Notice & Comment

Move Fast and Delegate Things: Can a FINRA for AI Survive Constitutional Scrutiny?

An audited self-regulation framework has been relied on to govern highly complex, evolving industries, such as securities. The concept is now attracting interest from those exploring how to govern frontier AI models. Notably, AI developers—including Google, OpenAI, and Anthropic—are among those interested in this route. Their policy recommendations include variants of a self-regulatory approach with three key commonalities. The first is reliance on third party evaluators, rather than a single government office or internal processes. The second is the development of a common set of standards, informed by expert analysis and refined on a regular basis. The third is that frontier models should be subject to both pre- and post-deployment assessment against those standards.

Policymakers seem intrigued by this general approach too, and the potential balance and adaptability it could provide. The White House has signaled that a FINRA-esque model may align with its AI ambitions. The FRONTIER Act set forth by Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) contains provisions that rhyme with such a regulatory framework.

This growing coalition in support for audited self-regulation is grounded in a few facts.

Highly-capable AI models present risks that warrant heightened scrutiny. These risks include but are not limited to cybersecurity threats, bioweapon development, mass surveillance, and loss of control scenarios in which models escape their test environments or otherwise bypass imposed safeguards. Recent testing by the UK AI Safety Institute documenting how frontier models may pursue long-term goals via unsanctioned behavior bolsters the case that such risks are prevalent and, under present safeguards, inadequately mitigated.

Existing government systems are not suited to detecting those risks nor to evaluating the adequacy of mitigations created by the labs. This lack of capacity is the result of several commonly accepted observations. Three stand out: limited government expertise on AI; the slow pace of regulatory processes; and a lack of investment in the science of AI to better understand how and whether to regulate it.

These observations amount to a serious argument for delegating substantial regulatory authority to private experts. Yet the argument is incomplete. Audited self-regulation has a documented history, and that history includes recurring failure modes and constitutional barriers that its advocates may not fully acknowledge. The most thorough accounting of both remains a 1994 report prepared for the Administrative Conference of the United States (ACUS).

The Promise and Pitfalls of Audited Self-Regulation

There is private and public demand for an independent, expert-driven AI auditing ecosystem that can move near the pace of AI development. These actors appear to be sold on the benefits of self-regulation, which have long been touted. In that 1994 ACUS report, Douglas C. Michael enumerated some of those upsides:

  • rules shaped by stakeholders with better knowledge of the regulated activity
  • enforcement that is less unpredictable and less rigid
  • increased compliance among regulated entities
  • lower regulatory costs on both the government and the regulated entities
  • the possibility of continually and more speedily improving the regulatory design

Michael, however, flagged from his exhaustive analysis of prior audited self-regulation schemes that disadvantages may undermine those favorable attributes. In particular, he noted that:

Self-regulation clearly raises the possibility that the rules will be tailored more to the regulated entities’ self-interest than the public interest. The enforcement may be varied and unpredictable, because a self-regulatory system has a greater opportunity for the regulators to exercise unreviewable discretion. And in certain subject areas, the concept of self-regulation is simply politically unacceptable.

Several questions follow. Is there an alternative approach that keeps the positives and corrects for the negatives? If not, do the proposals on the table avoid Michael’s pitfalls? And the focus of this essay: can that framework operate in a way that aligns with our constitutional order?

Delegation and Its Discontents

The Constitution is explicit that all power emerges from the people and that all delegations of that power must be subject to the ongoing consent and oversight of the public or their representatives. To borrow from Professor Louis Jaffe, “the prime political entity is the citizen.” Citizens constitute the public. The public operates to promote the public interest. They elect officials to further that aim. That mission is derailed by “capture” or the unjustified exercise of authority by one group over another. The question is whether the power of self-government will endure. The drafters did their best to ensure it would. They developed a constitutional order that was “intended to end competition among various public and private actors and the tortuous amalgam of loyalties that previously defined the disjointed political community.”

Over time, the Supreme Court has refined this tenet. One core limitation: “Congress cannot escape constitutional restraints by delegating government authority to private parties to accomplish indirectly what Congress cannot do directly,” per Paul J. Larkin, Jr. The Court has accordingly struck down laws that handed private actors regulatory power without sufficient public oversight.

One example is the Supreme Court’s decision in Carter v. Carter Coal Co. That case turned on the constitutionality of the Bituminous Coal Conservation Act of 1935. Two of the Act’s key provisions caught the attention of the justices. One allowed private actors on local coal district boards to set minimum and maximum prices. The other authorized a supermajority of large producers and a majority of workers to determine industry-wide wage and hour requirements. Coal producers operating outside of those potential agreements challenged the law. The Court sided in their favor, reasoning that the act “arbitrarily interfered with a coal producer’s property rights by vesting government power in the hands of a party interested in the outcome of a business transaction,” as summarized by Larkin.

Carter Coal marked the outer boundary of private governance, but not the end of regulatory experimentation with private actors. Private regulators have flourished within that boundary ever since—so much so that Professor Harold Abramson heralded the arrival of a “fifth branch of government” made up of private regulators. He specifically named the National Association of Securities Dealers (NASD)—the predecessor to FINRA—as a leaf of that branch. These regulators write rules and settle disputes; what varies is the length of the leash held by the government. That distance determines the efficacy and constitutionality of the underlying framework. Too close, and the benefits of audited self-regulation Michael cataloged start to wither. Too remote, and the Constitution becomes a problem.

The possibilities sort into three buckets: private regulators formally deputized by the government, as with occupational licensing boards, which raise few constitutional issues; private regulators with no government tie at all, and thus no power to coerce anyone; and private regulators tied to the government but short of formal deputization—private voluntary standards organizations, for instance—which develop rules and adjudicate disputes with varying degrees of formal government power.

Regulatory schemes in the final bucket may warrant intense constitutional scrutiny. The more politically and economically significant the regulated area, the greater the need for government oversight or the public may otherwise have a justifiable case that the scheme infringes on their role as sovereigns.

Whereas public actors are subject to manifold constitutional restrictions and direct or indirect electoral oversights, private actors in the third bucket may not be checked by the same legal and political safeguards. In prior eras, the Supreme Court has denied the constitutionality of such private regulators. In Schechter Poultry Corp. v. United States, the Court reviewed a framework under which trade or industry groups could draft codes of fair competition that would become law upon approval by the President. The Court queried:

But would it be seriously contended that Congress could delegate its legislative authority to trade or industrial associations or groups so as to empower them to enact the laws they deem to be wise and beneficent for the rehabilitation and expansion of their trade or industries?

The justices responded, “The answer is obvious. Such a delegation of legislative power is unknown to our law, and is utterly inconsistent with the constitutional prerogatives and duties of Congress.”

A consistent test has emerged for such delegation: whether the public retains the requisite degree of direct or indirect control. What form such control may take is a question the Court answered long ago—and revisited a year ago. In Sunshine Anthracite Coal Co. v. Adkins, decided in 1940, the Court blessed a private delegation scheme in which the private parties’ proposals were subject to agency “approv[al], disapprov[al], or modifi[cation].” Two features saved the arrangement: the private parties “function[ed] subordinately to” the agency, and the agency retained authority over and surveillance of their work.

Decades later, in FCC v. Consumers’ Research, the Court applied that same reasoning to the private company that administers the universal service fund. The agency appoints the company’s board, signs off on its budget, and issues the rules and directives the company must follow. That arrangement raised no constitutional red flags.

The rule is easier to state than to follow, especially in complex contexts. Congress’s most recent experiment in audited self-regulation—the Horseracing Integrity and Safety Authority (HISA), a private nonprofit that writes and enforces national rules for thoroughbred racing under Federal Trade Commission oversight—has now spent years in the courts. The Fifth Circuit held the original statute unconstitutional in 2022 because the Authority’s rulemaking was not subordinate to the FTC. Congress promptly amended the law to let the FTC abrogate, add to, and delete the Authority’s rules—language borrowed from the Exchange Act. That cured the rulemaking problem in the Fifth Circuit’s eyes but not the enforcement one: in 2024, and again in June 2026 after the Supreme Court instructed it to reconsider in light of FCC v. Consumers’ Research, the court held that the Authority’s power to investigate, subpoena, search, fine, and seek injunctions without meaningful FTC supervision violates the private nondelegation doctrine. In the Fifth Circuit’s telling, the private body in Consumers’ Research acted merely “as an aid” to its overseeing agency; the Authority, by contrast, is “in charge of” enforcement. The Sixth and Eighth Circuits see it differently, and the split appears bound for the Supreme Court.

Scholars have abstracted higher-level principles from such cases. The first test—to borrow from the AI world—is the harness imposed on the delegated actor. Professor Freedman contends that the Supreme Court has generally approved or tolerated delegations of power to the President because he is elected, duty bound to uphold the Constitution, cabined by the traditions and norms of the office, and subject to political pressure. Private delegates, however, rarely are cabined “by such profound imperatives.” Yet, as explored further below, each additional constraint on private actors threatens to undermine the underlying purpose of the delegation in the first place.

The second test, set forth by George Liebmann, narrows Freedman’s examination to four questions: Do the private delegates’ actions receive meaningful public or judicial review? Are the delegates chosen through public consent, as by nomination or confirmation by elected officials? Are they sworn to oaths of office? And do they have pecuniary interests in the determinations being made?

Liebmann stresses that any private delegation cannot infringe on procedural rights. To emphasize that point, he points to Justice Robert Jackson’s assertion that procedural fairness “yields less to the times, varies less with conditions, and defers much less to legislative intent” than substantive due process. The key takeaway is that any adjudicatory function in a private delegation regime will need to include procedural safeguards to survive scrutiny—though the source of that obligation is murkier than commonly assumed.

A clarification: two distinct doctrines are at work here and they are routinely conflated. The first is the private nondelegation doctrine. The second is procedural due process, which binds an adjudicator only if that adjudicator is a state actor. FINRA has long insisted it is not a state actor, and the federal courts have never settled the question. In a Georgia Law Review note surveying the case law, Jerrod Lukacs found that no circuit has held that a self-regulatory organization (SRO) exercising its regulatory powers is a purely private actor free from the Due Process Clause—but the courts holding the opposite did so in conclusory fashion, and most circuits have simply avoided the issue. Their favored escape routes: assume state action for the sake of argument and find the process adequate anyway, or rest the decision on the Exchange Act’s own command that SROs provide “a fair procedure.” The result is strange but stable—FINRA provides constitutionally adequate process because federal law requires it to, and that compliance is precisely what allows the courts to avoid deciding whether the Constitution requires it too.

The two doctrines interact in a manner that should trouble anyone sketching an AI FINRA on a whiteboard. As Sunshine Anthracite and Consumers’ Research teach, the accepted cure for a private nondelegation problem is subordination: the private body may act as an aid to a public agency that retains ultimate authority over its work. But ever greater subordination inches the private regulator closer to qualifying as a state actor. The tighter the government’s grip on the private regulator—the more its rules require agency signoff, the more its sanctions await agency review—the harder it becomes to maintain that the regulator is meaningfully private and, in theory, flexible and nimble. Loosen the harness and Carter Coal looms; tighten it and the full suite of constitutional constraints attaches, along with the bureaucratic accretion chronicled in the next section. An AI FINRA would be squeezed from both directions. The evolution of private governance in the securities industry illustrates this Catch-22.

Learning from the Federalization of FINRA

No institution better reveals that squeeze than the one the labs propose to copy. An emphasis on procedural protections has defined the evolution of self-regulation under FINRA and the SEC. The Securities Exchange Act of 1934 marked the high-water mark of exchange autonomy—and, correspondingly, the low point of SEC oversight. Each exchange registered with the SEC and pledged to enforce the Act and its own member-adopted rules. The SEC had the ability to revoke an exchange’s registration—a severe and significant step, but the agency could only alter exchange rules that pertained to specific categories.

A functional approach was the overriding design consideration in launching the first iteration of SEC oversight. The Act afforded private actors significant discretion given fears that direct government regulation would prove “ineffective, if not impossible.” William O. Douglas—then the SEC’s chairman, later a Justice—explained, “The exchanges take the leadership with the government playing a residual role. Government would keep the shotgun, so to speak, behind the door, loaded, well oiled, cleaned, ready for use but with the hope it would never have to be used.” Exchanges could adopt any rule not inconsistent with the Act. If an exchange took disciplinary action against a member for violating one such rule, the SEC had limited recourse to evaluate that decision.

Experience proved that the original Act’s hands-off approach was insufficient. SEC leadership successively made use of the Commission’s reserve powers to more directly shape the regulatory space. Congress responded by amending the Act in 1975. Its aim was to “ensure that there is no gap between self-regulatory performance and regulatory need.”

Procedural checks were the means to achieve that aim. Whereas the prior regulatory framework involved the SEC as a backstop, the amendments made it a participant. The Commission can now alter exchange rules and promulgate its own without going through the self-regulatory organizations (SROs)—the exchanges and NASD then, FINRA chief among them today. However, these steps come with procedural speedbumps: notice and comment before any new rule, a more thorough process before direct enforcement, and SEC clearance before certain exchange-initiated changes take effect. The net outcome was a more “cooperative” arrangement between the SEC and SROs.

It’s unclear whether these and related developments empowering the SEC align with the aims of an audited self-regulatory approach: technical matters left to experts, disputes routed to a neutral, expert arbiter with streamlined processes, uniformity where it’s needed, and regulatory competition where it’s beneficial.

This aspiration has not been realized by the SEC. Commentators have flagged the “federalization of self-regulation” as a modern trend. Slowly but surely and sometimes substantially, such as in the aftermath of a scandal, the SEC has reduced the scope of authority of the SROs. Regulatory requirements, including periodic information disclosures, that once were overseen exclusively by SROs have now become the domain of the SEC. The Commission has expanded its authority through placing pressure on SROs to adjust their rules. In some instances, according to Professor Onnig Dombalagian, these rules-by-coercion have effectively expanded the SEC’s authority beyond statutory limits. This is far from efficient. Rather than entrust SROs to govern effectively within their comparative advantage, the SEC now duplicates some of those tasks. On whole, since the 1930s, the Commission has “cajoled” the exchanges in ways that were likely not anticipated by those who rallied behind the Act. 

A return to the original posture of the SEC and SROs is unlikely. The courts, meanwhile, are being asked whether even the current posture goes too far. In Alpine Securities Corp. v. FINRA, the D.C. Circuit held in late 2024 that FINRA could not expel a member firm through its expedited proceedings before the SEC reviewed the merits—expulsion from FINRA being, as a practical matter, expulsion from the securities industry itself. The panel found that Alpine was likely to succeed on its private nondelegation claim to that extent, though it declined to decide whether FINRA’s hearing officers are unconstitutionally insulated from presidential appointment and removal. Judge Walker would have gone further and halted the expedited proceeding in its entirety.

A second front has opened in the Fourth Circuit. Frank Black and his North Carolina brokerage have been contesting a FINRA disciplinary action since 2015: four years of investigation, four years awaiting the SEC’s decision on appeal, a partial remand, a second round before FINRA and the SEC, and a petition dismissed in January 2025 because the SEC’s order was not yet final. Only in 2026—more than a decade in—did the case return to the Fourth Circuit on the merits. As noted by the New Civil Liberties Alliance (NCLA), which filed an amicus brief in the renewed appeal, FINRA falls short of many of the factors outlined by Freedman and Liebmann.

The harness that traditionally constrains agencies is absent when it comes to FINRA. The Administrative Procedure Act, the Sunshine Act, and the Freedom of Information Act all stop short of reaching FINRA. None of FINRA’s staff swear an oath to uphold the Constitution. FINRA officials are neither appointed nor removable by government officials (except in very few situations). Nor does it rely on any government funding. This financial independence, though in some ways an attribute, further distances FINRA from popular control. As the NCLA alleges, FINRA is “exempt from the most basic checks, balances, and transparency requirements designed to protect individuals from overzealous governmental coercion and punishment.”

Assuming that FINRA does stand on constitutionally shaky ground, calls to emulate it in a domain that has even fewer stakeholders and even greater economic and national security concerns warrant tremendous scrutiny.

The remaining question is how any FINRA for AI can avoid the bureaucratization that has undermined the efficiency of self-regulation pursuant to the Exchange Act while still adhering to constitutional safeguards.

Regulatory Imagination, Required

The answer is likely that it cannot. The desire for a FINRA for AI that moves at or near the pace of AI development runs aground when forced to align with procedural due process requirements under the Constitution.

Imagine a FINRA for AI concludes that a frontier model does not satisfy the body’s safety requirements, and the lab—like Alpine Securities before it—races to district court with a constitutional challenge. Expedited briefing occurs over a period of several days. The district court sides with the AI FINRA. The lab—having spent millions, if not billions, of dollars training that model—seeks an appeal. In the interim, its domestic rival and foreign competitors have released new models. The petitioning lab starts to see customers switch to other models. The circuit court requires weeks to sort through the arguments. AI FINRA prevails again. The lab appeals to the Supreme Court. The justices evaluate the case for at least a month. At this point, the lab is now well behind the frontier. The Supreme Court ultimately reverses the circuit court’s decision but remands the case for additional consideration of several key issues.

This hypothetical scenario could carry on for several months, if not years. Nor is this speculation. Frank Black waited more than ten years for a court to hear the merits of his dispute with FINRA—and his case involved roughly $70,000 in sanctions, not a frontier model.

The tension between regulatory flexibility and procedural due process is resolved, over time and with remarkable consistency, in favor of the latter. So long as that is the case, any regulatory regime that relies on existing institutions and timelines will necessarily set back an AI lab that contests a determination by the relevant body. The upshot is that individuals calling for a FINRA-like model for AI must exercise greater regulatory imagination.

For one, the AI FINRA must include additional elements of political accountability. The decisions rendered by that body are too consequential to leave to individuals with such an attenuated tie to the public. Additionally, the agency charged with serving as the backstop to the AI FINRA must not overstep. The odds of frontier AI governance becoming self-regulation-in-name-only can be reduced by specifying the decisions that must remain with the self-regulation organization or organizations.

What might that imagination yield? Start with the personnel. Justice Alito, concurring in Department of Transportation v. Association of American Railroads, stressed that the Constitution’s structural protections presume regulators who are appointed, removable, and bound by oath. An AI FINRA could borrow the point wholesale: public board members nominated by the President and confirmed by the Senate, officers who swear the oath, leadership removable by the overseeing agency for cause, and conflict rules that keep anyone with a pecuniary stake away from adjudications. Notably, none of these elements slows the body’s technical work. These design tweaks merely constrain who decides rather than at what pace and based on which factors.

The requisite speed can be established in another part of the regulatory design: the appeals architecture. Congress knows how to make courts move when it wants to. It has convened three-judge district courts with direct appeal to the Supreme Court for election-law disputes. It has imposed statutory deadlines on agency action and channeled sensitive matters to tribunals that decide in days rather than years. An AI FINRA statute could do the same: review of an exclusion decision by the overseeing agency within a fixed number of days, a single appeal to a designated circuit on an expedited timetable, and a status quo pending appeal set by statute rather than by ad hoc stay motions. Because FINRA already provides notice, hearings, and neutral adjudicators, no court has ever needed to decide whether the Constitution compels it to. An AI FINRA should explicitly adopt those characteristics from the outset: build the process in at the front end—disclosed evidence, reasoned decisions, genuine hearings—so that judicial review, when it comes, is narrow and fast.

Conclusion

The labs want a regulator that moves at the speed of their release cycles. The Constitution wants regulators who answer to the public. Ninety years of securities regulation teach that these demands do not coexist so much as take turns winning—and that the general war has tilted in the Constitution’s favor. Every scandal brings more federal oversight; every lawsuit brings more procedure; and the “self” in self-regulation grows more ceremonial with each battle. The Exchange Act began as an experiment in keeping the shotgun behind the door. Today the Commission stands in the room, and the courts are being asked whether even that arrangement is constitutional.

Nor should anyone expect an AI version to fare better. Congress’s most recent attempt at this model governs horseracing, and it has produced three trips to the Fifth Circuit, a Supreme Court remand, and a circuit split still awaiting resolution. A frontier lab facing exclusion will litigate with resources and urgency that no horsemen’s association can match. The day will come sooner than later that an AI FINRA gets challenged in court, justifying outsized attention to heading off those concerns at this design stage.

Audited self-regulation for AI is not impossible. Yet, history and recent case law developments makes the version sketched in the white papers—fast, expert, independent, and only loosely tethered to the government—unavailable. Congress can delegate, but it cannot delegate and walk away, especially when the questions are this important.

Kevin Frazier is the AI Innovation and Law Fellow at the University of Texas at Austin School of Law. He studies how to design regulatory ecosystems that accelerate AI adoption and diffusion.