~eScan Enterprise DLP prevents unauthorised transmission of trading strategies, client portfolios and other sensitive financial information to AI platforms~
An investment analyst researching market trends turns to an AI platform to analyse a client portfolio. Another researcher copies a proprietary trading model into an AI tool seeking optimisation suggestions, while a junior analyst uses AI to summarise a confidential deal memo.
Such use cases are becoming part of everyday workflows as financial institutions adopt AI for market research, financial modelling, investment analysis, report writing, portfolio optimisation and risk assessment. Platforms such as ChatGPT, Claude and Gemini can accelerate analysis and improve productivity, but they can also create a new data-security challenge when sensitive financial information is shared with external AI services.
Client portfolios, trading strategies, proprietary models, material non-public information and deal-related confidential information can potentially leave an organisation’s security boundaries. For financial institutions, such exposure can raise regulatory concerns, breach client confidentiality obligations and put competitive advantage at risk.
With hundreds of analysts and thousands of daily interactions with AI platforms, relying solely on employee training or restricting internet access may not be sufficient. The challenge is therefore shifting from whether employees should use AI to how financial institutions can enable legitimate AI use while maintaining control over the data being shared with these platforms.
A regional investment bank addressed this challenge by deploying eScan Enterprise DLP, enabling analysts to continue using AI for approved business activities while automatically preventing the transmission of confidential financial information to public AI platforms.
Controlling Data Before It Reaches AI Platforms
The eScan deployment uses an endpoint DLP agent to monitor AI interactions across analyst workstations, trading floors, research departments and mobile devices. The agent operates in the background, allowing users to continue their normal workflows while controls are applied to the data being transmitted.
Before data reaches an AI platform, the DLP agent can inspect content in real time, classify its sensitivity, identify confidential financial information and automatically block unauthorised transmission.
The information identified for protection can include client account details, trading strategies, proprietary models, material non-public information and deal-related confidential information.
This approach allows organisations to control data movement without taking a blanket approach of blocking AI platforms altogether.
The technology combines Neural Intelligence AI/ML, behavioural analysis, content-aware inspection and Optical Character Recognition (OCR) capabilities to identify and protect sensitive information. Its AI Platform Data Protection capability is designed to monitor and control data uploads to AI services including ChatGPT, Claude, Gemini and other AI platforms, helping prevent inadvertent sharing of sensitive documents while allowing legitimate AI-powered tasks.
For an analyst, an attempted transmission of confidential information can be stopped before the data reaches the external AI service, with the user receiving an indication that the request contains information that cannot be transmitted.
AI Workflows with Security Controls
The bank also established approved AI workflows for different business functions.
Market research uses approved Claude instances, general macroeconomic analysis uses Gemini, while public financial data research can use ChatGPT. Each approved workflow is supported by audit logging, enabling analysts to review their AI interaction history while compliance and audit teams gain visibility into how AI systems are being used.
The approach allows the organisation to distinguish between legitimate AI use and potentially risky data transfers instead of treating all AI usage as a security threat.
Data Classification and Governance
A key part of the implementation was defining what constitutes confidential information.
The bank established classifications covering public data, internal reference data, client-confidential information and trading-sensitive information. The endpoint agent then enforces these classifications automatically.
The implementation was integrated with existing compliance infrastructure, including surveillance systems, audit logging and compliance reporting. The bank also established governance policies covering AI tool approval, security updates as new AI platforms emerge and user training.
Analyst adoption was another important part of the implementation. The bank demonstrated that monitoring could help prevent inadvertent regulatory violations while approved AI workflows could support faster analysis than unrestricted use of public AI platforms. Early adoption by senior analysts helped drive wider acceptance across teams.
Hundreds of Confidential Data Transfers Blocked
During implementation, the solution prevented hundreds of attempted transmissions of confidential financial data to public AI platforms.
The blocked attempts included:
- Client portfolio information that could breach client confidentiality
- Trading strategies and execution models that could compromise competitive advantage
- Material non-public information that could create securities-regulation concerns
- Deal-related information protected under confidentiality agreements
The bank also established comprehensive audit trails covering who used an AI platform, when it was used, what data was being analysed and which system processed the request.
Such visibility can support compliance reviews by providing organisations with a record of AI-related data activity and the controls applied to it.
Enabling AI Without Losing Data Control
Financial institutions are increasingly looking at AI to improve research, analysis, decision-making and client servicing. But for organisations handling highly sensitive financial information, AI adoption also introduces a need for stronger data governance and visibility. Recent industry discussions have similarly highlighted security, governance and data protection as prerequisites for scaling enterprise AI.
For financial institutions, the choice does not have to be between banning AI and accepting uncontrolled data exposure. The focus can instead be on controlling what data reaches which AI system, under what circumstances and with what level of oversight.
Govind Rammurthy, CEO & MD, eScan, said:
“Financial services firms face a manufactured choice: restrict AI adoption to protect confidential data, or enable AI and hope analysts don’t accidentally leak trading strategies to ChatGPT. That’s a false choice. Monitor what data flows where. Block the confidential stuff automatically. Allow analysts to use AI for legitimate market research and analysis. It’s straightforward endpoint monitoring—the same principle that prevents data leakage to email or USB drives, just extended to LLM/AI platforms. You don’t need to restrict innovation. You need to control data flow.”
