Can I put client data into ChatGPT or other public AI tools?
No — not into the public or consumer version. The moment a client's name, holdings, or circumstances enter a public AI tool, you are processing personal data with no lawful basis for the tool's onward use, no data-processing contract, and no control over retention. The fix is a jurisdiction-specific data boundary, not a better prompt.
This is the single highest-intent question a wealth adviser asks about AI, and the short answer holds across the EU, the UK, and the US. What changes across those three jurisdictions is which rulebook makes it a breach and what documentation the answer demands. Below is the answer-first version, then the three-jurisdiction fix.
Why is client data in a public AI tool a problem at all?
Because a public or consumer AI tool is not a private workspace. It can retain, log, or train on what you enter, and its terms rarely give a regulated firm the contractual controls it needs. A client's name, holdings, health, and financial circumstances are personal data everywhere you operate, so entering them is a regulated processing decision you have to be able to justify before you make it, not after.
The distinction that matters is public/consumer versus a contracted enterprise deployment. A consumer ChatGPT account with no data-processing agreement and default training settings is the version this article says no to. A tool covered by a signed data-processing agreement, with training switched off by contract and appropriate data residency, is a different legal object. That is the boundary the fix draws.
What are the EU rules on client data in AI tools?
Under the GDPR (Regulation (EU) 2016/679), the moment client personal data enters a prompt, the regulation applies to that processing, and you need an Article 6 lawful basis for it. Pasting client data into a general-purpose tool never scoped for confidential financial data is a processing decision you must be able to justify. The sharper rule for wealth work is Article 22.
GDPR Article 22(1) gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on them. Where automated decision-making is permitted, Article 22(3) requires safeguards including the right to human intervention, to express a view, and to contest the decision. A suitability outcome or a portfolio action is exactly the kind of significant effect this covers.
The EU fix: keep live client data out of general-purpose AI tools; contain any real-data AI work inside a covered, contracted environment with an Article 6 lawful basis documented; and keep a named human in the loop on any decision that significantly affects a client, so Article 22's safeguards are real, not notional.
What are the UK rules on client data in AI tools?
Under UK GDPR and the Data Protection Act 2018, there is no AI exemption to data-protection law. The ICO is explicit that its generative-AI work confirms no 'AI exemption' exists. A public tool that retains or trains on your input leaves you with no lawful basis for that onward use and no control over where the data sits. It is the same Article 6 lawful-basis requirement as the EU, enforced here by the ICO.
The UK adds a documentation step the EU shares but the ICO states sharply: a Data Protection Impact Assessment. The ICO treats a DPIA as likely mandatory before the processing starts for AI systems that process personal data, under Article 35 of the UK GDPR. Firms that deploy the workflow first and reach for a lawful basis later have it backwards.
The UK fix: no live client data into any public AI tool; for real-data workflows, use a tool with a data-processing agreement, UK or EU data residency, and training-off by contract; complete the Article 35 DPIA and document the Article 6 lawful basis before the workflow goes live; and reflect the processing in your privacy notice.
What are the US rules on client data in AI tools?
For SEC-registered investment advisers and broker-dealers, the binding rule is Regulation S-P as amended in 2024. On 15 May 2024 the SEC adopted amendments (Securities Exchange Act Release No. 34-100155) that require covered institutions (including SEC-registered investment advisers, broker-dealers, investment companies, and transfer agents) to adopt a written incident-response program as part of their safeguards-rule policies, reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
The amendments also require notifying affected individuals as soon as practicable, and no later than 30 days after the firm becomes aware that unauthorized access to or use of sensitive customer information has occurred. Compliance dates are 3 December 2025 for larger entities and 3 June 2026 for smaller entities. The practical read for AI: routing customer information through a public tool you cannot oversee is hard to square with a safeguards program you must be able to evidence, and a tool that logs or leaks that data is exactly the unauthorized-use scenario the incident-response program exists to catch.
The US fix: treat any AI tool that touches customer information as in-scope for your Regulation S-P safeguards program; do not route customer information through a public tool your program cannot oversee; contract for oversight, and keep the five-year records the rule expects.
What is the fix that works across all three jurisdictions?
The same shape everywhere: a data boundary, a contract, and a record. Decide which tools are allowed to see client data and contain that work inside a covered, contracted environment: a data-processing agreement, training-off, appropriate data residency. Keep a named human on any decision that significantly affects a client. And keep live client data out of public or consumer AI tools entirely, as a baseline discipline that satisfies the strictest of the three regimes at once.
None of the three rulebooks regulates which model you pick. They regulate whether client data stays contained, whether a human owns the output, and whether you can reconstruct what happened. That is governance, and it sits in the workflow around the model, not in the model itself. A firm that draws the boundary once, correctly, is compliant in all three places for the same reason.
This is the work Serra Education does with wealth firms: adopting AI with the data boundary and the audit trail built in from the start, so the answer to "can I put client data in?" is a documented process, not a guess. The entry point is a Consulting 1 session, 250 EUR, credited toward the Tier 1 audit if you go on to the full engagement.
See the full picture at AI for Wealth. For the EU rules in depth, read the AI rules every EU wealth-management firm must follow; for the UK, the AI mistakes UK financial advisers make; and for why this is a governance problem, the AI gap in wealth is governance, not adoption. Serving external clients from the EU? Start with the EU wealth-manager compliance finder. To book the Consulting 1 session, use the report and booking page.
FAQ
Can I use ChatGPT at all as a wealth adviser?
Yes, for work that never touches client personal data: general drafting, summarising public research, learning a concept. The line is the data, not the tool. Keep live client names, holdings, and circumstances out of any public or consumer AI tool, and put real-data work inside a contracted environment with training switched off.
Is it safe if I anonymise the client data first?
Anonymising or using synthetic inputs is the right default and removes most of the risk, because genuinely anonymous data is outside data-protection law. But re-identifiable "anonymised" data is still personal data. If real client data must be processed, use a contracted tool with a data-processing agreement rather than relying on anonymisation alone.
Does using an enterprise or paid AI plan fix the problem?
Only if the plan gives you the contractual controls: a data-processing agreement, training-off by contract, and appropriate data residency. A paid consumer tier without those is still the public version for compliance purposes. Check the contract terms, not the price.
What if I already put client data into a public tool?
Treat it as a data incident. In the US, a covered adviser assesses it against the Regulation S-P incident-response program and the 30-day notification duty. In the EU and UK, assess it against the GDPR/UK GDPR breach-notification obligations. Document what happened, contain it, and fix the workflow so it cannot recur.
Do these rules apply to a US adviser and an EU firm the same way?
The answer, no public tools for client data, is the same, but the rulebook differs. The EU relies on GDPR Article 6/22; the UK on UK GDPR plus an ICO-expected DPIA; the US on Regulation S-P's 2024 safeguards and incident-response requirements. A single data boundary satisfies all three, which is why the fix is one discipline, not three.
Serra Education provides process and tooling consulting only, never Serra Wealth investment advice.
This article is general information on AI-adoption process and governance. It is not investment, legal, or compliance advice. Each firm is responsible for its own regulatory compliance and for validating any AI output it relies on. No live client data should be placed in any AI workflow that is not contracted and assessed for it. Regulatory positions and timelines can change; confirm current obligations with qualified counsel and against the primary sources before you rely on them.