eScan has highlighted the growing data-security risks facing financial institutions as analysts increasingly use generative AI platforms such as ChatGPT, Claude and Gemini for market research, financial modelling, investment analysis, portfolio optimisation and report writing.
The cybersecurity company said financial institutions increasingly need to balance AI adoption with protecting sensitive information, including client portfolios, proprietary trading strategies, financial models, material non-public information, and confidential deal-related data.
To address these risks, a regional investment bank has deployed eScan Enterprise DLP, enabling analysts to use approved AI platforms while automatically preventing the transmission of confidential financial information to external AI services.
The deployment uses an endpoint Data Loss Prevention (DLP) agent to monitor AI interactions across analyst workstations, trading floors, research departments and mobile devices. Before information is transmitted to an AI platform, the system can inspect content in real time, classify its sensitivity and block unauthorised transfers.
According to eScan, its AI Platform Data Protection capability uses AI/ML, behavioural analysis, content-aware inspection and Optical Character Recognition (OCR) to identify sensitive information and monitor data uploads to AI platforms.
The bank established data classifications covering public data, internal reference data, client-confidential information and trading-sensitive information. The bank enforces these classifications through endpoint controls, while audit logging provides visibility into AI usage for compliance and review.
The organisation also created approved AI workflows for specific functions. These included Claude for market research, Gemini for general macroeconomic analysis and ChatGPT for research involving public financial data.
During implementation, the solution reportedly blocked hundreds of attempted transmissions of confidential financial information to public AI platforms. The blocked data included client portfolio information, trading strategies and execution models, material non-public information and deal-related information covered by confidentiality agreements.
The implementation also provides audit trails covering AI platform usage, data analysed and the controls applied to each interaction.
Govind Rammurthy, CEO & MD, eScan, said financial institutions do not necessarily need to restrict AI adoption to protect confidential data, but should instead monitor and control how data moves to AI platforms.
As financial institutions expand their use of generative AI, eScan said data governance, endpoint monitoring and visibility into AI-related data activity will become increasingly important for enabling AI adoption while reducing the risk of confidential information leaving organisational security boundaries.

