As financial institutions increasingly adopt generative artificial intelligence (AI) for market research, financial modelling, investment analysis and risk assessment, controlling the information employees share with external AI platforms has emerged as a key data security challenge.
A regional investment bank has deployed eScan Enterprise DLP to enable analysts to use approved AI platforms for business activities while preventing the transmission of confidential financial information. During implementation, the solution blocked hundreds of attempted transfers of sensitive financial data to public AI platforms.
The deployment uses an endpoint Data Loss Prevention (DLP) agent to monitor interactions with AI services across analyst workstations, trading floors, research departments and mobile devices. The agent operates in the background and applies controls to information before it is transmitted to external AI platforms.
The DLP agent can inspect content in real time, classify its sensitivity, identify confidential financial information and automatically block unauthorised transmission. Protected information can include client account details, trading strategies, proprietary financial models, material non-public information and confidential deal-related data.
The solution combines AI/ML-based neural intelligence, behavioural analysis, content-aware inspection and Optical Character Recognition (OCR) to identify and protect sensitive information.
Its AI Platform Data Protection capability is designed to monitor and control data uploads to AI services, including ChatGPT, Claude, Gemini and other external AI platforms. This is intended to help organisations prevent inadvertent sharing of sensitive documents while allowing employees to use generative AI for authorised tasks.
For example, when an analyst attempts to transmit confidential information to an external AI service, the DLP system can identify the sensitive content and block the transmission before the information leaves the organisation's security environment. The user can also receive an indication that the request contains information that cannot be transmitted.
As generative AI becomes more embedded in financial workflows, such controls can help organisations establish clearer boundaries around the use of external AI services while reducing the risk of sensitive financial information being inadvertently disclosed.

