TL;DR: Financial services firms are adopting AI faster than they can govern it, creating measurable gaps in data handling, visibility, and disclosure obligations under GLBA and SEC rules, according to Cyberhaven’s 2026 AI Adoption & Risk Report: Financial Services. The control problem is not AI itself, but whether firms can prove where regulated data went, who touched it, and what controls were active.
NHIMG editorial — based on content published by Cyberhaven: Financial Services AI Security: Meeting GLBA and SEC Rules
By the numbers:
- Cyberhaven found a 17x difference in AI adoption between the most aggressive financial services firms and the most cautious ones.
- Cyberhaven research found that 32.3% of ChatGPT usage and 24.9% of Gemini usage occur through personal accounts, with Claude and Perplexity higher still at 58.2% and 60.9%.
- Cyberhaven reported that 79.7% of financial services firms are building with agent platforms, and coding assistant use jumped from 16.7% to 42.1% in a single year.
Questions worth separating out
Q: What breaks when employees use unapproved AI tools with company data?
A: Governance breaks because the organisation loses visibility into where data and secrets are going, who can access them, and how they are being reused.
Q: Why do AI agents complicate cloud identity governance?
A: AI agents complicate governance because they turn identity from a static permission holder into an operational decision-maker.
Q: How can security teams tell whether AI lifecycle controls are working?
A: They should look for evidence that access requests, policy enforcement, and usage visibility are centrally recorded and current.
Practitioner guidance
- Build a complete AI tool inventory Catalog standalone GenAI apps, embedded AI features, endpoint agents, and personal-account usage so security can see every data path that may involve regulated information.
- Classify regulated data before AI use Map nonpublic personal information, account data, and trading data to approved AI workflows so teams can block or flag submissions before they leave the controlled environment.
- Enforce identity-aware controls at data entry Apply AI-aware DLP and DSPM where data is entered into a tool, not only at the network boundary, because encrypted sessions hide the meaningful control point.
What's in the full article
Cyberhaven's full article covers the operational detail this post intentionally leaves for the source:
- A breakdown of how its Data Lineage approach records data movement into and out of AI tools across sanctioned and unsanctioned environments.
- Specific examples of how AI Security visibility works for GenAI applications, AI agents, and embedded AI features.
- How DSPM and DLP are positioned to support audit-ready records for GLBA, SEC, and contractual obligations.
- The article’s own description of Linea AI and how it prioritises high-risk tools and user populations.
👉 Read Cyberhaven’s analysis of financial services AI security and GLBA exposure →
Financial services AI security and regulatory exposure are colliding?
Explore further
AI security in financial services is becoming a data governance problem before it becomes a model risk problem. The article’s core point is that regulated data flows, not model outputs, create the first compliance failure mode. GLBA and SEC obligations follow the information, so organisations that cannot track where customer data went will struggle to defend any downstream AI control claims. The practitioner conclusion is simple: data traceability must be treated as a control requirement, not a reporting convenience.
A question worth separating out:
Q: Who is accountable when an AI agent accesses regulated data improperly?
A: Accountability sits with the teams that govern the agent's identity, the data classification, and the policy that allowed the access path. If those controls are disconnected, no single owner can explain why the access existed or why it was not removed sooner. Shared context is what makes accountability traceable.
👉 Read our full editorial: Financial services AI security is now a GLBA and SEC issue