I Found the Gap. I Built the Fix.

Scroll
JS Jessica Smith
About the Founder

Jessica SmithBuilder, Engineer, Operator.

  • 01AI Engineer and enterprise software developer with 10+ years of experience.
  • 02Built solutions for complex business problems across fintech, healthcare, and higher education.
  • 03Founder of FinTrail.
  • 04Based in Galena, Kansas.
Chapter One

The Problem.Quietly happening. Everywhere.

§ 01

Employees at banks and fintechs are using AI tools to do real work — reviewing loans, looking up accounts, handling sensitive customer data.

§ 02

Nobody is watching.

§ 03

An employee can paste a customer's Social Security Number into an AI prompt and there is no log, no audit trail, no way to prove what happened.

§ 04

When regulators ask "show me how AI was used" — most institutions have no answer.

The Data

The scale of the problem is not small.

Independent research across four studies — all pointing the same direction.

0%
of enterprise employees who use AI regularly paste company data into chatbot prompts.
LayerX Security Report · 2025
0%
of those copy-paste actions include PII or payment card data — SSNs, account details.
LayerX Security Report · 2025
0%
of sensitive data pasted into AI chatbots comes from unmanaged personal accounts.
LayerX Security Report · 2025
0%
of financial services professionals say colleagues use unapproved AI for customer communications.
Industry Research
Chapter Two

Is it illegal? Yes

§ GLBA Violation

The Gramm-Leach-Bliley Act

Requires financial institutions to strictly protect consumer data. Pasting a loan applicant's SSN or banking history into an unapproved AI chatbot — without consent or a secure enterprise agreement — is a direct federal privacy violation.

§ CFPB Mandate

The Consumer Financial Protection Bureau

Requires lenders to provide specific, accurate reasons for any credit denial. The CFPB has explicitly stated there is no special exemption for artificial intelligence. If a decision was influenced by unsanctioned AI with no audit log — the institution is legally indefensible.

§ Re-identification

"Anonymized" data is not safe

The combination of specific financial figures, dates, and locations can be re-identified — creating additional compliance exposure for the institution, even when employees believe they have scrubbed the data before pasting.

The Enforcement

Are they getting caught?

Immediate Termination

JPMorgan Chase, Bank of America, and Citigroup restricted or banned unauthorized AI platforms as early as 2023. Using these tools with sensitive client data is explicitly listed as a fireable offense.

Enforcement · Active

Legal Discovery — AI Prompts Are Evidence

If a bank is sued for discrimination, unfair lending, or a data breach, employee AI prompts become discoverable Electronic Stored Information. Courts can subpoena AI providers to access the full chat history. Shadow AI leaves a digital footprint lawyers will find.

Courts · Subpoenaed

Proactive IT Monitoring

Banks are deploying specialized network monitoring to detect, redact, or block sensitive information — SSNs, account numbers — from being pasted into AI chat windows in real time. Employees on personal devices and personal networks are increasingly caught during audits or discovery.

Deployment · Growing
The Fix

Introducing FinTrail.

FinTrail sits between the employee and the AI tool — and watches everything.

Sources & Further Reading

Thank you.

Name
Jessica Smith
Phone
417 · 499 · 7272
Email
nerdslovecoffee@gmail.com
LinkedIn
linkedin.com/in/nerdyjess