Not on a personal or free account, and not without a plan that meets the safeguarding guidelines every federally insured credit union already follows. Those guidelines, in Appendix A to 12 CFR Part 748, apply to member information “maintained by or on behalf of” the credit union, and they ask the credit union to do due diligence on any service provider that touches it and to require protective measures by contract. Staff typing a member’s details into a tool the credit union never vetted and has no contract with fails that test on its face. The obligation comes from what the tool receives and who has agreed to protect it, not from the tool’s name.
The question is not whether ChatGPT is allowed. It is whether the credit union has done the vendor oversight Appendix A asks for before member information reaches any AI service, and whether staff know where that line is.
What does Appendix A actually require when staff use an AI tool?
Appendix A to Part 748 is the credit union version of the Gramm-Leach-Bliley Act safeguards standards. It says a credit union’s information security program should be designed to ensure the security and confidentiality of member information and to protect against unauthorized access to or use of it that could result in substantial harm or inconvenience to a member. Four parts of the guidelines bear directly on AI tools.
- Assess risk (III.B). Identify reasonably foreseeable internal threats that could lead to unauthorized disclosure or misuse of member information. An employee pasting a loan file into an outside tool is a foreseeable internal threat once the tool exists.
- Manage and control risk (III.C). Consider access controls, encryption, and monitoring systems, and train staff to carry out the program. Regularly test the key controls.
- Oversee service providers (III.D). Exercise appropriate due diligence in selecting providers, require them by contract to implement appropriate measures, and where the risk assessment indicates, monitor them, including by reviewing audits or summaries of test results.
- Report to the board (III.F). At least annually, the board or a committee should hear about the program, including service provider arrangements and results of testing.
Appendix A defines a service provider as an entity that maintains, processes, or is permitted access to member information through services it provides directly to the credit union. An AI vendor the credit union signs with fits that definition. A tool an employee opens on their own does not, and that gap is the whole problem.
Does it change if staff use a free or personal ChatGPT account?
Yes, and it makes the answer harder. Appendix A III.D asks for a contract that requires the provider to implement appropriate measures. A free or personal account is an agreement between the employee and the provider on the provider’s standard terms. The credit union negotiated nothing, reviewed nothing, and cannot monitor anything under it. If a staff member puts member information into such an account, there is no III.D arrangement to point to, because none exists.
A business or enterprise agreement is different in kind, because the credit union can review its terms, negotiate them, and require the protections III.D describes. Whether a given agreement is enough is a due diligence judgment for the credit union and its counsel. Read the provider’s current terms rather than a summary, because they change.
Is pasting member data into an AI tool a disclosure under the privacy rule?
This is unsettled, and counsel decides it. Regulation P, the privacy rule at 12 CFR Part 1016 that credit unions follow, limits a credit union’s disclosure of nonpublic personal information to a nonaffiliated third party unless notice and opt out conditions are met (section 1016.10). Section 1016.13 makes an exception when the third party performs services for the credit union, but only if the credit union gives the initial notice and has a contract that prohibits the third party from disclosing or using the information other than to carry out the purposes for which it was disclosed. Other exceptions exist in sections 1016.14 and 1016.15.
So the contract is the hinge in this rule too. With no contract, the section 1016.13 condition is not met on its face. Whether a particular paste is a “disclosure” that needs a different exception is a legal question about the specific facts, and nothing we found in the rule or in NCUA’s AI page answers it.
Would a paste have to be reported to NCUA?
Only if it amounts to a reportable cyber incident, and the rule defines that narrowly. Under 12 CFR 748.1(c), a credit union must notify NCUA as soon as possible and no later than 72 hours after it reasonably believes it has experienced a reportable cyber incident. The definition covers a substantial loss of confidentiality, integrity, or availability from unauthorized access to or exposure of sensitive data, a disruption of operations, and a disruption or unauthorized access to sensitive data caused by a compromise of a credit union service organization, cloud service provider, or other third party hosting provider.
Nothing in that text says an employee’s paste is one. What the credit union should have is the response program Appendix A III.C.1.g describes, which specifies what to do when it suspects unauthorized access to member information, and a person who decides whether a given event crosses the line. That decision is far easier with a record of what happened than without one.
What has NCUA said about AI?
NCUA’s AI resource page, read September 28, 2026, lists two supervisory letters as the NCUA resources to reference when evaluating or performing due diligence on third party AI vendors: Letter 07-CU-13, Evaluating Third Party Relationships, and Letter 01-CU-20, Due Diligence Over Third Party Service Providers. It also points credit unions to NIST’s AI resources and to the tools the Treasury developed with the Artificial Intelligence Executive Oversight Group. The page names member data privacy among the challenges of partnering with AI companies. The page frames the job as third party due diligence, so the safeguarding guidelines and the vendor management letters above are the existing expectations it points to.
Letter 07-CU-13 says the planning, due diligence, and controls needed to safely engage a third party depend on the credit union’s risk profile and the type of relationship. Letter 01-CU-20 says a credit union should establish controls to ensure the relationship is meeting its expectations and the third party is meeting its responsibilities.
What changed recently?
On September 15, 2026, NCUA, the OCC, the Federal Reserve Board, and the FDIC published proposed Third-Party Risk Management Guidance (91 FR 58536, NCUA docket NCUA-2026-1684). For the purposes of the proposal, banking organizations include insured credit unions. The agencies say they plan to rescind and replace the 2023 interagency guidance, and they ask for comment on whether other guidance documents, interpretive letters, or resources on third-party risk management should also be rescinded. The proposal does not name Letter 07-CU-13 or Letter 01-CU-20, and its text does not mention artificial intelligence. It describes itself as not setting forth enforceable standards or prescriptive requirements. Comments are due November 16, 2026. Until anything is finalized, the letters above remain what NCUA’s AI page points to, so check that page again before relying on this list.
What you need in place
- A written AI use policy, approved through the same route as the rest of the information security program, that says which AI tools are approved and what member information may go into each. Appendix A III.A gives the board or a committee the job of approving the program.
- A list of the AI services in use and the agreement behind each one. An approved tool with a reviewed contract is a III.D arrangement. A tool with neither is not.
- Staff training that names the line in plain terms: what counts as member information and which tools it may go into (III.C.2).
- A way to see what is actually happening, not just what the policy says. Appendix A III.C.1.f asks a credit union to consider monitoring systems and procedures, and III.C.3 asks for regular testing of key controls.
- A response step for when member information reaches a tool it should not have (III.C.1.g), with a named decision maker for the 72 hour question under 12 CFR 748.1(c).
- Service provider arrangements and testing results in the annual board report (III.F).
For related reading, see how the same question plays out under HIPAA and what an AI audit trail is.
Sources
- 12 CFR Part 748, Appendix A, Guidelines for Safeguarding Member Information, sections I, II, and III.A to F. eCFR, read September 28, 2026.
- 12 CFR 748.0, Security program, and 12 CFR 748.1(c), Cyber incident report. eCFR, read September 28, 2026.
- 12 CFR 1016.10 and 1016.13, Limits on disclosure and the service provider exception. eCFR, read September 28, 2026.
- 15 U.S.C. 6801, Protection of nonpublic personal information. U.S. Code, read September 28, 2026.
- OCC, Board, FDIC, and NCUA, Proposed Third-Party Risk Management Guidance, 91 FR 58536 (September 15, 2026). Federal Register, read September 28, 2026.
- NCUA, Artificial Intelligence (AI) resource page, read September 28, 2026.
- NCUA Letter to Credit Unions 07-CU-13, Evaluating Third Party Relationships, December 2007, read September 28, 2026.
- NCUA Letter to Credit Unions 01-CU-20, Due Diligence Over Third Party Service Providers, November 2001, read September 28, 2026.
Where Verillian fits
Verillian governs AI use on the devices you enroll. A checkpoint on each device sits between your people’s AI tools and agents and the AI providers it supports. For Claude and Claude Code traffic (the Anthropic API format), a tool call your policy bans is removed before your machine can run it; for the other supported providers, it screens and records the usage, and the Claude desktop app and Cursor are recorded only, with no redaction. Each record is signed on the device it came from and hash-chained to the one before it, so a change to its signed fields is detectable, and it stays on your own infrastructure. It cannot show that nothing was omitted. Redaction is best-effort, not a guarantee that every value is caught. The admin server runs where you choose: on-prem or in a private cloud you run. macOS is the supported install today; Windows has an interim scripted installer and Linux builds from source.
For a credit union, that record can help evidence one part of the list above: what AI use started on an enrolled device, and when, which gives the person deciding a 72 hour question something to read. On redaction, a fresh install detects values such as a Social Security number or a card number and flags them without changing anything. An administrator has to set that value type to redact before it is replaced on the device, and then a Social Security number leaves as [US_SSN_REDACTED] rather than as the number itself. That is a screen on the values the detectors match, not a guarantee that every piece of member information is caught, and which of your staff’s tools reach the checkpoint, ChatGPT included, is something to confirm before relying on it. The architecture is aligned with the Appendix A safeguarding expectations for a credit union’s own program, not certified, because the guidelines set standards for the credit union’s program and do not certify a product.
Verillian does not see inside a vendor’s own cloud. When a vendor’s service calls a model on the vendor’s servers, as a vendor’s member chat assistant or a hosted lending tool does, the record of what that model received is created on the vendor’s side, and the contract is your lever for it. What Verillian gives you is the record of AI use that starts on your own devices.
Our compliance mappings show the controls the platform is designed to support, the financial services section covers what this looks like for a regulated institution, and the demo walks through a redaction on a real device.