Practical Guide

Governing AI in Your Firm

Vendor types, risks, controls, and policy language you can adapt. AI has not created a new class of risk — it has concentrated the existing ones, and put them inside tools your users were already using.

By Brian Edelman, Founder & CEO, FCI Cyber · Last updated: May 2026

Governing AI in a firm means categorizing every AI tool in your environment — third-party, fourth-party, or AI solution integrator — containing the AI-specific risks each one carries, putting data, identity, evidence, and boundary controls in place, and folding AI policy into your Acceptable Use Policy with signed user acknowledgment.

Related: AI Regulatory Guidance · IT & Cyber Disciplines · Data Security · FCI & AI

Overview

Why This Matters

AI has not created a new class of risk. It has concentrated the existing ones — and put them inside tools your users were already using. The same Nonpublic Information (NPI) your firm has always had to protect now flows into chat windows, embedded features, and third-party integrators at machine speed.

The question is no longer whether AI is in your stack. It is whether your firm knows where it lives, who is accountable for it, and what evidence you can produce when a regulator asks.

This page gives you a working framework: how to categorize the AI in your environment, the risks specific to it, the controls that contain them, and example policy language you can adapt for your AUP.

The firm — not the vendor, not the AI provider — owns the decision about what data goes into AI tools and what evidence proves it.

Prerequisites

Two Foundations

Before talking about AI specifically, two things must already be in place.

Data Classification

Every cybersecurity regulation requires it, and AI sharpens the consequence: if your firm has not defined what information is sensitive, it cannot define what is safe to put into an AI tool. The scope is no longer just PII. Most regulators now require protection of all Nonpublic Information (NPI), which includes:

•  Business Confidential Information (BCI)
•  Personal Financial Information (PFI)
•  Personally Identifiable Information (PII)
•  Protected Health Information (PHI)

Vendor Due Diligence — Unchanged for AI

AI vendors clear the same annual due diligence package as every other vendor: a SOC 2 report or ISO certification, a management assertion confirming the vendor runs its own cyber program, proof of cyber insurance, and current network penetration test and vulnerability scan results. AI status does not lower the bar — it raises the stakes of meeting it.

The AI-specific items under Controls to Put in Place below are additions to this baseline, not substitutes for it.

Categorize

The Three Forms AI Shows Up in Your Stack

Most firms underestimate how much AI is already in their environment because they only count the tools they explicitly purchased. AI typically reaches your firm in one of three ways.

Third-Party AI Solution
You bought it directly

A standalone AI product or service your firm selected and contracted with directly. Your users interact with it knowingly, and your firm is fully accountable for the due diligence and ongoing oversight of the vendor.

Ask: have we cleared this vendor through the same due diligence package we apply to every other third party?
Fourth-Party AI Solution
Embedded in something you already use

AI functionality your existing vendor has added to a product you have already approved — an AI feature inside your CRM, your email platform, or your document system. Your vendor selected the AI component; your firm inherits it. The primary due diligence responsibility sits with your vendor, but your firm must verify they performed it.

Ask: which of our existing vendors have added AI features, and what AI sub-providers are they now relying on?
AI Solution Integrator
A new entrant building on top of frontier models

In the last few years, a wave of new companies has approached financial services firms offering AI-built solutions layered on top of frontier models. They are often early-stage, lightly funded, and frequently lack the cyber maturity of the model providers they sit on. They will access extensive amounts of your private data.

Your firm has two ways to handle this kind of vendor — pick the one that matches the engagement.

Option 1 — Treat them as a third party. They must clear the full vendor due diligence package, and a third party with technical expertise should review their architecture before approval. Financial services firms often skip this step and miss serious risk, particularly when data is uploaded to another environment in the cloud.

Option 2 — For a solo consultant, treat them as an employee. Provide a corporate-owned computer carrying the same security tools your employees and affiliates use, and implement MFA that the firm controls. In this model the firm — not the consultant — is responsible for the protected device, the access controls, and the evidence that comes from them.

Ask: which path fits this engagement — and once we choose, who is accountable for the controls?

Contain

AI-Specific Risks

These are the risk classes your firm should track, separate from generic vendor risk.

Training on your data

Prompts, files, and outputs used to improve the vendor’s model — often by default, often reversible only by configuration.

Prompt and file leakage

NPI uploaded into a chat window, a summarizer, or an embedded feature without a record of what was sent or who saw it.

Shadow AI accounts

Employees signing up to AI tools with personal email addresses, bypassing every control the firm has put in place.

Hallucinated outputs feeding client-facing work

AI-generated content used in advice, communications, or documents without human review and without a paper trail.

Notetakers and meeting assistants recording without consent

Automated transcription joining calls by default, capturing client conversations before participants are told.

Vendor instability

Particularly with AI integrators — companies that may disappear, change hands, or alter terms, leaving the data they held in uncertain custody.

Exfiltration through AI channels

NPI moving out of the firm via AI tools to personal accounts, removable media, or unmanaged cloud apps.

Controls

Controls to Put in Place

The controls below extend your standard vendor and endpoint controls. We group them in four categories so the picture is clear, not a checklist.

Data Controls

Data retention. The vendor must state whether your data is stored, for how long, and for what purpose.

Data anonymization. The process must be documented and verifiable, not asserted.

Training opt-out. The vendor must allow your prompts, files, and outputs to be excluded from model training — contractually and technically.

DLP (Data Leakage Protection). The firm must have a system that monitors, alerts, or blocks transfers of NPI to cloud apps, AI tools, and removable media.

Identity Controls

Firm-managed business account. The firm holds the AI vendor relationship; personal accounts for firm use are not allowed.

User management. Provisioning, deprovisioning, and role-based access run through the firm, not the individual user.

Multi-factor authentication. MFA is required for every AI tool. No exceptions.

Evidence Controls

Logging and auditability. The vendor must maintain logs of data processing and administrative actions sufficient to support investigations, audits, and regulatory inquiries.

Log retention. Logs must be retained per your cyber program requirements and accessible to the firm.

Hardening evidence. Cybersecurity settings on the AI tool must be reviewed, documented, and produced on request.

Boundary Controls

Blocking unapproved AI tools. The firm must have a mechanism to block access to every AI tool that is not on the approved list.

Approved-list maintenance. The list is reviewed on a defined cadence as AI features and vendors change.

Adaptable Language

Example Policy Clauses

The clauses below are examples. Your firm should tailor them to its approved AI tools list, data classification standards, and supervisory procedures.

Approved AI tools only
The Firm’s Employees and Affiliates must not use AI Tools for Firm business activities unless the AI Tools are explicitly approved by the Firm.
No NPI in AI tools without approval
The Firm’s Employees and Affiliates must not input, upload, share, or process Nonpublic Information using any AI Tools — including Firm-approved AI Tools — unless the Firm has explicitly approved the use and documented the required safeguards.
No firm email for personal AI use
When using AI Tools for personal (non-Firm) purposes, Employees and Affiliates must not use any Firm-provided business email address or Firm-managed account credentials.
Notetaking and meeting assistant consent
Employees and Affiliates must only use notetaking or meeting-assistant applications approved by the Firm. Participants must give consent before any recording, transcription, or automated note capture begins. Recording and transcription must not be configured to start automatically at the beginning of a call.
Integration into the AUP
AI policy must be folded into the Firm’s cybersecurity program and Acceptable Use Policy (AUP). The AI clauses must be presented and explained to users, and users must sign the updated AUP.

Next Steps

What to Do This Week

Three concrete next steps a firm can take immediately.

Step 1
Inventory

List every AI tool in use across the firm, including AI features that came embedded in vendors you have already approved.

Step 2
Re-run due diligence on AI vendors

Apply your annual vendor due diligence package to every AI vendor and integrator on that list.

Step 3
Update and re-sign the AUP

Add the AI clauses, walk users through the changes, and re-collect signatures.

Put AI Governance in Place with FCI

FCI helps financial services firms govern AI — data classification, DLP, vendor due diligence, and the evidence trail that proves your controls are enforced.