Financial Institution AI Rules
The one-paragraph answer
GLBA AI compliance covers how financial institutions use AI when it touches nonpublic personal information (NPI) of consumers. The Gramm-Leach-Bliley Act has three main rules: the Privacy Rule (limits on sharing NPI), the Safeguards Rule (security requirements for NPI), and the Pretexting Provisions (against social engineering). All three now apply to AI systems handling customer financial data at banks, credit unions, mortgage companies, insurance companies, and non-bank financial services providers.
Financial institutions deploying AI face a stacked compliance environment. GLBA governs customer data. SR 11-7 governs models. FCRA/ECOA govern credit decisions. UDAAP governs consumer treatment. State laws add more. AI runs across all of these categories simultaneously. When a financial institution adds AI to fraud detection, credit decisioning, customer service, or marketing, every applicable law comes with it. GLBA is the baseline data protection layer that most institutions built compliance around, and adding AI stresses that layer.
Financial institutions must develop, implement, and maintain a written information security program. The FTC updated the Safeguards Rule in 2021 with more specific requirements: risk assessment, access controls, encryption, multi-factor authentication, monitoring, and incident response. AI systems processing NPI must be integrated into the security program.
Financial institutions must provide privacy notices explaining information practices, offer opt-out rights (in some cases), and limit sharing of NPI with non-affiliated third parties. AI vendors receiving NPI are third parties subject to these constraints unless service-provider exceptions apply.
Prohibit obtaining customer information under false pretenses. AI voice cloning and deepfake attacks against financial institutions raise pretexting concerns that GLBA anticipates.
Financial institutions remain responsible for how their AI vendors handle NPI. Vendor management, contract terms, and ongoing monitoring are Safeguards Rule requirements.
GLBA sits alongside SR 11-7 for banks, CFPB enforcement for consumer finance, and state financial regulator oversight. NAIC has issued AI guidance for insurance that layers on top of GLBA. Compliance programs must integrate across all applicable frameworks.
Every financial institution subject to GLBA is subject to the enhanced Safeguards Rule. The FTC and functional regulators (Federal Reserve, OCC, FDIC, NCUA, state insurance commissioners) enforce GLBA. Enforcement can produce substantial civil penalties and consent orders. Adding AI without integrating into GLBA compliance is a documented enforcement risk.
The academic literature on GLBA AI is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“ML can be less transparent and explainable than traditional regression models, which may raise unique questions about compliance”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“Effective data governance is important for minimizing data breach activity and mitigating bias”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about GLBA AI arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, GLBA AI becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
Yes. GLBA applies to any entity significantly engaged in financial activities, which reaches many fintechs.
Vendors processing NPI on behalf of the institution generally fall within service-provider exceptions if properly contracted. But third-party oversight obligations still apply.
Many states have their own financial privacy rules that impose additional obligations. California's CCPA/CPRA reaches financial services in some contexts. State insurance departments have their own rules.
The financial services sector-rules addendum in Volume III of The Operating Discipline for AI Library™ addresses GLBA-specific AI compliance, alongside SR 11-7 and CFPB coverage.
A bank adding AI to fraud detection is not doing one compliance exercise. GLBA governs the customer data. SR 11-7 governs the model. ECOA and FCRA govern any decision that touches credit. UDAAP governs how the customer experiences the outcome. State law adds more. GLBA AI compliance is the data protection floor beneath all of it, and it is the one most institutions assume is already handled because they handled it years ago for systems that were not AI.
The 2021 revision made the requirements specific rather than aspirational. Written risk assessment. Access controls with least privilege. Encryption of NPI at rest and in transit. Multi-factor authentication. Continuous monitoring or annual penetration testing plus biannual vulnerability assessments. A named qualified individual accountable for the program. Incident response plan. Each of these applies to AI systems processing NPI exactly as it applies to a core banking platform.
Most financial institutions do not build their AI. They buy it, and the vendor sees the data. The Safeguards Rule holds the institution responsible for that vendor's handling of NPI. Contracts must impose safeguards, permit oversight, and require incident notification. An AI vendor who cannot describe how NPI is segregated, retained, and deleted is a finding waiting to happen.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning GLBA AI that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including GLBA and AI, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →