Compliance decisions
When an AI leak needs FTC review
For a covered institution, the FTC notification requirement applies to a notification event involving at least 500 consumers. The rule concerns unauthorised acquisition of unencrypted customer information, including its access presumption and encryption-key condition. Notify as soon as possible and no later than 30 days after discovery when the requirement applies.
For FTC-covered financial institutions’ incident and compliance teams
The FTC threshold and notice recipient differ from other breach-notification regimes.
Entirely synthetic data counts and incidents. No actual breach determination, provider response or FTC notification is represented.01
Confirm that this is the relevant notification rule
First establish that the institution is covered by the FTC Safeguards Rule and that the information meets its definitions. A financial-sounding dataset is not enough to decide jurisdiction. Other regulators and state laws may impose separate duties; do not reuse this threshold as a universal financial-sector rule.
The fictional exercise concerns a covered firm whose employee sends a client spreadsheet to an unapproved AI account. It asks whether the FTC notification requirement is triggered, not whether the account was an appropriate procurement choice. Keep immediate containment and evidence preservation moving while the legal facts are assessed.
Source context: FTC: Safeguards Rule, what your business needs to know · 16 CFR 314.2: Definitions
02
Apply the acquisition and encryption conditions
Section 314.2 defines a notification event as acquisition of unencrypted customer information without the individual’s authorisation. For this purpose, information is considered unencrypted if its encryption key was accessed by an unauthorised person.
The rule presumes unauthorised acquisition includes unauthorised access to unencrypted customer information unless reliable evidence shows acquisition did not, or could not reasonably, occur. Do not replace that standard with “we have not seen misuse”. Establish the actual payload, account, recipient and access facts, including what any input-control evidence can and cannot prove.
Source context: 16 CFR 314.2: Definitions
03
Count affected consumers, not spreadsheet rows
Paragraph 314.4(j) requires notice to the FTC when the notification event involves the information of at least 500 consumers. Count unique affected or potentially affected consumers based on the relevant evidence. Repeated records for one person are not automatically additional consumers.
In the example, an 800-row file contains 620 distinct invented consumers. If the acquisition conditions are established, that scenario meets the numerical threshold. A second scenario involving 420 consumers does not meet this particular threshold, but it still needs incident handling and assessment of any other applicable notification duties.
Source context: 16 CFR 314.4: Information-security programme elements
04
Record discovery and the notification owner
The notice is due as soon as possible and no later than 30 days after discovery. The rule’s deemed-knowledge provision includes an employee, officer or other agent, excluding the person committing the breach. Record the relevant awareness and who had it; do not assume the uploader’s knowledge alone settles discovery or wait until an executive signs the report.
The FTC form requests high-level facts such as the reporting institution, information types, event dates where ascertainable, affected or potentially affected consumers and a general description. FTC guidance says to report what is known and update the report as more information becomes available. Do not delay solely because every field is not yet certain.
Source context: 16 CFR 314.4: Information-security programme elements · FTC: Safeguards Rule, what your business needs to know
05
Keep evidence exceptions and public-disclosure delays distinct
Reliable evidence about acquisition can affect the notification-event analysis. The rule also has a process for a law-enforcement determination affecting public disclosure. Do not treat an informal request or a pending investigation as permission to skip notifying the FTC.
The worksheet records the factual findings, threshold, owner and follow-up without submitting a notice. Use the actual incident response and legal review process for a real event. A later deletion request or future block is mitigation evidence, not automatic proof that the earlier acquisition never happened.
Source context: 16 CFR 314.2: Definitions · 16 CFR 314.4: Information-security programme elements
Put it into practice
FTC AI-exposure threshold exercise
Three fictional variants show why the threshold and reliable-evidence analysis must be documented separately.
Entirely synthetic data counts and incidents. No actual breach determination, provider response or FTC notification is represented.
Scope
Covered institution and customer information
Event
Acquisition, access presumption and encryption
Threshold
At least 500 distinct consumers
Action
FTC notice owner and discovery-based timing
| Condition or variant | Invented facts | Decision path |
|---|---|---|
| Scope check | The fictional firm is assumed FTC-covered for this exercise. | A real case must establish institutional and customer-information scope. |
| Variant A: threshold met | 620 distinct consumers; qualifying unauthorised acquisition established in the scenario. | Meets the numerical trigger; assign FTC notice as soon as possible within the 30-day outer limit. |
| Variant B: below this threshold | 420 distinct consumers; same assumed acquisition conditions. | This FTC numerical trigger is not met; investigate and assess other applicable duties. |
| Variant C: access with contrary evidence | 620 consumers; access occurred but reliable technical evidence may establish no acquisition. | Assess that evidence against the rule; do not infer an exception from a lack of known misuse. |
| Encryption check | A separate scenario involves encrypted data and an exposed decryption key. | Treat the key-access condition as part of the unencrypted-information analysis. |
| Discovery and report | Relevant employee, officer or agent discovery is recorded, excluding the person committing the breach; some scope facts remain uncertain. | Assign the owner, report known required facts when applicable and update rather than waiting for perfect certainty. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
ftc-ai-notification-exercise.mdInspect
# FTC AI-exposure threshold exercise
Entirely synthetic data counts and incidents. No actual breach determination, provider response or FTC notification is represented.
Three fictional variants show why the threshold and reliable-evidence analysis must be documented separately.
| Condition or variant | Invented facts | Decision path |
| --- | --- | --- |
| Scope check | The fictional firm is assumed FTC-covered for this exercise. | A real case must establish institutional and customer-information scope. |
| Variant A: threshold met | 620 distinct consumers; qualifying unauthorised acquisition established in the scenario. | Meets the numerical trigger; assign FTC notice as soon as possible within the 30-day outer limit. |
| Variant B: below this threshold | 420 distinct consumers; same assumed acquisition conditions. | This FTC numerical trigger is not met; investigate and assess other applicable duties. |
| Variant C: access with contrary evidence | 620 consumers; access occurred but reliable technical evidence may establish no acquisition. | Assess that evidence against the rule; do not infer an exception from a lack of known misuse. |
| Encryption check | A separate scenario involves encrypted data and an exposed decryption key. | Treat the key-access condition as part of the unencrypted-information analysis. |
| Discovery and report | Relevant employee, officer or agent discovery is recorded, excluding the person committing the breach; some scope facts remain uncertain. | Assign the owner, report known required facts when applicable and update rather than waiting for perfect certainty. |
## Review steps
- Establish the notification-event facts: Record authorisation, acquisition/access, encryption and key access, with the evidence supporting any exception.
- Count distinct consumers: Reconcile the payload and duplication rather than equating rows with people.
- Assign the FTC notice process: Record discovery, the responsible owner, deadline and updates; check other notification regimes separately.
## Synthetic count reconciliation
File rows: 800
Distinct invented consumers: 620
Duplicate rows: 180
Scenario A acquisition: assumed established for teaching
Scenario A numerical finding: at least 500 consumers
## Case record fields
Record the institution and scope, discovery evidence, data types, distinct consumer count, acquisition/encryption findings, reliable contrary evidence if any, notification owner, known facts submitted and subsequent updates.
No notice is generated or sent by this worksheet.
## Source and scope
Guide: https://aona.ai/resources/guides/ftc-safeguards-ai-exposure-notification/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- FTC: Safeguards Rule, what your business needs to know: https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
- 16 CFR 314.2: Definitions: https://www.law.cornell.edu/cfr/text/16/314.2
- 16 CFR 314.4: Information-security programme elements: https://www.law.cornell.edu/cfr/text/16/314.4
Download ftc-ai-notification-exercise.mdftc-ai-notification-exercise.csvInspect
Condition or variant,Invented facts,Decision path
Scope check,The fictional firm is assumed FTC-covered for this exercise.,A real case must establish institutional and customer-information scope.
Variant A: threshold met,620 distinct consumers; qualifying unauthorised acquisition established in the scenario.,Meets the numerical trigger; assign FTC notice as soon as possible within the 30-day outer limit.
Variant B: below this threshold,420 distinct consumers; same assumed acquisition conditions.,This FTC numerical trigger is not met; investigate and assess other applicable duties.
Variant C: access with contrary evidence,620 consumers; access occurred but reliable technical evidence may establish no acquisition.,Assess that evidence against the rule; do not infer an exception from a lack of known misuse.
Encryption check,A separate scenario involves encrypted data and an exposed decryption key.,Treat the key-access condition as part of the unencrypted-information analysis.
Discovery and report,"Relevant employee, officer or agent discovery is recorded, excluding the person committing the breach; some scope facts remain uncertain.","Assign the owner, report known required facts when applicable and update rather than waiting for perfect certainty."
Download ftc-ai-notification-exercise.csvBefore you proceed
Keep these distinctions clear
- No known misuse is not the same as no acquisition
- Use the reliable-evidence standard rather than an unsupported reassurance.
- Below 500 is not a universal exemption
- Other incident-response and notification requirements may still apply.
Apply it to employee AI use
Bring your actual data path.
Supported Aona policy and activity evidence may assist investigation of a specific employee input path.
It does not decide FTC reportability, determine every affected consumer or submit the notification.
Use a synthetic spreadsheet pattern to establish what the selected control and event evidence actually show.
Review your use caseFAQ
Questions for this decision
Does the 500 threshold mean 500 spreadsheet rows?
What if data was encrypted?
Can we wait for proof of harm?
Does this rule require us to notify customers through the FTC form?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- FTC: Safeguards Rule, what your business needs to know
Covered institutions, customer information, service-provider oversight and the notification threshold and process.
regulator · checked 2026-09-21 - 16 CFR 314.2: Definitions
Customer information, financial-institution scope and the definition and acquisition presumption for a notification event.
law · checked 2026-09-21 - 16 CFR 314.4: Information-security programme elements
Service-provider oversight under paragraph (f), and FTC notification timing, content and discovery under paragraph (j), including the exclusion of the person committing the breach from deemed institutional knowledge.
law · checked 2026-09-21