
A financial firm recently came to us excited about AI.
Employees were already experimenting with it to summarize documents, draft client communications, research information, organize meeting notes, and speed up administrative work.
From a productivity standpoint, there was a lot of potential.
Then we asked a different question:
What information are employees putting into these tools?
That changed the conversation.
Leadership knew employees were using AI. What they didn't know was which tools they were using, what information they were sharing with them, whether those tools had been approved, or how AI-generated work was being reviewed before it reached a client.
And that is where AI adoption can quickly become a cybersecurity and compliance issue for financial firms.
The challenge isn't whether your employees will use AI. Many already are.
The challenge is whether your firm is in control of how they use it.
FINRA's Message on AI Is Important
One misconception I hear is that because FINRA hasn't created an entirely separate rulebook for generative AI, firms can wait to develop AI governance.
That's not the case.
FINRA has made clear that its existing rules are technology neutral. In other words, using AI doesn't make your existing regulatory responsibilities disappear.
Depending on how your firm uses AI, existing requirements around supervision, communications, books and records, privacy, and other areas may still apply.
So, the question isn't simply:
"Are we allowed to use AI?"
A better question is:
"Can we use AI while continuing to meet our existing obligations?"
That's a much more useful conversation for leadership.
Risk #1: Your Employees May Be Sharing More Than They Realize
Imagine an employee needs help summarizing a lengthy client document.
They open a public AI tool, paste the document into the prompt, and ask for a summary.
Thirty seconds later, they have exactly what they needed.
But what else just happened?
Depending on the tool, account type, configuration, contractual terms, and information involved, that employee may have introduced sensitive business or client information into a system the firm has not evaluated or approved.
This is one of the reasons AI governance has to start with data governance.
Employees need clear guidance about what information can and cannot be entered into AI systems.
That may include:
- Personally identifiable information
- Client financial information
- Account information
- Internal financial data
- Confidential business information
- Proprietary research
- Credentials or authentication information
Telling employees to "be careful with AI" isn't a policy.
You need defined boundaries.
Risk #2: AI Can Create a Recordkeeping Problem
Here's another scenario.
An advisor uses AI to draft an email to a client. Another employee uses it to develop content for a presentation. Someone else uses an AI assistant to summarize a client conversation.
Now ask:
Which of those activities create business records your firm is required to retain?
AI doesn't eliminate recordkeeping obligations.
Financial firms already have requirements around preserving certain business communications and records. If AI becomes part of how those communications are created, reviewed, or delivered, firms need to determine how their existing retention and supervision requirements apply.
This becomes particularly important when employees start using AI tools outside the firm's approved technology environment.
If you don't know where business-related AI activity is happening, it becomes very difficult to govern it.
Risk #3: AI Can Be Confidently Wrong
Anyone who has spent time with generative AI knows how convincing an incorrect answer can sound.
That's manageable when you're asking AI where to go for lunch.
It's a much bigger problem when you're discussing financial information, regulations, client communications, or investment-related content.
AI should accelerate human expertise, not replace human judgment.
If an AI-generated answer influences something material, your firm needs to determine where human review belongs in that process.
The more consequential the decision, the more important that oversight becomes.
Risk #4: Shadow AI Is Becoming the New Shadow IT
Years ago, IT departments worried about employees downloading unauthorized software.
Today, the same problem is happening with AI.
An employee hears about a new AI tool on social media, creates an account, and starts using it for work.
No malicious intent.
They simply want to be more productive.
But now the organization may have business information flowing through a platform that IT, cybersecurity, and compliance don't even know exists.
That's Shadow AI.
And banning every AI tool isn't necessarily the answer. Employees will gravitate toward technology that makes their jobs easier.
The better strategy is to provide approved tools, clear policies, appropriate technical controls, and practical training.
Risk #5: Third-Party AI Still Creates Third-Party Risk
Many firms won't build their own AI systems.
They'll use AI features embedded into platforms they already rely on.
That's convenient, but it doesn't eliminate the need for due diligence.
Before enabling an AI solution, firms should understand questions such as:
What data can the AI access?
Where is that data processed and retained?
Is firm information used to train models?
What administrative controls are available?
Can access be restricted based on the employee's role?
Can activity be logged and monitored?
What happens to the data when the relationship ends?
AI vendor selection should involve cybersecurity and compliance, not just productivity.
So, What Should Financial Firms Do?
I don't believe the answer is to tell employees, "Don't use AI."
AI has too much potential to improve productivity, research, internal processes, and client service.
The goal should be controlled adoption.
Here are six places I recommend financial firms start:
1. Find Out How AI Is Already Being Used
Before writing policies, talk to your people.
Which tools are they using?
What are they using them for?
What information are they entering?
You may discover your organization is further along with AI adoption than leadership realizes.
2. Establish an AI Acceptable Use Policy
Clearly define approved tools, prohibited data, acceptable use cases, human review requirements, and escalation procedures.
Keep the policy understandable. If employees need a lawyer to interpret it, they probably won't follow it.
3. Classify Your Data
Your team needs to understand the difference between information that is public, internal, confidential, and regulated.
Then connect those classifications to your AI policy.
4. Approve AI Tools Before Deployment
Treat AI like any other business technology.
Evaluate security, privacy, access controls, data handling, vendor risk, and compliance requirements before deployment.
5. Keep Humans in the Loop
AI can draft, summarize, organize, and analyze.
But people remain accountable for the work.
Establish clear review requirements, particularly for client-facing communications, supervisory processes, and important business decisions.
6. Train Employees on AI, Not Just Cybersecurity
Employees need more than another annual security presentation.
Show them real examples.
Teach them what information should never be entered into an unapproved AI tool. Explain hallucinations. Demonstrate safe prompting. Give them approved alternatives.
When people understand the "why," good governance becomes much easier.
AI Governance Is Becoming Part of Cybersecurity Governance
For financial firms, AI adoption shouldn't live in a silo.
Your cybersecurity team shouldn't discover what compliance approved six months ago. Compliance shouldn't find out employees are using an AI platform after sensitive information has already been entered into it.
IT, cybersecurity, compliance, legal, and leadership need to be having this conversation together.
At Netready, this is increasingly part of the work we're doing with organizations adopting AI. We help businesses understand where their people are today, identify practical AI use cases, establish guardrails, secure the technology, and build employee confidence around responsible use.
Because successful AI adoption isn't about turning everything on.
It's about knowing what you're turning on, what it can access, who is using it, and how you're going to govern it.
Final Thought
AI presents an enormous opportunity for financial firms.
But innovation without governance creates risk.
If your employees are already using AI, don't start by asking whether you should stop them.
Start by asking:
Do we know what they're using, what data they're sharing, and whether we're still meeting our regulatory obligations?
If the answer is unclear, that's your starting point.
AI can move your business forward, but only when innovation and oversight move together. The goal isn't simply to use AI. It's to use it in a way that protects your clients, your data, and your firm.

310-553-3055
213-463-2100
