The AI Briefing

RegTech expert Tom reveals critical risks of using AI tools in regulated environments. Learn why uploading company data to ChatGPT or Claude could breach confidentiality agreements and what solutions exist for FinTech and HealthTech companies.

AI Data Ownership in Regulated Environments

Key Topics Covered
The Data Ownership Problem
  • Why uploading company data to consumer AI tools is risky
  • How confidentiality agreements and customer contracts are impacted
  • What happens to your data when you use AI vendors
  • The model training issue: vendors using your data to improve their products
Three Solutions for Safe AI Use
1. Read Your Contracts Carefully
  • Understanding vendor terms and conditions
  • Identifying data ownership clauses
  • Recognizing training rights in agreements
2. Disable Data Training Features
  • Finding the opt-out switches in AI platforms
  • Limitations of relying on vendor settings
  • Internal compliance challenges
3. Use Enterprise-Grade Solutions
  • Microsoft Foundry
  • AWS Bedrock
  • GCP Vertex
  • Databricks
  • Benefits of constrained environments
  • Maintaining control over model training
Regulated Industries Affected
  • FinTech
  • HealthTech
  • Any organization with confidentiality agreements
  • Companies subject to data protection regulations
Action Items
  • Audit current AI tool usage in your organization
  • Review vendor agreements for data ownership clauses
  • Establish AI usage policies and procedures
  • Evaluate enterprise AI platforms for your needs
  • Train employees on safe AI practices
Host
Tom - RegTech specialist focusing on AI and digital transformation in regulated environments
Chapters
  • 0:02 - Introduction: AI in Regulated Environments
  • 0:48 - The Data Ownership Problem
  • 1:47 - Why AI Vendors Train on Your Data
  • 2:18 - Solution 1: Read Your Contracts
  • 2:36 - Solution 2: Disable Training Features
  • 3:25 - Solution 3: Enterprise AI Platforms
  • 4:53 - Final Recommendations and Action Items

What is The AI Briefing?

The AI Briefing is your 5-minute daily intelligence report on AI in the workplace. Designed for busy corporate leaders, we distill the latest news, emerging agentic tools, and strategic insights into a quick, actionable briefing. No fluff, no jargon overload—just the AI knowledge you need to lead confidently in an automated world.

Today, I do a lot of work in

the RegTech field and helping

and advising companies when it comes to using

AI or digital transformation inside

of regulated environments,

FinTech, HealthTech, all those types of things.

One thing that I wanted to be able

to discuss with you today just briefly is

the use of AI inside of your organization

because there is a lot that we have

to think about when it comes to leveraging

AI on a regular basis, especially

when it comes to confidentiality agreements and who

owns the data.

Now, of course, when it comes to leveraging

AI models, everyone would like to be able

to think that they can just chuck a

spreadsheet full of company data

into your favorite chat GPT, clause, whatever,

and ask for a quick summary.

But as soon as you have done that,

if you don't have the right agreements in place,

you've suddenly breached a whole bunch of laws

and confidentiality clauses in

potentially many different customer contracts

because you've uploaded the data and

you no longer own the data.

It has gone to your favorite AI vendor

and at that point, you

basically own a copy of it because your

AI vendor now is going to train their

stuff from your model.

This is not new, of course,

for these vendors to be able to make

their money, they need more data.

And so depending on your agreements with

the AI vendor, you

will get different levels of confidentiality and

their commitment to not train off your data as an organization.

So what can you do about this?

Of course, there are many different things you

can do about this, but you have to

make sure that you have the right procedures

and policies in place.

One thing is when you're dealing with the

bigger vendors is making sure that you read

the contract properly because step

number one is read the contract.

Step number two can be like make sure

that if you're using a vendor but you

don't have a sort of global team

setup is to make sure that if there

is a switch to be able to switch

off vendors training off your data,

switch it off because last

time I checked, that was a pretty good

way of asking them to not do it

was by disabling it.

But of course, again,

you're still beholden to a vendor, that vendor

may or may not train off your data,

but also people inside your organization may not

switch and then you're still at risk of

capitulating to the

laws and regulations.

So the third option is using a framework

or a function that allows you to either

host a model or leverage a model that

is more under your direct control.

So when it comes to internal

use of LLMs, it may not be as

simple as signing up to anthropic

.com or chat GPT

and opening an account because what you might

want to be able to do is leverage

those models, but in a more constrained environment.

So we're talking about Microsoft

Foundry, AWS Bedrock, GCP Vortex,

and Databricks, for example.

If you're already a Databricks user, you can

leverage those models inside a Databricks and they're

not going to train the model

off your data because they're bringing the models

from external providers.

Of course, going back to what we were

saying the other day, you can, of course,

if you would so choose, then train models

off of your data so that it can

become more intelligent and answer more pertinent questions.

But that becomes something that you own and

a process that you manage.

And it is not an organization training

their own model off of your data for

no additional value to yourself.

And so, you know, if you're working in

regulated technology, just make sure before

you start uploading customer information to

your favorite AI model for a quick

summary, a quick check or any of that

type of stuff, just what happens to the

data that you upload, because

believe it or not, as soon as you

upload it, you may not own it.

So there we go.

A bit of food for thought, a bit

of something to do, a bit of homework

and go and check your own models and your agreements.

If you enjoyed this, I will be back

tomorrow with another AI briefing.

Thank you very much for joining me.

My name is Tom.

I will see you all soon.

Bye for now.