A plain-language breakdown of how the Gramm-Leach-Bliley Act and the FTC Safeguards Rule apply to AI platforms your employees are using today — and where the exposure points are.
If your organization is a bank, credit union, mortgage lender, investment advisor, insurance company, or any other entity subject to the Gramm-Leach-Bliley Act — GLBA applies to your AI tools. Not in some abstract future sense. Right now. The employees using ChatGPT, Microsoft Copilot, and other AI tools to handle customer inquiries, summarize documents, or draft communications are creating GLBA exposure that most institutions haven't addressed.
GLBA — the Gramm-Leach-Bliley Act — is a federal law that requires financial institutions to protect the privacy and security of their customers' nonpublic personal information (NPI). NPI includes names, addresses, account numbers, Social Security numbers, income information, credit history, and essentially any information collected in the course of providing financial services.
GLBA has three main components:
For AI tools, the Safeguards Rule is the primary concern. It requires covered institutions to develop, implement, and maintain a comprehensive information security program — and that program must now explicitly address AI.
In October 2021, the FTC finalized a major update to the Safeguards Rule (16 CFR Part 314). The amended rule went into effect on June 9, 2023. If your institution hasn't reviewed its information security program against the updated requirements, it's overdue.
The updated Safeguards Rule added several requirements that directly affect how financial institutions must govern AI tool use:
| Requirement | What it means for AI tools | Risk if ignored |
|---|---|---|
| Qualified Individual §314.4(a) |
You must designate a named individual responsible for your information security program. AI governance is part of that program. | High — examiners will ask for this name |
| Risk Assessment §314.4(b) |
Must identify and assess internal and external risks to NPI. AI tools are an external processing risk that must be assessed. | High — AI tools are an obvious gap |
| Access Controls §314.4(c)(1) |
Limit access to NPI to users with a legitimate business need. Employees feeding NPI into AI tools may be circumventing access controls. | High — very common in practice |
| Service Provider Oversight §314.4(f) |
Select and retain service providers that maintain appropriate safeguards. AI vendors (OpenAI, Microsoft, Anthropic, etc.) qualify as service providers. | Medium — requires vendor review |
| Monitoring & Testing §314.4(d) |
Continuously monitor and test the effectiveness of key controls. AI tool usage should be included in this monitoring. | Medium — often overlooked |
| Incident Response Plan §314.4(h) |
Maintain a written incident response plan. AI-related incidents (data sent to unauthorized AI system, AI-generated fraud, etc.) must be covered. | High — required by rule |
The exposure isn't hypothetical. Here are the most common ways AI tools create GLBA risk at financial institutions today:
The most immediate risk. An employee pastes a customer's loan application, account summary, or correspondence into ChatGPT to get a summary, draft a response, or analyze the content. In most cases, the AI platform the employee is using is a consumer-grade product with no data processing agreement, no NPI-specific protections, and potentially using inputs to train future models.
Employees don't wait for IT approval. AI tools are consumer-grade products that employees can access on their personal devices, through browser extensions, or via free accounts set up with a personal email. If you don't have an approved AI tool program, employees are using unapproved tools — and you have no visibility into what NPI is flowing where.
Even when an institution officially adopts an enterprise AI tool (Microsoft 365 Copilot, for example), many fail to review the data handling implications. Enterprise AI tools are generally safer than consumer counterparts — but "safer" isn't the same as "compliant." You need to review what the vendor does with your data, where it's processed, and what your contractual protections are.
When an employee uses AI to draft a customer communication and sends it without adequate review, you have an accuracy risk and potentially a disclosure risk. AI tools can hallucinate information, including inventing account details, regulatory requirements, or product features. A compliance-sensitive customer communication drafted by AI and sent without review is a meaningful risk.
This is the part most institutions miss. The GLBA Safeguards Rule requires covered institutions to:
When your employees use AI tools — even informally — those AI providers become de facto service providers processing your customers' NPI. The Safeguards Rule's service provider requirements apply.
Before approving any AI tool for use with NPI (or even general business use), your vendor assessment should verify:
Major AI vendors (Anthropic, OpenAI, Microsoft) do have enterprise tiers with DPAs and stronger data protections. The key is ensuring your institution is on those tiers — not consumer accounts — and has reviewed and executed the appropriate agreements.
A GLBA-compliant AI policy for a financial institution needs to address each of the Safeguards Rule requirements that AI touches. At minimum, your AI Acceptable Use Policy should:
Employees need to know what counts as NPI — not in legal terms, but in practical terms. "Don't paste anything with a customer's name and account number" is concrete. "Do not input nonpublic personal information" is not.
Maintain an approved AI tools list. Anything not on the list is unapproved. Employees who want to use an unapproved tool should have a clear process to request approval.
Not a binary prohibition. Most institutions can approve AI tools for internal purposes (non-NPI tasks) while restricting NPI input. Define the line clearly.
The GLBA Safeguards Rule requires a "qualified individual" for the security program. Your AI policy should identify who is responsible for AI governance specifically — even if that's the same person as your overall information security officer.
What should an employee do if they realize they accidentally input NPI into an unapproved AI tool? The policy should define a reporting process, and that process should connect to your existing incident response plan.
AI tools and regulations both change fast. The policy should be reviewed at minimum annually — and whenever a significant new regulation, enforcement action, or AI capability emerges that changes the risk landscape.
Use this to assess your current posture. Every "No" is a gap to address.
The BulldogAI AI Readiness Audit takes 2 minutes and identifies your specific GLBA exposure points. Full results with no email wall.
Take the Free Audit →