Compliance programs spend a great deal of time anticipating where enforcement will move next. Off-channel communications surveillance is a case where that question has a clear answer: nowhere new. The obligation has not changed. What has changed is the enforcement posture — and in ways that have significant strategic implications for how CCOs and their teams approach detection infrastructure.
The off-channel enforcement program produced approximately $3.6 billion in combined SEC and CFTC penalties — roughly $2.3 billion across approximately 95 SEC actions and $1.2 billion across approximately 26 CFTC-involved institutions. The highest single-firm penalty in the 2022 wave reached $125 million. These are not hypothetical exposures; they are executed penalties against named institutions, most of them recognizable names in global finance.
The enforcement program was built on a straightforward legal foundation. SEC Rules 17a-3 and 17a-4 require broker-dealers to capture and preserve all business-related electronic communications. The failure to capture off-channel communications — on personal devices, third-party messaging applications, encrypted platforms — was treated as a recordkeeping violation, not merely a supervisory one. FINRA Rule 3110's supervision obligation runs parallel: a firm must have written supervisory procedures and actually review a reasonable sample of electronic communications. A firm whose employees conduct business on channels that the supervisory program does not reach cannot satisfy either standard.
SEC Chair Atkins, speaking at the FINRA Annual Conference on May 12, 2026, characterized the off-channel sweep as precisely the model of how regulators should not act, and signaled that regulation by enforcement is over at the SEC under current leadership. FY2025 produced approximately 456 enforcement actions — a roughly 20-year low.
Against this backdrop, the February 2026 federal court decision in SEC v. Arete Wealth is clarifying. The off-channel charge in that case survived a motion to dismiss. The court's reasoning was direct: the rules say what they say. The enforcer's posture shifted; the underlying rule did not, and a court just affirmed it.
“The floor did not move. The enforcer did. A firm that interprets a softer posture as a reduced obligation is misreading the legal landscape.”
The practical reading: a firm that interprets a softer enforcement posture as a reduction in underlying obligation is misreading the landscape. The rule is unchanged, it has just been upheld in court, and a future administration could resume aggressive enforcement against a universe of firms whose programs were quietly walked back during the intervening period. The firms whose detection programs remained strong through this period will be better positioned in any enforcement environment.
The more operationally significant change in the current enforcement environment is the explicit elevation of self-reporting and cooperation credit as the primary determinants of penalty magnitude. The PJT Partners case is the clearest illustration: PJT received a $600,000 penalty in a peer population where similar violations produced penalties in the $8.5 million range. The delta is not attributable to the severity of the underlying violation. It is attributable to demonstrated cooperation, which began with proactive self-disclosure of violations the firm had discovered through its own supervisory program.
This reframes the value of detection infrastructure in a way that CCOs and CISOs should find legible to their boards. Detection tooling is no longer principally a cost of compliance — it is the instrument of the cooperation credit program. A firm cannot self-report a violation it has not detected. A firm whose supervisory program missed the violation entirely has no cooperation narrative to offer. Detection infrastructure is therefore directly correlated with the firm's ability to access the most favorable enforcement outcomes available in the current environment.
The most consequential limitation of keyword-based surveillance is not that it misses things — it is that it misses the things that matter most. The riskiest communications in a regulated financial services firm are rarely those that contain the obvious prohibited terms. Employees who are aware of surveillance, and employees who are not acting in good faith, both have strong incentives to avoid the vocabulary that would trigger a keyword match.
What they cannot avoid is the behavioral signature of the conduct. A portfolio manager coordinating a trade on material non-public information will, through the structure of their communications, exhibit behavioral patterns that are recognizable regardless of the words chosen. The timing of communications relative to trading activity, the information asymmetry implied by what is said and not said, the coordination pattern across parties — these are behavioral features that a keyword system cannot observe. They are precisely what behavioral inspection is designed to detect.
FINRA examiners have been explicit in recent years about what constitutes a reasonable supervisory system. A program that depends exclusively on keyword matching for detection — and that is honest with itself about what keyword matching catches — is not a program that can credibly claim to have identified violations that an examiner will subsequently find. The self-reporting credit program rewards the firms that actually find violations; finding them requires detection methods that match the evasion sophistication of the conduct.
A 2026 surveillance brief that did not address AI agents would be incomplete. AI agents are now deployed by financial services firms in roles that touch external communications — client-facing service agents, research synthesis tools that summarize and present findings, trading-adjacent tools that generate or summarize investment-related content. Each of these agents is capable of producing communications that carry compliance risk, and most of them operate without the supervisory controls that apply to human communications.
SEC examination priorities for 2026 include verification of AI-related claims in virtually all examinations. This is not narrowly about AI model validation — it extends to claims about what the firm's AI systems are and are not doing, and about the controls in place over those systems. A firm whose client-facing AI agent is generating investment-adjacent content without surveillance coverage has a disclosure problem as well as a compliance one.
The communications surveillance perimeter must now include the output of AI agents operating in any capacity that touches regulated conduct. An agent that could, under the right conditions, produce an implicit investment recommendation, a disclosure of material non-public information, or a misleading representation about a security must be subject to the same behavioral inspection as a human representative in the same role.
Surveillance infrastructure has historically operated in a vendor-cloud model: communications are transmitted to a vendor's processing environment, inspected, and findings are returned to the firm. This model was designed when data-residency and privacy obligations were less demanding, and when the alternative — in-tenant inference — was technically complex to deploy.
The regulatory environment has shifted. Multiple jurisdictions now impose data-residency requirements that restrict the transmission of certain communications to vendor environments. Privacy teams at regulated institutions are increasingly uncomfortable approving surveillance architectures that require regulated communications to leave the firm's control. And the SEC's examination scrutiny of third-party vendor arrangements means that the data-handling agreement with a surveillance vendor is itself a potential examination topic.
An in-tenant surveillance architecture — where the inspection logic runs inside the firm's own environment and no communication is transmitted externally for processing — addresses all of these concerns structurally rather than contractually. The communications never leave; there is nothing to disclose, no data-handling agreement to defend, and no residency exposure to manage. For regulated institutions whose communications include sensitive client data, MNPI, or protected health information, this is not a preference. It is a prerequisite for any realistic path to approval.
A communications surveillance program adequate to the 2026 environment should be able to demonstrate several things to an examiner. First, that it achieves total channel coverage — including the collaboration and messaging platforms that employees and agents actually use, not only the platforms that existed when the program was designed. Second, that its detection methodology is behavioral rather than purely keyword-based — that it can describe how it would have detected a specific pattern of misconduct that did not use prohibited vocabulary. Third, that it includes AI-agent communications within its perimeter. And fourth, that it generates time-stamped, policy-linked findings that could support a self-reporting narrative with specific evidence of when a violation was detected, by what method, and what was done with it.
Programs that can produce this demonstration are positioned well in any enforcement environment. Programs that cannot — because they sample rather than cover everything, rely on keyword detection, or exclude agent communications — carry a risk that the current enforcement posture may create the impression of having reduced, but that the underlying legal framework has not.
Compiled delivers total channel coverage, behavioral detection, and zero data egress — the architecture a current-state surveillance program requires.