Compliance7 min read

AI and Banking Secrecy in France: Is It Safe?

An adviser pastes statements into an AI. Banking secrecy (art. L.511-33 CMF) protects that data. The fix: anonymise before the prompt.

By Pierre de ONYRI

Yes, a bank can use AI. But not by handing it the real identity and amounts of its clients. An adviser pastes a statement to prepare a file. They paste a client's situation to draft a summary. That data then leaves the bank. It travels to a third-party AI provider. Yet it is covered by banking secrecy. There is a clean method: anonymise before the prompt, then restore the values locally.

The problem: pasting a client statement into an AI

The move looks harmless. An adviser wants to save time. They copy an account statement into a consumer AI. They ask for an analysis, a summary, a letter. The prompt travels to an external server. It holds the client's name, transactions and balances. This information can be retained or reused to train the model. It is no longer under the bank's control.

A banking file concentrates highly identifying data. Here is what a poorly prepared prompt can expose.

  • The name and contact details of the account holder.
  • The account number, the IBAN and the banking references.
  • The real amounts: balances, income, instalments, overdrafts.
  • The dated transactions that reveal patterns of daily life.

The stake: banking secrecy protects this information

The legal basis is clear. Article L.511-33 of the French Monetary and Financial Code binds the directors and employees of credit institutions to professional secrecy. The information they hold about their clients is confidential. This is known as banking secrecy. It binds the institution and its staff.

This secrecy allows only limited exceptions set by law. It cannot be raised against the supervisory authority, the Banque de France or the courts in criminal matters. Some sharing stays allowed for specific operations, such as a transfer of receivables or a relationship with a counterparty. A third-party AI provider fits none of these cases. Passing client data to it, outside the cases set by law, exposes the institution to a breach of secrecy. Breaching professional secrecy is punishable by the criminal penalties set by law.

The GDPR adds to the secrecy duty. For a client's data, the bank acts as the data controller. The CNIL, France's data protection authority, is firm on this. AI enjoys no exemption. As soon as an AI system processes personal data, the regulation applies fully. Pasting an identifying statement into an external AI therefore combines two risks. A breach of banking secrecy. A GDPR compliance question.

Is AI banned in banking?

No. This is the most common objection, and the answer is clear. Neither banking secrecy nor the ACPR bans AI. The ACPR supervises banking and insurance and protects clients. Since 2018, it has run work on AI in finance. It centres on evaluating and governing algorithms. The spirit is supervision, not prohibition.

So the problem is not the tool. It is the transfer of identifying data to a third party. Separate the two, and AI becomes a useful assistant again.

AssumptionThe reality
“AI is banned in banking”Neither banking secrecy nor the ACPR bans it; the ACPR frames its governance
“Pasting a statement into AI stays internal”It is a transfer to a third party; banking secrecy (art. L.511-33 CMF) is at stake
“AI escapes the GDPR”The CNIL stresses the GDPR applies as soon as an AI processes personal data
“Anonymising loses the analysis”AI reasons on the shape of the file; the real identity and amounts are not needed
The risk isn't using AI — it's the identifying details left behind in the prompt.

The fix: anonymise before the prompt

AI does not need the real name to be useful. It does not need the real amounts either. It reasons on the shape of a situation, not on identity. The minimisation principle points the same way. The CNIL invites you to reach the intended result with as little personal data as possible. Among the levers it lists, it places anonymisation and pseudonymisation carried out upstream first.

Two-part diagram: at top, a bank statement card whose identity line and amount line are in the clear (amber) passes a padlock / vault-door glyph, then reaches an AI card with an amber alert; at bottom, the same statement minimised shows only cobalt tokens, and the AI receives only tokens with a checkmark.
After French banking secrecy (art. L.511-33 of the Monetary and Financial Code), the CNIL's AI and GDPR recommendations, and the ACPR's work on algorithm governance.

The method is simple to put in place. It reduces exposure and supports minimisation. It does not lift your duties: banking secrecy and the GDPR remain your responsibility. But it removes the real identity and amounts from the prompt.

  1. 1Spot the identifying elements: name, IBAN, account number, amounts.
  2. 2Replace them with reversible tokens, in the browser.
  3. 3Send only the anonymised text to the AI.
  4. 4Restore the real values in the reply, locally, on your own machine.

That's what ONYRI Sanitize is for. The engine detects sensitive data — name, IBAN, account number, amounts — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymised text reaches the model. The AI never sees your clients' identity or real balances. You keep AI's help, while reducing exposure under banking secrecy and the GDPR.

Frequently asked questions

AI and banking secrecy in France: is it safe?
Yes, but not by handing AI the real identity and amounts of clients. Pasting a statement into a consumer AI transfers information covered by banking secrecy (art. L.511-33 of the Monetary and Financial Code) to a third party. The bank also stays the data controller under the GDPR. The fix: anonymise the name, IBAN and amounts before any prompt, then restore the values locally.
Does the ACPR ban AI in banking?
No. The ACPR (the French prudential supervision and resolution authority) does not ban AI in finance. Since 2018, it has run work on AI centred on evaluating and governing algorithms, with principles of transparency, accountability, human oversight and data protection. It is a supervisory framework, not a prohibition.
Is anonymising enough to be GDPR-compliant?
No, on its own it is not enough. Anonymising before the prompt reduces exposure and supports minimisation, a principle the CNIL stresses. But it does not lift banking secrecy and does not make the institution automatically GDPR-compliant. It is a control measure, not a compliance verdict. Your other duties remain in full.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next