SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Bank blocks confidential data leaks to public AI tools

Bank blocks confidential data leaks to public AI tools

Fri, 18th Sep 2026 (Today)
Karen Joy Bacudo
KAREN JOY BACUDO Finance Editor

A regional investment bank deployed eScan Enterprise DLP to block confidential data transfers to public AI platforms, stopping hundreds of attempted transmissions during implementation.

The bank introduced the controls as staff increasingly used generative AI tools for market research, financial modelling, investment analysis and risk assessment. Approved platforms included ChatGPT, Claude and Gemini, but the bank wanted to prevent employees from sending sensitive financial information beyond its own security controls.

The deployment centres on an endpoint data loss prevention agent that monitors AI interactions across analyst workstations, trading floors, research teams and mobile devices. eScan said the software inspects content in real time before it reaches an external AI service, classifies the material and blocks transmissions that breach policy.

Protected information included client account details, trading strategies, proprietary models, material non-public information and deal-related confidential information. The bank also created classifications for public data, internal reference data, client-confidential information and trading-sensitive information, which the endpoint agent enforced automatically.

AI controls

Rather than ban AI tools outright, the bank created approved workflows for different tasks. It directed market research to approved Claude instances, general macroeconomic analysis to Gemini, and research based on public financial data to ChatGPT.

This gave employees continued access to AI systems while limiting the type of information they could submit. If an analyst attempted to transmit restricted information, the request could be stopped before the data reached the public platform, and the user would be alerted.

The implementation was also linked to the bank's existing compliance infrastructure, including surveillance systems, audit logging and compliance reporting. Audit trails were set up to record who used an AI platform, when it was used, what data was analysed and which system processed the request.

Such records are likely to matter for financial institutions facing tighter scrutiny over data governance, client confidentiality and the handling of market-sensitive information. Public AI tools have become more common in front-office and research functions, but their use has raised concerns that staff may inadvertently disclose regulated or commercially sensitive material when drafting prompts or uploading documents.

Adoption challenge

The roll-out also addressed staff acceptance. eScan said early adoption by senior analysts helped support wider use across teams after the bank showed that monitoring could reduce the risk of inadvertent regulatory breaches while preserving legitimate research activity.

The blocked transfers covered several categories of sensitive information, including client portfolio information, trading strategies and execution models, material non-public information, and deal-related data protected by confidentiality agreements.

According to the supplier, the monitoring relies on a mix of machine learning, behavioural analysis, content inspection and optical character recognition to identify protected information. It extends familiar data loss prevention methods used for email and removable media to large language model platforms.

Financial firms have been weighing how to introduce AI tools into day-to-day work without creating new compliance risks. Analysts and deal teams can use generative AI to summarise research, test scenarios and organise information, but unrestricted use of consumer-facing tools can expose internal data, client records or transaction details to external services.

Many institutions have responded with bans or heavily restricted access. In this case, the bank adopted a model that separated acceptable use from prohibited data sharing and built oversight around approved systems.

Govind Rammurthy, Chief Executive Officer & Managing Director, eScan, described the approach as an alternative to a blanket prohibition on AI use.

"Financial services firms face a manufactured choice: restrict AI adoption to protect confidential data, or enable AI and hope analysts don't accidentally leak trading strategies to ChatGPT. That's a false choice. Monitor what data flows where. Block the confidential stuff automatically. Allow analysts to use AI for legitimate market research and analysis. It's straightforward endpoint monitoring-the same principle that prevents data leakage to email or USB drives, just extended to LLM/AI platforms. You don't need to restrict innovation. You need to control data flow," said Rammurthy.