The institutional logic behind both decisions is worth naming directly: JPMorgan and Goldman did not wait for a regulator to tell them Claude was unavailable in Hong Kong. Their legal teams assessed the licensing terms and drew the line themselves . That is a different kind of enforcement — quieter, faster, and largely invisible to the employees who absorb it. The microsoft/new-copilot-studio-tech-guide approach — building enterprise AI access structures around internal governance rather than external mandate — is exactly the model major financial institutions are now running in parallel. The compliance infrastructure that financial firms built for data sovereignty is being repurposed for AI access control, and it moves at the speed of a legal memo, not a regulatory cycle.
Loading story