An adviser pastes meeting notes into ChatGPT and asks for a summary for the client file. The notes contain the client's name, her passport number, the household income and two account numbers. That same afternoon, a claims handler three desks away asks a chatbot for a careful rejection letter, with the medical details from the claim still in it. Both answers are there in seconds. By then the data has already left the firm.
Clients share their financial situation because they expect it to stay within the firm. That trust is the heart of the profession, and it is exactly what is at stake in a prompt like that. This article lays out the challenges, shows what works in practice, and ends with the question every regulated firm gets sooner or later: can you show you have this under control?
Few sectors stack this much sensitive data
An average advice file holds more sensitive data than the entire administration of many other businesses. Passport numbers and ID documents. Account numbers and transaction overviews. Income and tax data, mortgage and valuation files, policy and pension data. Claims add medical details, KYC files add the UBOs of corporate clients, accounting adds payslips and annual accounts.
AI makes the work with those files faster. A summary of a client meeting, a first draft of an advice report, a careful reply to a complaint: it is there in seconds. The same speed makes the work more vulnerable, because whatever is in a prompt has left the firm before anyone thought about it.
How often that happens has now been measured. In a global study by KPMG and the University of Melbourne covering 48,000 workers in 47 countries (Trust, Attitudes and Use of AI, 2025), 58 percent said they knowingly use AI for work, 48 percent said they sometimes put sensitive company data into public AI tools, and 57 percent said they keep their AI use hidden from their employer. Translate that to a firm of ten: almost half have put sensitive data into a public tool at some point, and more than half will not tell you about it.
Nobody means to, it happens in the rush
The problem is rarely bad intent. It is an adviser who wants to write up a meeting between two appointments and does not strip the identifying details first. If that happens in a free AI tool without a data processing agreement, it is a data breach. Even when it was an accident. What such an agreement covers, and why the free tiers rarely have one, is in our article on data processing agreements and AI tools.
The reflex is a ban. That feels safe, but moves the use to personal laptops and phones, where there is no view at all. That is how shadow AI takes hold, precisely where the data is most sensitive. Training helps, only: people know the rules and forget them on busy days. What remains is a policy on paper, with no view of the tools in use and no evidence for an audit.
People need help at the moment itself, in the text field, while they type. And the firm needs a view of what is actually running. Those two things together are the fix.
First, a view of which AI is running
Before you can do anything about behaviour, you need to know what is being used. Next to ChatGPT, a firm quickly collects AI meeting recorders, transcription tools and clever plug-ins nobody ever approved.
The BeeSensible dashboard shows which AI tools are in use across the firm and how often, scored against a catalog of more than 700 tools, each with a risk score. You decide per tool what is allowed. BeeSensible never decides for you, and never shows who uses a tool. Open a tool that has not been approved and a gentle notice appears, pointing to the approved alternative. Never blocking, people can always continue.
ChatGPT