and client identifiers, plus language associated with draft communications. The policy combines identity and content. It may deny the request or redact a permitted field before routing it to an approved model endpoint under the firm's contract.

This extends the shadow AI governance framework with the attributes that capital-markets compliance already maintains.

Surveillance needs the event before the model receives it

Alerting after a provider returns the response gives compliance forensic value. Prevention requires a decision on the outbound request. The enforcement point should commit a record containing user identity and desk context, destination and content classifications, policy version and outcome, before permitted traffic reaches the model.

The response needs inspection and linkage as well. A model can produce an unapproved customer communication or insert unsupported performance language. It can also return content that crosses a barrier established by retrieval context. FINRA Rule 2210 obligations can apply to public communications produced with technology, as Notice 24-09 emphasizes. The business workflow still owns principal approval and final use.

The audit chain should let compliance move through a single sequence: source application, AI request, outbound decision, model response, inbound decision, human edit, approval, then the published or sent artifact. That sequence supports investigation without claiming that gateway evidence replaces the firm's official books and records.

Browser and embedded use set the discovery boundary

A consumer AI session in a browser may bypass the firm's configured AI proxy. DeepInspect inspects authenticated HTTP AI traffic routed through it. It cannot observe browser-only consumer traffic that takes another network path. Endpoint agents and enterprise-browser policy have to identify or stop that path, and so do DNS and egress controls. CASB discovery and managed-device restrictions cover the devices themselves.

Embedded AI in research terminals and CRM systems creates a different challenge. The same holds for communications tools and compliance platforms. The model call may occur inside the vendor's environment, beyond the firm's direct HTTP route. Notice 24-09 explicitly says embedded third-party capabilities are part of its regulatory framing. Vendor due diligence should identify the model subprocessors and data use, retention and entitlements, audit exports and supervisory integration.

The firm can route AI calls it controls through an enforcement point and contract for evidence on calls controlled by vendors. Pretending one sensor sees both paths produces a false inventory. The shadow AI detection article describes the discovery layers that complement inline control.

A defensible evidence package

A capital-markets AI evidence package should answer concrete questions. Which associated person or agent initiated the exchange? Which desk and legal entity applied? Did the prompt contain a restricted issuer or customer order, unpublished research or another sensitive category? Which endpoint received it? What policy version decided the route? Which supervisor reviewed the resulting business use?

Per-decision records should be exportable into the surveillance and records platform with stable identifiers. The firm can then apply retention according to its counsel-approved schedule and retrieve the AI events associated with an investigation or customer complaint, a research review or an examination request.

Application logs are useful for workflow actions. Provider logs are useful for model-service operations. The external enforcement record supplies policy evidence at the traffic boundary. Three records joined by request identifiers give a stronger reconstruction than any single system attesting to itself.

DeepInspect

DeepInspect operates inline between authenticated capital-markets applications or agents and HTTP-based LLM endpoints. It uses identity and business context supplied by the application, classifies routed prompts and responses, then evaluates per-role and per-route policy. The decision happens before traffic proceeds.

Every decision produces an identity-bound audit record: policy version, classification, destination, timestamp, outcome. Those records can feed the firm's surveillance and evidence workflows. Consumer browser sessions and vendor-controlled model calls that bypass the proxy remain outside DeepInspect's enforcement boundary, so firms need the endpoint and third-party controls described above.

Book a demo today.

Frequently asked questions

Does FINRA prohibit broker-dealers from using generative AI?

FINRA Notice 24-09 describes opportunities and reminds firms that existing obligations continue to apply. It asks firms to evaluate tools before deployment and maintain compliance for each use case. A firm can approve AI use with supervision and privacy controls, recordkeeping and communications controls, plus others mapped to the workflow.

Should every AI prompt be retained under Rule 17a-4?

The rule covers specified records and communications relating to the broker-dealer's business. Retention depends on the prompt's function and content, and on the governing record category. Legal and compliance teams should define the schedule. Architecture should preserve enough context to classify and retrieve covered exchanges instead of discarding everything by default.

Can existing communications surveillance ingest AI events?

Yes, when the AI control layer exports structured events carrying the fields surveillance needs: user, desk, timestamps, content categories, policy version, route, outcome. Surveillance teams can join those events to the email and chat archive. The same join works for voice and order records. The AI event is a distinct communication type with its own prompt and response semantics.