Financial Advisors: Stop Putting Client Data in Public AI

Every client detail a financial advisor pastes into public AI leaves their control. Here's the real risk, and the private alternative.

Kanoa Perman - Chief of StaffKanoa Perman - Chief of Staff
Financial Advisors: Stop Putting Client Data in Public AI

You've got twelve minutes between meetings. So you paste a client's allocation into ChatGPT to draft the rebalancing memo, or their family situation to rough out an estate note.

I get why. It's fast, and the memo reads fine. But AI for financial advisors has quietly split into two different things, and the version most advisors use every day has a problem nobody prices in: you're feeding someone else's machine with someone else's money.

TL;DR

  • Anything you paste into a public AI leaves your control the moment you hit enter. Unless you've changed the settings, consumer tools can retain it and learn from it.
  • Stripping the name off a client's details doesn't anonymize them. Net worth, family structure, and a timeline is often enough to identify someone.
  • Even with privacy solved, a general model can't hold your practice. It resets every session and writes memos that could belong to any advisor in the country.
  • The alternative is a private model trained on your process and your voice, never on client records, that you own and can delete at any time.

Where the prompt actually goes

Start with the mechanics, because they're worse than most advisors assume.

A public AI tool is not your CRM. There's no vendor agreement built around your obligations, no expectation of confidentiality that survives contact with the terms of service. Unless you've dug into the settings and opted out, what you type can be retained and used to train what the company builds next. The prompt doesn't get shredded after it answers you. It gets kept.

Now think about what's actually in your prompts. Account values. Concentrated positions. A divorce in progress. A beneficiary change that needs to happen quietly before a family conversation does. Your clients trust you with the most sensitive numbers in their lives, and those numbers are now sitting in infrastructure you can't audit, can't govern, and can't pull back.

Here's a test that takes ten seconds: would you be comfortable reading that prompt aloud with the client on the line? Most of the prompts I've seen advisors send would fail it, even the "anonymized" ones. Take the name off a client with a $4.2M concentrated position, three kids, and a pending divorce, and you haven't anonymized anyone. Specific details are the whole reason the prompt is useful, and specific details are exactly what makes a person findable.

You're held to a professional standard that was written long before chat windows that remember. "The tool was convenient" is not a defense you ever want to need.

The problem that stays even if privacy gets solved

Here's the part that gets less airtime. Suppose the retention issue vanished tomorrow. A general model would still be the wrong tool for a practice like yours.

It was trained on millions of portfolios and millions of writers, optimized to produce the answer that works reasonably well for most people. That's not a flaw. It's the design. But your value to clients is precisely the stuff that isn't average: that you know this client's risk tolerance shifted after the divorce, that this family needs the estate conversation handled in a specific order, that your quarterly letters sound a particular way because you've written two hundred of them.

A general model knows none of that, and can't accumulate it. Every session starts from zero. So you re-explain the situation, again, and get back a memo that reads like it could have come from any advisor in the country. Competent, generic, and not you.

You end up in the worst trade available: real confidentiality risk, in exchange for output you rewrite anyway.

What I'd use instead

This is where I'll tell you what we're building at Uare.ai, and I'll keep it honest.

An Individual AI is a private model built on one person: you, the advisor. It gets trained on what's yours to give, your investment philosophy, your process documents, your past letters and commentary, the way you explain a down quarter to a nervous retiree. Not on client records. It drafts in your voice, briefs you before reviews, and remembers your practice from one session to the next, because unlike a public tool, yours is the only practice it exists for.

The data terms are the opposite of the public-AI bargain: encrypted, governed entirely by your rules, revocable at any time, and never used to train anyone else's model.

What it won't do: it's not a portfolio management system, it won't generate investment recommendations for your clients, and it doesn't replace your compliance tooling or your custodian. It handles the layer around your judgment, the drafting, the prep, the recall, not the judgment itself. That part stays yours, which is the entire point.

And to be clear about how it gets built: Voice Capture is just the free front door, a few minutes of reading aloud so it starts from how you sound. The model actually takes shape from the material you feed it afterward, the documents and writing from years of practice, and from the conversations it keeps having with you, each one compounding on the last. Give it a month and it crosses the line that matters: it stops knowing what you sound like and starts knowing how you think.

The experiment worth running

Don't evaluate this on my say-so. Run the before-and-after.

Ask a brand-new Individual AI to draft a market-volatility letter and you'll get something clean and forgettable. Then upload a few pieces of your own work, two past client letters, your investment philosophy doc, a piece of commentary you're proud of, and ask for the same letter again. The second draft is the argument. It should open the way you open, reason the way you reason, and sound like something you'd actually sign.

Every client detail stays out of it, and everything you do upload stays on fixed terms: full control over your data, delete all of it at any time, never used to train public models.

That's the difference between borrowing intelligence and owning it. We call the owned kind Authentic Intelligence, and it's easier to recognize than to describe: it's the first AI draft you've read that didn't need to be told who you are.

FAQ

Is pasting client details into public AI really that risky, or is this overblown?

The risk isn't your intent, it's where the words go. Client holdings, net worth, and family circumstances are exactly the identifiable, sensitive details a public tool has no obligation to protect the way you do. Once they're in the prompt, you no longer control where they live.

Isn't it enough to remove names before pasting?

Usually not. A handful of specific details, position size, family structure, timing, can make a client identifiable without a name. De-identification is much harder than deleting one field.

What happens to my data on Uare.ai?

It trains your Individual AI and nothing else. Encrypted, governed by your rules, deletable at any time, and never used to train public models.

Does getting started cost anything?

No. Voice Capture is free on every Membership tier, and you can test the before-and-after with your own documents before deciding anything.

By Kanoa Perman, Chief of Staff at Uare.ai.

Uare.ai

Build your Individual AI.

Become a Member