Insight

Which AI tools a regulated practice can defend, and which it cannot

Where the data goes, what your obligations actually say, and the evidence trail you need if a regulator or a client asks.

What you will learn

  1. When a regulated firm can use a public AI model at all.
  2. Which five questions decide whether a tool is defensible.
  3. Why a vendor demonstration answers none of those questions.

Can a regulated firm use a public AI model at all?

Sometimes, and the answer turns on what leaves the building rather than on which model it is. Five questions decide it: where the prompt goes, whether it is retained, whether it trains anything, what the engagement letter already says about third parties, and whether you could show a regulator the trail twelve months later. A tool demonstration answers none of those, which is why the conversation in most partnerships stalls immediately after the demonstration and never restarts.

More common questions

Can a regulated firm use a public AI model at all?

Sometimes. The answer turns on what leaves the building: where the prompt goes, whether it is retained, whether it trains anything, what the engagement letter already says about third parties, and whether you could show a regulator the trail twelve months later.

Is a tool demo enough to decide?

No. A demonstration shows capability. Partners need destination, retention, training use, contractual cover and an evidence trail. Without those, the conversation stalls after the demo for good reason.

Should every workflow wait for a perfect policy?

Clear what you can clear, decline what you cannot defend, and write the trail as you go. Waiting for a perfect policy while staff use public tools unofficially is the higher risk.

Written for