Not on a personal or free account, and not into any AI tool the bank has not vetted and put under contract. The Interagency Guidelines Establishing Information Security Standards ask a bank to assess the risk that employees or others misuse customer information, to train staff, and to use due diligence and contract terms for any service provider that has access to it. Neither the guidelines nor the privacy rule sections we read name ChatGPT or any AI tool. The obligation follows what the tool receives and who has agreed to protect it. A bank that allows the use has to be able to show the tool, the contract, and the control.
The bank version of this question is nearly the credit union version, with different regulators. The rule text is parallel. What differs is who supervises the bank, and the 36 hour incident notice that applies to banks.
What do the Interagency Guidelines require when staff use an AI tool?
The guidelines implement section 501(b) of the Gramm-Leach-Bliley Act and section 39 of the Federal Deposit Insurance Act. The OCC, the Board, and the FDIC each publish them in their own part of the CFR: 12 CFR Part 30, Appendix B (OCC); Part 208, Appendix D-2 (Board); and Part 364, Appendix B (FDIC). We quote the OCC’s version below. The Supplement to it, on response programs, says its scope and definitions are identical to those of the guidelines. Four parts bear on AI tools.
- Assess risk (III.B). Identify reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer information.
- Manage and control risk (III.C). Consider access controls, encryption, monitoring systems and procedures, and response programs, and train staff. Regularly test key controls, with tests conducted or reviewed by parties independent of those who run the program.
- Oversee service providers (III.D). Exercise appropriate due diligence in selecting providers, require them by contract to implement appropriate measures designed to meet the objectives of the guidelines, and, where the risk assessment indicates, monitor them, including by reviewing audits or summaries of test results.
- Report to the board (III.F). At least annually, including service provider arrangements and results of testing.
The guidelines define a service provider as an entity that maintains, processes, or is permitted access to customer information through services it provides directly to the bank. An AI vendor the bank contracts with fits. A tool an employee opens on their own does not, and that is the gap.
Does it change if the employee uses a personal account?
Yes. Section III.D asks for a contract requiring the provider to implement appropriate measures. A personal or free account is an agreement between the employee and the provider on the provider’s standard terms. The bank negotiated nothing and can monitor nothing under it. If an employee puts customer information into such an account, there is no III.D arrangement to point to. A business agreement is different in kind, because the bank can review and negotiate its terms. Whether a given agreement is enough is a due diligence judgment for the bank and its counsel, and the provider’s current terms should be read directly.
The 2026 proposal to replace the third-party relationship guidance says that where a bank lacks a written agreement with a third party, the activity “is unlikely to constitute a third-party relationship.” That is proposed text, and we cover it in our post on third-party AI vendor risk. Its practical meaning here is that an employee’s personal account may fall outside the vendor framework, so the bank’s own information security controls carry the weight.
Is pasting customer data into an AI tool a disclosure under the privacy rule?
This is unsettled, and counsel decides it. Regulation P, 12 CFR Part 1016, limits a financial institution’s disclosure of nonpublic personal information to a nonaffiliated third party unless notice and opt out conditions are met (section 1016.10). Section 1016.13 excepts disclosure to a third party that performs services for the institution, but only if the institution gives the initial notice and has a contract that prohibits the third party from disclosing or using the information other than to carry out the purposes for which it was disclosed. Other exceptions are in sections 1016.14 and 1016.15.
With no contract, the section 1016.13 condition is not met on its face. Whether a particular paste is a “disclosure” that needs a different exception depends on the facts, and nothing in the rule text answers it.
What happens if customer information goes somewhere it should not?
The guidelines call for a response program that specifies actions to be taken when the bank suspects or detects unauthorized access to customer information systems (III.C.1.g). The Supplement to the guidelines describes the customer notice standard: when a financial institution becomes aware of an incident of unauthorized access to sensitive customer information, it should conduct a reasonable investigation to determine the likelihood of misuse, and if misuse has occurred or is reasonably possible, it should notify the affected customer as soon as possible. Sensitive customer information includes a name, address, or phone number in conjunction with a Social Security number, account number, or card number, among other items.
The Supplement also draws the line that records make matter: if the institution can determine “from its logs or other data precisely which customers’ information has been improperly accessed,” it may limit notification to those customers. If it cannot identify which customers, and misuse is reasonably possible, it should notify all customers in the group. Whether an employee’s paste is “unauthorized access” is a judgment call for the bank, and we found nothing that settles it.
Separately, the Computer-Security Incident Notification Rule requires a banking organization to notify its regulator no later than 36 hours after it determines a “notification incident” has occurred. The OCC’s version is at 12 CFR Part 53. A notification incident is a computer-security incident that has materially disrupted or degraded, or is reasonably likely to, operations, a business line, or financial stability. The definition turns on material disruption, and nothing in it describes a single paste of a customer record.
What you need in place
- A written AI use policy approved through the same route as the information security program (III.A), naming approved tools and what customer information may go into each.
- A list of AI services in use and the agreement behind each. An approved tool with a reviewed contract is a III.D arrangement. A tool with neither is not.
- Staff training that draws the line in plain terms: what counts as customer information and which tools it may go into (III.C.2).
- A way to see what is happening, not only what the policy says. III.C.1.f asks the bank to consider monitoring systems and procedures, and III.C.3 asks for regular testing of key controls.
- A response step for when customer information reaches a tool it should not have, with a named decision maker for the customer notice and 36 hour questions.
- Service provider arrangements and testing results in the annual board report (III.F).
Related reading: the credit union version, in can credit union staff put member data into ChatGPT, and how to prove what an AI model was given.
Sources
- Interagency Guidelines Establishing Information Security Standards, 12 CFR Part 30, Appendix B (OCC), sections I to III, and Supplement A, Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice. Parallel texts: 12 CFR Part 208, Appendix D-2 (Board) and Part 364, Appendix B (FDIC). eCFR, read September 28, 2026.
- 12 CFR 1016.1, 1016.10, and 1016.13 (Regulation P). eCFR, read September 28, 2026.
- 12 CFR 53.2 and 53.3, Computer-Security Incident Notification (OCC). eCFR, read September 28, 2026.
- OCC, Board, FDIC, and NCUA, Proposed Third-Party Risk Management Guidance, 91 FR 58536 (September 15, 2026). Federal Register, read September 28, 2026.
Where Verillian fits
Verillian governs AI use on the devices you enroll. A checkpoint on each device sits between your people’s AI tools and agents and the AI providers it supports. For Claude and Claude Code traffic (the Anthropic API format), a tool call your policy bans is removed before your machine can run it; for the other supported providers, it screens and records the usage, and the Claude desktop app and Cursor are recorded only, with no redaction. Each record is signed on the device it came from and hash-chained to the one before it, so a change to its signed fields is detectable, and it stays on your own infrastructure. It cannot show that nothing was omitted. Redaction is best-effort, not a guarantee that every value is caught. The admin server runs where you choose: on-prem or in a private cloud you run. macOS is the supported install today; Windows has an interim scripted installer and Linux builds from source.
For a bank, that record can help with the two hardest items in the list: seeing what AI use started on an enrolled device, and, if an incident is ever investigated, working from a record of captured interactions rather than reconstruction. On redaction, a fresh install detects values such as a Social Security number or a card number and flags them without changing anything. An administrator has to set that value type to redact before it is replaced on the device, and then a Social Security number leaves as [US_SSN_REDACTED] rather than as the number. That is a screen on the values the detectors match, not a guarantee that all customer information is caught, and which of your tools reach the checkpoint, ChatGPT included, is worth confirming before relying on it. The architecture is aligned with the Interagency Guidelines, not certified, because the guidelines set standards for the bank’s own program and do not certify a product.
Verillian does not see inside a vendor’s own cloud. When a vendor’s service calls a model on the vendor’s servers, as a vendor’s customer chat assistant or a hosted underwriting tool does, the record of what that model received is created on the vendor’s side, and the contract is your lever for it. What Verillian gives you is the record of AI use that starts on your own devices.
Our compliance mappings show the controls the platform is designed to support, the financial services section covers what this looks like for a regulated institution, and the demo walks through a redaction on a real device.
