Skip to content

Regulation

Is FINRA deregulating social media stock recommendations?

By Editorial TeamUpdated Aug 3, 2026
Authority
FINRA
Rule type
regulation
Jurisdiction scope
US federal
Effective date
Sep 11, 2026
Source text
Read primary rule text ↗

Retail communications generally require principal pre-approval before first use and must satisfy FINRA content, supervision, recordkeeping, and recommendation standards; AI and social media content remain covered.

No. As of August 3, 2026, FINRA is not deregulating unauthorized stock recommendations on social media under securities law. Regulatory Notice 26-14, published July 9, 2026, is a proposal, comments are due September 11, 2026, and current Rule 2210 remains in force unless and until FINRA adopts a final rule change. What FINRA has proposed is more specific: replace broad principal pre-approval of many retail communications with a firm-run, risk-based pre-approval framework, delete the old static-versus-interactive social media distinction, and make clear that business communications remain regulated whether a human, a finfluencer arrangement, or AI technology generated them. [1]

That distinction matters because the compliance question is not whether a post looks like an ad, a reply, a repost, or a chatbot answer. It is whether the broker-dealer used, adopted, entangled itself with, supervised, retained, or caused a business communication that must meet FINRA content, supervision, recordkeeping, and recommendation standards.

Brokerage compliance review pipeline with social media tiles and a chatbot bubble routed into risk-tier review lanes
QuestionWhat binds todayWhat FINRA proposesWhat would not disappear
Retail communication approvalRule 2210 generally requires an appropriately qualified registered principal to approve retail communications before first use or filing, subject to specified exceptions. A retail communication is one distributed or made available to more than 25 retail investors within any 30-calendar-day period. [2]Regulatory Notice 26-14 would move to a risk-based pre-approval model administered by the member firm, using specified risk factors and written supervisory procedures. [1]The firm would still have to supervise communications and be able to show why a communication did or did not require pre-use approval.
Social media formatFINRA has long treated social media under communications and supervision principles, with compliance analysis often turning on whether content was static or interactive.The proposal would delete the static-versus-interactive distinction because FINRA says finfluencer risk persists regardless of whether content is static or interactive. [1]A risky recommendation, exaggerated claim, or misleading product statement would not become acceptable because it appeared in an interactive feed.
AI and chatbot contentCurrent communications rules do not exempt content because software helped generate it.The notice states that member communications remain subject to the rule regardless of whether generated by a human or AI technology, and it specifically discusses GenAI risks including hallucination risk and data protection. [1]Supervision, retention, content standards, and recommendation obligations would still have to be addressed.
Performance projectionsRule 2210 generally bars retail communications from predicting or projecting performance, with narrow exceptions. [2]A separate proposal, SR-FINRA-2026-004, would for the first time permit certain performance projections and targeted returns with audience-tailoring and disclosure conditions. [4]That separate proposal is not the same thing as the Rule 2210 supervision overhaul, and NASAA has opposed it absent additional guardrails. [4]

The current rule is still the baseline

Current Rule 2210 starts from a blunt but administrable premise: retail communications generally need principal approval before the earlier of use or filing, unless an exception applies. It also contains content standards, filing requirements for certain materials, limits on projections, and disclosure obligations when recommendations are made, including disclosures of certain financial interests. [2]

For social media, that means a firm cannot treat the platform as the compliance category. A polished campaign about a structured product, a paid finfluencer video, a registered representative’s repost, and a chatbot response may all travel through different operational channels, but the firm-side questions remain familiar: who prepared it, who approved it, what product or strategy it promoted, whether it included performance data, whether it made a recommendation, whether it was fair and balanced, and whether the firm can retrieve the record later.

Nothing in Notice 26-14 says a social media stock recommendation can evade those questions because it was conversational, automated, or distributed through a third-party personality. FINRA’s proposal is aimed at the allocation of review attention, not at making retail-facing content standards optional.

What changes: from blanket pre-use approval to documented risk classification

The most important move in Regulatory Notice 26-14 is the proposed shift away from broad principal pre-approval of retail communications toward a risk-based framework. Under the proposal, firms would classify communications using risk factors and supervisory procedures, then decide which communications require pre-use principal approval and which may be supervised through other controls. [1]

Side-by-side diagram contrasting a single bottleneck review lane with communications sorted into parallel risk-tier review lanes

That is a material change, but it is not a release valve that allows marketing or growth teams to relabel communications as low risk by preference. FINRA describes eight proposed risk factors. The notice specifically includes factors such as product complexity, the qualifications and experience of the person preparing the communication, whether performance data appears, and the method of distribution. [1]

Those factors point to the actual redesign firms would need. A static post about branch hours is not in the same supervisory category as a short-form video naming a leveraged product, a targeted campaign using back-tested performance, or an AI chat response that compares individual securities. The proposal would let the firm build different controls for different risks, but it would also make the classification decision itself a supervisory artifact. If the firm later cannot explain why a communication bypassed pre-use approval, the framework will not help much.

The economic assessment gives FINRA’s reason for questioning the current allocation of review and filing resources. In FINRA’s sample of 2023-2025 filings, 24% of 4,501 retail communications filed pre-use were noncompliant, compared with 10% of 172,898 filed post-use; FINRA also reported that roughly 69% of first-year member filings in the sample were noncompliant. [1]

Those figures should not be read as a misconduct rate for all broker-dealer communications or all social media posts. They are FINRA’s sample figures from an economic assessment, and they measure filings that reached FINRA under the existing regime. Their narrower usefulness is enough: they show why FINRA thinks the current model may be over-reviewing some low-risk materials while still needing focused intervention for communications and firms that generate higher compliance problems.

Deleting the static-interactive line does not legalize finfluencer risk

The proposed deletion of the static-versus-interactive distinction will be easy to misread. The older distinction was useful when a firm’s website brochure and a registered person’s online conversation felt operationally different. It is less useful when retail investors encounter product claims through reposts, stitched videos, paid clips, platform-native messages, and chat interfaces that do not fit the old categories cleanly.

FINRA’s explanation is direct: finfluencer risk “persists regardless of whether the content is static or interactive.” [1] That sentence is the hinge. FINRA is not saying interactive content is too fluid to supervise. It is saying the old format line should not decide whether the communication receives meaningful review.

A firm using finfluencer content would still need to ask ordinary but uncomfortable questions. Was the influencer compensated? Did the firm script, approve, amplify, or otherwise become entangled with the message? Did the content make promissory statements, omit material risks, or present performance in a misleading way? Did it identify conflicts where required? Did the firm preserve the post, comments, edits, approvals, and related communications?

The enforcement backdrop is consistent with that reading. FINRA brought three 2024 finfluencer-related actions, dated March 15, April 3, and June 10, alleging posts that were not fair and balanced or were exaggerated or promissory; the June action also included supervision and recordkeeping failures and Regulation S-P violations. [3] Those actions do not prove that every social media stock discussion is a broker-dealer violation, and they should not be converted into an unregistered-advice theory without the facts to support it. They do show that FINRA’s concern sits squarely in communications, supervision, books-and-records, privacy, and control failures.

AI-generated communications remain communications

The AI portion of Notice 26-14 is not a separate AI rulemaking, but it is not decorative language either. FINRA states that member communications remain subject to Rule 2210 “regardless of whether they are generated by a human or AI technology.” [1] For a firm deploying chatbots, AI-assisted content drafting, automated campaign tools, or AI-generated responses in customer-facing channels, that sentence blocks the most convenient misreading of the proposal.

Compliance supervisor reviewing AI chatbot conversation bubbles with hallucination-risk alert and archive icon

A chatbot response can be a business communication even if no employee typed the final words. If it describes a security, compares products, discusses account action, or frames a strategy for a retail investor, the firm still has to decide how the output is supervised, retained, tested, escalated, and corrected. The relevant approval point may move upstream into tool governance, prompt constraints, retrieval controls, content libraries, exception reports, and post-use surveillance. It does not vanish.

FINRA names GenAI risks including hallucination risk and data protection. [1] Those risks are not solved by adding a footer that says AI may be wrong. A hallucinated product feature, fabricated performance claim, inaccurate fee description, or false statement about suitability can still create a communications problem. A tool that exposes customer information or uses protected data in an unapproved way can create a privacy and supervision problem before anyone reaches the content-standard analysis.

Firms already building AI governance for investment tools should connect that work to communications supervision rather than leaving it in a model-risk silo. The practical file should show what the AI tool is allowed to say, what it is blocked from saying, which data sources it uses, how outputs are sampled, how exceptions are escalated, and how records are preserved. For a deeper treatment of AI model controls in trading and compliance systems, see AI model stock-trading compliance.

Where stock recommendations raise a separate layer of review

Questions about unauthorized stock recommendations on social media under securities law tend to collapse several issues into one. A firm-side communications analysis under Rule 2210 is not the same as a full suitability or Regulation Best Interest analysis, and it is not the same as a fraud or market-manipulation case. But the lanes can overlap.

If a communication merely discusses a market theme in general terms, the communications file may carry most of the weight. If it identifies a particular stock, ETF, option strategy, or leveraged product and urges action by a retail investor, the firm should assume that recommendation standards may also come into view. That is especially true when the content is targeted, personalized, tied to account data, or delivered through an interactive tool that can adapt its answer to the user.

This is where social media and AI design choices become legal facts. A generic post visible to the public, a sponsored clip sent to a defined customer segment, and a chatbot answer based on holdings data do not present the same recommendation profile. Firms reviewing high-volatility or leveraged products should also connect the communication review to their suitability and product-risk files; for example, the analysis in SOXL long-term suitability risks shows why product structure can matter even before the marketing language is assessed.

The parallel performance-projection fight is nearby, not identical

SR-FINRA-2026-004 should be kept in the same briefing folder but not in the same mental box. Filed February 20, 2026, that separate proposal would permit performance projections and targeted returns for the first time under specified audience-tailoring and disclosure conditions. NASAA has opposed the proposal absent additional guardrails. [4]

The distinction matters for supervision design. Notice 26-14 addresses how communications are reviewed and supervised under a proposed risk-based model. SR-FINRA-2026-004 addresses whether certain content that is now broadly prohibited in retail communications could be allowed under conditions. A social media campaign containing projected returns would therefore require two separate questions: is the firm’s review process compliant, and is the projection itself permitted?

What firms should do before the September 11 comment deadline

The comment window is short enough that firms should not wait for a final rule to test whether their current procedures can support the proposed framework. The useful exercise is not to announce that fewer communications will need review. It is to map which communications would still require pre-use approval, who would make the risk decision, and what evidence would remain after the fact.

  • Inventory communication channels: firm websites, registered representative social accounts, paid influencer arrangements, reposts, short-form videos, email campaigns, app notifications, chatbot outputs, AI-generated drafts, and third-party content the firm adopts or amplifies.
  • Draft risk-tiering criteria that track FINRA’s proposed factors, including product complexity, preparer qualifications, performance data, and distribution method.
  • Decide which categories still require pre-use principal approval, rather than leaving that decision to channel owners or campaign teams.
  • Create a record of risk classification decisions, including why lower-risk communications were eligible for post-use or surveillance-based supervision.
  • Document AI-tool governance: permitted use cases, restricted topics, source controls, prompt and output testing, hallucination monitoring, human escalation, and data-protection controls.
  • Confirm that AI and chatbot outputs can be retained and retrieved in a form usable for supervision, examination, and dispute review.
  • Keep recommendation standards in the review process when content names securities, suggests action, targets a customer segment, or adapts to user-specific information.
  • Separate comments on the Rule 2210 supervision proposal from comments on the performance-projection proposal, even if the same business teams care about both.

Compliance teams should also be precise internally about vocabulary. “Risk-based” does not mean “unapproved.” “Interactive” does not mean “outside the rule.” “AI-generated” does not mean “not a firm communication.” If those terms are not controlled before adoption, the proposed flexibility will be translated by other teams into a permission structure FINRA has not offered.

Until FINRA adopts a final rule, current Rule 2210 remains the operative standard. If the proposal moves forward, the stronger compliance posture will not be looser social media controls. It will be better risk classification, documented supervision, retrievable records, and explicit governance for AI-generated communications and chatbot outputs.

References

  1. Regulatory Notice 26-14, FINRA, July 9, 2026.
  2. FINRA Rule 2210, FINRA.
  3. FINRA and SEC Float Concerns Over Social Media Finfluencers, Carlton Fields.
  4. A Pivotal Moment for Broker-Dealer Communications with FINRA, Mintz, July 14, 2026.

Operationalizing workflow

No workflow has been explicitly linked to this obligation yet. See Workflows generally.

Illustrative cases

No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.

← Back to Regulation

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →