Skip to content
Skip to content

Building a culture of privacy: The precondition for AI in banks

Building a culture of privacy: The precondition for AI in banks

Building a culture of privacy: The precondition for AI in banks

Building a culture of privacy: The precondition for AI in banks

Headshot of Connor Hyatt

Connor Hyatt

Connor Hyatt

Share

Bank executives treat privacy as the brake on artificial intelligence, the function that says no after the technology committee has said yes. The sequence is backwards. A bank cannot run a model on personal data it cannot locate, or on a permitted use it cannot prove, so privacy decides whether the model runs at all.

To test that, we read the compliance ladder in the CFPB's own rule against the FDIC's count of institutions in each asset band. 1,198 insured bank charters sit in a band the rule has already dated for handing a named customer's personal data to an authorized third party, and 1,180 of them sit in bands the rule dates 2027 or later. The thesis follows: in a bank, a privacy culture is the precondition for artificial intelligence rather than a constraint on it.

The privacy rulebook already asks where the data sits and who may use it

The 2 questions a model puts to a bank are already the law's questions. Since 2001 the privacy rule has required a firm that obtains a customer list from a nonaffiliated financial institution, outside the rule's own exceptions, to pass that list on as limited by the opt out direction of each consumer on it. The permission travels with the data, field by field, not with the system that holds it.

The data rights rule asks the other half. It requires a bank to make a customer's data available on request, to the customer and to a third party the customer authorizes, in an electronic form both can use. The Fair Credit Reporting Act then prices data a bank holds but was not permitted to use: pulling a consumer report without a permissible purpose is itself the violation.

All 3 describe 1 capability, which we call permission lineage: the ability to say, for any field of personal data a bank holds, where that field physically sits, where it came from, and which uses the customer permitted. It is 1 step past data lineage, which traces the data and not the permissions attached to it.

Supervisors already price the absence in hundreds of millions and call it governance

What the missing capability costs is on the public record, in the regulators' own words. Across 8 announcements we enumerated from the OCC, the Federal Reserve Board and the CFPB, 2020 to 2024, 8 penalties at 5 institutions total $692.6 million, each either naming a failure in the governance, quality, accuracy, security or permitted use of customer or regulatory data, or citing a statute whose subject is that data.

The largest in the set we assembled is the $400 million the OCC assessed against 1 bank for deficiencies that include data governance, and the word in the order is governance, not breach. Nearly 4 years later the same bank paid $75 million more, because certain persistent weaknesses remained, in particular with regard to data, and the Federal Reserve added $60.6 million the same day for a combined $135.6 million.

The rest of the set reads the same way. Migrating significant technology operations to the public cloud without first assessing the risk cost 1 bank $80 million, and the order cites the Interagency Guidelines Establishing Information Security Standards. Another paid $28 million for breakdowns that included knowing its customer data was wrong for a year or more and shipping it to the credit bureaus anyway.

None of those findings is a breach in the newspaper sense. Each is a finding about ownership: who holds the field, who checked it, and who was permitted to use it, the register supervisors reach for when a bank has lost track of its own data.

The deadline in the data rights rule is a data location deadline, not a portal project

Banks are reading section 1033 as an interface to build. The rule's own text makes it a location and permission problem: no interface can serve a request the bank cannot trace to the fields a named customer owns. 18 institutions sit in the band the rule dates April 2026, and 14 of them reach that tier on the rule's own measurement, the ceiling on the number the date can bind.

The mass of the ladder sits later and lower. 142 more sit in the band dated April 2027, with 130 in that tier on the rule's own measurement. The middle of the market, 266 institutions, sits in the band dated April 2028, with 228 in that tier, and 457 of the smallest on the ladder sit in the band dated April 2030, with 402 in that tier.

Below $850 million in assets, 3,032 institutions carry no dated obligation on today's balance sheet, and that is not an exemption. The floor is the Small Business Administration size standard, and an institution that has held more than that at any point since January 2025 does not drop back out. Where the data sits is often not the bank's own system, which we treated in AI readiness in mid-market banks.

1,198 FDIC insured bank charters sit in an asset band the rule has already dated for handing a named customer's personal data to an authorized third party; 1,038 of them, 87 percent, fall in the bands the rule dates April 2028 to April 2030.

Source: Lunon analysis of 12 CFR 1033.121 (CFPB) and FDIC call report data read 2026-09-11, banded on each charter's latest reported total assets.

The regulator that used to force the question has stopped asking it

Every external clock that would have forced a bank to build permission lineage has been stopped, reopened or pushed back. The CFPB reopened the data rights rule itself in August 2025, asking whether the privacy and security picture it first drew for section 1033 still holds. It filed 29 public enforcement actions in 2023 and 28 in 2024, then 9 in 2025 and 0 in the first 8 months of 2026.

The retreat is on the agency's own record. In 2025 it closed about 40 percent of its pending investigations, dismissed or withdrew 19 actions, terminated or modified a pending order or issued a no action letter in 22. Europe moved its own date too: the high risk rules in Annex III now apply from December 2027.

None of the underlying obligations changed. The statute behind the data rights rule stands, the privacy rule is unchanged, and the penalties above are still the price of getting it wrong. What was removed is the forcing function, and without it only a culture keeps the work moving.

The supervisors ranked the data ahead of the technology, then left generative AI outside the rulebook

The Basel Committee put it in one line: many banks still lack quality data, which is a prerequisite for embarking on any digitalisation project. The same report assessed 31 of the world's largest banks, and 2 of 31 could satisfy their own supervisors on risk data, nearly a decade after the standard was published.

Its remedy is 2 things at once, and banks keep buying only the first. The Committee asks for a robust data governance framework the board owns, and for a culture of ownership and accountability for data quality across the organization, with named data owners, independent validation units and data quality indicators reported to the board.

Then the rulebook stepped back from the newest systems. In April 2026 the Federal Reserve, OCC and FDIC replaced the model risk guidance banks had worked to since 2011, and the revised guidance puts generative and agentic AI outside its scope, leaving the controls to a bank's own governance practices. The OCC's risk report names data privacy alongside explainability among the unique challenges of those systems.

That letter is expected to be most relevant to banking organizations above $30 billion in assets regulated by the Federal Reserve, while 1,127 of the 1,198 insured charters in a dated asset band report less than $30 billion of their own assets. Charters and banking organizations are different populations and we claim no equivalence. For most of the ladder the controls on AI over personal data are the bank's own to write.

Europe writes the same test into the conditions for deploying a credit model

Europe states the claim as law. A credit model is a high risk system by name in Annex III of the AI Act. Article 10 of the Act as adopted asks the 2 questions directly, requiring the data governance practices to cover the origin of the data and, for personal data, the original purpose of the collection. That is permission lineage written into the conditions for putting a credit model on the market.

The authority that enforces the privacy rule prices the same failure. The Irish regulator fined 1 bank €463,000 over breach notifications from a corrupted feed into the national credit register, which included accidental alterations of customers' own records, and €750,000 for failing the integrity and confidentiality principle in a banking app.

Its most recent bank decision, April 2026, turns on 3 data breaches at 1 contact center, in 2 of which the same bad actor made 51 calls, and in 1 of which staff missed the security procedure on at least 5 calls. The final fines of €277,500 came in €107,500 below the maximum the regulator proposed in its draft decision, because the bank acknowledged the flaws and moved quickly. Culture is a mitigating factor in writing.

Permission lineage is 3 facts about every field, and the filings name none of them

None of the 3 parts of permission lineage is a technology choice.

  • Location says where the field sits. For most banks the answer spans several systems and at least 1 outside provider, and no single owner can produce it on demand.

  • Provenance says where the field came from. Article 10 of the AI Act asks for exactly this, and the privacy rule has asked a version of it since 2001.

  • Permitted use says what the customer allowed. No system of record stores it: the permission was captured in a disclosure or an opt out at another moment in the relationship.

In the fiscal year 2025 annual reports of the 12 largest United States bank holding companies that file with the SEC, 10 of the 12 name the Gramm-Leach-Bliley Act, all but JPMorgan Chase and Charles Schwab; 4 name personal financial data rights, Wells Fargo, Goldman Sachs, U.S. Bancorp and PNC. Only 1, JPMorgan Chase, describes a privacy program. The 12 are JPMorgan Chase, Bank of America, Citigroup, Wells Fargo, Goldman Sachs, Morgan Stanley, U.S. Bancorp, PNC, Truist, Capital One, Bank of New York Mellon and Charles Schwab. The phrase chief privacy officer turns up in 68 annual report documents filed in that window, not 1 from these 12.

Data lineage appears in 4 annual reports filed between November 2025 and March 2026, none from a large United States bank. The single privacy program named there is described as training on confidentiality and security and on responding to unauthorized access. At another bank the section 1033 obligation appears in a list of recent rulemakings, 1 clause long and last, after fair lending and small business reporting.

Absence of a phrase is not absence of the function. It is absence of the disclosure, and the disclosure is what a board reads and signs. A bank that has built permission lineage has something to describe, and in these filings almost nobody describes it.

What happens before April 2028 turns on permission, not on which model a bank licenses

Nothing external will force this work. Every clock has been pushed out, the revised guidance has stepped back from the systems banks are actually buying, and the agency that wrote the data rights rule has reopened it. That leaves the answer inside the bank, with the people who hold the fields.

The banks that can say where a customer's data sits and which uses that customer permitted will put models on personal data while doing so is still an advantage. The rest will run pilots on data they cannot account for, and will reach April 2028 with an interface to build and no permission lineage to connect it to. Privacy was never the constraint on artificial intelligence in banking. It was the entry ticket.

Related posts

Related posts

Palantir alternatives

Best Palantir alternatives for mid-market companies in 2026

Best Palantir alternatives for mid-market companies in 2026

Eight Palantir alternatives for companies of 100 to 2,000 people and PE portfolios: what each one is, who it fits, what it publishes about price, and where it falls short.

Eight Palantir alternatives for companies of 100 to 2,000 people and PE portfolios: what each one is, who it fits, what it publishes about price, and where it falls short.

Diligence before IC

Commercial diligence before IC: What converges in 30 days and what never will

Commercial diligence before IC: What converges in 30 days and what never will

Sponsor buyers set their own decision window at about a month, so the work that matters before IC is classifying the thesis variables rather than collecting more of them.

Sponsor buyers set their own decision window at about a month, so the work that matters before IC is classifying the thesis variables rather than collecting more of them.

Thesis to execution

From investment thesis to execution: The variables to re-measure after close

From investment thesis to execution: The variables to re-measure after close

2 operating variables carry 93 percent of the unlevered gain in the current-cycle attribution of buyout value creation, yet after close the scoreboard becomes adjusted EBITDA.

2 operating variables carry 93 percent of the unlevered gain in the current-cycle attribution of buyout value creation, yet after close the scoreboard becomes adjusted EBITDA.

Start with the decision in front of you.

Tell us what your team needs to understand, evaluate, or deliver.