What Client Data Should Never Go Into AI: A Checklist for Advisory Firms

Somewhere in your firm this week, someone pasted a client's information into an AI chatbot to save themselves twenty minutes. They weren't being reckless. They were being helpful — cleaning up a meeting note, drafting an email, summarizing a statement. The tool gave them a good answer, and they moved on.

That moment is the one an examiner or a cyber insurer will eventually ask you about. Not "do you use AI?” everyone does now — but "what client data has left your control, and how do you know?" If the honest answer is "it depends on who you ask," you have a governance gap, not a technology problem.

The short answer: what client data should never go into AI

As a working rule, no material nonpublic client information should ever go into a public, consumer AI tool — one where you clicked "agree" on the terms and never signed anything. That includes client names tied to holdings, account numbers, Social Security numbers, balances, income, health or family details, login credentials, and anything covered by your books-and-records obligations. The reason is simple: with most consumer tools, you can't say where that data goes, whether it trains a model, or how you'd retrieve it if a regulator asked. Based on current public guidance, that uncertainty is the problem regulators and insurers care about, because safeguarding nonpublic personal information is an obligation regardless of which tool created the exposure.

The nuance most articles skip: the line isn't really about the *data* alone — it's about the *terms* attached to the tool holding it. The same client summary that's a problem in a free chatbot may be acceptable in an enterprise tool that contractually doesn't train on your inputs and keeps records you can produce. So, the checklist below is really two questions asked together: *what* is the data, and *where* is it going.

Why "just don't use AI" isn't the answer

Telling your team not to use AI is a policy that will be quietly ignored by lunchtime. The tools are too useful and too available. The firms that get in trouble aren't the ones using AI — they're the ones using it invisibly, with no line drawn and no record of where client data went. The goal isn't prohibition. It's to bring AI use back under the firm's umbrella: known tools, a clear data line, and evidence you can show. Policies that only live in a PDF nobody reads are aspirational. This checklist is meant to be operational.

The checklist: client data that should never go into a public AI tool

Print this. Put it next to the four governance questions your firm should be able to answer at any time — what AI are we using, what data is exposed, what controls exist, and what regulatory or business risk remains.* Every item below is a "what data is exposed" answer waiting to happen.

1. Direct client identifiers tied to anything financial. Full names paired with holdings, account numbers, Social Security or tax ID numbers, dates of birth, home addresses. A first name alone is low risk; a name next to a portfolio balance is nonpublic personal information.

2. Account and financial specifics. Balances, positions, transaction history, income, net worth, account numbers, statement screenshots. This is the core of what safeguarding rules are built to protect.

3. Credentials and access data. Passwords, MFA codes, custodian or portal logins, API keys, security-question answers. These never belong in any chatbot, enterprise or not a prompt is not a password manager.

4. Sensitive personal and family circumstances. Health conditions, disability, divorce, addiction, estate conflicts, a beneficiary nobody's supposed to know about. Planning conversations are full of this, and it's exactly the material that does the most damage if exposed.

5. Third-party and related-party data. Spouses, children, business partners, trustees, beneficiaries. These people never consented to your tool choices, which turns their data into a consent problem on top of a security one.

6. Anything that is — or becomes — a business record. Client communications, meeting summaries, and documentation supporting investment recommendations may be subject to SEC books-and-records retention requirements. If AI is used to generate or materially contribute to those records, firms should be able to retain and reproduce them as part of their compliance program.

7. Legal, privileged, or under-litigation material. Anything involving counsel, a complaint, an arbitration, or a regulatory inquiry. Putting it into an uncontrolled tool can undermine privilege and create discoverable copies you don't control.

8. Material nonpublic information, where it applies. If your firm ever touches MNPI, a public AI tool is one of the last places it should land. Treat this as a bright line.

If any item on this list is going *anywhere near* an AI tool at your firm today, that's not a reason to panic — it's the starting point of the one conversation worth having: where is the line, and who drew it?

What to do instead: draw the line once, then enforce it

You don't need a hundred-page policy. You need a short, real one and the tooling to back it.

Draw an exposure line and write it down. Sort client data into three buckets: never goes into any AI tool (credentials, SSNs, MNPI), only goes into approved enterprise tools with the right terms (names with financials, meeting notes), and safe for general tools (anonymized, aggregated, or already-public information). This is your "what data is exposed" answer, in writing.

Pick the approved tools and check their terms — not their marketing. Look for tools that contractually state they don't train on your inputs, that offer data-processing terms suited to regulated firms, and that let you retain records. Vendor security claims are the vendor's claims until you verify them; treat the contract as the source of truth, not the sales page.

Make the record automatic. If AI contributes to a client communication or an investment recommendation, the resulting records—and, where appropriate, the prompts and outputs used to create them—should be captured automatically as part of the workflow, not left to memory. That's how you answer an SEC examiner with confidence instead of scrambling to reconstruct what happened.

Train the team on the line, not on fear. People follow rules they understand. Ten minutes on "here's what never goes in, here's the tool that's approved, here's why" beats a policy memo nobody opens.

Revisit it quarterly. New tools appear, staff change, someone's assistant gets an AI feature overnight. A line drawn once and never revisited becomes aspirational again.

None of this reduces your risk to zero — nothing does. Done well, it reduces the realistic exposure paths that show up on an exam or a cyber insurance application, and it gives you evidence that what you say you do, you actually do.

Frequently asked questions

Does entering client data into ChatGPT violate Regulation S-P?

Not automatically. However, it can create the type of privacy and information security risk that Regulation S-P is intended to address. Whether a particular use complies depends on the firm's policies, the AI provider's contractual and technical safeguards, and how nonpublic personal information is handled. Firms should work with compliance counsel to evaluate those risks rather than assume any AI tool is automatically permissible. As a best practice, avoid entering nonpublic client information into consumer AI tools unless the firm has completed appropriate due diligence and approved the use under its AI governance program.

Can financial advisors use ChatGPT at all?

Yes — for the right tasks. Drafting general content, learning a concept, or working with anonymized information is very different from pasting a client's statement into a chat window. The question isn't whether advisors can use AI; it's which data goes into which tool.

Does the paid or enterprise version make it safe for client data?

A paid tier with enterprise terms — no training on your inputs, appropriate data-processing terms, record retention — is a materially different risk profile than the free version and may be appropriate for some client data. "Safe" is a conclusion you draw after reviewing the actual contract and your own controls, not a feature you buy. Read the terms; don't trust the tier name.

Do we have to tell clients we use AI?
Not necessarily. There is no blanket SEC requirement to disclose every use of AI. But if AI materially influences your advisory services, affects how client information is handled, or changes disclosures your clients rely on, your firm should evaluate whether additional disclosure is appropriate. The safest time to answer that question is during your AI governance review—not during an SEC examination.

What should our AI use policy actually say about client data?

At minimum: which tools are approved, the three-bucket data line above, who to ask when it's unclear, and how AI-touched records get retained. Short and enforced beats long and aspirational.

Bring your AI use back under the firm's umbrella

If you can't answer "what client data has gone into which AI tool" with confidence, you're not behind it, you're where most advisory firms are right now. The firms that will do well when an examiner or insurer asks are simply the ones who drew the line early and can prove it.

That's what our AI Governance Assessment is built to do: map what AI is actually in use across your firm, identify where client data is exposed, and give you a written line and a remediation path you can hand to an examiner or an underwriter. It answers the four governance questions before someone else asks them for you.

If AI has quietly become part of how your firm works — and it has — this is the conversation to have before it's the one you're forced into. Start with an AI Governance Assessment or take this short self-assessment quiz to see where you stand.