Why firms are losing control of customer data in the age of AI
Executive summary
Artificial intelligence is transforming financial services at unprecedented speed. More than 85% of financial institutions are now actively deploying AI across fraud detection, risk modelling, trading and customer service. Global annual spending on AI in the sector exceeds $20 billion. The race to adopt is well underway.
But in the rush to capture competitive advantage, a critical vulnerability has emerged: the systems, policies and checkpoints that protect customer data were not designed for this new paradigm. Legacy compliance frameworks built for structured databases and controlled access points are being overwhelmed by a technology that operates in fundamentally different ways.
Financial services firms are moving too fast with AI adoption and failing to establish sufficient guardrails to keep customer data protected. The consequences are not hypothetical. They are already materialising.
1. The speed problem: adoption without architecture
The financial services industry has adopted AI at a pace that far outstrips its governance infrastructure. A 2025 survey by Caspian One found that 70% of financial institutions were using AI at scale, up from 30% in 2023. McKinsey reports that 91% of banking institutions have established centralised generative-AI functions. Hedge funds, wealth managers and insurers are in the same race, with 68% of hedge funds now employing AI for market analysis and trading strategies.
Yet the implementation reality tells a different story. According to Deloitte, only 38% of AI projects in finance meet or exceed their return-on-investment expectations. More than 60% of firms report significant implementation delays. The gap between ambition and execution is enormous, and within that gap lies a growing data-protection crisis.
The question is not whether financial services firms should adopt AI. It is whether they can do so without losing control of the data their customers have entrusted to them.
The problem is structural. Most financial institutions have layered AI capabilities onto existing technology stacks without fundamentally rethinking data governance. Customer records, transaction histories, account details and personally identifiable information are flowing through systems and workflows that were never designed with large language models in mind.
2. The shadow-AI crisis
Perhaps the most immediate and underappreciated risk is “shadow AI”: employees using unsanctioned artificial-intelligence tools in the workplace without organisational oversight or approval.
In practical terms, employees across financial services are copying customer data, account numbers, transaction records, loan applications and investment portfolios into consumer-grade AI tools to help draft emails, analyse spreadsheets, summarise documents and generate reports.
The Samsung warning
Although Samsung is not a financial services firm, its March 2023 incident remains the canonical illustration of this risk. In three separate instances, Samsung engineers uploaded proprietary source code and confidential meeting transcripts into ChatGPT's free web interface, data that was then incorporated into OpenAI's training pipeline.
For a bank or insurer, the equivalent is an analyst pasting customer portfolio data into ChatGPT to generate a summary, or a compliance officer feeding sensitive regulatory correspondence into Claude to draft a response. The data leaves the controlled environment, enters a third-party system and, if the employee is using a free or personal account, may be used to train the model itself.
The training-data question
This is where the risk becomes acute. Consumer-tier AI services operate under fundamentally different data-handling policies from their enterprise counterparts.
OpenAI ChatGPT free tier
Conversations may be used to train and improve models.
Anthropic Claude free and Pro tiers
As of late 2025, data from free, Pro and Max accounts may be used for training unless the user explicitly opts out.
Enterprise versions
OpenAI and Anthropic prohibit training on customer data by default for enterprise and API clients.
The distinction is critical. When an employee uses a personal AI account at work, they are effectively opting their employer's customer data into a training pipeline. Once incorporated into model weights, there is no mechanism for recall. The data cannot be deleted, corrected or retrieved. It becomes part of the model's learned knowledge permanently.
3. People are not being trained
The shadow-AI problem is not primarily a technology failure. It is a training failure. Employees are not being equipped with the knowledge they need to understand the data implications of the tools they are using.
The Verizon 2025 Data Breach Investigations Report found that 15% of employees routinely use generative AI on corporate devices. Separately, 33% of workers admit to sharing data on unapproved AI platforms, with 37% disclosing employee data and 24% sharing sales or financial data through these channels.
In most cases, these employees are not acting maliciously. They are trying to be more productive. They have discovered that AI tools can help them work faster, write better and analyse data more efficiently. But they have not been told, or have not understood, that using a personal ChatGPT account to process customer data is fundamentally different from using an enterprise-grade tool with appropriate data protections.
The absence of clear AI-usage policies, combined with a lack of practical training, has made well-intentioned employees the primary vector for data exposure.
This training gap extends beyond individual contributors. Many compliance teams and risk officers are themselves still developing fluency with AI technologies. They understand traditional data-handling protocols, but may not fully grasp how large language models process, retain and potentially surface the information fed into them.
4. The regulatory reckoning
Regulators are paying attention. Across multiple jurisdictions and agencies, the regulatory framework around AI and data protection in financial services is tightening rapidly.
US Securities and Exchange Commission
AI became a focal point of the SEC's 2025 examination priorities. The first “AI-washing” enforcement actions arrived in March 2024, with combined penalties of US$400,000. The Cyber and Emerging Technologies Unit has described rooting out AI-related fraud as an immediate priority.
New York Department of Financial Services
October 2024 guidance described four primary AI cybersecurity risks. From November 2025, firms must maintain complete asset inventories and implement data-minimisation practices, including disposal of non-public information that is no longer needed.
GDPR and the European Data Protection Board
A December 2024 opinion requires documented, case-by-case legitimate-interest assessments before personal data is used for AI training. The standard is that it must be very unlikely that individuals could be identified.
California Consumer Privacy Act
AI-specific provisions took effect across 2025 and 2026. AB 1008 recognises that personal information can exist within AI systems. Penalties are US$2,500 per unintentional violation and US$7,500 per intentional violation, per affected consumer.
For a financial institution with millions of customer records, the arithmetic is sobering.
5. The cost of inaction
The financial and operational risks of inadequate AI data governance are not theoretical. They are quantifiable and growing.
Beyond direct financial exposure, firms face reputational damage that can erode client trust for years. In wealth management and private banking, where relationships are the primary asset, a data breach involving AI mishandling of customer information can be existential.
6. What prudent firms are doing
The firms navigating this transition most effectively share several characteristics. They are not avoiding AI; they are building the infrastructure to use it responsibly.
1. Establish clear AI-usage policies
The starting point is a written, enforceable policy defining which AI tools are sanctioned, how they may be used and what data may and may not be processed through them. It must distinguish enterprise-grade tools with appropriate data-handling agreements from consumer-tier products that should be prohibited for work involving customer or proprietary data.
2. Invest in AI literacy
Employees at every level need to understand AI data handling. This is not about banning tools. It is about ensuring everyone from front-line advisers to executives understands the difference between an enterprise API call and a personal ChatGPT conversation, and why that distinction matters for clients.
3. Deploy enterprise-grade infrastructure
AI must operate within controlled environments with appropriate data isolation, access controls, audit trails and retention policies. This often means moving away from legacy systems that cannot support the segmentation and monitoring requirements of modern AI governance.
4. Build continuous monitoring and audit
AI governance is not a one-time implementation. It requires ongoing monitoring of data flows, regular audits of AI-tool usage and adaptive policies that evolve as the technology and regulatory landscape develop.
7. Closing the gap
The financial services industry stands at an inflection point. AI offers genuine transformative potential, but only if the infrastructure supporting it is as sophisticated as the technology itself. The current trajectory, in which adoption dramatically outpaces governance, is unsustainable.
The firms that emerge strongest will treat AI data governance not as a compliance burden but as a competitive advantage: a signal to clients, regulators and the market that they take their stewardship responsibilities seriously.
For legacy institutions, this often requires more than policy changes. It requires a fundamental re-examination of the technology stack itself, ensuring that systems can support the data isolation, access controls and audit capabilities that modern AI governance demands.
This is not a problem that can be solved with a memo. It requires architecture.
About Dark Arts
Dark Arts is a boutique software-development firm specialising in financial-systems rescue and modernisation. We work with lenders, insurers, debt litigators, credit bureaus, fund managers and other financial services organisations to modernise their technology infrastructure, ensuring it can support the compliance, security and data-governance requirements of an AI-enabled world.
If you are concerned about your organisation's AI data-governance posture, or recognise the gap between your current systems and where they need to be, we should talk.
Schedule a confidential discussionSources
- Cyberhaven, Shadow AI Report 2024
- Microsoft, Work Trend Index 2024
- CIO Dive, Samsung Employees Leaked Corporate Data via ChatGPT, April 2023
- IBM, Cost of a Data Breach Report 2024
- New York Department of Financial Services, Industry Letter on AI Cybersecurity Risks, 16 October 2024
- US Securities and Exchange Commission, press release 2024-36, 18 March 2024
- Deloitte Center for Financial Services, 2024
- California Consumer Privacy Act, AB 1008, effective 1 January 2025
- US Securities and Exchange Commission, 2025 Examination Priorities
- European Data Protection Board, Opinion on AI Models and GDPR, 18 December 2024
- Verizon, 2025 Data Breach Investigations Report