The Gramm-Leach-Bliley Act governs how financial institutions handle nonpublic personal information. Title V splits into privacy obligations — notices and opt-out before sharing customer information — and a data security mandate requiring a written information security program. Which rule applies, and which agency enforces it, depends entirely on what kind of institution you are.
Which rule applies to you
This is where most summaries go wrong, because GLBA is implemented through different instruments for different institutions.
Banks, thrifts and credit unions are covered by the Interagency Guidelines Establishing Information Security Standards, issued under GLBA sections 501 and 505(b) and codified by each prudential regulator — the OCC's version sits at 12 CFR part 30, Appendix B. These require a board-approved written program, administrative, technical and physical safeguards, access controls, encryption, independent testing of key controls, intrusion monitoring, a response program, and at least annual reporting to the board.
Non-bank financial institutions fall under the FTC Safeguards Rule at 16 CFR part 314. Broker-dealers answer to the SEC, insurers to their state regulator. Hospitals are generally not GLBA-covered at all — a health system is governed by HIPAA unless it operates a lending arm.
Privacy is separate again: rulemaking authority moved to the CFPB under Dodd-Frank and now sits in Regulation P at 12 CFR part 1016, while the FTC retains enforcement for entities in its jurisdiction.
What the Safeguards Rule requires
Section 314.4 sets nine elements: a designated Qualified Individual, a written risk assessment the program is built on, safeguards including encryption in transit and at rest and multi-factor authentication, annual penetration testing with vulnerability assessments at least every six months, personnel training, service provider oversight, periodic reassessment, a written incident response plan, and an annual written report from the Qualified Individual to the board.
Breach notification sits at 314.4(j): notify the FTC within thirty days of discovering an event affecting five hundred or more consumers. Institutions holding information on fewer than five thousand consumers are exempt from several elements under 314.6. The current text dates from the November 2023 amendment, effective May 2024; nothing has changed in 2025 or 2026.
What it means for AI
There is no AI-specific rule or formal interpretation under GLBA. That is not an exemption — it is the ordinary situation in which existing obligations apply to a new channel without anyone restating them.
A model that receives customer information in a prompt is processing nonpublic personal information, and a vendor operating that model is a service provider subject to oversight. The encryption, access control and monitoring requirements apply to that path like any other. What is new is that the path is unstructured text, which is why DLP for AI and egress control do work conventional tooling does not. Keeping the processing inside the perimeter is one answer to the service-provider question — see AI sovereignty and the financial services page. The annual board report is easier to produce when the underlying records are generated by enforcement rather than assembled afterwards, which is the point of examination readiness.
Related terms
FFIEC · NYDFS Part 500 · DLP for AI · Information barrier · Full glossary
Verified against primary sources in September 2026. Regulations change. If something here is out of date, tell us and we will correct it.
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs