Let's begin with a hard truth, and it is not the one you are expecting. The problem with AI in a regulated firm is almost never the AI itself. It is a small setting, usually switched on by default, that quietly decides what happens to everything your team types into it. Your compliance officer often cannot tell you exactly why that setting worries them. But their instinct is correct, and this article is about why.
The Feature Nobody Reads
When you sign up to most AI tools, somewhere in the settings, and very often already ticked, there is a permission. It says something close to this: your conversations may be used to improve the model, and may be reviewed by a person in order to do so. Sometimes it is dressed up as "help make our AI better". Sometimes it is tucked into a data-retention clause that tells you how long your inputs are kept, and where. The wording changes. The effect does not. The things your people type, and the documents they paste, leave your control and become raw material for somebody else's product.
For most of the world, typing in recipes and holiday plans, this is harmless. For a firm that moves money through regulated rails, it is a very different matter.
Why Your Compliance Officer Is Right
Think about what actually gets typed into these tools once your team grows comfortable with them. A client's name sitting next to their account position. A transaction that has not settled yet. A question about a customer who happens to be under review. Material non-public information (MNPI) about a deal that has not been announced. None of it feels dramatic in the moment. It is just someone trying to get their work done a little faster.
But if that setting is on, you have now sent client data, and possibly MNPI, to a third party who may retain it, may train a model on it, and may have a human being read it. You did not vet where it is stored. You did not check which country it sits in. You cannot get it back. If your examiner asked you today to explain what client data has left your perimeter, and where it went, you could not answer them honestly.
That is the thing your compliance officer is smelling, even when they cannot put it into words. They are not being awkward for the sake of it. They are being right.
The Sentence Every Vendor Will Say
Here is where it gets slippery. You will raise this with a software provider, and they will settle you down with a sentence that sounds like an answer, "Our AI is enterprise-grade and fully compliant." Let's translate that, because it commits them to almost nothing.
"Enterprise-grade" is a tier of pricing. It is not a promise about your data. "Compliant" refers to their certifications, their processes, their building, and not to your use of their tool. A provider can be genuinely, honestly compliant as an organisation, while the way your team uses their product breaks three of your obligations before lunch.
This is the most important idea in the whole piece, so let's say it as plainly as it can be said. Compliance is not a feature of the vendor's product. It is a property of how you use it. You cannot buy it in a subscription. You either govern it, or you don't.
What Being Prepared Looks Like
The good news is the same as it always is. You do not need to be a technologist to get this right. You need to know your own firm, and you need to make a few deliberate decisions before anybody starts pasting client data into a chat box. In reality, it looks something like this.
Know what data you would feed it. Before a single tool is approved, decide which categories of information are allowed nowhere near it. Client personal data, account information, anything close to MNPI, anything your regulator would ask about. Write the list down. This is your refuse-list, and it is worth more than any feature comparison you will ever read.
Read the one setting that matters. In every tool your team already touches, find the data-use and retention setting. Know whether your inputs train the model, whether a person can review them, how long they are kept, and in which country. If you cannot find that out, that is itself your answer.
Keep a human in front of the wheel. The low-risk, defensible uses of AI in a regulated firm are almost always internal, and they always have a person checking the output before it does anything that matters. Rank your uses by their value inside the compliance perimeter, not by how new and clever they are.
Log the decision. When you approve a use, write down in a sentence why it is safe and what the guardrail is. That one paragraph is what you hand an examiner, instead of a shrug.
The Questions To Put To Your Vendor (And Your Own Team)
Being prepared means walking into the conversation already holding the right questions. Here are the ones that separate a straight answer from a sales answer. Ask them exactly like this, and ask for the replies in writing.
- "When my team types into your tool, is that input used to train or improve your models. Yes or no?"
- "Can a person at your company read what we type, and under what circumstances?"
- "How long is our data retained, and in which country is it stored?"
- "If we ask you to delete everything, what exactly gets deleted, and how would we verify that it is gone?"
- "What can your tool do on its own, without a person approving it first?"
A good provider answers these plainly. A provider who responds with more questions of their own, or who says the word "enterprise" three times and moves on, has just told you everything you needed to know.
Your End Result
Notice what we have not said. We have not told you to ban AI, and we have not told you to be afraid of it. Fear, uncertainty and doubt (FUD) is precisely the trap that makes regulated firms either freeze completely or overspend wildly, and neither of those serves you. AI, used on purpose and inside a boundary you have drawn deliberately, is genuinely useful and entirely defensible.
The firms that win are not the ones who refuse it out of fear, and they are certainly not the ones who paste client data into a free tool and hope for the best. They are the ones who decided, in advance, what was safe. That is the entire game. Decide what is safe before you use it, and not after your examiner asks.
If you have read this far and quietly realised that you do not actually know what that setting is doing inside the tools your team already uses, that is worth an hour of your time. The Clarity Audit is a paid, 60 to 90 minute working session, followed by a written diagnostic that tells you what is safe to adopt given your regulator, and what to refuse. If it turns out you are already in good shape, we will tell you that too.