The situation
The compliance lead at a mid-sized MGA opens the annual vendor review from one of the federally regulated insurers it writes business for. This year there is a new block of questions: which AI tools do your staff use, how do you stop policyholder information from being entered into them, and how would you know if it happened. The cover note mentions the insurer's obligations under OSFI Guideline B-10.
A credit union operations manager hears something similar from a banking services partner. A wealth management firm's portfolio team has been drafting client letters in ChatGPT for a year. In each case the first question is the same: OSFI does not regulate us, so do these guidelines even apply?
What the rules actually say
Who B-10 and B-13 bind
Guideline B-10, finalized in April 2023 and effective May 1, 2024, and Guideline B-13, which OSFI announced would take effect on January 1, 2024, both apply to federally regulated financial institutions: banks, insurance companies, trust and loan companies, and foreign branches. A federal credit union continued under the Bank Act falls within that group. Most credit unions do not; they answer to a provincial regulator such as FSRA in Ontario or the AMF in Quebec. Wealth managers are registrants under provincial securities law, and MGAs are licensed provincially.
Neither guideline mentions artificial intelligence. B-13 does expect institutions to protect data throughout its life cycle, including data loss prevention controls for data in use (section 3.2.5), and to regularly test employees' awareness of cyber threats (section 3.1.7). A paragraph of client information typed into a chatbot is data in use.
How they reach you anyway
Through your federally regulated partners. B-10 defines a third-party arrangement broadly and names brokers (mortgage, insurance, deposit) and technology companies among its examples. The institution keeps accountability for risks arising from those arrangements, expects confidentiality protections to be spelled out in agreements, and must manage subcontracting risk. If your staff handle its customers or data, the AI tool your employee pastes that data into becomes part of its supply chain. That is why the questions arrive in vendor reviews and contract renewals.
Through provincial guidance built on the same model. FSRA's IT Risk Management Guidance, effective April 1, 2024, applies to every FSRA-regulated entity, including credit unions and insurance agencies. FSRA states that its practices are aligned with OSFI's Technology and Cyber Risk Management guideline. Its data management practice expects confidential data to be secure, and its outsourcing practice keeps accountability with the regulated entity. In Quebec, the AMF's Guideline for the Use of Artificial Intelligence takes effect May 1, 2027 and covers any use of AI systems by the institution, whether or not it involves client records.
Through securities guidance. For wealth managers, CSA Staff Notice 11-348 (December 2024) creates no new requirements, but says existing policies should account for AI risks and reminds registrants to protect the confidentiality of KYC and other client information.
What OSFI has said about employee AI use
The clearest statement is the OSFI-FCAC risk report of September 2024. It identifies employees using publicly accessible generative AI tools as a risk, points to controls such as monitoring, employee education, and preventing confidential data from being entered into prompts, and adds that institutions that do not use AI should still consider updating their frameworks. The report says it is not guidance. Partners read it anyway.
Why policies and bans fall short
A partner's questionnaire rarely stops at "do you have a policy". The follow-up asks how you know it is followed, and a signed acknowledgement is not evidence of what happened in a browser tab last Tuesday.
A ban has the opposite problem. Staff who find AI useful keep using it on personal accounts, where the firm has no record at all; LayerX found that 71% of generative AI connections use personal, non-corporate accounts (LayerX, 2025). As our piece on why banning ChatGPT does not work explains, the risk does not shrink, it goes dark. Traditional DLP tools also tend to watch files and email rather than the text typed into a prompt box, which is exactly the data in use that B-13 and FSRA describe.
What a practical control looks like
- Map what reaches you. List your federally regulated partners, read the AI and data clauses in those agreements, and note which provincial guidance applies to you. Confirm the result with your compliance advisor or counsel.
- Inventory actual AI use, including personal accounts, so your answers are grounded in fact.
- Write a short policy naming the sanctioned tools and the data that must never be entered into public ones: member and client identifiers, account and policy numbers, SINs, KYC files, and underwriting data. Our AI acceptable use policy generator is a starting point.
- Train, then test. Periodic awareness testing mirrors what B-13 expects of federal institutions.
- Control the point of entry, not just the network, so sensitive data is stopped before it is submitted.
- Define an incident path. Decide who assesses a disclosure, when a privacy breach assessment is triggered, and when a regulator or partner must be told (FSRA's guidance, for example, expects notice of a material IT risk incident normally within 72 hours).
- Keep evidence you can hand to a partner at the next vendor review.
Sanitized Ai is a browser extension built for steps 4, 5, and 7. When an employee pastes or uploads client or member information, financial data, or personal information into an AI assistant, it redacts or blocks the sensitive content before submission and explains in plain language what was flagged and why, so the training happens at the moment it matters. Once content is submitted to a public AI tool it cannot be recalled and becomes subject to the provider's terms, so catching it first is the point.
Administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) that never shows prompt content. That record can support a partner questionnaire or a regulator conversation as evidence of reasonable safeguards, though it does not guarantee any outcome. See how this fits financial services on our finance page, or read how the same evidence helps with cyber insurance renewals.