Your team is probably already using AI tools. The compliance question is whether you have any control over what they put into them.
Does anyone on your staff use ChatGPT, Microsoft Copilot, Google Gemini or another AI tool for work? Without an explicit policy, the answer is almost certainly yes. In a regulated business (healthcare, financial services, legal, or anyone handling personal data), that makes AI a compliance topic now, not later. There's no need to panic or ban AI outright. The better move is to deploy it deliberately. Here is what the obligations look like, framework by framework.
HIPAA's Privacy and Security Rules apply to protected health information (PHI) in any form. If someone pastes a patient's name, date of birth or diagnosis into an AI tool to draft a letter or summarize a chart, that PHI may be processed and retained by the AI vendor in ways no Business Associate Agreement (BAA) covers.
Most general-purpose AI tools are not set up for PHI by default. Some business versions can be, but that takes a BAA with the vendor, the right configuration, and ongoing checks that the configuration still holds. A big, well-known vendor name is not a HIPAA compliance program. For practices, our page on IT support for medical and dental practices covers the wider picture.
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect customers' nonpublic personal information (NPI) and to oversee the security practices of their service providers. For non-bank financial institutions, the FTC Safeguards Rule spells this out: a written information security program, risk assessment and service-provider oversight. An AI tool that processes NPI (account numbers, income data, Social Security numbers) is a service provider for that purpose.
That means a vendor review, an agreement that addresses your obligations, and documented evidence that you evaluated the vendor's security. "We use Copilot" is not a vendor oversight program. See our GLBA dictionary entry and Do you help financial advisors stay SEC, FINRA, and GLBA compliant?
PCI DSS is built around keeping the cardholder data environment small: the fewer systems that touch card data, the smaller your compliance scope. An AI tool used in any workflow involving cardholder data is potentially in scope. The more common risk is shadow IT, where staff use personal AI tools on company devices that also handle payments, creating data flows outside any controlled environment.
The rules differ depending on who you are. The SEC's 2023 cybersecurity disclosure rules (Form 8-K Item 1.05) apply to public companies. For registered investment advisers and broker-dealers, the relevant obligations come from amended Regulation S-P: a written incident response program, customer notification within 30 days of discovering unauthorized access to sensitive customer information, and oversight of service providers. The compliance dates have passed for both larger and smaller firms. AI touches these rules in three places:
Our IT for financial advisers and wealth managers page covers how we support firms with these requirements.
Copilot deserves specific attention because its defaults are often not what a compliance officer would choose. Copilot can reach any document, email or Teams message the user has permission to open, and in a loosely configured Microsoft 365 tenant that can be far more than anyone intended. It can also surface sensitive information in its answers in ways that aren't obvious.
A controlled Copilot rollout usually involves sensitivity labels, data loss prevention rules, permission cleanup, retention policies and audit logging. Several of these are not configured out of the box. We help clients review and set up these controls as part of our Microsoft 365 support.
For a practical checklist, see AI Compliance Risks: HIPAA, PCI, and Data Privacy.
NerdSquad is not a law firm; confirm your obligations with your compliance counsel.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.