Client NPI, Confidentiality, and the Reg S-P Trap
An advisor is between a 9:30 review and an 11:00 prep call. He has a Zocks transcript from a discovery meeting the day before. He wants to draft a follow-up note. He opens a free public LLM on his personal phone, removes the client's name from the transcript, and pastes the rest โ DOB, employer name, AGI, account types and balances, beneficiary names, the home town โ with the prompt "draft a follow-up email referencing three specifics from this meeting." The output is good. He copies it, edits for tone, and sends. He believes he has anonymized the data. Under Reg S-P (17 CFR Part 248) and the GLBA Safeguards Rule, he has not. Removing a name from a dataset that contains DOB plus employer plus AGI plus account types plus beneficiary names plus home town is not anonymization โ it is pseudonymization at best, and the combination is re-identifiable. This lesson builds the practical paste-and-don't-paste decision framework for the 2026 advisor, maps the three tool tiers (free public LLM, enterprise LLM, vendor-hosted advisor AI), explains why "I removed the name" is not a Reg S-P defense, and walks the 30-day breach clock and IRP trigger when something gets pasted that should not have been.
What Counts as Anonymization vs. Pseudonymization Under Reg S-P
The distinction between anonymization and pseudonymization is not academic โ it is operationally consequential under Reg S-P, the GLBA Safeguards Rule, NY DFS 23 NYCRR 500, California CPRA's CCPA framework, and increasingly state-by-state AI rules. Anonymization is the irreversible transformation of personal data such that the data subject cannot be re-identified, even when the anonymized dataset is combined with other available data. Pseudonymization is the substitution of identifying fields with synthetic identifiers in a way that allows re-identification when combined with separately held information or with other available data sources.
The wealth-specific reality: most "anonymization" advisors believe they are doing is actually pseudonymization, and the combination of seemingly innocuous attributes is highly re-identifying. A 1999 study (and many subsequent confirmations) showed that birth date + ZIP code + sex was sufficient to uniquely identify roughly 87% of the US population. Add employer name and AGI bracket and the uniqueness rises to nearly 100%. The advisor who pastes a "name-removed" Zocks transcript into a free LLM has shared re-identifiable client NPI with a third-party service provider lacking an executed data-handling agreement. The fact that the LLM's training-on-inputs terms permit the input to flow into future model training amplifies the exposure. Under the May 2024 Reg S-P amendments, this is the kind of event that triggers the firm's IRP evaluation and potentially the 30-day customer notification clock.
The Three Tool Tiers and What Can Be Pasted Into Each
Tier 1 โ Free Public LLMs and Consumer AI
Examples: ChatGPT free tier, Claude.ai consumer, Gemini consumer, Perplexity free, browser-extension AI tools without enterprise agreements, mobile AI apps used on personal devices. Categorically off-limits for any client NPI, including pseudonymized client NPI. Permitted inputs: general financial concepts ("explain the IRC ยง72(t) SEPP exception"), general regulatory questions ("what is the FINRA Rule 4511 retention period"), draft language with no client-specific facts ("draft a generic Roth conversion concept memo"). The category-level prohibition is the operational simplification that prevents most exposures.
Tier 2 โ Enterprise LLMs with Executed Data-Handling Agreements
Examples: OpenAI Enterprise / Team with appropriate data controls, Microsoft Copilot for the firm tenant, Google Gemini Enterprise / Workspace with appropriate data residency, Anthropic Enterprise. The data-handling agreement must provide no-training-on-inputs, data residency, breach notification (within 72 hours per the May 2024 Reg S-P service-provider oversight requirement), and audit rights. Permitted with controls: client NPI may flow into Tier 2 tools when the firm's WSPs permit and the user is operating from a firm-managed device with MFA, in compliance with the firm's data-classification matrix. The 2026 enterprise LLMs in this tier handle most use cases.
Tier 3 โ Vendor-Hosted Advisor AI
Examples: Jump (meeting notes), Zocks (meeting notes), FinMate AI, Sybill, Zeplyn, Holistiplan (tax extraction), FP Alpha (estate / insurance / tax extraction), Wealth.com (estate), RightCapital / eMoney / MoneyGuidePro (planning), Orion Eclipse (portfolio), Salesforce FSC + Einstein (CRM), Wealthbox AI, Redtail Engage, Catchlight (prospecting), SmartAsset (lead-gen), Smarsh / Global Relay (archiving). These tools are purpose-built for advisor workflows; their data-handling agreements at the appropriate enterprise tier are designed for client NPI flow. The firm's vendor due diligence (L4 Ch2) verifies SOC 2 Type II, data residency, breach SLA, contract provisions, and sub-processor flow-down. Permitted with controls: client NPI flows into Tier 3 tools when due diligence is complete, the contract is executed, and the firm's WSPs include the tool in the approved inventory with the appropriate data categories.
The Paste-and-Don't-Paste Decision Framework
The practical decision the advisor makes dozens of times a day is whether the content about to be pasted is permitted into the tool about to be used. The framework is two questions in sequence.
Question 1: Is this NPI?
Anything that, alone or in combination, can identify a customer or relate to a customer's financial circumstances is NPI. The wealth-specific NPI catalog includes: client name + any account-related fact, account number, SSN, DOB, address, employer name + financial position, transaction history, planning facts, family structure, beneficiary designations, tax return facts, brokerage statement facts, K-1 / Schedule K-1 facts, trust provisions, estate document facts, the existence of the advisory relationship (in many contexts), and combinations of attributes that allow re-identification (DOB + ZIP + sex; employer + AGI bracket; geographic + occupation + age combinations).
Question 2: Which Tier Is This Tool?
If NPI = no, any tier is acceptable. If NPI = yes, Tier 1 (free public LLM) is prohibited; Tier 2 (enterprise LLM with executed agreement) and Tier 3 (vendor-hosted advisor AI) are acceptable subject to the firm's data-classification matrix and WSPs covering the specific data category. If unsure about either question, default to the most conservative option: assume NPI, default to vendor-hosted advisor AI or the Holistiplan-style structured integration that handles the data extraction within the secure environment.
Practical Quick Reference
"Explain the IRC ยง72(t) SEPP exception" โ any tier. "Draft a generic concept memo on Roth conversions" โ any tier. "Summarize the attached Zocks discovery transcript with the client's name and DOB and employer and AGI" โ Tier 2 or Tier 3, not Tier 1. "Extract the line items from this 1040" โ Tier 3 (Holistiplan or equivalent integrated tool), or Tier 2 with care, never Tier 1. "Help me think through this hypothetical client situation with all NPI removed and generalized" โ any tier, but with caution to ensure the generalization is genuine and not pseudonymization.
Why "I Just Removed the Name" Is Not a Reg S-P Defense
Three reasons the "I removed the name" pattern fails as a Reg S-P or GLBA defense.
Reason 1: Re-Identification Risk
As discussed above, combinations of attributes commonly remaining in a "name-removed" dataset (DOB, ZIP, employer, AGI bracket, account types, account sizes, family structure) routinely permit re-identification with high probability. The de-identification standard under HIPAA's Safe Harbor identifies 18 specific identifiers that must be removed; the wealth context has no equivalent safe harbor and the combinations remaining in a typical advisor paste are highly identifying.
Reason 2: The Purpose of the Paste Defeats Anonymization
The advisor pastes content because the content relates to a specific client and the advisor wants AI output relating to that specific client. Even if the content were perfectly anonymized at the paste moment, the advisor's downstream use re-identifies it (the follow-up email goes to the named client; the recommendation memo references the named account; the AI's output is operationally re-attached to the named customer). The "anonymization" was never functional.
Reason 3: The Data Flow and Vendor Terms
Free public LLMs' terms of service typically permit the vendor to use inputs to improve the service, including training future models. The pasted content โ name removed or not โ flows into the vendor's data flow. Under Reg S-P's expanded service-provider oversight, the firm should have an executed data-handling agreement before NPI flows to the vendor, with controls on training, residency, breach, and audit. The free tier has no such agreement; the data flow is uncontrolled. The pseudonymization on the front end does not change the data-flow problem on the back end.
The 30-Day Breach Clock and the IRP Trigger When Something Gets Pasted
The May 2024 Reg S-P amendments require the firm to provide notification to affected individuals as soon as practicable but no later than 30 days after becoming aware that NPI was, or is reasonably likely to have been, accessed or used without authorization. Three operational implications when an unauthorized paste is discovered.
How Discovery Happens
Discovery patterns include: registered-person self-report (training-driven), quarterly attestation cycle, shadow AI detection (network traffic analysis revealing traffic to unauthorized AI vendor domains, endpoint monitoring revealing AI tool installation, IAM logs revealing unusual access), customer complaint or inquiry, vendor self-disclosure (e.g., an AI vendor notifies the firm that one of the firm's email addresses was used to access an unauthorized account), regulator inquiry.
The Firm's Evaluation
Once aware, the firm evaluates whether unauthorized access or use is reasonably likely. For most fact patterns involving consumer-tier AI with training-on-inputs terms, the answer is yes. The firm activates the IRP, identifies the affected customer(s), determines the scope, and prepares the notification. The 30-day clock runs from awareness. NY DFS 23 NYCRR 500 may impose a parallel 72-hour Superintendent notification for NY-Covered Entities. State breach-notification statutes layer on by customer residency. FINRA 4530 reporting may apply if certain customer-harm thresholds are met. The L4 Ch3 L4 AI Incident Response lesson develops the playbook.
The Customer Notification
The notification must include sufficient detail for the affected individual to understand the incident and the firm's response. Reg S-P's notification rule (and related state statutes) include specific content requirements that the firm's templates should pre-stage. The notification is delivered as soon as practicable but no later than 30 days; the operational reality is most firms target delivery within 7-14 days once awareness is established to allow time for affected individuals to take protective action.
The Supervisor Perspective and the Tuesday Attestation
From the CCO or OSJ seat, the operational defense against unauthorized AI use is the combination of architecture, controls, and culture. Architecture: enterprise LLM tenants are deployed with executed agreements, vendor-hosted advisor AI is approved with documented diligence, the data-classification matrix is tool-specific and accessible, and the WSPs document the framework. Controls: endpoint monitoring detects unauthorized AI installations, network-traffic analysis detects traffic to unauthorized AI vendor domains, IAM enforces access, MFA is required on firm-managed devices, and shadow AI detection runs continuously. Culture: registered persons understand why the discipline matters (the cumulative compounding of small unauthorized pastes is the supervisory failure under Rule 3110 reasonable design), quarterly attestation cycles surface unauthorized use, training reinforces the framework, and the "Tuesday attestation" โ a recurring brief acknowledgment by every advisor confirming compliance with the AI acceptable-use policy in the prior period โ is the operational glue. The 2026 firm without continuous attestation and detection is operating in the visibility gap the FINRA 2026 Report frames as itself a supervisory failure.
A Handful of Honest Edge Cases
The Mobile-on-the-Road Edge Case
An advisor on a road trip needs to draft a follow-up between meetings. The firm's enterprise LLM is accessible via mobile app on the firm-managed device. The acceptable-use policy permits the workflow. The compliant path: use the mobile app on the firm-managed device, not a personal phone with a consumer chatbot. The architecture must make the compliant path available.
The Vendor Sub-Processor Edge Case
A Tier 3 vendor-hosted advisor AI uses a sub-processor (often an LLM provider) for the AI capability. The firm's executed agreement with the vendor must flow-down the no-training, residency, and breach SLA controls to the sub-processor. The L4 Ch2 vendor DDQ asks the question explicitly.
The Screenshot / Photo Edge Case
An advisor takes a screenshot of a custodian statement and uses an AI tool's image-input feature to summarize. The screenshot contains NPI in image form. The same tier analysis applies: image-based input is data input, and the data-handling agreement covers image inputs. Free public AI's image-input feature is categorically off-limits for NPI screenshots.
The Cell-Phone Call Edge Case
An advisor uses a personal cell phone for a quick client check-in call. AI transcription on personal devices is shadow AI; the call should be on a firm-managed line with the firm's approved meeting AI (Zocks, Jump, FinMate) or recorded via the firm's archive (Smarsh, Global Relay) per Rule 4511.
Key Takeaways
- "I removed the name" is not anonymization under Reg S-P. Combinations of DOB, ZIP, sex, employer, AGI bracket, account types, family structure, and beneficiary names routinely permit re-identification with high probability. Wealth has no HIPAA Safe Harbor equivalent; pseudonymization is the operational reality of most "anonymized" pastes.
- The three tool tiers: Tier 1 (free public LLM โ categorically off-limits for any client NPI), Tier 2 (enterprise LLM with executed data-handling agreement โ permitted with controls per WSPs), Tier 3 (vendor-hosted advisor AI like Jump, Zocks, Holistiplan, FP Alpha, Wealth.com, RightCapital, eMoney, Orion Eclipse, Salesforce FSC + Einstein, Wealthbox, Redtail, Catchlight, Smarsh โ permitted with controls after due diligence).
- The paste-and-don't-paste decision framework: two questions โ Is this NPI? Which tier is this tool? โ with the conservative default of treating ambiguous content as NPI and using the higher-tier tool.
- Why removing the name does not defend: (1) re-identification risk from remaining attributes; (2) the purpose of the paste re-attaches the data to the named client downstream; (3) the data flow into the vendor and the absence of an executed data-handling agreement are independent issues from the front-end pseudonymization.
- The 30-day breach clock and IRP trigger activate when the firm becomes aware that NPI was, or is reasonably likely to have been, accessed or used without authorization. Most consumer-tier-AI pastes meet the reasonably-likely standard. Discovery patterns: self-report, attestation, shadow AI detection, complaint, vendor disclosure, regulator inquiry. NY DFS 72-hour Superintendent notification may layer on for NY-Covered Entities; state breach statutes by customer residency; FINRA 4530 if applicable.
- Supervisor defense: architecture (enterprise tenants, vendor diligence, data-classification matrix, WSPs), controls (endpoint, network, IAM, MFA, shadow AI detection), culture (training, quarterly attestation, the Tuesday-attestation discipline).
- Honest edge cases: mobile-on-the-road (use firm-managed device + enterprise LLM mobile app), vendor sub-processors (flow-down controls in the contract), screenshot / photo (same tier analysis applies; image-input is data input), cell-phone call (use firm-managed line and approved meeting AI, not personal devices).
Skill.re