Risk
Somewhere at your firm, someone is pasting a client's holdings into a chatbot. They do not think of it as a data transfer. Their compliance officer would.
Not maliciously, and probably not by you. An advisor is preparing for a review, wants help turning performance figures into a paragraph a client will read, and pastes the numbers into a chatbot. Or a paraplanner drafts a summary of a client's situation to get help structuring it. Or someone uploads a statement to have a table extracted.
None of these people think of themselves as transferring client data to a third party. Every one of them just did.
The instinct is to ban it. Bans fail here for a specific reason: the tools are genuinely useful, the usage is invisible, and the person using them is under time pressure and getting a real benefit. A prohibition that cannot be observed and removes something valuable produces quieter usage, not less of it.
The second instinct is a policy document nobody reads. That satisfies a checklist and changes nothing.
For a fiduciary the issue is not that AI was used. It is whether client information left the firm's control, where it went, and whether you could describe that to an examiner or a client.
| Question | Why it matters |
|---|---|
| Did identifying information leave? | Names, account numbers, balances tied to a person. Aggregate or stripped data is a different conversation. |
| Under whose terms? | Consumer tools and enterprise agreements differ substantially on retention and training. |
| Is it retained, and for how long? | The answer determines whether this was a transfer or a disclosure. |
| Could you reconstruct what was sent? | If not, you cannot answer the question when it is asked. |
Individual advisors pasting into chatbots is the retail version. The wholesale version is quieter: every vendor in your stack is adding AI to their own slice, inside their own walls, under their own terms.
Five vendors means five sets of terms governing what happens to your client data when it passes through a model — five retention policies, five security postures, five answers you have never read. And you are the fiduciary who answers for all five.
This is not a solved problem for anyone, including vendors. What distinguishes a defensible position is not certainty — it is being able to describe where your client data goes, under what terms, and who decided. Most firms cannot currently do that for their existing stack, which is a more immediate exposure than anything a chatbot has caused.
Questions this did not answer? Ask them directly — that is what the twenty minutes is for.
Book 20 minutes with Kyle