Investment Bank Blocks Hundreds of Confidential Data Transfers to Public AI Platforms


Posted September 17, 2026 by MicroWorld

eScan Enterprise DLP enables controlled use of ChatGPT, Claude and Gemini while preventing unauthorised transmission of trading strategies, client portfolios and other sensitive financial information

 
As financial institutions increasingly use generative AI for market research, financial modelling, investment analysis and risk assessment, controlling what data employees share with external AI platforms has become a critical security challenge. Client portfolios, trading strategies, proprietary models, material non-public information and deal-related data can potentially leave an organisation’s security boundaries when entered into public AI tools such as ChatGPT, Claude and Gemini.



A regional investment bank addressed this challenge by deploying eScan Enterprise DLP, enabling analysts to use approved AI platforms for legitimate business activities while automatically preventing the transmission of confidential financial information. During implementation, the solution blocked hundreds of attempted transfers of sensitive financial data to public AI platforms.

Controlling Data Before It Reaches AI Platforms
The eScan deployment uses an endpoint DLP agent to monitor AI interactions across analyst workstations, trading floors, research departments and mobile devices. The agent operates in the background, allowing users to continue their normal workflows while controls are applied to the data being transmitted.

Before data reaches an AI platform, the DLP agent can inspect content in real time, classify its sensitivity, identify confidential financial information and automatically block unauthorised transmission. The information identified for protection can include client account details, trading strategies, proprietary models, material non-public information and deal-related confidential information.

The solution combines Neural Intelligence AI/ML, behavioural analysis, content-aware inspection and Optical Character Recognition (OCR) capabilities to identify and protect sensitive information. Its AI Platform Data Protection capability is designed to monitor and control data uploads to AI services including ChatGPT, Claude, Gemini and other AI platforms, helping prevent inadvertent sharing of sensitive documents while allowing legitimate AI-powered tasks.

For an analyst, an attempted transmission of confidential information can be stopped before the data reaches the external AI service, with the user receiving an indication that the request contains information that cannot be transmitted.

AI Workflows with Security Controls
The bank also established approved AI workflows for different business functions, allowing employees to use AI based on the nature and sensitivity of their work. Market research uses approved Claude instances, general macroeconomic analysis uses Gemini, while public financial data research can use ChatGPT.

Each approved workflow is supported by audit logging, enabling analysts to review their AI interaction history while compliance and audit teams gain visibility into how AI systems are being used.

The approach allows the organisation to distinguish between legitimate AI use and potentially risky data transfers instead of treating all AI usage as a security threat.

Data Classification and Governance
A key part of the implementation was defining what constitutes confidential information. The bank established classifications covering public data, internal reference data, client-confidential information and trading-sensitive information. The endpoint agent then enforces these classifications automatically.

The implementation was integrated with existing compliance infrastructure, including surveillance systems, audit logging and compliance reporting. The bank also established governance policies covering AI tool approval, security updates as new AI platforms emerge and user training.

Analyst adoption was another important part of the implementation. The bank demonstrated that monitoring could help prevent inadvertent regulatory violations while approved AI workflows could support faster analysis than unrestricted use of public AI platforms. Early adoption by senior analysts helped drive wider acceptance across teams.

Hundreds of Confidential Data Transfers Blocked
During implementation, the solution prevented hundreds of attempted transmissions of confidential financial data to public AI platforms.

The blocked attempts included:

Client portfolio information that could breach client confidentiality
Trading strategies and execution models that could compromise competitive advantage
Material non-public information that could create securities-regulation concerns
Deal-related information protected under confidentiality agreements
The bank also established comprehensive audit trails covering who used an AI platform, when it was used, what data was being analysed and which system processed the request. Such visibility can support compliance reviews by providing organisations with a record of AI-related data activity and the controls applied to it.

Enabling AI Without Losing Data Control
Financial institutions are increasingly looking at AI to improve research, analysis, decision-making and client servicing. But for organisations handling highly sensitive financial information, AI adoption also introduces a need for stronger data governance and visibility. Recent industry discussions have similarly highlighted security, governance and data protection as prerequisites for scaling enterprise AI.

For financial institutions, the choice does not have to be between banning AI and accepting uncontrolled data exposure. The focus can instead be on controlling what data reaches which AI system, under what circumstances and with what level of oversight.

Govind Rammurthy, CEO & MD, eScan, said: “Financial services firms face a manufactured choice: restrict AI adoption to protect confidential data, or enable AI and hope analysts don’t accidentally leak trading strategies to ChatGPT. That’s a false choice. Monitor what data flows where. Block the confidential stuff automatically. Allow analysts to use AI for legitimate market research and analysis. It’s straightforward endpoint monitoring—the same principle that prevents data leakage to email or USB drives, just extended to LLM/AI platforms. You don’t need to restrict innovation. You need to control data flow.”
 
Contact Email [email protected]
Issued By eScan
Phone 09152714447
Business Address Plot No 80, Road no 15, MIDC, Marol, Andheri East
Andheri East
Country Malaysia
Categories Computers , Software , Technology
Tags enterprise , dlp , ai , endpoint
Last Updated September 17, 2026