Key takeaways
- The FTC's Gramm-Leach-Bliley Act Safeguards Rule requires financial institutions — a definition that includes many insurance agencies, lenders, and advisors — to maintain a written information security program protecting customer information.
- The Safeguards Rule doesn't mention AI by name, but its administrative, technical, and physical safeguard requirements apply to any system, including an AI tool, that processes customer financial information.
- A breach-notification requirement has been in effect since May 2024 — if an AI tool is part of how a breach happens, that notification clock still starts.
- Vendor oversight is a named requirement of the Safeguards Rule, which means an AI vendor handling customer financial data isn't exempt from the due-diligence your firm already owes its other service providers.
- This guide is general information, not legal advice — GLBA compliance programs should be reviewed by qualified counsel or a compliance officer.
A financial advisor's assistant uploads a client's account statement to an AI tool to help draft a summary letter. An insurance agent pastes a policyholder's claim details into a chatbot to write a status update. Neither action is unusual anymore — and neither one is automatically covered by the security program most firms already have in place for everything else they do with customer data.
This guide covers the GLBA Safeguards Rule as it applies to financial and insurance offices adopting AI tools, and where the rule's existing requirements already reach into AI use even without saying "AI" anywhere in the text.
What the Safeguards Rule requires
The Gramm-Leach-Bliley Act's Safeguards Rule, enforced by the FTC, applies to financial institutions — a term the FTC defines broadly to include not just banks, but companies that offer financial products or services: lenders, financial and investment advisors, insurance agencies, and similar businesses, including auto dealers that arrange financing. If your business fits that definition, the rule requires you to develop and maintain a written information security program with administrative, technical, and physical safeguards for customer information.
It also requires clear disclosure of your information-sharing practices, opt-out rights for customers regarding certain data sharing, and — as of a requirement that took effect in May 2024 — notification when a security event affecting customer information crosses a defined threshold.
Where AI tools intersect with an existing security program
The Safeguards Rule's current text doesn't call out AI specifically. What it does is set a broad, technology-neutral requirement: any system handling customer information needs administrative, technical, and physical safeguards, whatever that system happens to be. An AI tool that a staff member uses to draft correspondence, summarize a file, or analyze account data is, functionally, a system handling customer information the moment real customer data goes into it — and it falls under the same obligation as your core banking or policy-management software.
That has a few concrete implications for a financial or insurance office bringing AI into daily work:
- Access controls apply. If your security program limits who can access customer account data, that same limit should extend to who can paste that data into an AI tool.
- Vendor oversight applies. The Safeguards Rule requires oversight of service providers that handle customer information — an AI vendor processing customer financial data is a service provider under that same lens, not a special exception.
- Breach notification applies. If customer information is exposed through an AI tool — sent to the wrong recipient, stored insecurely by a vendor, or otherwise mishandled — that can trigger the same notification obligation as any other type of breach.
"We're just using a free tool, not a paid vendor contract" doesn't change the underlying analysis. If customer financial information goes into that tool, the tool is processing customer information under the Safeguards Rule's framework — free or paid.
Vendor due diligence for AI tools specifically
The Safeguards Rule expects financial institutions to select service providers capable of maintaining appropriate safeguards, and to require those safeguards by contract. For an AI vendor, that translates into a specific set of questions before any customer financial data goes near the tool:
| Question | Why it matters under the Safeguards Rule |
|---|---|
| Does the vendor's contract include data-security commitments? | The Rule expects contractual safeguards with service providers, not just informal trust |
| Is customer data used to train the vendor's AI models? | Affects whether the data effectively leaves your control indefinitely |
| What access controls exist on the vendor's side? | Your access-control obligations don't stop at your own systems — they extend through your vendors |
| How does the vendor handle a data incident on their end? | Your breach-notification clock may depend on when the vendor tells you something went wrong |
| Can the vendor support your audit or exam requirements? | Regulators may ask how AI tools fit into your existing information security program |
These questions sit inside a broader vendor-vetting process — see our full AI vendor security checklist for the complete 20-question version applicable to any AI purchase, financial services or otherwise.
Practical controls for financial and insurance offices
- Add AI tools explicitly to your written information security program, rather than leaving them as an unaddressed gap.
- Restrict which AI tools staff can use with real customer account, policy, or claims data — an approved-tools list, as covered in our approved AI tools guide, closes this gap directly.
- Require redaction of account numbers before customer data goes into any AI drafting task — see our guide to protecting customer PII for a redaction process your team can use.
- Include AI vendors in your existing service-provider risk assessment cycle, not a separate, informal process.
Notes for financial services and insurance specifically
Financial advisors and lenders tend to have the highest exposure around account statements, credit applications, and portfolio summaries. Insurance agencies see it most in claims correspondence and policy servicing, where a customer's full policy number and claim history often sit together in one document — exactly the combination that shouldn't go into a general AI tool unredacted. See our financial services and insurance agencies pages for how we tailor a security-program addendum for each.
Where AI fits in your annual risk assessment
The Safeguards Rule expects a written information security program built around a periodic risk assessment — identifying where customer information lives, what could go wrong, and what controls address that risk. AI tools deserve their own line item in that assessment, not an afterthought bolted on separately. A useful approach is to walk through your actual AI-touching workflows the same way you'd walk through any other system: where does customer data enter the tool, who can access it while it's there, what happens to it after the task is done, and what would happen if that data were exposed.
For a small financial or insurance office, this doesn't need to be an elaborate exercise. A short table — tool name, what customer data it touches, whether a BAA or data processing agreement is in place, and the date it was last reviewed — covers most of what an examiner or auditor will actually ask to see, and it's far easier to produce on short notice than trying to reconstruct the answer from memory during an actual exam.
Training the team that touches customer accounts daily
Client-facing staff — loan officers, account representatives, claims adjusters — are the ones most likely to reach for an AI tool mid-task, often without thinking of it as a security decision at all. A short, recurring training that covers which AI tools are approved for account and policy data, and the redaction habit of stripping account numbers before pasting anything into a drafting tool, does more to reduce real exposure than a policy document nobody reads after onboarding.
Common mistakes
- Treating AI as outside the existing security program. The Safeguards Rule doesn't need a separate "AI section" to apply — it already covers any system touching customer information.
- Skipping vendor due diligence because a tool is "just for drafting." If real customer data goes in, the vendor is a service provider under the Rule regardless of the task's purpose.
- No one designated to answer AI-vendor questions. Assign this to whoever already owns your information security program — don't leave it as everyone's job and no one's.
- Assuming a free tool has no obligations attached. Cost has no bearing on whether the Safeguards Rule's expectations apply to how customer data is handled.
◆ Small Business AI Kickstart
Get AI ready today.
Before it's too late.
yforest AI Labs comes to your company, trains your team, and ships your first tools.
FAQ
Does the GLBA Safeguards Rule mention AI specifically?
No. It sets technology-neutral requirements for safeguarding customer information, which apply to any system handling that data, including an AI tool, even though AI isn't named in the rule's text.
Which businesses does the Safeguards Rule apply to?
Financial institutions as defined broadly by the FTC — including lenders, financial and investment advisors, insurance agencies, and similar businesses that offer financial products or services.
Is a free AI tool exempt from vendor due-diligence requirements?
No. If real customer financial information goes into it, the tool is functioning as a service provider under the Safeguards Rule's framework, regardless of cost.
Does a security incident involving an AI tool trigger breach notification?
It can. The Safeguards Rule's notification requirement, in effect since May 2024, applies to a qualifying security event affecting customer information, whatever system that information was processed on.
Is this guide legal or compliance advice?
No. This is general information, not legal advice. Have your compliance officer or attorney review your specific information security program.
Sources
This guide is general information, not legal advice. Have a qualified attorney review any policy before you adopt it.