Nearly seven in ten compliance professionals expect AI to be the most likely source of compliance problems this year.
If that concern sounds familiar, it is a reasonable one. It is also manageable.
Most of the worry comes down to two questions. Both have clear answers.
1. Client data and privacy
The concern: putting confidential client information into an AI tool means entering names, account numbers, Social Security numbers, or holdings into a system where you may not control how the data is stored or used.
That concern is valid, and the fix is straightforward:
Treat a public AI model the way you would treat a public website like Google. You would not type a client’s account number into a Google search box, so do not put it into a public AI tool.
The exception is a secured, firm-controlled environment, such as Microsoft 365 Business with enterprise data protection, where your data stays inside your own protected tenant and is not used to train outside models. In that setting, the rules are different.
When you are not in a secured environment, strip the specifics. You can ask a general planning or research question without attaching a client’s name or account number to it.
2. Hallucinations, or reliance on output that is wrong
The concern: AI can produce an answer that reads as polished and confident but contains a wrong figure, a misstated rule, or a citation to a source that does not exist.
Send that to a client, and you own it. Under the Marketing Rule, anything client-facing is a communication, regardless of who or what drafted it.
Optimal Insight
Neither concern is a reason to avoid AI. Both are reasons to use it with the discipline you already apply to your own work: review, source-check, document.
AI does not change the standard of care. It only changes who produces the first draft. Want more hands-on AI techniques? Sign up for The Optimal AdvisorAI Learning Center. Built for financial professionals.

