Control over AI
Blog
Compliance and AI 9 min read

AI in financial services: control over client data, with evidence for your supervisor

Meeting notes full of account numbers end up in ChatGPT faster than any policy can catch. What that means for a regulated firm, and how to keep control without banning AI.

ChatGPT5
Can you summarise this client meeting note for the file?
Of course. Paste the note below and I'll turn it into a short summary.
ChatGPT can make mistakes. Check important info.

The example above is interactive. Click a highlighted value to see your action options.

Quick answer

Financial services firms handle passport numbers, account numbers, income, policy and pension data every day. If that data ends up in a free AI tool without a data processing agreement, it is a data breach, even when it was an accident. Financial supervisors look at sound business operations and the duty of care towards clients; careful handling of client data is part of both. Banning AI moves the use to personal devices. What works: a view of which AI tools are in use, a highlight while you type, documents cleaned before sharing, and aggregated counts as evidence for audits, DPIAs and supervisory questions.

01

Meeting notes with a passport number and IBAN end up in a prompt in the rush of a normal day, not out of malice

02

In a free AI tool without a data processing agreement, that is a data breach

03

Supervisors look at sound business operations and duty of care; careful handling of client data is a demonstrable part of both

04

A ban pushes AI use to personal devices; a view of the tools and help while typing work better

05

Counts of detections and how they were handled are your evidence for audits, DPIAs and supervisory questions

An adviser pastes meeting notes into ChatGPT and asks for a summary for the client file. The notes contain the client's name, her passport number, the household income and two account numbers. That same afternoon, a claims handler three desks away asks a chatbot for a careful rejection letter, with the medical details from the claim still in it. Both answers are there in seconds. By then the data has already left the firm.

Clients share their financial situation because they expect it to stay within the firm. That trust is the heart of the profession, and it is exactly what is at stake in a prompt like that. This article lays out the challenges, shows what works in practice, and ends with the question every regulated firm gets sooner or later: can you show you have this under control?

Few sectors stack this much sensitive data

An average advice file holds more sensitive data than the entire administration of many other businesses. Passport numbers and ID documents. Account numbers and transaction overviews. Income and tax data, mortgage and valuation files, policy and pension data. Claims add medical details, KYC files add the UBOs of corporate clients, accounting adds payslips and annual accounts.

AI makes the work with those files faster. A summary of a client meeting, a first draft of an advice report, a careful reply to a complaint: it is there in seconds. The same speed makes the work more vulnerable, because whatever is in a prompt has left the firm before anyone thought about it.

How often that happens has now been measured. In a global study by KPMG and the University of Melbourne covering 48,000 workers in 47 countries (Trust, Attitudes and Use of AI, 2025), 58 percent said they knowingly use AI for work, 48 percent said they sometimes put sensitive company data into public AI tools, and 57 percent said they keep their AI use hidden from their employer. Translate that to a firm of ten: almost half have put sensitive data into a public tool at some point, and more than half will not tell you about it.

Nobody means to, it happens in the rush

The problem is rarely bad intent. It is an adviser who wants to write up a meeting between two appointments and does not strip the identifying details first. If that happens in a free AI tool without a data processing agreement, it is a data breach. Even when it was an accident. What such an agreement covers, and why the free tiers rarely have one, is in our article on data processing agreements and AI tools.

The reflex is a ban. That feels safe, but moves the use to personal laptops and phones, where there is no view at all. That is how shadow AI takes hold, precisely where the data is most sensitive. Training helps, only: people know the rules and forget them on busy days. What remains is a policy on paper, with no view of the tools in use and no evidence for an audit.

People need help at the moment itself, in the text field, while they type. And the firm needs a view of what is actually running. Those two things together are the fix.

First, a view of which AI is running

Before you can do anything about behaviour, you need to know what is being used. Next to ChatGPT, a firm quickly collects AI meeting recorders, transcription tools and clever plug-ins nobody ever approved.

The BeeSensible dashboard shows which AI tools are in use across the firm and how often, scored against a catalog of more than 700 tools, each with a risk score. You decide per tool what is allowed. BeeSensible never decides for you, and never shows who uses a tool. Open a tool that has not been approved and a gentle notice appears, pointing to the approved alternative. Never blocking, people can always continue.

Search tool, vendor or categoryโ€ฆ
700+ tools
ChatGPT๐Ÿ‡บ๐Ÿ‡ธ
HighAllowed
Claude๐Ÿ‡บ๐Ÿ‡ธ
MediumAllowed
DeepSeek๐Ÿ‡จ๐Ÿ‡ณnew
CriticalNot allowed
Perplexity๐Ÿ‡บ๐Ÿ‡ธnew
MediumNo decision yet
Mistral๐Ÿ‡ซ๐Ÿ‡ท
LowNo decision yet
Midjourney๐Ÿ‡บ๐Ÿ‡ธ
MediumNo decision yet

Every tool, scored for risk

700+ AI tools, each scored Low to Critical, with nothing pre-approved or pre-blocked until someone decides.

More about AI Tools

For a regulated firm this is also the start of a register: per tool the vendor, the hosting, and a recorded decision. The AI Tools module keeps that register up to date continuously.

A highlight at the moment it matters

The second half of the fix sits in the text field itself. An adviser summarises a client meeting. The passport number and IBAN get a red highlight, the name and phone number a yellow one. The highlight appears while you type, like a spell-checker. The choice stays with the adviser: remove, replace with a realistic stand-in so the prompt still works, or mask with a label. Nothing is ever blocked. The example at the top of this page shows exactly that moment, and it works: click a highlighted value to see the actions.

The same happens in email and chat. The extension runs in Chrome and Edge, in 18 apps: ChatGPT, Claude, Gemini, Copilot, Perplexity, Gmail, Outlook, Slack, WhatsApp Web, LinkedIn and more. The desktop app also covers Outlook, ChatGPT, Claude and Copilot as native apps. How the highlight works and what happens to the text is on the Realtime Privacy page.

Across financial services the scene shifts, but the moment is always the same:

  • Mortgage and financial advice. Summarise an application or meeting notes without passport numbers and IBANs. Valuation reports and pension statements cleaned first, then shared.
  • Insurance and claims. Summarise a claim while the medical details get a highlight. Policy and account details visible before sending.
  • Accounting and payroll. IDs and salaries in payslips and annual accounts get a highlight. KYC and UBO files anonymised before they go into an AI tool.
  • Banking and wealth management. Transaction overviews highlighted in reporting prompts, client reports anonymised for analysis.

A claims handler summarising the claim of Aoife Walsh does not need to send her diagnosis and policy number along. The summary is no worse for it, the processing a lot smaller.

Files cleaned before they leave the firm

Not everything sensitive travels as typed text. An application file, valuation report or annual account moves as a PDF: forwarded to a colleague, shared with a lender, or pasted into an AI tool for a first pass. For that route, the desktop app or the browser opens the document itself. The sensitive fields are already ticked, you decide what gets blacked out and export a clean copy. Hidden document properties are stripped too, so nothing rides along in the file's metadata.

PreviewAnonymise (4)
The desktop app marks sensitive fields in a document for you to redact before you share it or paste it into AI.

Where that check runs is your choice: on the device, or on our servers in the EU. In both cases the document is not stored.

The evidence supervisors, the GDPR and the AI Act ask for

Back to the question this article started with: can you show you have this under control? For a financial services firm that question comes from three directions at once.

Financial supervision. Supervisors look at sound business operations and the duty of care towards clients, whether that is the FCA in the UK, the AFM in the Netherlands or another national authority. There is no separate supervisory stamp for AI. But careful handling of client data is unmistakably part of sound operations, and that is the measure BeeSensible makes demonstrable: there is a policy per tool, there is help at the moment of typing, and there are counts of what happens. BeeSensible does not solve your supervisory obligations. It makes one part of them concrete and showable.

GDPR. The accountability principle asks you to show appropriate measures. The highlight at the input moment supports data minimisation exactly where personal data is about to leave the firm. The aggregated counts of detections and how they were handled serve as evidence in an audit and a DPIA.

EU AI Act. AI literacy has been mandatory since February 2025 for everyone who works with AI, since the Digital Omnibus as an effort obligation. You need to be able to show what you do. Highlights at the moment of typing are a working way to put it into practice: the employee sees what is sensitive in every prompt and stays at the wheel. How the deadlines look after the omnibus is in the AI Act timeline.

The dashboard brings those three together. The accountability view translates the same observations into substantiation per framework and per measure.

See

Which AI tools are actually in use, how often, and at what risk. Every tool scored against a catalog of more than 700.

See the AI Tools module
Decide

Every tool's status is the organisation's own call: allowed, limited, not allowed. The risk score is advice, never a verdict.

Help

That decision shows up while someone works: a notice on the tool, a highlight while you type. Never a block.

See Realtime Privacy
Substantiate

The same observations become substantiation: aggregated figures per framework and per measure. Never the text, never one person.

Dashboard ยท Accountability GDPRNIS2AI Act
  • Register of AI services

    Vendor, hosting, and a decision per tool

    Substantiated
  • AI literacy

    Highlights at the moment of typing and figures on how they were handled

    Substantiated
  • Appropriate security

    Critical data highlighted and handled before sending

    Substantiated
  • Data breach procedure

    BeeSensible provides the early signal; reporting and follow-up remain your own process

    Not substantiated
One set of observations, usable as substantiation in every framework. BeeSensible supports compliance; it does not make you compliant by itself.

The groundwork fits the sector. A data processing agreement is signed with every customer and a product DPIA is available on request. Detection runs on the user's own device, or on ISO 27001 certified EU infrastructure. Typed text is never stored, and the dashboard never shows content and never one person.

Policy and training alone, or with help in the text field

The trade-off as it looks at most firms:

Policy and training aloneWith BeeSensible
The rules live in a documentThe signal lives in the text field, at the moment itself
No view of which AI tools are in useThe dashboard shows AI use per tool
A data breach surfaces after the factSensitive data is visible before sending
No evidence for the auditCounts of detections and what happened to them
A ban pushes AI to personal devicesNothing is blocked, the employee stays in control

Policy and training stay necessary. What gets added is the moment where both fail most often: the rush, right before sending. That is where the highlight appears, and where the adviser still gets it right. What employees should keep out of prompts altogether is in what not to share with AI.

For internal discussion, the financial services leaflet sums this story up on two pages. More sector context is on the finance teams page. And to see it on your own texts first: in a 20-minute demo we show the highlights on texts like the ones your firm writes.

FAQ

Common questions

Can a financial adviser paste client details into ChatGPT?

Not into a free or personal version. Client details are personal data, and often sensitive ones, such as passport numbers, income figures or medical details in a claim. Processing them in an AI tool requires a legal basis, data minimisation and a data processing agreement with the provider. In practice the task usually works without the identifying details, by removing or replacing them before the prompt is sent.

Is it a data breach when client data ends up in a free AI tool?

Yes. Without a processing agreement, personal data leaves the organisation with no agreements in place about what happens to it. That is a data breach, even when it was an accident. Depending on the risk to the people involved, it must be reported to your data protection authority, such as the ICO in the UK, and sometimes to the client.

What do financial supervisors expect from AI use?

Supervisors look at sound business operations and the duty of care towards clients, whether that is the FCA in the UK, the AFM in the Netherlands or another national authority. There is no separate supervisory stamp for AI. Careful handling of client data is part of sound operations, and when questions come you want to show which measures are in place and that they work. A policy on paper alone is a thin answer.

Should we ban AI at the firm?

A ban feels safe, but moves the use to personal laptops and phones, where nobody has any view of it. In a 2025 study by KPMG and the University of Melbourne, 57 percent of workers said they keep their AI use hidden from their employer. The durable route is to make safe use possible and to make the risk visible at the moment it appears.

How do we show an auditor or DPO that the measures work?

With counts instead of intentions. The BeeSensible dashboard shows, in aggregate, which AI tools are in use, how much sensitive data got a highlight and what happened to it. Never the text itself and never one person. Those counts work as evidence in an audit, a DPIA and conversations with a supervisor.

Does this work for mortgage files and annual accounts?

Yes, for PDF documents. You open an application file, valuation report or annual account in the desktop app or the browser first. The sensitive fields are already ticked, you decide what gets blacked out and export a clean copy. Hidden document properties are stripped too.

See how BeeSensible works

Detect sensitive data before it leaves your team, in any app, in real time.