{"id":7002,"date":"2026-05-20T14:27:38","date_gmt":"2026-05-20T14:27:38","guid":{"rendered":"https:\/\/basesolutionsllc.com\/?p=7002"},"modified":"2026-05-20T14:27:38","modified_gmt":"2026-05-20T14:27:38","slug":"securing-ai-risk-compliance-and-data-protection","status":"publish","type":"post","link":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/","title":{"rendered":"Securing AI: Risk, Compliance, and Data Protection"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"7002\" class=\"elementor elementor-7002\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2cfd4805 e-flex e-con-boxed e-con e-parent\" data-id=\"2cfd4805\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4af67b37 elementor-widget elementor-widget-text-editor\" data-id=\"4af67b37\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Most firms we work with have a defensible cybersecurity posture, including patching cycles, endpoint protection, email filtering, MFA, an annual pen test, and the basics properly maintained. However, none of it stops an employee from pasting a client file into a chatbot.<\/p><p>For fifteen years, cyber programs at small and mid-sized firms have been built around the assumption that sensitive data stays inside the firm. But AI tools break that assumption on the first day of use.<\/p><p>AI is already in the building at most professional services firms, <a href=\"https:\/\/basesolutionsllc.com\/the-state-of-ai-in-your-business-today\/\">as the first blog of this series<\/a> laid out, usually well before the firm even knows it. What firms should be checking is whether their current security and compliance setup covers it.<\/p><h2>What a public AI tool does with your data<\/h2><p>A wealth manager pastes a portfolio summary into ChatGPT to redraft it for a client. The data leaves the firm at that moment, sent over the public internet to OpenAI&#8217;s servers and processed there. Depending on the account tier, it may also be retained for some period.<\/p><p>Free and Plus tiers of ChatGPT and similar consumer tools allow the provider to use inputs to improve future models unless the user actively opts out. Enterprise and Team tiers usually don&#8217;t. The default for an employee who signed up with a personal email is the more permissive setting.<\/p><p>That single paste is a third-party disclosure of covered information by an employee acting in good faith under a deadline. It bypasses email DLP because nothing was emailed. The firewall sees only a routine outbound connection to a domain it has no reason to flag.<\/p><h2>What the regulated rulebooks already say<\/h2><p>The fact that AI is new does not reset the regulatory clock.<\/p><p>Legal<br \/>The American Bar Association issued <a href=\"https:\/\/www.americanbar.org\/news\/abanews\/aba-news-archives\/2024\/07\/aba-issues-first-ethics-guidance-ai-tools\/\">Formal Opinion 512 in July 2024<\/a>, its first formal guidance on lawyers using generative AI. Model Rule 1.6, confidentiality, applies in full. Lawyers are responsible for knowing how a generative AI tool uses the data they put into it, and informed consent from the client is required before client confidences go into a tool that may retain or train on them. Boilerplate consent in the engagement letter doesn&#8217;t satisfy the rule. For <a href=\"https:\/\/basesolutionsllc.com\/legal-law-firm-it\/\">law firms working with BASE<\/a>, this is the single change with the biggest impact on how AI is rolled out internally.<\/p><p>Financial<strong><br \/><\/strong>The <a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/ftc-safeguards-rule-what-your-business-needs-know\">FTC&#8217;s GLBA Safeguards Rule<\/a> requires financial institutions, including independent RIAs and many <a href=\"https:\/\/basesolutionsllc.com\/banking-and-financial-services-it\/\">smaller financial services firms<\/a>, to maintain a written information security program covering every system that handles customer information. A consumer AI tool an associate signed up for on a personal Gmail is not part of that program.<\/p><p>Accounting<strong><br \/><\/strong>The <a href=\"https:\/\/pub.aicpa.org\/codeofconduct\/ethicsresources\/et-cod.pdf\">AICPA&#8217;s confidentiality rule (1.700.001)<\/a> and <a href=\"https:\/\/www.irs.gov\/tax-professionals\/section-7216-information-center\">the IRS&#8217;s Section 7216<\/a> restrictions on the use of taxpayer information both predate generative AI but apply to it cleanly. A 1040 dropped into a free AI tool during tax season is a disclosure of client information to an unrelated third party.<\/p><p>Healthcare<br \/>For HIPAA-regulated workflows that touch protected health information, the same logic applies. A clinician dictating notes into a public AI transcription tool, a practice manager summarizing patient correspondence in ChatGPT, or a research coordinator drafting a clinical trial protocol with a free model are all third-party disclosures of PHI. A vendor that processes PHI is <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/covered-entities\/index.html\">a business associate under HHS rules<\/a>, and most public AI tools are not.<\/p><h2>The threats your stack wasn&#8217;t built to withstand<\/h2><p>NIST&#8217;s <a href=\"https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\">Generative AI Profile of the AI Risk Management Framework<\/a>, published in July 2024, identifies twelve risk categories specific to generative AI. Several deserve immediate attention from professional services firms.<\/p><p>Sensitive information disclosure now ranks number two on <a href=\"https:\/\/genai.owasp.org\/llm-top-10\/\">OWASP&#8217;s Top 10 for LLM Applications<\/a>, up from number six in the previous edition. The incidents driving that jump have been employees pasting client information and source code into public chatbots.<\/p><p>Prompt injection sits at the top of the same list. In the indirect form, a malicious instruction is hidden inside something the AI processes, like a contract or a vendor proposal, and the model carries it out. A firm using an AI assistant that can summarize incoming email or search internal documents has just expanded its attack surface in a way last year&#8217;s pen test did not cover.<\/p><p>Vendor due diligence is the area where most cyber programs are furthest behind. The process built for cloud and SaaS is well-established at most firms. The AI version usually isn&#8217;t. The questions are different. How is the model trained? What data is retained? Where is processing happening? What&#8217;s the breach notification window?<\/p><h2>AI is not a separate security problem<\/h2><p>The mistake we see most often is treating AI security as a new program. It is a set of new questions inside the <a href=\"https:\/\/basesolutionsllc.com\/cyber-security-consulting\/\">existing security and compliance program<\/a>, such as which tools are sanctioned, who has access, what data leaves the firm and through which channels, and what the regulator would say if asked.<\/p><p>Firms that try to bolt AI controls on as a standalone module end up with two programs that don&#8217;t talk to each other. Firms that fold AI into the existing posture end up with one defensible program that survives the next regulatory cycle.<\/p><h2>Secure the ground before you climb further<\/h2><p>The first blog in this series argued that most firms don&#8217;t know how much AI is already in their building. The second laid out the policy that gives employees a sanctioned way to use it. The third move is making sure the ground that policy sits on has been checked.<\/p><p>For professional services firms in the DMV, the starting point is a <a href=\"https:\/\/basesolutionsllc.com\/cyber-risk-assessment\/\">current inventory of every AI tool in use<\/a> and a map of the regulated data flowing through them. The next step is rebuilding the vendor review process for the questions generative AI raises.<\/p><p><a href=\"https:\/\/calendly.com\/atulbhagat\/30min\">Book a consultation with BASE Solutions<\/a> to review your AI security and compliance posture.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-46c3cfc e-flex e-con-boxed e-con e-parent\" data-id=\"46c3cfc\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-38cf95a elementor-widget elementor-widget-image\" data-id=\"38cf95a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/calendly.com\/atulbhagat\/30min\">\n\t\t\t\t\t\t\t<img decoding=\"async\" loading=\"lazy\" width=\"1200\" height=\"400\" src=\"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/CTA-1-4.png\" class=\"attachment-full size-full wp-image-7007\" alt=\"\" srcset=\"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/CTA-1-4.png 1200w, https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/CTA-1-4-300x100.png 300w, https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/CTA-1-4-1024x341.png 1024w, https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/CTA-1-4-768x256.png 768w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Most firms we work with have a defensible cybersecurity posture, including patching cycles, endpoint protection, email filtering, MFA, an annual pen test, and the basics properly maintained. However, none of it stops an employee from pasting a client file into a chatbot. For fifteen years, cyber programs at small and mid-sized firms have been built [&hellip;]<\/p>\n","protected":false},"author":23,"featured_media":7005,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","_auhfc":[],"footnotes":""},"categories":[34],"tags":[],"class_list":["post-7002","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Build an AI Acceptable Use Policy for Your Business<\/title>\n<meta name=\"description\" content=\"A practical guide to writing an AI Acceptable Use Policy your team will actually follow, without slowing down work or pushing AI underground.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Build an AI Acceptable Use Policy for Your Business\" \/>\n<meta property=\"og:description\" content=\"A practical guide to writing an AI Acceptable Use Policy your team will actually follow, without slowing down work or pushing AI underground.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/\" \/>\n<meta property=\"og:site_name\" content=\"BASE Solutions LLP\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-20T14:27:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/Featured-Image-2-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Atul\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Atul\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Build an AI Acceptable Use Policy for Your Business","description":"A practical guide to writing an AI Acceptable Use Policy your team will actually follow, without slowing down work or pushing AI underground.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_GB","og_type":"article","og_title":"How to Build an AI Acceptable Use Policy for Your Business","og_description":"A practical guide to writing an AI Acceptable Use Policy your team will actually follow, without slowing down work or pushing AI underground.","og_url":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/","og_site_name":"BASE Solutions LLP","article_published_time":"2026-05-20T14:27:38+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/Featured-Image-2-1.png","type":"image\/png"}],"author":"Atul","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Atul","Estimated reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/#article","isPartOf":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/"},"author":{"name":"Atul","@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/#\/schema\/person\/c5ecb71674eb1faff93ab0e0e14e9aca"},"headline":"Securing AI: Risk, Compliance, and Data Protection","datePublished":"2026-05-20T14:27:38+00:00","mainEntityOfPage":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/"},"wordCount":986,"publisher":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/#organization"},"image":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/#primaryimage"},"thumbnailUrl":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/Featured-Image-2-1.png","articleSection":["AI"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/","url":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/","name":"How to Build an AI Acceptable Use Policy for Your Business","isPartOf":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/#website"},"primaryImageOfPage":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/#primaryimage"},"image":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/#primaryimage"},"thumbnailUrl":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/Featured-Image-2-1.png","datePublished":"2026-05-20T14:27:38+00:00","description":"A practical guide to writing an AI Acceptable Use Policy your team will actually follow, without slowing down work or pushing AI underground.","breadcrumb":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/#primaryimage","url":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/Featured-Image-2-1.png","contentUrl":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2026\/05\/Featured-Image-2-1.png","width":1200,"height":628,"caption":"Securing AI: Risk, Compliance, and Data Protection"},{"@type":"BreadcrumbList","@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/securing-ai-risk-compliance-and-data-protection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/basesolutionsllc.com\/staging\/6761\/"},{"@type":"ListItem","position":2,"name":"Securing AI: Risk, Compliance, and Data Protection"}]},{"@type":"WebSite","@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/#website","url":"https:\/\/basesolutionsllc.com\/staging\/6761\/","name":"BASE Solutions LLP","description":"","publisher":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/basesolutionsllc.com\/staging\/6761\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/#organization","name":"BASE Solutions LLP","url":"https:\/\/basesolutionsllc.com\/staging\/6761\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/#\/schema\/logo\/image\/","url":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2024\/03\/Logo-Footer-1.svg","contentUrl":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-content\/uploads\/2024\/03\/Logo-Footer-1.svg","width":193,"height":53,"caption":"BASE Solutions LLP"},"image":{"@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/basesolutionsllc.com\/staging\/6761\/#\/schema\/person\/c5ecb71674eb1faff93ab0e0e14e9aca","name":"Atul","url":"https:\/\/basesolutionsllc.com\/staging\/6761\/blog\/author\/atul\/"}]}},"_yoast_wpseo_title":"How to Build an AI Acceptable Use Policy for Your Business","_yoast_wpseo_metadesc":"A practical guide to writing an AI Acceptable Use Policy your team will actually follow, without slowing down work or pushing AI underground.","yoast_noindex":false,"_links":{"self":[{"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/posts\/7002","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/comments?post=7002"}],"version-history":[{"count":0,"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/posts\/7002\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/media\/7005"}],"wp:attachment":[{"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/media?parent=7002"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/categories?post=7002"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/basesolutionsllc.com\/staging\/6761\/wp-json\/wp\/v2\/tags?post=7002"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}