Guide · Regulatory Compliance

What GLBA Means for Your AI Tools

A plain-language breakdown of how the Gramm-Leach-Bliley Act and the FTC Safeguards Rule apply to AI platforms your employees are using today — and where the exposure points are.

In this guide

  1. What GLBA requires (the short version)
  2. The 2023 Safeguards Rule update and what changed
  3. Where AI tools create GLBA exposure
  4. AI vendors as "service providers" under GLBA
  5. What your AI policy needs to say
  6. Quick compliance checklist

If your organization is a bank, credit union, mortgage lender, investment advisor, insurance company, or any other entity subject to the Gramm-Leach-Bliley Act — GLBA applies to your AI tools. Not in some abstract future sense. Right now. The employees using ChatGPT, Microsoft Copilot, and other AI tools to handle customer inquiries, summarize documents, or draft communications are creating GLBA exposure that most institutions haven't addressed.

1. What GLBA Requires (The Short Version)

GLBA — the Gramm-Leach-Bliley Act — is a federal law that requires financial institutions to protect the privacy and security of their customers' nonpublic personal information (NPI). NPI includes names, addresses, account numbers, Social Security numbers, income information, credit history, and essentially any information collected in the course of providing financial services.

GLBA has three main components:

For AI tools, the Safeguards Rule is the primary concern. It requires covered institutions to develop, implement, and maintain a comprehensive information security program — and that program must now explicitly address AI.

2. The 2023 Safeguards Rule Update

In October 2021, the FTC finalized a major update to the Safeguards Rule (16 CFR Part 314). The amended rule went into effect on June 9, 2023. If your institution hasn't reviewed its information security program against the updated requirements, it's overdue.

Note on scope: The FTC's Safeguards Rule applies to "financial institutions" as defined by GLBA — which is broader than just banks. Mortgage brokers, auto dealers that arrange financing, payday lenders, tax preparers, and many others are covered. If you handle consumer financial information, you're likely covered.

Key changes in the 2023 update relevant to AI

The updated Safeguards Rule added several requirements that directly affect how financial institutions must govern AI tool use:

Requirement What it means for AI tools Risk if ignored
Qualified Individual
§314.4(a)
You must designate a named individual responsible for your information security program. AI governance is part of that program. High — examiners will ask for this name
Risk Assessment
§314.4(b)
Must identify and assess internal and external risks to NPI. AI tools are an external processing risk that must be assessed. High — AI tools are an obvious gap
Access Controls
§314.4(c)(1)
Limit access to NPI to users with a legitimate business need. Employees feeding NPI into AI tools may be circumventing access controls. High — very common in practice
Service Provider Oversight
§314.4(f)
Select and retain service providers that maintain appropriate safeguards. AI vendors (OpenAI, Microsoft, Anthropic, etc.) qualify as service providers. Medium — requires vendor review
Monitoring & Testing
§314.4(d)
Continuously monitor and test the effectiveness of key controls. AI tool usage should be included in this monitoring. Medium — often overlooked
Incident Response Plan
§314.4(h)
Maintain a written incident response plan. AI-related incidents (data sent to unauthorized AI system, AI-generated fraud, etc.) must be covered. High — required by rule

3. Where AI Tools Create GLBA Exposure

The exposure isn't hypothetical. Here are the most common ways AI tools create GLBA risk at financial institutions today:

Customer NPI entering AI platforms

The most immediate risk. An employee pastes a customer's loan application, account summary, or correspondence into ChatGPT to get a summary, draft a response, or analyze the content. In most cases, the AI platform the employee is using is a consumer-grade product with no data processing agreement, no NPI-specific protections, and potentially using inputs to train future models.

This is happening right now at your institution. Multiple studies have found that 60-80% of employees at financial institutions have used consumer AI tools at work. A significant portion have used them with customer or business-sensitive data. Unless you have a policy prohibiting this and can demonstrate employee training, you have an active GLBA exposure.

Shadow AI (tools IT doesn't know about)

Employees don't wait for IT approval. AI tools are consumer-grade products that employees can access on their personal devices, through browser extensions, or via free accounts set up with a personal email. If you don't have an approved AI tool program, employees are using unapproved tools — and you have no visibility into what NPI is flowing where.

AI vendor data handling

Even when an institution officially adopts an enterprise AI tool (Microsoft 365 Copilot, for example), many fail to review the data handling implications. Enterprise AI tools are generally safer than consumer counterparts — but "safer" isn't the same as "compliant." You need to review what the vendor does with your data, where it's processed, and what your contractual protections are.

AI-generated outputs without review

When an employee uses AI to draft a customer communication and sends it without adequate review, you have an accuracy risk and potentially a disclosure risk. AI tools can hallucinate information, including inventing account details, regulatory requirements, or product features. A compliance-sensitive customer communication drafted by AI and sent without review is a meaningful risk.

4. AI Vendors as "Service Providers" Under GLBA

This is the part most institutions miss. The GLBA Safeguards Rule requires covered institutions to:

When your employees use AI tools — even informally — those AI providers become de facto service providers processing your customers' NPI. The Safeguards Rule's service provider requirements apply.

Practical implication: If an employee pastes NPI into a consumer AI tool (ChatGPT's free tier, for example), there is no data processing agreement, no GLBA-compliant contractual safeguards, and no oversight mechanism. That's a direct Safeguards Rule violation. The fix is either (a) prohibit NPI from entering that tool with enforcement mechanisms, or (b) move to an enterprise tier with appropriate DPA terms.

What to require from AI vendors

Before approving any AI tool for use with NPI (or even general business use), your vendor assessment should verify:

Major AI vendors (Anthropic, OpenAI, Microsoft) do have enterprise tiers with DPAs and stronger data protections. The key is ensuring your institution is on those tiers — not consumer accounts — and has reviewed and executed the appropriate agreements.

5. What Your AI Policy Needs to Say

A GLBA-compliant AI policy for a financial institution needs to address each of the Safeguards Rule requirements that AI touches. At minimum, your AI Acceptable Use Policy should:

Define the scope of NPI

Employees need to know what counts as NPI — not in legal terms, but in practical terms. "Don't paste anything with a customer's name and account number" is concrete. "Do not input nonpublic personal information" is not.

Designate approved and prohibited tools

Maintain an approved AI tools list. Anything not on the list is unapproved. Employees who want to use an unapproved tool should have a clear process to request approval.

Define what NPI can enter which tools

Not a binary prohibition. Most institutions can approve AI tools for internal purposes (non-NPI tasks) while restricting NPI input. Define the line clearly.

Name an AI governance owner

The GLBA Safeguards Rule requires a "qualified individual" for the security program. Your AI policy should identify who is responsible for AI governance specifically — even if that's the same person as your overall information security officer.

Cover incident reporting

What should an employee do if they realize they accidentally input NPI into an unapproved AI tool? The policy should define a reporting process, and that process should connect to your existing incident response plan.

Establish a review cadence

AI tools and regulations both change fast. The policy should be reviewed at minimum annually — and whenever a significant new regulation, enforcement action, or AI capability emerges that changes the risk landscape.

6. Quick GLBA AI Compliance Checklist

Use this to assess your current posture. Every "No" is a gap to address.

Tip: This checklist maps directly to the BulldogAI free audit questions. If you want a scored assessment of your institution's posture — with your top gaps identified — take the 2-minute audit at bulldogai.ai.

See Where Your Gaps Are — Free

The BulldogAI AI Readiness Audit takes 2 minutes and identifies your specific GLBA exposure points. Full results with no email wall.

Take the Free Audit →