SEC Regulation SP and AI Handling of Customer Records
Outdated rules now govern AI systems handling sensitive customer financial data.

Regulation S-P just closed a 24-year gap, and the timing could not be more pointed: the rule was built for filing cabinets and dial-up connections, and it now governs the AI systems reading through client emails and drafting portfolio notes. The SEC adopted amendments to Reg S-P on May 16, 2024, effective August 2, 2024, and the compliance clock is already running for the largest firms. What makes this update different from a routine regulatory refresh is that it never mentions artificial intelligence by name, yet AI tools fall squarely within its reach anyway. That's the tension this piece works through: a 2000-era privacy rule, amended in 2024, now stretched over technology nobody in the room was thinking about when the amendments were drafted.
Go back to the original text. Reg S-P came out of the Gramm-Leach-Bliley Act, and its core obligations, the Safeguards Rule, the Disposal Rule, annual privacy notices, were built around a world of paper files and early electronic recordkeeping. The SEC's own March 2023 proposing release said the amendments were needed "to address the expanded use of technology and corresponding risks." That's a fairly dry sentence for what amounts to an admission: the agency knew its 2000-vintage framework had fallen behind the systems actually touching customer data. What follows is the shape of that catch-up, and where AI sits inside it.
Which institutions are covered and what data the rule protects
The amended rule reaches broker-dealers, registered investment advisers, registered investment companies, funding portals, and transfer agents, whether they're registered with the SEC or with another appropriate regulatory agency. Transfer agents, at least those registered with the SEC, were previously covered under the Disposal Rule, and now sit under both the Disposal Rule and the Safeguards Rule. That's a meaningful widening of scope for an entity type that handles enormous volumes of shareholder records.
The rule also draws a "larger entities" line that determines compliance timing. SEC-registered investment advisers with $1.5 billion or more in assets under management, investment companies with $1 billion or more in net assets, and broker-dealers that don't qualify as small entities under the Securities Exchange Act all fall into this bucket, with an earlier deadline than everyone else.
But the definitional work that matters most for AI purposes is the two-tier structure for protected data. "Customer information" is broad: any record containing nonpublic personal information about a customer, in any form, handled by the institution or on its behalf, including data received from another financial institution about that firm's customers. "Sensitive customer information" is a narrower subset, the stuff whose exposure could create a reasonably likely risk of substantial harm or inconvenience. Social Security numbers, driver's license and passport numbers, tax IDs, biometric data, electronic identifiers, account credentials, all of it is in this tighter category.
Why does the distinction matter so much? Because the 30-day breach notification duty only attaches to sensitive customer information. The incident response program itself, though, has to address unauthorized access to customer information broadly, the wider category. An AI tool that mishandles a client's mailing address triggers different obligations than one that leaks a Social Security number, even though both events involve "customer information" in the plain-English sense. Firms that don't track this asymmetry carefully will misjudge their own notification duties.
The five new obligations every covered institution must now meet
Larger entities had until December 3, 2025 to comply. Smaller entities have until June 3, 2026, and that date is closing in fast enough that firms without a program in place are now working under real time pressure.
The first requirement is a written incident response program. Firms need documented policies and procedures to detect, respond to, and recover from unauthorized access to customer information, covering how the firm assesses which systems and data were affected, the scope of the incident, containment steps, and customer notification procedures. The SEC didn't prescribe a specific design here. Firms can tailor the program to their own operations, but it has to exist on paper and reflect the firm's actual practices.
Second: the 30-day breach notification clock. Once a firm discovers unauthorized access to sensitive customer information, notice has to reach affected individuals as soon as practicable and no later than 30 days out. The clock starts at discovery, not once an investigation wraps up, which is a meaningfully tighter standard than firms may be used to under overlapping state breach laws. There's an out: the rule includes a harm-based exception under which notice may not be required in certain limited circumstances. An Attorney General can also delay notification for national security or public safety reasons. Content requirements for the notice track existing state breach reporting standards, so firms aren't building this from scratch.
Third, and most relevant to AI vendors: service provider oversight paired with a 72-hour notification requirement. Institutions need written policies covering due diligence and ongoing monitoring of service providers, and those providers must notify the covered institution as soon as possible and no later than 72 hours after discovering a breach touching customer information. The covered institution stays on the hook for compliance even when the notification duty has effectively been delegated to the vendor. Contracts will likely need rewriting to build in incident response and notification language. And the 72-hour requirement doesn't technically have to be nailed down contractually, firms have some flexibility in how they get that assurance, but going without a contractual commitment leaves a gap that's hard to defend during an exam.
Where AI tools fit inside this framework
When a broker-dealer or an RIA runs generative AI over customer nonpublic personal information, Reg S-P applies. It does, fully, with no carve-out. The safeguards obligation, the incident response duty, and the service-provider regime all apply the moment an AI system touches customer data, even if the rule's drafters never pictured that scenario.
AI vendors are service providers under this framework, full stop. The SEC's Division of Examinations has flagged third-party vendor oversight as within scope of Reg S-P reviews, and separately named AI risk as a cybersecurity training and controls priority. The agency hasn't explicitly fused these into one "vendor AI" category, but the practical effect is the same: an AI vendor handling customer information is a service provider, and the 72-hour breach notification requirement applies to that vendor exactly as it would to a legacy custodian or clearing firm.
The list of what counts as a vendor is wider than most compliance teams assume. Marketing firms, portfolio management sub-advisers, AI tools transcribing meeting notes or summarizing emails, even affiliated entities that operate functionally as third parties, all of it falls inside the oversight obligation. A subsidiary's AI platform doesn't get a pass just because it shares a parent company.
So how wide is the gap between AI adoption and AI governance right now? Roughly 40% of investment adviser firms have implemented AI tools internally. Of those, 44% have no formal testing or validation process for AI outputs. Nearly half of firms already using AI in some internal capacity have no structured way of checking whether that AI is doing what it's supposed to, and just as few can say it's handling customer data the way Reg S-P requires. That's a documented compliance gap regulators have already flagged, representing a real exposure rather than a hypothetical one. That's a documented compliance gap regulators have already flagged.
The practical fix firms are reaching for is a written acceptable-use policy for AI, spelling out what's fine (drafting internal notes, summarizing non-sensitive documents) and what's off-limits (typing a client's Social Security number into a public-facing AI chatbot). Without that line drawn clearly, staff will route sensitive information through consumer-grade AI tools that sit entirely outside any Reg S-P service-provider agreement. That's an uncovered exposure in the most literal sense: no contract, no due diligence, no 72-hour notification duty, because the tool was never onboarded as a vendor. It just showed up in someone's browser tab.
What regulators are examining and enforcing
The SEC's Division of Examinations named Reg S-P compliance with the 2024 amendments as a 2026 priority, a list issued under Chairman Paul Atkins. Information security and Reg S-P have appeared in the Division's examination priorities for multiple consecutive years, which tells its own story: it is a persistent, recurring focus. It's a standing fixture of exam planning.
What do examiners actually look at? Whether firms have built, implemented, and maintained policies covering administrative, technical, and physical safeguards. Governance practices, data loss prevention, access controls, account management, and how the firm responds to and recovers from cyber incidents. Training and security controls that respond specifically to AI-driven threats, the SEC names AI directly here, it's not buried in generic cyber language. Vendor oversight activity, including whether a firm has documented visibility into how its vendors are using AI internally. And whether a firm's public disclosures about its AI use are accurate, matched against actual policies and supervisory practices.
FINRA runs a parallel track for broker-dealers. Its 2026 Annual Regulatory Oversight Report reminded member firms of the June 3, 2026 deadline, and back in January 2025, FINRA asked firms to update information about third-party vendor engagements, with particular attention to mission-critical systems and functions. That request lines up directly with AI deployment questions: which vendor is running the AI, what does it touch, and is it mission-critical to the firm's operations?
How firms should build AI governance that satisfies Reg S-P
Start with a gap analysis. Pull the existing cybersecurity and incident response policies and test them against each of the five obligations above, specifically asking whether they account for AI-generated data flows and AI vendor relationships. Most legacy policies were written before anyone at the firm was feeding client data into a language model, so this step usually reveals blind spots fast.
From there, build an actual inventory of AI touchpoints. Every AI tool, internal or third-party, that processes, stores, or transmits customer information or sensitive customer information needs to show up on this list. That includes tools that feel internal but aren't, structurally, a subsidiary's AI platform or an affiliate's portfolio analytics tool still counts as a third party for these purposes, even if it shares a logo with the parent firm.
Vendor contracts need a hard look next. Any AI vendor touching customer data should have breach notification language matched to the 72-hour standard, along with documented due diligence and ongoing monitoring throughout the relationship. As noted above, the rule doesn't require this to be locked in contractually, but firms remain responsible either way, so getting it in writing is the safer path regardless of what the rule technically demands.
Finally, the acceptable-use policy needs teeth. Defining permitted and prohibited AI uses on paper does nothing if nobody reads it. Training, signed acknowledgment, and actual monitoring are what turn a policy document into something that holds up when an examiner asks to see it. A written policy nobody follows is arguably worse than no policy at all, because it creates a paper trail showing the firm knew the risk and didn't enforce its own rule.



