Technology

Write the boundary,
not the tool list.

Almost every advisory firm now contains people using general AI tools, and a large share have no written position on it.

The gap between what firms allow and what people do

Almost every advisory firm now contains people using general-purpose artificial intelligence tools, and a large share of those firms have no written position on it. Not a permissive position — no position.

That is itself a policy, and it is the one that is hardest to defend, because it means the firm has not decided anything and cannot say what it expects.

Start with the boundary, not the tool

The instinct is to write a list of approved products. That list is stale in a quarter and it addresses the wrong question.

The durable framing is about data: what may leave the firm, in what form, to a service the firm does not control. Once that is decided, individual tools can be assessed against it as they appear, and the policy survives the next product launch.

A policy naming approved products expires. A policy defining what may leave the building does not.

The four categories worth defining

CategoryExampleTypical position
Public informationMarket commentary, general research, drafting Generally permitted
Firm-internal, non-clientProcess documents, job descriptions, training Permitted with firm-controlled tooling
Anonymised client contextA scenario with names and figures removed Permitted where genuinely anonymised, which is harder than it sounds
Identifiable client informationNames, balances, health, family circumstances Only in systems the firm has assessed and contracted with

Most firms find their real exposure is in the third row, because staff believe removing a name is sufficient anonymisation. An unusual balance, a named employer and a city frequently identify a person on their own.

Consumer tiers and enterprise tiers are not the same product

The same brand-name service often has very different terms depending on which tier is used — particularly around whether submitted content may be retained or used to improve the model. The difference is a settings page and a contract most users have never seen.

If your policy permits a tool, it must specify the tier, because permitting the name permits the weakest version of it.

What the policy should actually contain

The disclosure question

Whether and how to describe your use of these tools in client-facing documents is a judgement your chief compliance officer owns. What is not a judgement call is the underlying requirement that your disclosures and your actual practice agree with each other.

The examination question is not whether you use artificial intelligence. It is whether you can describe what you do, show it is what you said, and demonstrate that client information went only where you said it went.

What is already happening at most firms →

The one that decides the rest

How many boundaries does your firm actually have? Every separate vendor holding client data is another set of terms, another retention policy and another assessment to keep current.

Firms running one system have one boundary to defend. Firms running five have five, and in practice they have reviewed two.

Questions this did not answer? Ask them directly — that is what the twenty minutes is for.

Book 20 minutes with Kyle