RatedWithAI

RatedWithAI

Accessibility scanner

Financial PrivacyAugust 13, 2026

Your AI Vendor Became a Service Provider the Moment Someone Pasted a Loan File

The FTC Safeguards Rule doesn't care that the tool was free, that IT never approved it, or that the data left in a chat window instead of an API call. If customer information reached a third party, you owe diligence, a contract, and ongoing assessment — and the breach clock is 30 days.

30 days
Maximum window to notify the FTC after discovering a notification event affecting 500+ consumers
Activity
Not charter — what makes you a 'financial institution' under the FTC's version of the rule
Public
FTC breach notices are published, so the incident becomes a discoverable business fact

The Scope Problem: You Are Probably Covered

Most companies that get caught by the Safeguards Rule never thought of themselves as financial institutions. The FTC defines the term by what you do, borrowing the Bank Holding Company Act's concept of activities that are financial in nature. That sweeps in a long list of businesses that would describe themselves as retailers or professional services firms:

COVERED
Auto and equipment dealers
Arranging or facilitating customer financing — the single largest covered population under the FTC's rule
COVERED
Mortgage brokers and lenders
Originating, brokering, or servicing residential loans
COVERED
Tax preparers and accountants
Preparing returns and holding income, dependent, and account data for individuals
COVERED
Collection agencies
Servicing consumer debt and holding account-level obligation data
COVERED
Non-SEC-registered investment advisers
State-registered and exempt advisers fall to the FTC rather than the SEC's own safeguards regime
COVERED
Finders and lead generators
Bringing together buyers and sellers of financial products, including many fintech marketplaces

There is a relief valve: institutions holding customer information on fewer than 5,000 consumers are exempt from some of the heavier requirements — the written risk assessment, the annual report to the board, continuous monitoring or penetration testing, and the incident response plan. They are not exempt from the rest, and notably not from the service provider oversight duty that AI adoption puts under pressure.

What Counts as Customer Information Inside an AI Workflow

GLBA protects nonpublic personal information: personally identifiable financial information you obtain in connection with providing a financial product or service, plus any list or grouping derived from it. In an AI workflow, that definition catches more than teams expect.

  • The prompt. An applicant's name, income, and credit situation pasted into a summarization tool is customer information in transit.
  • The retrieval index. Embeddings built from customer files are a derived grouping — vectorization is not de-identification, since the index exists precisely to return the underlying record.
  • The output. A model-generated risk narrative about a named applicant is new customer information you now hold and must protect.
  • The logs. Prompt and completion logs retained by the vendor for abuse monitoring are copies of customer information sitting in a system you do not control.
  • The fact of the relationship. Even without dollar figures, the fact that a named person is your customer is protected.

The Oversight Duty, Applied to AI

The Safeguards Rule's service provider provision is short and has three moving parts: select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them based on their risk. AI vendors stress all three, because the data handling terms change more often than the contract renews.

1. Selection Diligence
  • Identify every subprocessor in the chain, including the foundation model provider behind a wrapper product
  • Confirm in writing whether inputs or outputs are used to train or improve models, and whether that is a default or an opt-out
  • Determine prompt and completion retention periods, including abuse-monitoring logs held outside the main data store
  • Establish data residency and whether inference can be routed to another region during capacity events
  • Verify encryption in transit and at rest, and whether the vendor can decrypt your content
  • Ask what happens to embeddings and fine-tuned weights on termination, not just to raw files
2. Contract Terms
  • Bind the vendor to implement and maintain safeguards for customer information, not merely to 'industry standard security'
  • Prohibit training on your data without separate written consent, and make it survive product changes
  • Require notice of new subprocessors with a right to object before they go live
  • Set an incident notification window short enough to leave you room inside your own 30-day FTC clock
  • Preserve audit or assessment rights, or accept an evidence substitute you have actually read
  • Specify deletion and return obligations on termination with a defined completion deadline
3. Periodic Assessment
  • Re-review data handling terms on a schedule, because AI vendors revise them between renewals
  • Track model and endpoint changes that move your data to a different provider
  • Re-check that opt-outs from training are still enabled after major product releases
  • Confirm the vendor's own security report still covers the system your data flows through
  • Reassess when your usage expands from a pilot team to a production workflow

The Requirements AI Adoption Most Often Breaks

The rule's substantive controls were written for conventional systems. Each one has a specific failure mode once a model sits in the middle of the workflow.

Access controls limited to what each role needs
Breaks when: A retrieval assistant indexed a shared drive and now answers questions using files the asking employee could never have opened directly
Inventory of systems holding customer information
Breaks when: The inventory lists the CRM and the loan origination system, but not the six AI tools staff signed up for with company email
Multi-factor authentication for anyone accessing information systems
Breaks when: The AI vendor's console is protected by a shared password because the seat tier that supports SSO costs more
Encryption of customer information in transit and at rest
Breaks when: Content is encrypted end to end, but prompt logs retained for safety review sit in a separate store outside that guarantee
Secure disposal within two years of last use
Breaks when: Deleting the source documents leaves the derived embeddings and any fine-tuned artifacts intact
Change management procedures
Breaks when: The vendor silently swaps the underlying model to a different provider and the subprocessor list changes without a ticket
Monitoring of authorized user activity
Breaks when: Nobody logs which customer records were surfaced through the assistant, so post-incident scoping is guesswork

The 30-Day Notification Trap

Since the reporting amendment took effect, non-bank financial institutions must notify the FTC of a notification event — unauthorized acquisition of unencrypted customer information affecting at least 500 consumers — as soon as possible and no later than 30 days after discovery. Two details matter more than the deadline itself.

First, the clock starts at discovery, and discovery is imputed: knowledge held by any employee other than the person who caused the event counts. A support engineer noticing that an AI integration returned another customer's data starts your clock, even if the incident report reaches leadership three weeks later.

Second, the notice is published. The FTC posts these filings, which means the incident becomes a permanent, searchable business fact that counterparties and plaintiffs' firms can find. That changes the calculus on prevention spending in a way private breach regimes do not.

Shadow AI Is the Live Exposure

The most common Safeguards gap in 2026 is not a failed control — it is an unlisted system. Staff adopt AI tools with a work email and a personal credit card, and those tools never enter the inventory, never get a contract, and never get assessed. The rule does not distinguish between a vendor procurement approved and a vendor an employee found. Both are service providers receiving customer information. Start your remediation with an expense-report and SSO-log sweep, not with a policy document.

GLBA Is Not the Only Layer

GLBA compliance is frequently mistaken for a complete answer on financial data. It is one layer of several that apply to the same AI workflow:

  • State privacy laws generally exempt data covered by GLBA, but the exemption is often data-level rather than entity-level — your marketing and web analytics data is not shielded by it.
  • Fair lending rules apply independently. A model that is perfectly secure can still produce a disparate impact problem under ECOA.
  • The privacy notice rule under GLBA governs what you told customers about sharing. Routing data to an AI vendor may exceed the sharing described in a notice written years ago.
  • Contractual flow-downs from funders, warehouse lenders, and card networks often impose stricter vendor terms than the rule itself.

Frequently Asked Questions

Our AI tool is only used internally. Does that change anything?

No. The Safeguards Rule regulates the security of customer information wherever it sits, and an internal-only tool still receives that information as a service provider unless it runs entirely on infrastructure you control. Internal use narrows the disclosure risk to customers, but the inventory, access control, encryption, disposal, and vendor assessment obligations are unchanged.

Does the exemption for institutions under 5,000 consumers get us off the hook?

Partially. The reduced-requirement exemption removes the written risk assessment, the incident response plan, continuous monitoring or annual penetration testing plus semiannual vulnerability assessments, and the annual written report to your governing body. It does not remove the requirement to designate a qualified individual, implement access controls and encryption, oversee service providers, or dispose of customer information securely. Small tax and mortgage shops adopting AI tools still owe the vendor oversight duty.

Is a vendor's promise not to train on our data enough?

It is necessary but not sufficient, and it is also unstable. Training is one of several uses; retention for abuse monitoring, human review of flagged content, and subprocessor routing all persist even under a no-training commitment. Get the commitment in the contract rather than the marketing page, and re-verify it after major product releases, because default settings change and enterprise tiers sometimes gate the setting you relied on.

Who should the 'qualified individual' be if AI is now in the workflow?

The rule requires you to designate a single qualified individual responsible for overseeing and enforcing the information security program, and that person can be an employee or an affiliate or service provider. What AI adoption changes is the reporting surface: whoever holds the role needs visibility into tool procurement and expense approvals, not just into infrastructure, because the systems that create exposure are now bought by business teams rather than by IT.

We use a bank partner. Doesn't their compliance cover us?

Their compliance covers their obligations. If you hold customer information yourself, you have your own program obligation, and your bank partner's oversight of you typically adds contractual requirements on top rather than substituting for the rule. In practice, sponsor banks are now asking direct questions about AI vendors and training use during periodic reviews, so an unanswered vendor inventory becomes a partnership problem before it becomes a regulatory one.

Start With the Inventory, Not the Policy

Every Safeguards obligation that AI breaks traces back to the same root cause: a system holding customer information that nobody wrote down. You cannot contract with a vendor you don't know you have, assess a data flow you haven't mapped, or scope an incident across tools that never entered the register.

Pull the SSO logs and the last two quarters of expense reports, list every AI tool that appears, and mark which ones have ever received a customer name. That list is your remediation backlog, ordered by risk, before a single policy document gets edited.