Yes, and no rule tells you to stay away from the tool. What decides it is which of two federal rules governs your firm, and whether the tool you use is written into the information security program that rule already requires of you. Both questions are about your own paperwork rather than about the model.

This is a plain reading of two published rules and the FTC's own guide for small firms, not legal advice. Your compliance counsel and your regulator have the last word.

First, work out which rule writes your program

Two regulators wrote two rules for firms holding customer financial information, and a firm sits under one of them. The FTC's Safeguards Rule, 16 CFR part 314, says it "sets forth standards for developing, implementing, and maintaining reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer information" (16 CFR 314.1(a), retrieved from the eCFR on 2026-08-05).

Who that covers is not left to guesswork. The FTC's own small entity compliance guide lists the examples in section 314.2(h), among them "credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, and investment advisors that aren't required to register with the SEC" (FTC, "FTC Safeguards Rule: What Your Business Needs to Know", retrieved 2026-08-05). Read the last clause twice. It is the hinge.

Firms that are required to register with the SEC, along with broker-dealers, answer to the SEC's Regulation S-P at 17 CFR 248.30 instead. The rule calls them covered institutions and asks for written policies and procedures of its own. The broad idea is the same. The text is not, and neither are the rules about who you have to notify when something goes wrong.

Exhibit 1

One question sorts an advisory firm into one of two rulebooks.

Required to register with the SEC? No: FTC Safeguards Rule 16 CFR part 314 State-registered advisers Investment advisers not required to register with the SEC Credit counselors and other financial advisors Tax preparation firms Yes: SEC Regulation S-P 17 CFR 248.30 SEC-registered investment advisers Broker-dealers Both are what the rule calls covered institutions Different text, different regulator, different notification rules.
Note: the left column reproduces four of the thirteen examples the FTC lists, not the whole list, and the guide is a compliance guide rather than the regulation. Mixed firms exist, and a firm can hold obligations under other rules at the same time. If your registration status is not obvious to you, that is the question to take to counsel first.

There is no BAA to go and ask for

Most advisers arrive at this subject having read something written for doctors, where the first move is getting a business associate agreement signed. Gramm-Leach-Bliley has no such instrument. Nothing in the Safeguards Rule asks you to collect a form from your vendor, which is why looking for one leads nowhere.

The rule puts the work on you instead. Section 314.4(f) tells a covered firm to oversee service providers by "(1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; (2) Requiring your service providers by contract to implement and maintain such safeguards; and (3) Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards" (retrieved 2026-08-05).

So the question about a chat tool is not whether the vendor signed anything special. It is whether this vendor sits in your written program, is bound by contract to safeguards, and gets looked at again on a schedule. The FTC puts the same duty in plainer words in its guide: "Select service providers with the skills and experience to maintain appropriate safeguards. Your contracts must spell out your security expectations, build in ways to monitor your service provider's work, and provide for periodic reassessments of their suitability for the job." The guide also tells firms to "Assess your apps", covering third-party software used to store, access or transmit customer information, and to encrypt that information at rest and in transit.

Exhibit 2

The Safeguards Rule asks three things of every vendor, and firms usually skip the third.

1 Select Providers capable of maintaining appropriate safeguards for the customer information at issue. 2 Bind Require those safeguards by contract. A public privacy page is not a contract with your firm. 3 Reassess Periodically, based on the risk they present and the continued adequacy of their safeguards. 16 CFR 314.4(f)(1) to (3). An AI tool that holds customer information is a service provider like any other one.
Note: the wording in steps one to three is the regulation's own, condensed. The rule sets no interval for the reassessment and no template for the contract, so "periodically" is a judgment your program has to record and defend.

If you are SEC-registered, the vendor's breach becomes your letter to write

Reg S-P opens on the same ground. "Every covered institution must develop, implement, and maintain written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer information" (17 CFR 248.30(a)(1), retrieved 2026-08-05). Paragraph (a)(3) adds that those policies must include "a program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, including customer notification procedures."

The clause an advisory firm should care about sits inside the notification test. It reaches an incident "that occurred at the covered institution or one of its service providers that is not itself a covered institution", unless the firm determines after a reasonable investigation that the information is not reasonably likely to be used in a way causing substantial harm or inconvenience.

Put client financial data into an AI tool and you have taken on notification duties for that tool's breaches. Not the vendor's duty, yours. The vendor will publish its own incident notice on its own schedule; the letter that has to reach your clients still has your firm's name at the top, and the investigation behind it still has to be yours. Which is a good reason to know which tools hold what while nothing is going wrong.

What this means for the account you buy

A personal subscription runs on a published policy the vendor can revise on its own. A business or API agreement is a contract with your firm named in it. That is what step two above is asking for. The gap between the two shows up in the vendors' own words. Anthropic's commercial terms state that "Customer Content is Customer's Confidential Information", while Google tells users of its unpaid tier, in bold, "Do not submit sensitive, confidential, or personal information to the Unpaid Services". OpenAI's business and API products do not train on customer content by default, and keep abuse-monitoring logs for 30 days, with zero data retention available only on request and only for some endpoints. Those pages were last read on 2026-08-13, and vendor terms change often enough that a program relying on them needs its own recheck date.

None of that turns a chat tool into a compliant system by itself. It gives you something to point at when the reassessment comes round, which is more than a personal login can offer. And most of the work in an advisory firm never touches client information in the first place, so the honest first step is sorting which of your tasks actually carry client data rather than buying anything.

For the narrow slice that genuinely cannot leave the building, running the model on your own hardware takes the service provider out of the picture altogether. The program stays, and the safeguards plus the evidence that they work are then yours to produce. We have written separately about what keeping the model on a machine in your own office costs.

What to do this quarter

Write down which of the two rules applies to your firm, with the reason. List every AI tool anyone in the office uses, personal accounts included, because those are the ones missing from the program. Move any work touching client information onto a contracted tier. Add each tool to the written program with a named owner and a date for the next look. Then read your incident response plan and check it answers the question of what happens when the breach is at a vendor rather than at your desk.

That is a short list, and the hard part is the first item on it rather than the tooling. If you would like a hand setting the guardrails before the tools, that is work we do.

Common questions

Can financial advisors use ChatGPT?

Yes. No rule in either regime bans generative AI. Both regimes ask you to run a written information security program and to bring any provider handling customer information inside it. Where firms get into difficulty is entering client information through a personal account nobody has written down, which fails the program duty regardless of how the tool behaves.

Does the Safeguards Rule apply to a state-registered adviser?

The FTC's compliance guide lists "investment advisors that aren't required to register with the SEC" among the examples of covered financial institutions, and names credit counselors, other financial advisors and tax preparation firms alongside them. Advisers required to register with the SEC fall under Reg S-P at 17 CFR 248.30 instead. Confirm your own status rather than assuming it, because the two rules have different notification mechanics.

Do I need a signed agreement with the AI vendor?

There is no BAA under Gramm-Leach-Bliley, so there is nothing of that shape to chase. What 16 CFR 314.4(f)(2) does require is "Requiring your service providers by contract to implement and maintain such safeguards", which in practice means the commercial or enterprise agreement rather than the consumer terms of service. Whether a given agreement's wording satisfies your program is a question for your counsel.

Start a conversation

All notes Start a conversation