Companies Rushed to Approve AI. Now Regulators Want the Receipts
This year, regulated firms made significant investments into AI, knowing that if they didn’t, they would quickly be left behind by their peers. But what most of them still can’t show is how it’s used and what measures are in place to protect sensitive data, and that’s the evidence regulators are asking for.
Over the past year, under real pressure to keep pace, most regulated firms moved to put AI on an official footing, and most did roughly the same thing. They settled on an enterprise tool, signed the agreement, connected it to single sign-on, and rolled it out to their people. For many that meant Microsoft Copilot inside the existing tenant. For others it was a licensed ChatGPT or Claude deployment with a contract confirming that company data would not be used to train the model. It was a reasonable, defensible decision, and for most organizations it felt like the moment AI shifted from experiment to a managed asset for their team.
The difficulty is that approving a tool and governing how it gets used are not the same undertaking, and the distance between the two is where most of the current risk now lives.
An enterprise agreement does real work. It establishes a contractual boundary, keeps your data out of model training, and puts authentication under your IT team’s control. What it does not address is which of your data actually flows into the tool, how sensitive material is handled once it arrives there, or whether any record exists of what was asked and what came back. Those questions sit outside the license entirely. They are the substance of governance, and they are what regulators have begun to ask about.
While Everyone Was Deploying, the Question Changed
The debate used to be whether AI should be allowed in the workplace at all. That question has largely resolved itself. What regulated firms are being asked now is more specific and more demanding: can you show how AI is being used across the business and demonstrate that sensitive information stays controlled while it is?
FINRA’s 2026 Regulatory Oversight Report sets the expectation plainly. Member firms are expected to bring generative AI under a supervision and model-risk framework, test the tools for privacy, reliability, and accuracy, and monitor them in use, which the report describes as storing prompt and output logs and keeping a person in the loop to review what they produce. The bar has moved from whether a tool was approved to whether its use can be supervised and evidenced.
The healthcare industry is in a similar spot. HIPAA’s requirements attach to protected health information (PHI) whether it moves through the EHR or an AI assistant. The Office for Civil Rights has moved to update the HIPAA Security Rule for the first time in more than twenty years in ways that would raise the bar for any system, AI included, that touches that PHI data.
In both settings, approval is a procurement milestone. Governance is what an examiner asks to see. Most firms can produce the contract that authorized the tool; far fewer can produce the record of how it has been used since, and that record is exactly what is now being asked for.
Shadow AI Is Part of the Same Problem
Unsanctioned AI usage gets most of the attention when people speak of shadow AI, and the current numbers are hard to wave off. IBM’s 2026 Cost of a Data Breach Report found that shadow AI played a role in 43 percent of breaches, more than double compared to the year before, and that among organizations hit by an AI-related incident, 92 percent had no real access controls around the tools involved. IBM’s own read on its data is worth sitting with: it is AI adoption without governance, not AI itself, that drives the risk.
This same conclusion applies to sanctioned AI usage. People route around a sanctioned tool when it is too limited to help or so restricted that it slows them down, and a governance posture built only to forbid pushes that usage somewhere no one can see. The unsanctioned and the sanctioned problem resolve the same way. When the approved path is genuinely useful and properly governed, shadow usage recedes on its own, and the AI a firm actually endorses finally has controls beneath it.
What Governing the Tool Actually Involves
What you need to control (who can reach which data, how sensitive material is handled, and whether any of it is on the record) is the same across Copilot, Claude, ChatGPT, and Gemini, even though the way you enforce it differs from one to the next. Access needs to be bound to the permissions each person already holds, so the AI tool cannot reach data the user could not already open themselves. Sensitive material must be classified and held back the moment someone tries to access it, rather than only where it happens to be stored. Every AI-assisted action should be logged, so the evidence of how the tool has been used exists well before anyone asks to see it. And the whole arrangement needs to run inside the firm’s own environment and identity controls, extending them rather than widening the perimeter.
None of that is included with an enterprise license, and none of it is a one-time setup. It has to be configured for the specific environment, enforced continuously, and revised as the tools change underneath it, which they do with some regularity. That ongoing work is the real distance between having approved AI and being able to account for it.
The firms that come through the next few years without incident are unlikely to be the ones that adopted AI earliest, or the ones that restricted it most aggressively. They will be the ones that can answer the question underneath all of this by opening their records and showing plainly how AI has been used and who was cleared to use it. Permission got the tools in the door; proof is what lets them stay.
This is the work Abacus’ Secure AI service was built to do. Secure AI is how Abacus governs the tools your firm has already approved, keeping their use controlled and on the record. And, if you’re not yet sure how your own AI use would hold up to that question, an AI Risk & Readiness Assessment is built to tell you.
FAQ
Not on its own. An enterprise agreement gives you a contractual boundary and keeps your data out of model training, but it doesn’t control which data flows into the tool, classify sensitive material, or record how the tool is used. Regulators such as FINRA now expect supervision and evidence, which approval alone doesn’t produce.
Approving AI is a procurement decision: you’ve chosen a tool and permitted its use. Governing it is an ongoing discipline: binding access to existing permissions, classifying and restricting sensitive data at the point of use, logging every AI action as evidence, and keeping it all inside your own environment.
Yes. Copilot provides Microsoft’s enterprise controls, but how your specific data is used, classified, and evidenced remains your responsibility. Secure AI adds that governance layer on top of Copilot, in addition to other tools like Claude, ChatGPT, or Gemini.
