August 5, 2026 · 6 min read
Can financial advisors use ChatGPT with client data?
Short answer: yes, with the right account and the right habits — and most practices currently have neither. The long answer is worth five minutes, because the difference between “fine” and “a problem you can't undo” comes down to two decisions most practices never consciously made.
The question underneath the question
When an advisor asks “can I use ChatGPT?”, the real question is: where does what I type actually go?
Everything you paste into an AI chatbot leaves your office and is processed on the provider's servers. That alone isn't alarming — your email does the same. What matters is what the provider may do with it afterwards, and that depends almost entirely on which tier of account you're on.
On free consumer accounts, what you type may be used to improve the provider's models, depending on your settings — settings most people have never opened. On business tiers, providers generally commit that your data is excluded from training by default, and give an administrator controls to enforce it. The terms differ by provider and change over time, which is exactly why this should be a checked setting with a date on it, not an assumption.
So the first decision is simple, and it costs about thirty dollars a month: client work happens on business accounts, or it doesn't happen.
The second decision: what crosses the line
Even on a properly configured business account, some things should never enter an AI tool. In a Canadian or US practice, that list is short and absolute: SINs or SSNs, account numbers, dates of birth, banking details, government ID, health information — and client documents. Not summarized, not partially, not “just this once to save retyping.”
Almost everything else becomes workable once you strip identifiers first. Compare:
- “Here's Priya Raman's statement — draft her a note about her RRSP room.” Not acceptable, on any account, ever.
- “Draft a plain-language explanation of how unused RRSP room carries forward, for a client in her late fifties.” Fine — and the output is just as useful.
That habit — the sixty seconds it takes to replace a name with a role and round the numbers — is the single highest-value behaviour you can teach a team. The safe prompt almost always works as well as the risky one, which is why teams actually adopt it.
Why this matters more in your industry than most
A financial practice doesn't just hold personal information; it holds it under professional and regulatory obligations — and those obligations extend to the third parties you hand data to. A free chatbot account your office manager signed up for is, functionally, an unvetted service provider processing client information with no agreement, no record, and no one accountable.
The uncomfortable part: in most small practices, this is already happening. Someone helpful discovered that ChatGPT writes excellent follow-up emails, and nobody had ever told them where the line was — because nobody had drawn one.
What “doing it right” actually looks like
- Business-tier accounts, signed in with practice email, training-data sharing verified off — with the date you checked.
- A short written policy: the never-list, the strip-identifiers rule, and who to tell when something goes wrong.
- Ninety minutes of training, so the rules live in people's heads rather than a drawer.
- A person reviews anything AI-drafted before it reaches a client. AI writes drafts; humans send them.
None of that is exotic. It's an afternoon of configuration and a morning of training — which is why the practices that skip it aren't saving meaningful money, just deferring an awkward conversation to a worse moment.
If you want to know where your own practice stands, the two-minute AI Risk Scorecard will tell you honestly — and the one-page starter policy is free either way.
Wondering where your practice stands?
Eight questions, two minutes, an honest score — and a free one-page policy to start from.