โ†
AI for Financial Advisors & Wealth Managers
Aware ยท M9 ยท lesson 9 of 17 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Reg S-P, GLBA Safeguards, NY DFS Part 500, and the State Patchwork
๐Ÿ“–
now learning

Reg S-P, GLBA Safeguards, NY DFS Part 500, and the State Patchwork

15 min

An advisor on a coffee break opens a free public LLM on a personal phone and pastes a client's 1040 page-one (name, SSN, address, dependents, AGI) to "see if AI can spot any Roth conversion windows." Eight seconds later the chatbot returns a useful answer. The advisor takes a screenshot, walks back to the office, and forgets about the prompt. Under the May 2024 amendments to Regulation S-P (17 CFR Part 248), this is an information-sharing event with a third-party service provider that has no executed agreement with the firm; it implicates the firm's breach-response obligations; it potentially triggers the 30-day notification clock if the firm cannot satisfy itself that the information has not been used in a manner that resulted in substantial harm or inconvenience; it implicates the GLBA Safeguards Rule; it likely triggers state-level cyber rules (NY DFS Part 500, California CPRA, Texas DIR) depending on residency and the firm's jurisdictional footprint; and for the annuity-licensed advisor it implicates the NAIC AI Model Bulletin and Model #275. The 1040 page-one โ€” name, SSN, address, AGI โ€” is nonpublic personal information; the public LLM is a third-party service provider; and the advisor's screenshot is not the only record that exists.

Reg S-P โ€” The Foundation

Regulation S-P, codified at 17 CFR Part 248, is the SEC's customer-information privacy regulation for broker-dealers, investment advisers, investment companies, and transfer agents. The rule consists of three core components: (1) privacy notices to customers describing the firm's information-sharing practices; (2) limits on disclosure of nonpublic personal information ("NPI") to nonaffiliated third parties absent the customer's opportunity to opt out (subject to exceptions); and (3) the Safeguards Rule, requiring covered institutions to adopt written policies and procedures reasonably designed to protect customer NPI. The May 2024 amendments โ€” the most consequential update to Reg S-P since adoption โ€” added a fourth pillar: a written incident response program (IRP) with mandatory 30-day notification to affected customers in specified breach scenarios, plus expanded service-provider oversight requirements.

What Counts as NPI

NPI under Reg S-P is personally identifiable financial information that is not publicly available. It includes information the customer provides to the firm, information about the customer or any transaction obtained from any source, and information that results from any transaction with the customer. In wealth, NPI is essentially everything: name combined with account number, SSN, DOB, address, financial position, transaction history, planning facts, family structure relevant to financial circumstances, beneficiary information, tax returns, brokerage statements, K-1s, trust provisions, the existence of the relationship itself in many contexts.

The May 2024 Amendments โ€” Substance

The amendments, adopted May 16, 2024, made four substantive changes. First, covered institutions must adopt and implement a written incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. Second, covered institutions must provide notice to affected individuals as soon as practicable but no later than 30 days after becoming aware that NPI of an individual was, or is reasonably likely to have been, accessed or used without authorization. Third, the amendments expanded the scope to cover "transfer agents" and clarified treatment of "customer information" more broadly than the prior "consumer" framing. Fourth, the amendments tightened the service-provider oversight obligation โ€” covered institutions must implement procedures to oversee the data-handling practices of service providers, including contractual requirements obligating the service provider to take appropriate measures to protect against unauthorized access to and use of customer information and to notify the institution as soon as possible but no later than 72 hours after becoming aware of a breach.

Effective Dates

The amendments became effective August 2, 2024. Compliance dates were tiered: large entities (broker-dealers, investment companies, investment advisers with $1.5B+ in AUM, and certain transfer agents) by December 2025; smaller entities by June 2026. As of May 2026, the compliance dates have arrived for both tiers and the SEC's examination program is actively testing IRP adequacy, vendor oversight, and breach response.

GLBA Safeguards Rule and the Overlap

The Gramm-Leach-Bliley Act of 1999 established the federal regime for financial-institution privacy and data security. The Safeguards Rule (originally adopted by the FTC for non-bank financial institutions and revised in 2021 to add specific safeguards) requires covered institutions to develop, implement, and maintain a comprehensive written information security program with administrative, technical, and physical safeguards proportional to the size and complexity of the institution. For SEC-regulated entities, Reg S-P operationalizes the GLBA Safeguards Rule's requirements. Bank-affiliated wealth practices may be subject to the FRB / OCC / FDIC implementations of GLBA instead of or in addition to Reg S-P, depending on charter.

The overlap matters operationally because the same advisor practice may be testing against Reg S-P (SEC-side) and GLBA (FTC- or bank-regulator-side) requirements simultaneously, with the practitioner consensus being to satisfy the more demanding obligation on each requirement and document the program in a unified written information security program that maps to both.

The State Cyber and AI Patchwork

State law has added a thickening layer on top of the federal regime. By May 2026, every advisor practice must understand at least four state regimes by name.

NY DFS 23 NYCRR 500

New York's Department of Financial Services Cybersecurity Regulation, originally adopted in 2017 and amended in 2023 (the "Second Amendment"), applies to "Covered Entities" โ€” including DFS-licensed insurance companies, banks, and certain investment-adviser registrations with New York nexus. The regulation requires: (a) a cybersecurity program with documented risk assessment; (b) a written cybersecurity policy; (c) a Chief Information Security Officer (CISO) or equivalent; (d) multi-factor authentication for remote access and privileged accounts; (e) encryption of NPI in transit and at rest; (f) third-party service provider security policies with due diligence; (g) cybersecurity training; (h) an incident response plan; (i) 72-hour notification to the Superintendent of certain cybersecurity events; and (j) annual CISO reporting and certification of compliance to the DFS. The 2023 Second Amendment heightened obligations for the largest covered entities (Class A) including independent audit and additional controls, expanded business-impact analysis, and tightened MFA and access-management requirements.

California CPRA

The California Consumer Privacy Act (CCPA), amended and extended by the California Privacy Rights Act (CPRA) effective January 2023, governs the handling of personal information of California residents by covered businesses. The CPRA created the California Privacy Protection Agency (CPPA) and added rights including: the right to know what personal information is collected and shared; the right to delete; the right to correct; the right to opt out of sale or sharing; the right to limit use of sensitive personal information; and the right to data-portability. For wealth practices, the CPRA applies in addition to GLBA โ€” GLBA-covered "personal information" is generally exempt from CPRA's substantive privacy obligations, but the data-breach notification regime, the right to know about and limit use of certain information, and the recently-expanding CPRA enforcement (including AI-related rulemaking by the CPPA) all apply. The CPPA's draft regulations on automated decisionmaking and AI affect wealth practices using AI for client-affecting decisions.

Texas DIR and the State CISO Frameworks

Texas Department of Information Resources publishes cybersecurity frameworks adopted by Texas state entities and increasingly referenced by Texas-based private financial services firms; Texas also enacted SB 768 / HB 4 (the Texas Data Privacy and Security Act) effective July 2024, applying to certain businesses processing the personal data of Texas residents. The DIR framework, while not directly applicable to most RIAs, has become a state-level reference standard the practitioner consensus increasingly accommodates.

NAIC AI Model Bulletin and Model #275

For the annuity-licensed advisor, two NAIC instruments matter most. The NAIC AI Model Bulletin (issued in December 2023 by the NAIC Innovation, Cybersecurity, and Technology (H) Committee) provides regulator expectations on insurer use of AI systems โ€” fairness, accountability, governance, and consumer protection โ€” and has been adopted in modified form by at least two dozen state insurance departments. NAIC Model #275 (Suitability in Annuity Transactions Model Regulation, revised 2020 to add a "best interest" standard) governs annuity suitability and the producer's obligations in recommending an annuity; the revised version aligns with Reg BI's framing but lives under state insurance authority. AI-assisted annuity recommendations therefore implicate both the AI Model Bulletin's governance expectations and Model #275's best-interest documentation requirements, with state DOI variation in specific implementation.

Where Client NPI Legally Cannot Go

The single most practical operational rule for the 2026 advisor practice: client NPI cannot go into a free public LLM or any third-party AI service that does not have an executed data-handling agreement with the firm meeting Reg S-P's service-provider oversight requirements. The L1 Ch5 L2 lesson on client NPI confidentiality develops the practical paste-and-don't-paste framework in detail; this lesson establishes the regulatory anchor.

Categorically Prohibited Targets

Free public LLMs (ChatGPT free tier, Claude.ai consumer, Gemini consumer, Perplexity free), free public chatbot integrations, browser extensions that send page content to an AI service without an enterprise agreement, personal AI assistants on advisor personal devices used for client work, and any AI service whose terms of service permit training on user inputs without an enterprise carve-out. These are categorically off-limits for client NPI.

Permitted With Controls

Enterprise LLMs with executed data-handling agreements (OpenAI Enterprise / Team with the appropriate data controls, Microsoft Copilot for the firm's tenant, Google Gemini Enterprise / Workspace with appropriate data residency, Anthropic Enterprise) where the agreement provides no-training-on-inputs, data residency, breach notification, and audit rights. The firm's vendor due diligence โ€” L4 Ch2 develops the 40-question DDQ โ€” must verify these controls before NPI flows.

Vendor-Hosted Advisor AI

Jump, Zocks, Holistiplan, FP Alpha, Wealth.com, RightCapital, eMoney, MoneyGuidePro, Orion Eclipse, Wealthbox, Redtail, Salesforce FSC + Einstein, and other vendor-hosted advisor AI tools generally have data-handling agreements suitable for NPI when the firm is on the appropriate enterprise tier. The firm's vendor due diligence verifies the SOC 2 Type II report, the data flow, the breach SLA, and the contractual provisions.

The 30-Day Breach Clock and the IRP Trigger

The May 2024 Reg S-P amendments created a 30-day notification clock and an IRP architecture that every advisor practice must operationalize. The trigger: the firm becomes aware that NPI of an individual was, or is reasonably likely to have been, accessed or used without authorization. The clock: notification to the affected individual as soon as practicable, but no later than 30 days. The notification content: the firm must include sufficient detail for the affected individual to understand the incident and the firm's response; the notification rule includes specific content requirements.

How AI Incidents Trigger the Clock

Three AI incident patterns trigger the 30-day clock. First, a registered person pastes client NPI into an unauthorized AI service (the coffee-break scenario above) โ€” the firm must evaluate whether unauthorized access or use is reasonably likely; in most fact patterns involving consumer-tier AI with training-on-inputs terms, the answer is yes. Second, a vendor-side breach affects an authorized AI tool โ€” the 72-hour vendor notification SLA in the firm's service-provider oversight contracts triggers the firm's own evaluation. Third, a prompt-injection or data-exfiltration attack on the firm's authorized AI infrastructure produces unauthorized NPI access โ€” the firm's IRP activates.

The IRP Architecture

The IRP must, per the May 2024 amendments, include procedures to detect, respond to, and recover from unauthorized access. Operationally: (a) detection through monitoring, IAM logging, endpoint controls, network traffic analysis, and registered-person attestation; (b) response procedures with named roles (incident commander, CCO, CISO, communications lead, outside counsel) and a documented escalation chain; (c) notification procedures (the 30-day clock, the content of customer notice, the regulator notifications including NY DFS 72-hour where applicable, the state breach notification requirements, the FINRA 4530 reporting if applicable, the E&O carrier notification); (d) recovery procedures including containment, eradication, and post-incident review with documented control updates. The L4 Ch3 L4 lesson on AI Incident Response develops the playbook in detail; this lesson establishes the regulatory triggers.

The Tuesday Morning Decision Restated

Back to the coffee-break 1040 paste. The compliant version of that workflow: the advisor opens the firm's authorized enterprise LLM (with executed Reg S-P-compliant data-handling agreement) on a firm-managed device with MFA, pastes the 1040 (or, better, uploads through the firm's Holistiplan integration which extracts and tokenizes the data), receives the answer, the production chain is captured in the firm's archive (Smarsh, Global Relay) under Rule 4511 / Rule 204-2 retention, and the advisor returns to the meeting prep. No 30-day clock, no IRP activation, no NY DFS 72-hour reporting, no state breach notice cascade, no FINRA AWC. The compliant version takes 12 seconds longer than the non-compliant version. That 12-second discipline is the entire L1 Ch5 NPI lesson and the firm's entire data-classification matrix in one moment.

Key Takeaways

  • Reg S-P at 17 CFR Part 248 is the SEC's customer-information privacy regulation. The May 2024 amendments (effective August 2, 2024; compliance December 2025 large / June 2026 smaller) added a written incident response program requirement, a 30-day customer notification clock for unauthorized NPI access, and expanded service-provider oversight including a 72-hour vendor breach-notification SLA.
  • GLBA Safeguards Rule establishes the federal financial-institution information security regime; Reg S-P operationalizes it for SEC-regulated entities. Practices satisfy the more demanding obligation on each requirement and document in a unified WISP.
  • NY DFS 23 NYCRR 500 requires Covered Entities to maintain a cybersecurity program, written policy, CISO, MFA, encryption, third-party-service-provider oversight, training, IRP, 72-hour Superintendent notification, and annual certification. The 2023 Second Amendment tightened obligations for Class A entities.
  • California CPRA created the CPPA and rights including know, delete, correct, opt-out of sale/sharing, limit use of sensitive PI; GLBA-covered information is generally exempt from substantive CPRA privacy obligations but the breach-notification regime, certain rights, and CPPA AI / automated-decisionmaking rulemaking apply.
  • NAIC AI Model Bulletin and Model #275 apply to the annuity-licensed advisor โ€” AI governance expectations from the Bulletin plus best-interest annuity recommendation documentation under Model #275, with state DOI implementation variation.
  • Client NPI cannot go to free public LLMs. Permitted: enterprise LLMs (OpenAI Enterprise / Team, Microsoft Copilot tenant, Google Gemini Enterprise / Workspace, Anthropic Enterprise) with executed data-handling agreements; vendor-hosted advisor AI (Jump, Zocks, Holistiplan, FP Alpha, Wealth.com, RightCapital, eMoney, MoneyGuidePro, Orion Eclipse, Wealthbox, Redtail, Salesforce FSC + Einstein) on appropriate enterprise tiers with verified SOC 2 Type II and data-flow controls.
  • The 30-day breach clock + IRP architecture is the operational defense. Three AI incident patterns trigger: unauthorized AI use by a registered person, vendor-side breach of authorized AI, and prompt-injection / data-exfiltration on firm-authorized AI infrastructure. L4 Ch3 L4 develops the AI Incident Response playbook.