What Financial Services Firms Should Never Enter Into AI Tools

Wednesday June 10, 2026

Introduction

Artificial intelligence (AI) is increasingly becoming part of everyday work across financial services firms.

Teams are using AI to improve written communication, summarise meetings, assist with research and reduce administrative workload.

In many firms, adoption has already begun informally.

Staff may be experimenting with AI tools to improve productivity, often with positive intent and without introducing formal governance.

The issue is rarely whether AI should be used.

For most organisations, some level of use is already occurring.

The more important question is:

What information should never be entered into AI tools?

For financial services firms, this matters more than in many other industries.

Client confidentiality, privacy obligations and regulated operational environments create a higher expectation around how sensitive information is handled.

The objective is not to prohibit AI.

The objective is to ensure staff can benefit from productivity improvements without unintentionally creating confidentiality, privacy or governance risks.

Why This Matters More in Financial Services

Financial services firms routinely manage highly sensitive information.

This often includes:

  • personally identifiable information
  • financial account details
  • superannuation and investment information
  • Statements of Advice (SOAs)
  • commercially sensitive discussions
  • confidential client circumstances

Unlike many industries, advisory environments operate close to financial decision-making, regulated obligations and long-term client trust.

Because of this, information entered into AI tools requires greater consideration.

Even where staff are simply attempting to work more efficiently, inappropriate handling of information may introduce:

  • confidentiality concerns
  • privacy obligations
  • regulatory risk
  • cyber insurance considerations
  • client trust issues

In most cases, the risk is not deliberate misuse.

It is uncertainty around what is and is not appropriate to enter into AI systems.

Understanding the Difference Between Public and Business AI Environments

Not all AI environments operate in the same way.

One of the most important distinctions for financial services firms is the difference between public AI tools and business-managed AI environments.

Public or consumer-grade AI tools are often designed for general use.

Depending on the platform and settings, organisations may have limited visibility into:

  • how information is handled
  • data retention practices
  • administrative oversight
  • organisational governance controls

Business-managed AI environments are typically designed to operate within structured organisational settings.

Depending on the environment, this may provide:

  • greater administrative oversight
  • user access controls
  • alignment with organisational security settings
  • more structured governance

For leadership teams, the issue is often not whether staff are using AI.

It is whether staff understand which environments are appropriate for business use.

Without clear guidance, teams may default to whichever tools are easiest to access.

This can create unnecessary confidentiality and governance risk.

1. Client Identifiable Information

As a general principle, identifiable client information should not be entered into public or unapproved AI tools.

This commonly includes:

  • client names
  • dates of birth
  • addresses
  • phone numbers
  • email addresses
  • account numbers
  • Tax File Numbers (TFNs)
  • personally identifiable information (PII)

Even where AI is being used for harmless productivity purposes, identifiable information should generally be removed or anonymised.

For example, rather than entering:

“Please rewrite this client summary for John Smith, aged 61, who is preparing for retirement.”

A safer approach may be:

“Please improve the structure and clarity of this retirement planning summary for a pre-retirement client.”

The objective is not to limit efficiency.

It is to ensure confidential information remains protected while still allowing staff to benefit from AI assistance.

2. Financial Account Information

Financial account information should generally not be entered into public or unapproved AI tools.

Even where the objective is simply to summarise information or improve documentation, financial details can introduce unnecessary confidentiality and privacy risk.

This may include:

  • bank account information
  • investment account numbers
  • superannuation account details
  • portfolio balances
  • asset allocations
  • cash flow details
  • financial position summaries linked to identifiable individuals

While information may seem harmless in isolation, multiple pieces of financial data combined can create a detailed picture of a client’s circumstances.

Where AI assistance is required, information should generally be anonymised and simplified.

For example, rather than entering:

“Please summarise this client portfolio containing $2.1 million across super, managed funds and cash investments.”

A safer approach may be:

“Please improve the wording and structure of this diversified investment portfolio summary for a high-net-worth client.”

The objective is to separate productivity assistance from identifiable financial information wherever possible.

3. Statements of Advice (SOAs) and Advice Documentation

Statements of Advice and related financial documentation require particular care.

These documents often contain:

  • identifiable client information
  • detailed financial circumstances
  • personal objectives
  • risk profiles
  • investment recommendations
  • regulated advice considerations

For this reason, firms should carefully consider whether identifiable advice documentation is appropriate for use within public or unapproved AI environments.

This does not necessarily mean AI cannot assist with documentation.

In many firms, AI may still support productivity by helping to:

  • improve writing clarity
  • refine document structure
  • simplify internal communication
  • assist with formatting or summarisation

However, outputs should generally remain subject to:

  • human review
  • compliance oversight where appropriate
  • professional judgement
  • internal approval processes

AI should support professional advice processes — not replace them.

Professional accountability remains central within regulated advisory environments.

4. Confidential Client Circumstances

Some of the most sensitive information managed by financial services firms relates to a client’s personal circumstances.

This information may not always appear financially sensitive at first glance, but can often involve highly confidential or personal matters.

This may include:

  • family disputes
  • relationship breakdowns
  • estate planning matters
  • health-related financial considerations
  • business ownership disputes
  • personal hardship circumstances
  • succession planning issues

Even where names are removed, leadership teams should encourage staff to exercise caution when entering highly personal client matters into AI systems.

In financial advisory environments, confidentiality extends beyond financial data alone.

Client trust often depends on discretion around deeply personal circumstances.

The practical question firms should ask is:

Would we be comfortable explaining to a client how this information was being used?

If the answer feels uncertain, a more cautious approach is generally appropriate.

5. Internal Compliance, Risk or Sensitive Business Matters

Financial services firms should also exercise caution when entering internal business information into AI tools.

Some of the most commercially sensitive information within a firm may relate to internal compliance, governance or operational matters.

This may include:

  • compliance investigations
  • breach discussions
  • internal audit findings
  • client complaints
  • risk assessments
  • remediation activities
  • commercially sensitive business strategy
  • staff performance or employment matters

While these discussions may not involve client financial information directly, they can still introduce confidentiality and governance concerns.

Leadership teams should ensure staff understand that AI tools are not necessarily appropriate environments for sensitive internal matters without clear organisational guidance.

The question is not simply whether information appears confidential.

It is whether the information would be considered sensitive if disclosed outside the business.

Practical Alternatives for Safe AI Use

None of this means financial services firms should avoid AI entirely.

In practice, many organisations can benefit significantly from AI when used thoughtfully and within clear boundaries.

Practical safeguards often include:

  • removing identifying client information before using AI
  • using generic scenarios instead of real client details
  • providing staff with practical guidance on appropriate use
  • using approved organisational AI environments where appropriate
  • requiring human review of AI-generated outputs
  • maintaining professional judgement and compliance oversight

For example, rather than asking AI to review an identifiable client recommendation, staff may instead ask for assistance improving structure, readability or general wording using anonymised examples.

The objective is to separate productivity assistance from confidential information wherever possible.

Used appropriately, AI can support operational efficiency without compromising privacy, governance or client trust.

The Reality: Staff Are Probably Already Using AI

For many leadership teams, one of the most important realities is this:

AI adoption often begins before formal governance exists.

In many firms, staff are already experimenting with AI to:

  • rewrite emails
  • improve written communication
  • summarise meetings
  • draft internal documentation
  • research unfamiliar topics
  • improve efficiency in repetitive tasks

In most cases, this occurs with positive intent.

Staff are attempting to save time and improve productivity.

The governance risk emerges when leadership assumes AI is not being used — when in reality, informal adoption has already begun.

For many financial services firms, the practical first step is not prohibition.

It is introducing clear, proportionate guidance around what information should never be entered into AI systems.

This creates consistency, visibility and accountability while still supporting operational efficiency.

Leadership Perspective

For leadership teams within financial services firms, the objective is rarely to stop staff using AI.

The productivity opportunity is increasingly difficult to ignore.

The more important consideration is ensuring AI use occurs within practical and governed boundaries.

Clear guidance around confidential information, approved environments and professional oversight helps firms reduce unnecessary risk while still benefiting from efficiency gains.

The strongest environments are rarely those that prohibit AI entirely.

They are typically the organisations that recognise AI is already becoming part of modern work and introduce practical safeguards to support responsible use.

Technology should support client relationships, operational accountability and professional trust — not undermine them.

If you’re unsure how this applies to your environment, we’re happy to walk you through it.

If useful, you can see how we approach IT support and cybersecurity specifically for financial services firms here: → IT & Cybersecurity Services for Financial Services Firms

Related Financial Services Technology Guidance

You may also find these related guides helpful:

About this guidance

This guidance is based on MSP Blueshift’s experience supporting organisations where technology plays a critical role in day-to-day operations.

We work closely with Financial Services businesses, where performance, large file access, and collaboration across teams require a structured and well-managed approach to technology.

Our focus is on ensuring technology environments remain stable, secure, and aligned with how the business operates — while continuously evolving through structured improvement, automation, and the practical application of emerging technologies such as AI.

Get in touch
MSP Blueshift team meeting