AI and Compliance: What to Know Before Deploying AI

AI and Compliance: What Every Business Needs to Know Before Deploying AI Tools

Your team is probably already using AI tools. The compliance question is whether you have any control over what they put into them.

Does anyone on your staff use ChatGPT, Microsoft Copilot, Google Gemini or another AI tool for work? Without an explicit policy, the answer is almost certainly yes. In a regulated business (healthcare, financial services, legal, or anyone handling personal data), that makes AI a compliance topic now, not later. There's no need to panic or ban AI outright. The better move is to deploy it deliberately. Here is what the obligations look like, framework by framework.

HIPAA and AI

HIPAA's Privacy and Security Rules apply to protected health information (PHI) in any form. If someone pastes a patient's name, date of birth or diagnosis into an AI tool to draft a letter or summarize a chart, that PHI may be processed and retained by the AI vendor in ways no Business Associate Agreement (BAA) covers.

Most general-purpose AI tools are not set up for PHI by default. Some business versions can be, but that takes a BAA with the vendor, the right configuration, and ongoing checks that the configuration still holds. A big, well-known vendor name is not a HIPAA compliance program. For practices, our page on IT support for medical and dental practices covers the wider picture.

GLBA and AI

The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect customers' nonpublic personal information (NPI) and to oversee the security practices of their service providers. For non-bank financial institutions, the FTC Safeguards Rule spells this out: a written information security program, risk assessment and service-provider oversight. An AI tool that processes NPI (account numbers, income data, Social Security numbers) is a service provider for that purpose.

That means a vendor review, an agreement that addresses your obligations, and documented evidence that you evaluated the vendor's security. "We use Copilot" is not a vendor oversight program. See our GLBA dictionary entry and Do you help financial advisors stay SEC, FINRA, and GLBA compliant?

PCI DSS and AI

PCI DSS is built around keeping the cardholder data environment small: the fewer systems that touch card data, the smaller your compliance scope. An AI tool used in any workflow involving cardholder data is potentially in scope. The more common risk is shadow IT, where staff use personal AI tools on company devices that also handle payments, creating data flows outside any controlled environment.

SEC rules and AI

The rules differ depending on who you are. The SEC's 2023 cybersecurity disclosure rules (Form 8-K Item 1.05) apply to public companies. For registered investment advisers and broker-dealers, the relevant obligations come from amended Regulation S-P: a written incident response program, customer notification within 30 days of discovering unauthorized access to sensitive customer information, and oversight of service providers. The compliance dates have passed for both larger and smaller firms. AI touches these rules in three places:

  • Books and records. AI-assisted client communications may need to be captured by your archiving system. If an adviser uses a standalone AI tool that sends output outside your normal channels, those messages may never be archived.
  • Service-provider oversight. An AI vendor that handles customer information falls under the same oversight expectations as any other vendor.
  • Marketing accuracy. The SEC has brought enforcement actions against advisers for misrepresenting their use of AI. Any claim about AI in your investment process needs to be accurate and documented.

Our IT for financial advisers and wealth managers page covers how we support firms with these requirements.

The Microsoft 365 Copilot configuration problem

Copilot deserves specific attention because its defaults are often not what a compliance officer would choose. Copilot can reach any document, email or Teams message the user has permission to open, and in a loosely configured Microsoft 365 tenant that can be far more than anyone intended. It can also surface sensitive information in its answers in ways that aren't obvious.

A controlled Copilot rollout usually involves sensitivity labels, data loss prevention rules, permission cleanup, retention policies and audit logging. Several of these are not configured out of the box. We help clients review and set up these controls as part of our Microsoft 365 support.

What a well-controlled AI deployment looks like

  • Approved tools list: which AI tools are authorized, for what purposes and with what types of data. It doubles as a vendor oversight record.
  • Data handling boundaries: clear, enforced limits on which regulated data may go into AI tools.
  • Vendor review: for any AI tool touching regulated data, review the vendor's security, sign the right agreements (a BAA for HIPAA, a service-provider agreement for GLBA or Reg S-P) and document the review.
  • Archiving check: confirm AI-assisted client or patient communications are captured where your records rules require it.
  • Endpoint and access controls: EDR and a Zero Trust approach should cover the devices and accounts your AI tools run on.
  • Training: staff need to know what they can and cannot put into AI tools, and why. Security awareness training is a standard part of NerdSquad cybersecurity plans, and AI use belongs in it.

For a practical checklist, see AI Compliance Risks: HIPAA, PCI, and Data Privacy.

NerdSquad is not a law firm; confirm your obligations with your compliance counsel.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity services for businesses