30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

AI data leaks under Reg S-P

For a covered institution, an AI-related customer-information incident belongs in the Regulation S-P response programme. Assess its nature and scope, contain it and determine the affected-individual notice obligation. The reasonable-investigation exception, 30-day outer notice limit and service-provider notification duties are distinct from the FTC’s 500-consumer rule.

For SEC-covered institutions’ privacy, incident-response and compliance teams

Aona field notesC19
Different recipient, different clock
Provider → institution → individual

Do not reuse the FTC threshold or treat a provider notice as the customer notice.

Synthetic event, customers and roles. No actual investigation finding, notice, provider assurance or control result is represented.

01

Identify the institution, information and system

Section 248.30 defines covered institutions, including the relevant broker-dealers, investment companies, investment advisers and transfer agents. Check the actual registration and rule scope. Customer information can include information about other financial institutions’ customers that the covered institution handles, not only its own direct customer list.

Identify the AI service, account, feature and information that may have been accessed or used without authorisation. A staff upload, connected system or service-provider incident can require assessment. The label unapproved AI is a trigger to investigate the facts, not a complete legal conclusion.

Source context: 17 CFR 248.30: Customer-information safeguards and response

02

Activate assessment and containment

The response programme must be reasonably designed to detect, respond to and recover from unauthorised access to or use of customer information. It includes assessing the nature and scope of the incident, identifying affected systems and information types, and taking appropriate steps to contain and control it.

Preserve relevant evidence in the approved incident system while limiting further disclosure. Reconcile the employee’s account with available application, provider and security evidence. Distinguish a submission that was actually blocked from one that reached a service; a planned control outcome is not evidence of what occurred.

Source context: 17 CFR 248.30: Customer-information safeguards and response

03

Assess notice to affected individuals

The rule addresses affected individuals whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorisation. It permits the stated exception after a reasonable investigation determines that the information has not been, and is not reasonably likely to be, used in a manner resulting in substantial harm or inconvenience.

Where notice is required, provide it as soon as practicable and no later than 30 days after the relevant awareness described in the rule, subject to its specific delay provisions. Do not transplant the FTC rule’s 500-consumer threshold. A smaller count does not resolve the Regulation S-P notice analysis.

Source context: 17 CFR 248.30: Customer-information safeguards and response

04

Keep service-provider notification separate

The institution’s written procedures must be reasonably designed to oversee service providers and ensure the specified safeguards and notice. The service-provider expectation includes notifying the institution as soon as possible, and no later than 72 hours after awareness of the described breach involving unauthorised access to its maintained customer-information system.

That provider-to-institution notification is not the institution’s affected-individual notice. A written arrangement may have a provider send individual notices on the institution’s behalf, but the institution retains the obligation to ensure the required notice. Use the final rule’s oversight framework rather than treating every term in the earlier proposal as adopted.

Source context: 17 CFR 248.30: Customer-information safeguards and response · SEC: Regulation S-P final rule, 3 June 2024

05

Add an AI-specific insert to the existing plan

The worked insert below adds AI account, feature, recipient and retained-copy questions to an existing response process. It assigns operational roles without inventing a real incident determination. Keep the resulting investigation and notice records in the authorised evidence system.

The 2024 final rule provided larger and smaller entities 18 and 24 months respectively from its 3 June 2024 publication to comply. Those original transition periods are no longer future dates as of this guide’s review. Confirm the institution’s applicable scope and current obligations, then test the response handoffs with synthetic material.

Source context: 17 CFR 248.30: Customer-information safeguards and response · SEC: Regulation S-P final rule, 3 June 2024

Put it into practice

Regulation S-P AI incident insert

A fictional covered institution investigates a spreadsheet of 40 invented customers sent through an unapproved AI feature. The count is deliberately below the separate FTC threshold.

Synthetic event, customers and roles. No actual investigation finding, notice, provider assurance or control result is represented.

Keep the notice paths distinct
01

Service provider

Notify the institution under the applicable provider provision

The described outer limit is 72 hours.

02

Covered institution

Assess, contain and investigate

03

Affected individual

Receive required notice from or on behalf of the institution

Apply the separate notice conditions and timing.

Regulation S-P AI incident insert
Response stepWorked insert for the fictional eventOwner and evidence
Identify scopeRecord the institution, AI account, feature, spreadsheet and potentially affected information.Compliance and incident lead establish the actual rule and system scope.
Contain and preserveStop additional uploads and preserve relevant facts without spreading the spreadsheet.Incident team records timing, payload evidence and completed actions.
Investigate sensitive informationDetermine what was accessed or used and assess the substantial-harm-or-inconvenience standard.Privacy/legal owner documents the reasonable investigation and any exception conclusion.
Assess individual noticeDo not treat 40 consumers as automatically below a Regulation S-P threshold.Notice owner applies the actual rule and relevant 30-day outer limit.
Coordinate provider noticeObtain the service-provider facts and assess the applicable 72-hour provider-notification requirement.Vendor owner separates provider notice from notices to affected individuals.
Close and improveRetain decisions, actual notices if any and the remediation record.Response owner updates the plan; no live notice is generated by this exercise.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

regulation-sp-ai-response-insert.mdInspect
# Regulation S-P AI incident insert

Synthetic event, customers and roles. No actual investigation finding, notice, provider assurance or control result is represented.

A fictional covered institution investigates a spreadsheet of 40 invented customers sent through an unapproved AI feature. The count is deliberately below the separate FTC threshold.

| Response step | Worked insert for the fictional event | Owner and evidence |
| --- | --- | --- |
| Identify scope | Record the institution, AI account, feature, spreadsheet and potentially affected information. | Compliance and incident lead establish the actual rule and system scope. |
| Contain and preserve | Stop additional uploads and preserve relevant facts without spreading the spreadsheet. | Incident team records timing, payload evidence and completed actions. |
| Investigate sensitive information | Determine what was accessed or used and assess the substantial-harm-or-inconvenience standard. | Privacy/legal owner documents the reasonable investigation and any exception conclusion. |
| Assess individual notice | Do not treat 40 consumers as automatically below a Regulation S-P threshold. | Notice owner applies the actual rule and relevant 30-day outer limit. |
| Coordinate provider notice | Obtain the service-provider facts and assess the applicable 72-hour provider-notification requirement. | Vendor owner separates provider notice from notices to affected individuals. |
| Close and improve | Retain decisions, actual notices if any and the remediation record. | Response owner updates the plan; no live notice is generated by this exercise. |

## Review steps

- Verify the legal and data scope: Identify covered institution status, customer information and potentially affected individuals without borrowing another rule’s threshold.
- Track separate notice duties: Record provider awareness, institution awareness, responsible recipients and the applicable timing.
- Evidence any exception: A reasonable investigation must support the relevant conclusion; a lack of reported misuse alone is not the record.

## Fictional response-plan insert

Trigger: employee reports using an AI feature with a spreadsheet containing 40 invented customer records.
Immediate routing: incident lead, privacy/compliance owner and vendor owner.
Evidence questions: which account and feature; what information; what actually reached the provider; which recipients and copies; what access/use occurred; what mitigation is evidenced.
Notice analysis: apply Regulation S-P’s affected-individual and investigation conditions. Do not apply the FTC 500-consumer threshold.
Provider coordination: document the separate provider-to-institution notice and facts.
Final decision: no live determination or notice in this exercise.

This insert supplements an existing institution-specific plan; it does not replace its roles, legal assessment or notice procedures.

## Source and scope

Guide: https://aona.ai/resources/guides/regulation-sp-ai-incident-response/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- 17 CFR 248.30: Customer-information safeguards and response: https://www.law.cornell.edu/cfr/text/17/248.30
- SEC: Regulation S-P final rule, 3 June 2024: https://www.govinfo.gov/content/pkg/FR-2024-06-03/html/2024-11116.htm
Download regulation-sp-ai-response-insert.md
regulation-sp-ai-response-insert.csvInspect
Response step,Worked insert for the fictional event,Owner and evidence
Identify scope,"Record the institution, AI account, feature, spreadsheet and potentially affected information.",Compliance and incident lead establish the actual rule and system scope.
Contain and preserve,Stop additional uploads and preserve relevant facts without spreading the spreadsheet.,"Incident team records timing, payload evidence and completed actions."
Investigate sensitive information,Determine what was accessed or used and assess the substantial-harm-or-inconvenience standard.,Privacy/legal owner documents the reasonable investigation and any exception conclusion.
Assess individual notice,Do not treat 40 consumers as automatically below a Regulation S-P threshold.,Notice owner applies the actual rule and relevant 30-day outer limit.
Coordinate provider notice,Obtain the service-provider facts and assess the applicable 72-hour provider-notification requirement.,Vendor owner separates provider notice from notices to affected individuals.
Close and improve,"Retain decisions, actual notices if any and the remediation record.",Response owner updates the plan; no live notice is generated by this exercise.
Download regulation-sp-ai-response-insert.csv

Before you proceed

Keep these distinctions clear

The FTC threshold does not transfer
Regulation S-P’s notice analysis is not resolved by counting fewer than 500 people.
The provider does not take over accountability
Even if it sends notices on the institution’s behalf, the institution retains the stated obligation.

Apply it to employee AI use

Bring your actual data path.

Supported Aona policy and activity evidence may assist an investigation of a particular employee AI input path.

It does not determine Regulation S-P notice obligations, conduct the institution’s legal investigation or send notices.

Use the fictional spreadsheet scenario to test incident evidence and handoffs while separately validating the selected input control.

Review your use case

FAQ

Questions for this decision

Is an event involving fewer than 500 customers exempt?
Do not import the FTC Safeguards notification threshold into Regulation S-P. Apply the latter rule’s own customer-information, affected-individual and investigation provisions.
Are the 72-hour and 30-day limits the same notice?
No. The described 72-hour provision concerns service-provider notification to the institution; the 30-day outer limit concerns the institution’s required affected-individual notice under its separate conditions.
Can a provider notify individuals for the institution?
The rule permits a written arrangement for that action, but the covered institution retains the obligation to ensure that required notice is provided.
Does every AI submission require individual notice?
Assess the actual information, access or use, affected individuals and the rule’s reasonable-investigation exception. An application label alone cannot determine the outcome.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. 17 CFR 248.30: Customer-information safeguards and response

    Covered institutions, customer and sensitive customer information, response and notice duties, investigation exception and service-provider oversight.

    law · checked 2026-09-21
  2. SEC: Regulation S-P final rule, 3 June 2024

    Final amendments and the 18-month larger-entity and 24-month smaller-entity compliance periods from publication; distinct from the proposal.

    law · checked 2026-09-21
Regulation S-P: respond to AI data disclosures | Aona