AI Compliance Risks: Reg S-P, GLBA, HIPAA and PCI DSS

AI Compliance Risks: What Businesses Need to Know About HIPAA, PCI, and Data Privacy

AI tools don't get a pass on compliance because they're new. If an AI tool touches client financial data, patient records or card data, the same rules apply to it as to any other system, and your business is still responsible for how that data is handled.

A common assumption in AI adoption conversations is that a reputable vendor, a cloud product or widespread use means the compliance question is already handled. It usually isn't. AI tools process data, and in many businesses that data carries specific legal obligations. Those obligations don't change because the software is powered by AI, and AI adds a few wrinkles the older frameworks weren't written for.

This article covers what to check before you hand sensitive data to an AI tool, and how to adopt AI without creating a compliance problem. NerdSquad is not a law firm; confirm your obligations with your compliance counsel.

The core issue: AI tools are data processors

When an AI agent reads your inbox, drafts responses, looks up records to answer scheduling questions or analyzes financial data for a report, it is processing that data. The processing being automatic doesn't change what the data is or which rules apply.

Every framework NerdSquad works with regularly (HIPAA, PCI DSS, SOC 2, GLBA, SEC rules for advisers and FINRA rules for broker-dealers) has something to say about how data is processed, who processes it, where it goes and what protections must be in place. AI tools fall inside those frameworks like any other system.

Financial services: SEC Regulation S-P and the FTC Safeguards Rule

Which rule applies depends on how your firm is regulated.

SEC-registered advisers and broker-dealers

For registered investment advisers (RIAs) and broker-dealers, the governing privacy and safeguards rule is SEC Regulation S-P. The amendments adopted in May 2024 require a written incident response program, notice to affected customers within 30 days of discovering unauthorized access to sensitive customer information, oversight of service providers and supporting records. Larger entities had to comply by December 3, 2025, and smaller entities by June 3, 2026, so these requirements are now in effect.

An AI vendor that processes client information is a service provider under that oversight requirement. You should be able to show you vetted it, that your contract requires it to protect the data, and that it will notify you of a breach. Client communications an AI drafts or sends may also fall under books-and-records rules, so make sure they are captured and retained like any other business communication. Broker-dealers also answer to FINRA rules on supervision and communications.

Other financial businesses under GLBA

Tax preparers, mortgage brokers and other non-bank financial institutions that aren't SEC-registered fall under the FTC Safeguards Rule, issued under the Gramm-Leach-Bliley Act (GLBA). It requires a written information security program, a qualified individual responsible for it, risk assessments, multi-factor authentication, encryption and oversight of service providers. Since May 2024 it also requires notifying the FTC within 30 days when unencrypted information of 500 or more consumers is involved in a security event. Insurance agencies are generally regulated under state insurance law, so check with your counsel which rules apply to you.

For any of these firms, an AI tool that touches client financial data needs the same due diligence as any other vendor: a written contract, data processing terms and confirmation that its security meets the standard. Our page on IT for investment advisers and financial firms covers how we support this work, and GLBA (Gramm-Leach-Bliley Act) explains the law in more detail.

HIPAA and AI: medical and dental practices

HIPAA governs how protected health information (PHI) is handled. If an AI tool can access patient names, appointment records, clinical notes, insurance details or any other PHI, HIPAA applies to that tool.

A Business Associate Agreement comes first

A vendor whose software creates, receives, maintains or transmits PHI on your behalf is a business associate, and you need a signed Business Associate Agreement (BAA) before PHI touches its system. Major vendors such as Microsoft and Google will sign BAAs for eligible business products. Many consumer-tier AI products won't, so using them with patient data creates a HIPAA problem regardless of how the output is used. Pasting patient notes into a free consumer chatbot to summarize them is a clear example of what not to do.

Training data is a real concern

Many AI tools, especially consumer tiers, use what you type to train or improve their models. If PHI goes in, it may be retained or used in ways that conflict with HIPAA's minimum necessary standard and its limits on disclosure. Business agreements typically include data processing terms that prevent this; consumer terms often don't.

Audit trails and access logging

The HIPAA Security Rule requires audit controls that record activity in systems containing PHI. If an AI agent reads records, generates summaries or sends communications, those actions need to be logged like any other system access, and the logs need to be retained and reviewed. Our page on IT support for medical and dental practices covers how we approach this.

PCI DSS and AI: businesses that take card payments

PCI DSS governs how payment card data is handled. If your business accepts credit cards, you operate within it whether you think about it much or not.

The risk is usually less about an AI tool processing card data directly and more about a tool with broad access touching systems or logs that contain card data. An AI agent with access to email might encounter forwarded receipts. An analytics tool with access to transaction data might ingest more than it needs.

PCI's scope principle applies: AI tools should reach only the data they need, and systems holding cardholder data should be evaluated carefully before any AI tool is connected to them. If an agent can reach your cardholder data environment, it may be pulled into PCI scope, with all the security and assessment requirements that brings. See PCI DSS explained for the basics.

General data privacy, including Florida law

Outside specific regulated industries, privacy and data security laws still apply. For Florida businesses, the key law is the Florida Information Protection Act (FIPA, Florida Statutes s. 501.171). It requires reasonable measures to protect personal information and notice to affected individuals within 30 days of a breach, plus notice to the Florida Department of Legal Affairs when 500 or more Floridians are affected. The Florida Digital Bill of Rights is a consumer privacy law that applies only to very large companies, so most small and midsize businesses aren't covered by it. If you have customers in other states, their laws (such as California's CCPA/CPRA) may also apply.

Points that come up with AI tools:

  • Data minimization. Give an AI tool only the personal data it needs. A marketing tool that needs email addresses and purchase history shouldn't see your entire customer database.
  • Retention and deletion. If a customer asks you to delete their data, can you confirm it isn't sitting in a vendor's logs or training set?
  • Where data is processed. Some AI vendors process data outside the United States, which can add obligations depending on the data involved.
  • Automated decisions. Using AI to make decisions that affect customers (credit, pricing, eligibility) may trigger disclosure obligations under newer state laws.

Practical steps before you deploy an AI tool with sensitive data

None of this means you can't use AI. It means asking the right questions first.

  1. Identify what data the tool can access. Not just what you intend it to use, but everything its permissions let it reach.
  2. Match the data to the rules. Client financial data: Regulation S-P or the FTC Safeguards Rule. PHI: HIPAA. Card data: PCI DSS. Personal information: FIPA and any other applicable state laws.
  3. Review the vendor's terms. Will it sign a BAA or equivalent contract? Do its terms prohibit training on your data? What are its retention and deletion practices?
  4. Use business-tier products for sensitive data. Consumer tiers rarely include the contractual protections regulated data requires. If a tool doesn't offer suitable business terms, keep regulated data out of it.
  5. Grant least-privilege access. Give the tool the minimum access it needs, protected with multi-factor authentication. Don't grant broad access and hope it stays away from sensitive data.
  6. Log and review AI activity. Any agent acting on its own in your environment should have audit logging turned on, and someone should review those logs regularly.
  7. Document your assessment. Examiners and auditors increasingly expect evidence of due diligence on AI tools. A short written record of how you evaluated a tool before deploying it is worth having.

How NerdSquad approaches AI compliance for clients

NerdSquad helps businesses in Southwest Florida put security controls and documentation in place for healthcare, financial services, legal and retail requirements. AI doesn't change those frameworks; it adds new tools that need to be evaluated within them.

When we help a client deploy an AI agent or connect an AI tool, compliance is part of the conversation from the start: identifying which rules apply, reviewing vendor terms, configuring access, setting up audit logging and making sure the deployment doesn't quietly expand what falls under audit or examination.

We don't certify compliance; that's the job of your auditors and counsel. We make sure the technical environment supports your compliance program and that AI tools don't undermine the work you've already done to protect client data. If we already handle your cybersecurity, adding AI governance is a natural next step. For broader context, see The AI-Powered Company: Inspiration, Reality, and the Risks and Your AI Employee: How Agentic AI Can Manage Your Inbox, Calendar, and More.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT for financial advisers and wealth managers