9 AI Governance Controls Banks Need for ChatGPT, Copilot, and Coding Assistants
For banks, AI governance for ChatGPT, Copilot, and coding tools means enforcing policy during the AI interaction, not just writing rules into an acceptable-use policy. The main risk for a supervised institution is confidential data leaving through a personal account, a developer plugin, or an unsanctioned tool that logging never reaches. Security and compliance teams need real-time inspection and audit evidence for every session. Aurascape discovers AI use, classifies data inline, and creates interaction records.
Last updated: August 2026.
Most bank AI governance frameworks stop at policy documents and vendor contracts. The enforcement gap sits elsewhere: at the moment an employee pastes a customer record into ChatGPT on a personal account, or a developer accepts a coding assistant suggestion that carries proprietary source code. The controls that close that gap operate at the interaction layer, where the bank can see and act on what is actually being sent, in real time. Banks do not need another AI policy memo. They need proof that policy decisions were enforced during actual AI use.
The nine controls below map each requirement to what it does, why it matters for a supervised institution, where Aurascape fits, and the audit evidence an examiner can review. The list starts with human-to-AI use today (employees typing into ChatGPT or Copilot), then extends to human-to-agent delegation and emerging agent-to-agent execution as a bank’s AI program matures.
The Regulatory Landscape for Bank AI Use
Banking supervisors in the United States and abroad have moved from general AI awareness guidance to specific expectations for how institutions discover, assess, monitor, and document AI use. The nine controls below are organized around those expectations. Understanding the landscape helps compliance officers map each control to the obligation it serves.
In the United States, the framework for bank AI governance spans four bodies of existing guidance rather than a single AI-specific rule. The Office of the Comptroller of the Currency (OCC), the Federal Reserve, and the Federal Deposit Insurance Corporation (FDIC) apply their third-party risk management guidance (most recently aligned in the 2023 Interagency Guidance on Third-Party Relationships) to AI vendors, including ChatGPT, Copilot, and coding assistants that process bank information. That guidance requires documented due diligence, risk assessment, contractual protections, and ongoing monitoring for any third party that accesses, transmits, or stores bank data.
Model risk management expectations, set in the Federal Reserve’s SR 11-7 guidance and the OCC’s equivalent, now reach AI applications that influence decisions in credit, fraud, compliance, and customer service. Banks that let employees use AI tools for any decision-relevant task face examiner questions about validation, use-case documentation, output monitoring, and human oversight. Controls 8 and 9 below address those expectations directly.
The Gramm-Leach-Bliley Act (GLBA) and its implementing rules, including the GLBA Safeguards Rule revised in 2023, require financial institutions to run a comprehensive information security program covering data in all forms. Regulators confirm that customer information shared with or processed by AI tools falls within GLBA scope, so Controls 3 and 4 below are compliance requirements, not optional risk management steps.
The FFIEC has issued supplemental guidance on AI and machine learning that stresses explainability, fairness testing, and audit trails for AI-assisted decisions, especially in consumer-facing applications. Internationally, the EU AI Act sets binding obligations for high-risk AI systems in financial services, covering human oversight, transparency, and documentation that parallel several controls below.
Most of this guidance shares one expectation: banks can demonstrate control. They know which AI tools are in use, what data those tools can reach, and how decisions that relied on AI output were made and monitored. The nine controls below satisfy exactly those expectations, and each one produces the kind of evidence a bank examiner is likely to request. For a broader mapping of compliance frameworks to bank AI obligations, see the guide to AI compliance frameworks and governance for banks and investment firms.
1. Acceptable-Use Policy Backed by Real-Time Enforcement
An acceptable-use policy for AI tools defines which tools employees may use, for what data, and under what conditions. For a bank, it also has to cover personal-account use, consumer-grade AI, and developer tooling, not just enterprise-licensed software. ISACA found that 90% of organizations say employees use AI tools, yet only 38% have a formal, comprehensive AI policy and 25% have none (ISACA, 2026).
Aurascape turns policy into enforcement. It can coach users away from a risky prompt, notify them of the applicable rule, require an enterprise account for approved apps, and block a confidential upload before it reaches the tool (Aurascape, 2026). Coach and notify actions carry the training message at the moment of use, and the interaction record documents user acknowledgment. The evidence for this control is a per-user log of which policy applied and what action ran, available to compliance under role-based access control (RBAC) for privacy.
2. Shadow AI Discovery Across Network, Endpoint, and Personal Accounts
Shadow AI discovery finds the AI apps, accounts, and agents in use that security never approved, including tools that never touch monitored network egress. It matters because unsanctioned tools sit outside tenant controls, retention terms, and audit logging. The National Cybersecurity Alliance found that 43% of workers admit sharing sensitive workplace information with AI tools without employer knowledge (National Cybersecurity Alliance, 2025).
Aurascape discovers AI use across network, endpoint, and API planes. On endpoints, it detects AI apps and personal accounts through process and filesystem analysis, finding tools that never surface in network monitoring (Aurascape, 2026). Compliance gets a continuously updated inventory by user, app, and account type as the evidence for this control.
3. Data Leakage Control at the Prompt and Upload
Data leakage control for AI tools stops sensitive information from leaving through prompts, file uploads, code snippets, and connector outputs before it reaches the AI service. It matters because a permitted destination can still carry an impermissible interaction, and traditional data loss prevention (DLP) tools act on file patterns rather than the content of an AI exchange.
Aurascape applies 600+ real-time data classifiers to inspect content inline and redact or block before data leaves the session (Aurascape, 2026). The Cloud Security Alliance found that 61% of organizations reported data exposure involving AI agents (Cloud Security Alliance, 2026). The evidence for this control is a record of the data category detected, the prompt or upload context, and the policy action that followed.
4. Enterprise Tenant Enforcement for Sanctioned Tools
Tenant enforcement requires approved AI tools to run under the bank’s enterprise account, not an employee’s personal login. It matters because personal accounts sit outside the bank’s data-retention terms, eDiscovery rights, and legal protections, and examiners increasingly ask whether a bank can show that AI use occurred on controlled infrastructure.
Aurascape distinguishes enterprise tenants from personal accounts inline and applies the require tenant action before permitting use, enforcing this in real time rather than relying on employee compliance (Aurascape, 2026). The evidence for this control is a per-session account-type record showing which login was active during each interaction.
5. Third-Party AI Vendor Risk Assessment and Copilot Readiness
Vendor risk assessment for AI tools scores each application on data handling, retention, terms of service, and breach history before rollout or sanctioning. For a bank, this is a third-party risk management obligation: AI vendors that process customer information, generate advice, or connect to internal systems need the same diligence as any other service provider. Treat AI vendors that process bank data, generate customer-facing content, or connect to internal systems as third-party relationships that require documented risk review.
Aurascape helps security teams prioritize discovered AI apps by risk, usage, account type, and the data each tool can reach (Aurascape, 2026). For Microsoft 365 Copilot rollouts, Aurascape identifies overshared content and risky access before access expands, and shows compliance what data the Copilot environment can reach (Aurascape, 2026). For a broader view of bank obligations, see the guide to AI compliance frameworks and governance for banks and investment firms. The evidence for this control is the app risk profile and the scoped access inventory at the time of sanctioning.
6. Coding Assistant and IDE Plugin Oversight
Coding assistant oversight applies the same data classification and policy actions to developer tools that a bank applies to chat interfaces. It matters because coding assistants handle proprietary source code, API keys, and infrastructure secrets, and most banking AI governance frameworks treat them as a footnote. Stack Overflow reports that 84% of developers use or plan to use AI coding tools, up from 76% in 2024 (Stack Overflow, 2025).
Aurascape decodes IDE and command-line assistant traffic and applies data classification and policy actions to developer tool interactions inline (Aurascape, 2026). For a detailed breakdown, see how to secure AI coding assistants in financial services and prompt injection in IDE coding assistants. The evidence for this control is a per-interaction record for developer tools, equivalent to the record for chat interfaces.
7. Prompt Injection and Unsafe Output Controls
Inbound threat prevention stops malicious instructions and unsafe content from reaching a user or a downstream workflow through AI tools. It matters because AI tools ingest untrusted content from documents, web pages, and tool results. OWASP ranks prompt injection (LLM01), sensitive information disclosure (LLM02), and excessive agency (LLM06) among the top risks for applications using large language models (OWASP, 2025).
Aurascape detects and blocks prompt injection, including instructions carried in tool results, and jailbreak attempts at the proxy layer (Aurascape, 2026). The evidence for this control is a record of the threat detected, the source context, and the enforcement action applied.
8. Model Risk Management Extension to AI Applications
Model risk management (MRM) for AI applications extends the validation, use-case approval, monitoring, and evidence requirements that bank examiners apply to quantitative models to the AI tools and agents employees use. For higher-risk AI use cases, a bank should be able to document the approved use case, the data used, the output reviewed, and the human oversight applied.
Examiners applying MRM principles to AI tools look for a documented inventory of AI use cases, evidence that outputs were reviewed before influencing decisions, and an ongoing monitoring record. The FFIEC’s supplemental AI and machine learning guidance reinforces the expectation that institutions explain AI-assisted outcomes and show that controls stayed effective over time. Aurascape may support evidence for MRM validation by producing interaction-level records that show the data an AI application received, the response it returned, and the policy controls active during the session (Aurascape, 2026). The evidence for this control is the interaction record by application, user group, and date range, accessible under RBAC for the model risk function.
9. Interaction-Layer Audit Evidence and Delegated Administration
Interaction-layer audit evidence captures who used AI, which account, what data was shared, what the AI returned, which tool was invoked, and which policy decision occurred, distinct from model-level or network logs. It matters because examiners ask for this granularity for AI-assisted decisions, and a governance structure needs executive ownership plus a way for business units to run scoped controls without IT bottlenecks.
Aurascape creates interaction records for audit and effectiveness, governed by role-based access control (RBAC) for privacy. Auri gives line-of-business owners role-based, natural-language access to usage, risk, and policy while central compliance and an executive risk owner keep global control (Aurascape, 2026). This is where a bank turns policy into evidence a supervisor can review.
Control-to-Evidence Checklist for Bank AI Governance
The table below maps each control to the AI tool examples it covers, the enforcement point, and the audit evidence the bank can produce for examiners.
| Control | Tool Examples | Enforcement Point | Aurascape Audit Evidence |
|---|---|---|---|
| Acceptable-use enforcement | ChatGPT, Claude, Gemini | Inline proxy, before data leaves | Per-user policy log with action applied |
| Shadow AI discovery | Unsanctioned AI apps, personal ChatGPT | Network, endpoint, API planes | AI app inventory by user, app, account type |
| Data leakage control | ChatGPT, Copilot, coding assistants | 600+ real-time classifiers, inline | Data category detected, policy action, session context |
| Tenant enforcement | ChatGPT Enterprise vs. personal, Microsoft 365 | Inline, before session proceeds | Per-session account-type record |
| Vendor risk and Copilot readiness | Microsoft 365 Copilot, embedded SaaS AI | Pre-rollout assessment | App risk profile, overshared content inventory |
| Coding assistant oversight | GitHub Copilot, Cursor, Tabnine, Claude Code | IDE and CLI traffic, inline | Per-interaction developer tool record |
| Prompt injection controls | All AI tools accepting external content | Proxy, before content reaches user | Threat type, source context, action applied |
| Model risk monitoring | ChatGPT, Copilot, built AI applications | Interaction layer, continuous | Interaction record by app, user group, date range |
| Agent tool-call governance | AI agents, MCP-connected tools | Zero-Bypass MCP Gateway, inline | Decoded record: user, server, tool, parameters, action |
How Banks Should Sequence These Controls
Deploy these controls in an order that gives compliance and risk teams visibility first, then enforcement, then examiner-ready evidence:
- Assign executive ownership. Name a risk owner and a governance committee accountable for AI use, risk acceptance, and policy sign-off before controls go live.
- Discover every AI app, account, and agent across network, endpoint, and API planes. Include personal accounts and coding assistants. Build the inventory before writing policy rules, so the rules reflect actual usage.
- Score each discovered app against your vendor risk and third-party risk management criteria. Separate sanctioned, tolerated, and prohibited tiers before any enforcement runs.
- Map your data classifiers to bank data categories: customer records, account numbers, proprietary source code, and any data subject to GLBA, FFIEC, or state privacy obligations.
- Turn on coach and notify actions first, paired with documented user acknowledgment. Employees learn the policy, compliance sees usage patterns, and the bank builds a baseline before moving to block or redact actions.
- Require enterprise tenants for sanctioned tools and block confidential uploads to personal accounts. Document this in the acceptable-use policy so the enforcement is auditable.
- Govern agent tool execution and run pre-production assessments for AI the bank builds or pilots, tying results to the model risk validation record.
- Create interaction records and delegate scoped administration to business-unit compliance owners under central oversight. Confirm RBAC controls on who can access records before the first examiner request.
Side-by-Side Comparison: Policy-Document Controls vs. Interaction-Layer Enforcement
The table below shows the side-by-side comparison between the controls most banking frameworks describe and the enforcement layer that acts on the AI interaction itself.
| Capability | Policy Document or Network Edge | Aurascape |
|---|---|---|
| Personal-account coverage | Documents the rule, but does not show which account was active during the AI session | Detects personal ChatGPT accounts on endpoints and enforces the require tenant action inline |
| Data inspection point | Acts on destination or file pattern, not the content of the prompt | 600+ real-time data classifiers applied inline to the prompt and upload |
| Coding assistant control | Rarely inspects IDE and command-line assistant traffic | Decodes IDE and command-line assistant traffic with inline data classification and policy actions |
| Agent tool execution | Logs network traffic but does not gate the individual tool call | Zero-Bypass MCP Gateway marks approved calls and blocks unmarked calls inline. Note: Model Context Protocol (MCP) is one common tool-execution pattern, not the whole agent access-control problem. |
| Audit evidence | Captures logs at the model or network layer, not the interaction | Records AI interactions and governed tool calls with user, account, data category, and policy action |
Aurascape enforces policy in real time through allow, coach, notify, redact, redirect, block, capture, and require tenant actions (Aurascape, 2026). That lets a bank coach an employee off a risky prompt, redact a customer record, or block a personal-account upload without shutting down the tool. Aurascape is additive to an existing SSE, SASE, CASB, DLP, or SWG stack, with no rip-and-replace.
Frequently Asked Questions
How should banks govern employee AI tools?
Banks should govern employee AI tools at the interaction layer, not only in policy documents. That means discovering every AI app and account, classifying data inline before it leaves a session, requiring enterprise tenants for sanctioned tools, and creating an audit record of each interaction and policy decision that compliance can review under role-based access controls.
Which regulators are most focused on bank AI governance right now?
In the United States, the OCC, Federal Reserve, and FDIC apply existing third-party risk management guidance and model risk management expectations to AI tools. The FFIEC has issued supplemental guidance emphasizing explainability and audit trails for AI-assisted decisions. Internationally, the EU AI Act imposes binding obligations on high-risk AI use in financial services, including human oversight, transparency, and documentation requirements that map directly to the controls in this article.
Why is an acceptable-use policy not enough for a bank?
An acceptable-use policy cannot see or stop the moment an employee pastes confidential data into a tool. ISACA reports that most organizations lack a comprehensive AI policy, and even those that have one often cannot enforce or audit it. Real-time inspection at the interaction layer converts the policy into an enforced control and creates the evidence trail examiners request.
What evidence should compliance retain for AI-assisted decisions?
Compliance should retain records that show who used AI, which account or tenant was active, what data was shared with the tool, what the tool returned, and what policy control applied. Aurascape creates interaction records at that granularity, governed by role-based access control for privacy, so compliance and model risk officers can respond to examiner requests without reconstructing them from network or API logs.
How does Microsoft Copilot rollout differ from other AI tools for a bank?
Microsoft 365 Copilot connects to SharePoint, Teams, and email, so it inherits whatever oversharing already exists in the Microsoft 365 environment. Before rollout, a bank should identify what data the Copilot environment can reach, remediate overshared content, and confirm tenant controls are in place. Aurascape helps with pre-rollout assessment and ongoing monitoring of Copilot interactions once the tool is live.
How does this support model risk management requirements?
Bank examiners increasingly expect validation, ongoing monitoring, and documentation of AI use cases alongside quantitative model governance. Aurascape may support evidence for model risk management by capturing interaction-level records of each AI session and the policy controls that were active. This gives model risk officers a basis for ongoing monitoring, framed as a capability rather than a compliance guarantee.
Do these controls cover coding assistants like GitHub Copilot?
Yes. Aurascape decodes IDE and command-line coding assistant traffic and applies the same inline data classification and policy actions it applies to chat interfaces. Proprietary source code, API keys, and secrets get inspected before they leave the session, and each interaction creates an audit record equivalent to a chat session.
How does delegated governance work without losing central control?
Business-unit compliance owners use Auri to see usage and administer scoped, context-specific policies in natural language, while central compliance and an executive risk owner keep global oversight and RBAC controls on the interaction record. This distributes policy administration without creating separate systems of record or losing the single audit trail examiners expect.
Aurascape gives banks an enforcement layer for employee AI use: discovery across covered network, endpoint, and API paths, inline data classification for ChatGPT, Copilot, and coding assistants, tenant enforcement at the interaction moment, and interaction records that can help produce examiner evidence. Bank AI governance starts with rules. It gets stronger when those rules are enforced during use and backed by auditable records.
See how Aurascape governs employee AI tools across your bank →
Aurascape Solutions
- Discover and monitor AI Get a clear picture of all AI activity.
- Safeguard AI use Secure data and compliancy in AI usage.
- Secure Agentic AI Secure how your teams use AI and build AI agents.
- Copilot readiness Prepare for and monitor AI Copilot use.
- Coding assistant guardrails Accelerate development, safely.
- Frictionless AI security Keep users and admins moving.
- AI Governance & Compliance Move from AI policy to enforceable governance.