The GLBA Safeguards Rule: what AI use leaves in the audit record a financial institution reads.

For the information security officer who serves as the Qualified Individual under the FTC rule, the chief compliance officer, and the vendors that handle customer or member information at a bank, credit union or non-bank lender, this page puts each rule next to what a Verillian record holds of staff AI use on enrolled devices.

What the Safeguards Rule and the guidelines ask

What the rule asksA Verillian record showsIt does not show
'Customer information means any record containing nonpublic personal information about a customer of a financial institution, whether in paper, electronic, or other form, that is handled or maintained by or on behalf of you or your affiliates.' 16 CFR 314.2(d). The OCC's guidelines say 'maintained by or on behalf of' the institution, and the NCUA's say the same of member information. 12 CFR Part 30, App. B, I.C.2.e; Part 748, App. A, I.B.2.dValues your policy flags are swapped for a placeholder on the device before a prompt goes out, and the entry records the swap. Detection is best effort.Whether a prompt held customer information. A value outside the set the detectors catch goes out as typed.
Implement and periodically review 'access controls, including technical and, as appropriate, physical controls to: (i) Authenticate and permit access only to authorized users to protect against the unauthorized acquisition of customer information; and (ii) Limit authorized users' access only to customer information that they need to perform their duties and functions'. 16 CFR 314.4(c)(1). The banking guidelines list 'Access controls on customer information systems, including controls to authenticate and permit access only to authorized individuals and controls to prevent employees from providing customer information to unauthorized individuals who may seek to obtain this information through fraudulent means', which each institution 'must consider' and adopt if it concludes the measure is appropriate. 12 CFR Part 30, App. B, III.C.1.a; Part 748, App. A, III.C.1.aA signed policy on each enrolled device rules a captured request allowed, redacted or blocked, for the providers it names. The entry carries that ruling, with the user and device the checkpoint reports.Who may sign in to a customer system, multi-factor authentication, or what an employee can open. Those sit in your identity and application controls. A device that is not enrolled, or a provider the policy leaves out, is not ruled.
'Protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest', or, where encryption is infeasible, secure it with 'effective alternative compensating controls reviewed and approved by your Qualified Individual'. 16 CFR 314.4(c)(3). Encryption is 'the transformation of data into a form that results in a low probability of assigning meaning without the use of a protective process or key, consistent with current cryptographic standards and accompanied by appropriate safeguards for cryptographic key material.' 314.2(f). The banking guidelines list 'Encryption of electronic customer information, including while in transit or in storage on networks or systems to which unauthorized individuals may have access'. 12 CFR Part 30, App. B, III.C.1.c; Part 748, App. A, III.C.1.cAES-256-GCM seals entry content, and the key belongs to your institution. The content sits on infrastructure you run, and Verillian never receives it.Encryption of anything else you hold, the connection between a device and a provider, or how a provider stores what it receives. Whether the scheme is 'consistent with current cryptographic standards' is for your security team and your examiner. No certification is claimed.
'Implement policies, procedures, and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information by such users.' 16 CFR 314.4(c)(8). An authorized user is 'any employee, contractor, agent, customer, or other person that is authorized to access any of your information systems or data.' 314.2(a)A request the checkpoint captures on an enrolled device, bound for a provider the policy names, becomes an entry holding the provider, the ruling, the clock time and the user and device the checkpoint reports. Signing happens on the device, which links each entry by hash to its predecessor, so an altered signed field can be detected. The admin server you run tests each new entry on receipt and flags any that fails to link or verify.Activity outside the checkpoint, such as another AI tool on a device that is not enrolled, a provider the policy leaves out, or work done inside a customer system. It does not judge whether a use was authorized. An entry removed from the newest end leaves no gap, and nothing here shows that no entry is missing.
Develop, implement and maintain 'procedures for the secure disposal of customer information in any format no later than two years after the last date the information is used in connection with the provision of a product or service to the customer to which it relates', unless it 'is necessary for business operations or for other legitimate business purposes, is otherwise required to be retained by law or regulation, or where targeted disposal is not reasonably feasible due to the manner in which the information is maintained'. The institution must also 'Periodically review your data retention policy to minimize the unnecessary retention of data'. 16 CFR 314.4(c)(6). The banking guidelines ask for 'appropriate measures to properly dispose of customer information and consumer information'. 12 CFR Part 30, App. B, III.C.4Entries are held on infrastructure your institution runs, so its own retention and disposal procedures apply to them. No retention setting is described here.Whether the content in an entry is customer information, which turns on what staff typed. The period your program applies, or when the information was last used for a customer's product or service.
A service provider is 'any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution that is subject to this part.' 16 CFR 314.2(r). The institution must take 'reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue', require them 'by contract to implement and maintain such safeguards', and periodically assess them 'based on the risk they present and the continued adequacy of their safeguards'. 314.4(f)(1) to (3). The banking guidelines ask for 'appropriate due diligence in selecting its service providers', a contract requirement, and, 'where indicated by' the risk assessment, monitoring that includes a review of 'audits, summaries of test results, or other equivalent evaluations'. 12 CFR Part 30, App. B, III.D.1 to 3; Part 748, App. A, III.D.1 to 3The named provider each captured request went to, and when, so a reviewer can read which providers staff reached from enrolled devices.Whether a provider meets that definition, what its contract says, or whether its safeguards are adequate. Verillian assesses no provider and sees nothing of a provider's own handling once a request arrives. A provider absent from the signed policy does not appear.
'Regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems, and procedures, including those to detect actual and attempted attacks on, or intrusions into, information systems.' 16 CFR 314.4(d)(1). The banking guidelines list 'Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into customer information systems', and say tests of key controls 'should be conducted or reviewed by independent third parties or staff independent of those that develop or maintain the security programs'. 12 CFR Part 30, App. B, III.C.1.f, III.C.3; Part 748, App. A, III.C.1.f, III.C.3A reviewer can search entries in the admin console your institution runs and export them as a plain file, to read how the AI-use control has ruled over time.Penetration tests, vulnerability assessments, or the detection of attacks on your systems. It does not watch for intrusions. The export is a plain file.
'Establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in your control', which must address, among other areas, 'Documentation and reporting regarding security events and related incident response activities'. 16 CFR 314.4(h), (h)(6). Section 314.6 says paragraph (h) does not apply to 'financial institutions that maintain customer information concerning fewer than five thousand consumers.' 314.6. The banking guidelines list 'Response programs that specify actions to be taken when' an institution 'suspects or detects that unauthorized individuals have gained access to customer information systems, including appropriate reports to regulatory and law enforcement agencies'. 12 CFR Part 30, App. B, III.C.1.g; Part 748, App. A, III.C.1.gWhich provider each captured request went to, and when, for a responder asking what an enrolled device sent. It is an input to an investigation, not a plan.The plan, its roles or its communications, or whether an event happened. Requests that never passed the checkpoint, and what a provider did with a request after receiving it, are outside the record.
'If the notification event involves the information of at least 500 consumers, you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event.' 16 CFR 314.4(j)(1). A notification event is the 'acquisition of unencrypted customer information without the authorization of the individual to which the information pertains.' 314.2(m). 'Section 314.4(j) is effective as of May 13, 2024.' 314.5When each captured request was sent and to which provider, for a reviewer to set beside a discovery date.Whether information was acquired without authorization, whether it was unencrypted, how many consumers are involved, or when an event was discovered. Whether something is a notification event is for your counsel.
LimitsCaptured requests only: those sent from enrolled devices to providers the signed policy names. Detection is best effort, and only the Claude API format has been verified. Content is kept only where the checkpoint can read the conversation, which excludes the Claude desktop app and Cursor.Completeness, traffic that bypasses the checkpoint, or anything inside an AI provider's own cloud. Nor is Verillian a GLBA product: it leaves open what counts as customer information or who is a service provider. No certification is claimed, and nothing here is legal advice.

Sources: the eCFR, current to October 7, 2026, with every section below read on October 8. The FTC Safeguards Rule, 16 CFR Part 314, is quoted for non-bank financial institutions. For banks, the OCC, FDIC and Federal Reserve appendices carry the same words in sections III.C and III.D apart from the institution's name and a few connecting words, so the OCC text is quoted; the NCUA's Appendix A follows the same structure for member information. Every quotation comes from: 16 CFR 314.1, 16 CFR 314.2, 16 CFR 314.4, 16 CFR 314.5, 16 CFR 314.6, 12 CFR Part 30, Appendix B (OCC), 12 CFR Part 364, Appendix B (FDIC), 12 CFR Part 208, Appendix D-2 (Federal Reserve), 12 CFR Part 748, Appendix A (NCUA).

Aligned, not certified: Verillian holds no certification for these rules. This page is not legal advice. Counsel and your examiner decide whether the rules are met.

To read an entry next to a rule, bring a sample request to a demo. We read every request and reply.

Questions about the Safeguards Rule and AI

Does the GLBA Safeguards Rule apply to AI tools staff use?

The rule turns on customer information, not on which tool holds it. Section 314.2(d) reaches customer information 'handled or maintained by or on behalf of you or your affiliates', and the banking guidelines use the same 'maintained by or on behalf of' wording. A text search of 16 CFR Part 314 and the OCC, FDIC, Federal Reserve and NCUA appendices on eCFR (current to October 7, 2026) finds no mention of artificial intelligence, machine learning, generative systems, chatbots or algorithms. Your counsel decides whether a given prompt held customer information.

Is an AI provider a service provider under the Safeguards Rule?

It is if it fits the definition in section 314.2(r): a person or entity that 'receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution'. Where it does, section 314.4(f) asks for reasonable steps to select and retain it, a contract requiring safeguards, and periodic assessment. Whether a particular provider fits is a question for your counsel, and Verillian assesses no provider.

What logging does the FTC Safeguards Rule ask for?

One clause: policies, procedures and controls 'designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information by such users' (section 314.4(c)(8)). The word log appears nowhere else in Part 314, and the text names no fields, no format and no retention period for a log. Section 314.4(c)(6) sets a disposal point for customer information, which an entry's content may be.

Does using Verillian make us GLBA compliant?

No. Verillian applies policy at the devices you enroll and records each captured request in a signed entry on infrastructure you run. Your risk assessment, your Qualified Individual, your provider contracts, incident response and notification all remain your institution's call, alongside your vendors and counsel. Aligned, not certified.

Read an entry beside the Safeguards Rule.

Thirty minutes. Bring a sample request, watch it ruled live, and open the signed record together.