Bates Research | 08-11-26
Shadow AI Meets Reg S-P
As the use of GenAI and related LLM-based tools proliferates in the workplace, organizations are faced with the increased risk of scenarios of unapproved (or un-sanctioned) tools that may enable data flight of sensitive, proprietary, or confidential information. That pattern has a name: “Shadow AI,” the use of generative AI outside a firm's approved technology and governance framework. At firms subject to SEC or FINRA oversight, it becomes a direct extension of obligations the firm already carries under Regulation S-P.
The gap shows up in the data. ISACA's 2026 AI Pulse Poll of more than 3,400 digital trust professionals found that 90 percent believe employees are already using AI at work, while only 38 percent report a formal, comprehensive AI policy. The instinct is to treat Shadow AI as an IT problem: block a few domains, add a policy line, move on. That response leaves the exposure intact. Shadow AI is a supervision question, and it deserves the rigor applied to any system touching customer data.
What Happened
Two regulatory threads converged this year. First, the SEC's 2024 amendments to Regulation S-P reached their final compliance milestone. Larger entities complied by December 3, 2025. Smaller entities, including most registered investment advisers under $1.5 billion in assets under management, complied by June 3, 2026. The amendments require a written incident response program, 30-day breach notification, and oversight of service providers that touch customer information. The SEC named Reg S-P a 2026 examination priority, and examiners will test whether firms can identify every system, AI tools included, that processes nonpublic personal information.
Second, FINRA's 2026 Annual Regulatory Oversight Report added a dedicated generative AI section for the first time, stating that existing supervision, books and records, and Regulation Best Interest obligations apply in full to AI-assisted work. It flags unmonitored AI agents, unreviewed client-facing outputs, and unvetted third-party tools as gaps examiners will probe. In practice: an employee who pastes client data into a free AI tool has moved nonpublic personal information to an unvetted service provider, exactly the scenario the amended requirements target.
Why It Matters
A firm's AI footprint and its Reg S-P footprint are now one. An asset inventory that omits AI tools is incomplete, and an AI policy silent on how customer data flows through those tools is missing its safeguards. Regulators do not mandate specific technologies. They expect documentation of how technology gets used, how outputs get monitored, who holds accountability, and how records get retained. Nobody expects a firm to have eliminated Shadow AI. Examiners expect it to know where Shadow AI exists, to have assessed the risk, and to produce a supervisory record.
Meeting that standard does not require an elaborate program. The NIST AI Risk Management Framework organizes AI risk around governing, mapping, measuring, and managing, and Bates Group translates it into five supervisory functions that match how compliance programs operate: Govern, Protect, Monitor, Supervise, and Respond. A small advisory shop might apply them through one officer approving each tool, a one-page inventory, and a second review of AI-drafted client communications. A larger broker-dealer applies the same functions through a governance committee, automated alerts, and incident response integration.
The implementation scales. The questions do not. Every firm should answer three on demand: who approved this AI tool, what firm data it can reach, and who reviewed the output before it went out. Paper alone will not hold. Employees reach AI tools through personal accounts the firm never sees, so governance becomes real only when those tools sit under the same controls as any other software.
Bates Group’s Perspective
Across engagements with advisers, broker-dealers, and fintech clients, the Bates Group team sees a consistent pattern. Firms maintain a mature Reg S-P safeguards program on paper while daily employee AI use has outpaced that documentation, with compliance and security each assuming the other has AI covered. Closing the gap follows a consistent path: scope the actual AI use cases, map them against the existing supervisory framework, and build documentation an examiner can follow.
Action Items
Firms working toward Reg S-P compliance and FINRA's 2026 expectations should consider the following:
- Keep an up-to-date list of every AI tool that can see client information. A small firm might keep this as a shared spreadsheet one person reviews each month. A larger firm might use an automated scanning tool that flags new AI activity across the network. Either way, treat the list as part of your Reg S-P records, not just an IT to-do.
- Use the NIST AI Risk Management Framework as a guide, sized to fit the firm. A small advisory shop might apply it through a one-page policy and a single approver for new AI tools. A larger broker-dealer might apply the same framework through a formal governance committee with written procedures. Both give examiners a structure they already recognize.
- Make sure AI tools go through the same sign-in and data protection checks as other software. A small firm might simply require staff to access AI tools through the firm's existing login system rather than a personal account. A larger firm might add automated alerts that flag when someone tries to paste account numbers or other client data into an AI tool (etc.).
- Extend existing vendor due diligence and service-provider oversight under Reg S-P to any AI vendor, covering data retention, training rights, and breach-notification terms.
Update the written incident response program to name AI-related data exposure as a reportable event, and test it via a tabletop exercise before the next exam cycle.
How Bates Group Helps
When employee AI use outpaces written policy, firms face examination findings they cannot document their way out of. Bates Group helps financial services firms build AI governance examiners can follow. Contact Technology Advisory team leader Antonio Rega to assess where your firm's AI tool usage may fall outside your Reg S-P safeguards.
Antonio Rega
Managing Director, Tech Forensics, eDiscovery, Data Privacy/Security
Sources
- ISACA 2026 AI Pulse Poll
- NIST AI RMF Framework
- OWASP Gen AI Security Protocols
- ISO 42001 AI Management System
- Indirect Prompt Injection Attacks: A Lurking Risk to AI Systems (Crowdstrike, December 04, 2025)
- FINRA Publishes 2026 Regulatory Oversight Report to Empower Member Firm Compliance (FINRA, December 09, 2025)
- Shadow AI Is Really a Workflow Problem (ACEDS, July 14, 2026)