How to Keep MNPI Out of Public AI Tools
Material non-public information in a public chatbot is a disclosure you cannot take back. Here is how MNPI actually leaks into AI tools, and the control stack that keeps it out.

Every firm that handles material non-public information has spent decades building walls around it. Restricted lists, information barriers, need-to-know access, trade surveillance. Then generative AI arrived, and the fastest way to leak MNPI became a text box that helpfully autocompletes.
Paste MNPI into a public AI tool and it has left your control. There is no recall button. Here is how that happens in practice at otherwise careful firms, and the controls that actually stop it.
Why a public chatbot is different
When MNPI leaks through a person, you know who knew what and when, and there is a framework for dealing with it. When it leaves through a public AI tool, you have handed it to a third party under terms most employees have never read. Depending on the plan, the input may be retained, reviewed, or used to train future models. Even on the best terms, the information now sits on infrastructure you do not control, and you cannot demonstrate it was contained.
For investment advisers, this is not an abstract worry. Section 204A of the Advisers Act requires written policies reasonably designed to prevent the misuse of material non-public information. A firm whose employees can paste deal terms into a consumer chatbot does not have those policies in practice, whatever the manual says. Broker-dealers face the same question through their supervisory obligations. And for anyone bound by an NDA or a confidentiality wall, the paste itself can be the breach, before anyone trades on anything.
There is also the question you will eventually be asked, by an examiner, a counterparty, or your own board: can you show that MNPI stayed inside the firm? With a public tool in the picture and no controls around it, the honest answer is no, and that answer is expensive.
How MNPI actually gets into AI tools
Nobody at a serious firm opens a chatbot and types out a takeover target on purpose. The leaks are side effects of ordinary work.
Meeting notes and AI notetakers. An AI notetaker joins a call where a live deal gets discussed, and the transcript now lives with whatever service runs the notetaker. Or an employee pastes raw notes from a board meeting into a chatbot and asks for a clean summary. The summary is excellent. The notes contained MNPI.
Email drafting. Ask a public tool to soften an email about a delayed earnings announcement or a pending restructuring, and you have disclosed the event in order to get the wording help.
Deal documents. A term sheet, a letter of intent, a purchase agreement pasted in for a summary or a clause comparison. Deal documents are dense with exactly the information that must not leave.
Diligence questions. The subtle one. An analyst asks a chatbot whether an acquisition at a given multiple in a named industry makes sense, or how a specific company might fund a large purchase. No document was pasted, but the question itself describes the deal. Prompts are disclosures too.
Spreadsheets and models. A cap table, a revenue model, a pipeline export pasted in for a formula fix or a sanity check. The employee is thinking about the formula. The tool now has the numbers, and the numbers are the story.
The control stack that actually works
One policy memo does not stop any of the paths above. A stack of controls does, and each layer covers the gaps in the one before it.
Data classification keyed to authorization. A GREEN, YELLOW, RED model that tells every employee which class of information can touch which tools. GREEN is public and low-risk material, fine for approved tools. YELLOW is internal and client material with conditions attached. RED is MNPI, privileged, and restricted material, which touches nothing the firm has not explicitly approved for exactly that purpose, and for many firms touches no AI tool at all. The classification has to be keyed to the obligation on the information, not the document type, because the same spreadsheet can be GREEN one week and RED the next once a deal goes live.
An approved-tools list with teeth. A short list of tools the firm has vetted, on the specific plans it vetted, with everything else clearly out of bounds. The plan matters as much as the vendor. An enterprise agreement with no-training commitments, retention controls, and audit logs is a different product from the consumer app with the same logo. This is also why a governed rollout of an enterprise tool, like a managed Claude deployment, beats a ban that pushes people onto personal accounts you cannot see.
Enterprise terms and hard limits for the workflows that touch MNPI. Some work should never reach a general-purpose chatbot on any plan: deal analysis, restricted-list material, anything inside an information barrier. For those workflows the rule is explicit: MNPI touches only the tools and workflows the firm has approved for exactly that purpose, on enterprise terms with retention, access controls, and audit logs to match, and nothing else. A handful of firms with extreme obligations go further and keep such work on infrastructure they run themselves. That option exists in the market, it is a heavy lift to operate, and most firms do not need it. What every firm needs is the written rule, enforced by configuration, so containment does not depend on anyone's judgment at six on a deadline night.
Training and certification. The classification only works if people can apply it in the moment. That means short, concrete training built on the actual leak paths above, and a signed certification so every employee has acknowledged the rules. In our experience the diligence-question example changes behavior more than any policy language, because most people genuinely do not realize a prompt can be a disclosure.
What to do if it already happened
Assume that at some point it will. An employee tells you, or you find it in a tool's admin logs. What matters then is the response.
Do not quietly delete the chat and move on. Document what was entered, when, into which tool, and on which plan, because the plan determines the retention and training terms that apply. Involve the compliance officer immediately, and counsel where the information was covered by an NDA or an information barrier. Check what the vendor's terms and settings actually let you do. Enterprise plans often support deletion requests, and some consumer tools now offer training opt-outs. Then treat the root cause: the employee usually was not reckless, they were missing a sanctioned way to do the task, and the durable fix is giving them one.
Handled this way, a single incident becomes evidence that your controls work: detection, escalation, documentation, remediation. Hidden, it becomes something much worse when it surfaces later.
Where to start
Start with the map, not the tools. Which of your workflows touch MNPI, which tools are actually in use today, and where do those two lists overlap? That gap analysis is the core of an AI readiness assessment, and it takes weeks, not months. From there the classification, the approved list, and the governance follow in a defensible order, with the controls only as heavy as the workflows genuinely need.
Key takeaways
- MNPI in a public AI tool has left your control, and there is no recall.
- The leaks are side effects of ordinary work: meeting notes, email drafts, deal documents, and diligence questions.
- A prompt can be a disclosure even when no document is pasted.
- The control stack: classification keyed to authorization, an approved-tools list by plan, enterprise terms, hard limits for RED workflows, and certification.
- If it happens, document and escalate. A hidden incident is far worse than a handled one.
Talk it through
Handling MNPI and rolling out AI at the same time? Start with a 45-minute call.