Compliance

Can financial advisors put client data in ChatGPT?

Published July 23, 2026 Last verified August 5, 2026

A straight answer for advisors and compliance officers weighing ChatGPT, Claude, and the rules that actually govern where client data can go.

The direct answer is yes, you can type a client's name, account number, or portfolio detail into ChatGPT's chat window, and the harder question is whether your compliance program has ever looked at where that text goes. It travels to a vendor's servers under that vendor's own policy, not your firm's, and the SEC's updated privacy rules require firms to oversee the service providers that handle customer information. Advisors can still use ChatGPT and Claude for real work. The rest of this page covers what the rules say and the setup that gets advisors the benefit of these tools while keeping their compliance program in the loop. None of it is legal advice, and your compliance officer or counsel gets the final word on your firm's own obligations.

Advisors are asking this question more because ChatGPT and Claude have gotten good enough to be genuinely useful for drafting, summarizing, and research, in the same twelve months the amended Reg S-P safeguards rule reached every RIA and FINRA published its first dedicated guidance on generative AI. The tools got more tempting and the rules got more specific at the same time, so the honest answer needs both halves.

Can you put client data in ChatGPT?

Physically, yes. Nothing in ChatGPT's interface stops you from pasting a client's name, account number, holdings, or a paraphrased summary of their situation into the chat box, and the model will answer. The real question for an advisor is what happens to that information after you hit enter, not whether typing it in is technically possible.

That text is sent to OpenAI's servers to generate a response, and from there, what happens depends on your plan and your settings rather than anything your firm controls. A Free or Plus account may use the conversation to train future models unless training is turned off in Data Controls settings. ChatGPT Team, Enterprise, and business API access don't train on your data by default. Either way, the information has left your firm's systems and landed on infrastructure your compliance program has probably never reviewed.

Some firms have gone further and licensed ChatGPT Enterprise for the whole office, treating that as the fix. It solves the training question and adds admin-level retention controls, but it doesn't automatically solve the other two problems on this page. The firm still needs to review OpenAI as a vendor under Reg S-P, and it still needs a way to capture AI-assisted client communications in its own archiving system. Buying the enterprise tier is a start, not the finish line.

This shows up in ordinary moments, not just theoretical ones. An advisor answering a quick client question from their phone, using the free ChatGPT app because it's already installed, creates the same exposure as an advisor pasting a full case file into the desktop version. The device doesn't change what happens to the words once they're sent.

Some advisors try to soften this by stripping names and account numbers before pasting, asking about "a client with a $2 million portfolio and two grown children" instead of naming anyone. That reduces the privacy exposure meaningfully and works fine for a hypothetical research question with no real client attached. It doesn't solve the recordkeeping question in the next section on its own, and it only works if the advisor remembers to redact every single time, which is exactly the kind of manual step a compliance program should design around rather than depend on.

That's the part regulators care about. Reg S-P doesn't ask whether ChatGPT is a good or bad product. It asks whether the firm knows where customer information goes and runs a real oversight process for every vendor that touches it. An AI tool an advisor started using on their own, without looping in compliance, is the kind of gap the amended rule was written to surface.

Is it safe to use ChatGPT for client emails?

Client emails carry two separate risks when they run through a consumer AI tool, and most advisors only think about one of them.

The first is privacy. An email to a client often names an account number, a balance, a beneficiary, or a specific holding. Pasting that email into ChatGPT to fix the tone or tighten the wording sends all of it to OpenAI's servers the moment you hit enter. Under the amended Reg S-P safeguards rule, the vendor-oversight duty covers outside providers that handle customer information, and most advisors haven't set up any review for a consumer chat tool they started using on their own.

The second risk gets missed more often. A client email is a business communication. FINRA member firms have to retain and supervise those communications the same way they retain any other correspondence about a client's account, and RIAs carry a parallel recordkeeping duty under the Investment Advisers Act. A conversation that happens inside a personal ChatGPT account usually isn't captured by the firm's archiving system at all. Regulators have already spent the last few years fining firms over messaging apps employees used without telling compliance, and an AI chat tool used the same way is shaping up to be the next version of that same problem. If a client complains, or an examiner asks for the correspondence file, the AI-assisted draft is often just missing.

The same exposure covers more than typed text, too. Uploading a PDF statement, a screenshot of a client's account dashboard, or a scanned form into ChatGPT to summarize it sends the entire document to the vendor's servers, not just the sentence you needed answered. A one-line question can turn into a full-document upload without anyone deciding that on purpose.

What Reg S-P, the SEC, and FINRA actually require

Four separate pieces of the regulatory picture apply here, and the fourth explains why no vendor gets to claim it solved the other three for you.

The amended Reg S-P safeguards rule

The SEC adopted amendments to Regulation S-P in May 2024, extending the safeguards and disposal rules that used to apply mainly to broker-dealers to registered investment advisers, investment companies, and transfer agents as well. Larger firms had to comply by December 3, 2025, and the deadline for smaller advisory firms landed June 3, 2026, which means every RIA is now inside the rule regardless of size. Covered firms need a written incident response program, a documented process for reviewing the third-party vendors that touch customer information, and a notification clock. Firms generally have to tell affected individuals about a breach as soon as practical, and within 30 days once they learn sensitive customer information was exposed. The disposal side of the same rule matters just as much. Firms have to dispose of customer information securely once it's no longer needed, and that duty doesn't disappear just because a copy sits on a vendor's server instead of the firm's own drive. An AI vendor that receives client data is the kind of service provider that review was built for, and whether a firm's current AI use fits its own vendor-review process is a question compliance officers are now being asked to answer.

The SEC's exam priorities for fiscal year 2026

The SEC's Division of Examinations released its 2026 priorities in November 2025, and artificial intelligence made the list as an area of increased focus. Examiners are checking whether a firm's actual use of AI matches what it discloses to clients and regulators, reviewing the security controls firms use to manage AI-related risk, and running sweep exams of firms most likely to have adopted AI early, including robo-advisers and algorithmic trading funds. The priorities also expect firms to have an AI policy in their compliance manual, whether that's a standalone document or a section added to an existing one. A firm whose advisors picked up ChatGPT or Claude on their own, with nothing written down about it, is a plausible finding in exactly the kind of review the SEC has said it plans to run.

FINRA's 2026 regulatory oversight report

FINRA published its 2026 Annual Regulatory Oversight Report in December 2025 with a dedicated section on generative AI for the first time. The report expects member firms to assess their regulatory obligations before deploying a GenAI tool, build a governance framework around how it gets supervised, and test for hallucinations and bias rather than trust the output. The most common use FINRA observed among member firms was summarizing documents and pulling information out of large volumes of text, which is close to what an advisor is doing when they paste a client email into ChatGPT to redraft it. The report treats that use case as one to govern, not one to ignore.

The AI-washing enforcement actions, and why there's no "SEC-approved AI"

In March 2024 the SEC fined two investment advisers, Delphia and Global Predictions, a combined $400,000, $225,000 from Delphia and $175,000 from Global Predictions, for overstating the role artificial intelligence played in how they managed money. It was the industry's first enforcement action for what regulators now call AI-washing. The lesson outlasts those two firms. No AI vendor, not ChatGPT's maker, not Claude's maker, not Briefly, carries an SEC seal of approval, because that seal doesn't exist. Any product marketed as SEC-compliant AI or SEC-approved AI is making a claim the SEC has already shown it will investigate and fine.

Put together, these four things point to the same short list of questions firms are working through with their compliance officers. Which AI tools are advisors actually using, beyond the ones the firm officially licenses? Does an AI vendor that receives client data get the same review as any other vendor? Does a written policy name the approved tools and the boundaries around them? And does a vendor's compliance-sounding language hold up against the actual rule text?

Six questions worth putting to any AI vendor

Ask the vendorWhat the rule requires
Where do client files or details go once the tool processes them?The disposal rule under Reg S-P still applies even when a copy sits on a vendor's server instead of your own drive.
Whose agreement governs the processing, a business contract or a personal consumer account?The amended rule calls for documented oversight of service providers, and a data processing agreement is what that file usually holds.
Does the vendor train future models on your conversations, and can that be turned off?Free and Plus-tier defaults can differ from what a business plan commits to in writing.
What does the vendor keep after you delete a conversation or opt out of training?The safeguards rule's disposal duty turns on what a vendor actually holds onto, not just what it promises to delete.
Is there a written incident-response commitment behind this vendor relationship?The amended Reg S-P rule requires a written incident response program and a notification clock, not an assumption that the vendor has one.
Can your firm archive this tool's conversations the way it archives other client communications?FINRA's books-and-records rules cover business correspondence broadly, and firms are asking whether AI-assisted conversations fall inside that.

The checklist above works for any AI vendor your firm is weighing. See how Briefly answers these questions, since that's the one vendor we can speak to firsthand. Prefer to talk it through instead? Book a demo.

What about Claude?

Claude raises a version of the same question, with one extra layer. Anthropic sells Claude across several plans, and the plan determines what happens to your conversations. The difference between the two paths is bigger than most advisors realize, and one of them is far easier for a compliance program to document.

On the business side, Anthropic's commercial terms state it plainly. Anthropic may not train models on customer content from Claude for Work, Claude Enterprise, or the API. The commitment sits in the contract itself rather than in a settings toggle, and it comes with a data processing agreement a compliance program can actually file. Deleted conversations purge from Anthropic's systems within 30 days.

Personal accounts on the Free, Pro, or Max plan work differently. Since Anthropic's August 2025 consumer terms change, those conversations train future models unless the user turns training off in privacy settings, and conversations used for training are kept for up to five years. Anthropic's July 2026 privacy policy update added a detail worth knowing. Even with training turned off, a conversation that Anthropic's automated systems flag for safety review can still be used for model improvement, and flagged content is retained for up to two years. The opt-out is real, and it has a ceiling.

The practical starting point is which plan you're on. Many firms keep client work on a business plan, where the no-training commitment is contractual and the retention terms are written down, and an advisor on a personal account can at least turn training off in settings and read what that setting does and does not cover. Either way, the Reg S-P vendor-oversight question from the last section still applies, because Anthropic processes whatever enters the conversation, training or not.

Claude for Work and Claude Enterprise also add administrative controls Anthropic markets toward regulated industries, including configurable data retention windows and activity logs an admin can review. None of that is a compliance certification by itself. It's infrastructure a firm's compliance program still has to evaluate, document, and monitor, the same as it would for any other vendor with access to anything client-related.

A solo advisor paying for Claude Pro out of pocket is on exactly the plan that trains by default. A larger RIA that negotiated a Claude for Work agreement for the whole team is not, though that same RIA still has to confirm procurement actually landed on a business plan and not a handful of individual Pro subscriptions advisors expensed on their own. The two setups can look identical day to day and carry different obligations underneath.

What advisors use instead

Advisors who want the research and drafting benefit of a large language model without creating a new compliance exposure are moving toward a different structure. Instead of sending client files to an AI vendor, the AI reads the files where they already live, on the advisor's own computer, and only a narrow slice of nonclient information travels anywhere else.

Broadly, advisors evaluating AI tools are choosing between three structures. The first is a consumer AI tool used directly, the path on the left below. The second is a hosted private AI platform, where a vendor still runs servers full of client data, just servers with the firm's name on the contract instead of the public tool. That structure still leaves the same vendor-oversight and breach-notification questions in place, just with better paperwork behind them. The third keeps client files out of any new vendor's storage and has the AI read them locally instead, under the Claude plan the firm already holds. The diagram below compares the first structure with the third, since that's the comparison advisors ask about most.

The common path

Cloud AI tools

  1. You paste a file, or type client details, into the chat
  2. The text travels to the vendor's servers
  3. The vendor's own policy decides what happens to it next
  4. From a regulator's view, it's now an undocumented service provider holding your client's data
What Briefly does instead

Briefly inside Claude

  1. You ask a question inside Claude
  2. Briefly reads the relevant file on your own computer
  3. Claude reads the file and Anthropic processes it, under your firm's own Claude plan
  4. Briefly's server sees your sign-in, a check that your seat is active, de-identified preference rules, and a short usage record for each tool call, never the file

The left side is what happens with a consumer AI tool used directly. The right side is what happens when the same question runs through an AI knowledge base for financial advisors built to sit inside Claude instead of alongside it.

Briefly is built around the right-hand path. It's a connector that runs inside Claude Desktop, the local option this page is about, and it fits a team that already works inside Claude day to day. Briefly also runs as a browser workspace for firms that would rather have Briefly handle the setup. An advisor using the connector points it at a folder of client documents, emails, and notes already stored on their computer. When they ask a question in Claude, whether that's prepping for tomorrow's meeting or answering something specific about a client's account, Briefly reads the relevant files locally and writes the answer with the source cited. With the Briefly connector, client files never reach Briefly's servers. Only your sign-in, a check that your seat is active, de-identified preference rules, and a short usage record for each tool call do, and Claude reads the files under your firm's own Claude plan. Briefly is advisory-workflow software only. It reads files and never touches accounts, trading, or custody.

That's why the Reg S-P questions from earlier in this page narrow. Briefly never receives the client file, so there's nothing of your clients' on our servers to safeguard or disclose in a breach notice. Anthropic still processes what Claude reads, under the firm's own Claude plan, so that plan stays in your vendor file the way it already does today. What Briefly avoids adding is a second, unreviewed vendor holding client data.

This page covers the two most common paths. For a full comparison of what Claude can and can't see out of the box, and how advisors are giving it secure access to client files beyond Briefly, see Claude for financial advisors.

Frequently asked questions

Can financial advisors put client data into ChatGPT?

Typing a client's name, account number, or portfolio detail into ChatGPT sends that data to OpenAI's servers under a consumer agreement the firm never reviewed. The amended Reg S-P rule requires firms to oversee the service providers that handle customer information, and few firms have any oversight arrangement with OpenAI on file.

Is ChatGPT compliant with SEC and FINRA rules for financial advisors?

ChatGPT itself isn't approved or rejected by the SEC or FINRA, and how an advisor uses it is what compliance programs look at. Pasting client information into the consumer chat window raises Reg S-P and recordkeeping questions firms are bringing to their compliance officers. General research or drafting with no client specifics raises far fewer of them.

Does Regulation S-P apply to AI tools advisors use with client data?

The amended Reg S-P safeguards rule, in force for all RIAs since June 3, 2026, requires firms to oversee the third-party service providers that touch customer information, and an AI vendor receiving client data matches the kind of service provider the rule describes. The rule also calls for a written incident response program and a documented vendor review process.

Can financial advisors use Claude for client work?

Yes, and the plan is what matters. Claude for Work, Enterprise, and API accounts fall under Anthropic's commercial terms, which state that Anthropic may not train models on customer content. Personal Free, Pro, and Max accounts train on conversations unless the user opts out, and safety-flagged chats can be used even after opting out. Many firms keep client work on a business plan for that reason.

Does my firm need a written policy on AI tools like ChatGPT and Claude?

Many firms are writing one now. FINRA's 2026 oversight report says firms should assess and supervise their use of generative AI, and the SEC's 2026 exam priorities look at whether a firm's actual AI use matches what it discloses. Both reviews get easier to answer with a written policy naming which tools are approved, and what yours should say is a question for your compliance officer.

Do advisors need to archive AI chat conversations under FINRA rules?

FINRA's books-and-records rules cover business correspondence broadly, and firms are asking their compliance officers whether an AI chat that drafts a client email or discusses an account functions as business correspondence under them. Most consumer AI chat tools were not built with archiving in mind, which is part of the gap compliance teams are mapping.

Is there an SEC-approved AI tool for financial advisors?

No, and no vendor can honestly claim that certification exists. The SEC fined two investment advisers, Delphia and Global Predictions, a combined $400,000 in 2024 for overstating their AI capabilities to clients. The lesson for advisors evaluating any AI tool, including Briefly, is to verify specific claims rather than trust a compliance label.

What's the safest way for advisors to use AI with client information?

One structure keeps client files in the firm's own storage and has the AI read them there, under an agreement the firm has already reviewed. Briefly, an AI knowledge base for financial advisors, is built that way. Its connector runs inside Claude Desktop, client files never reach Briefly's servers, and only your sign-in, a seat check, de-identified preference rules, and a short usage record for each tool call do. Claude reads the files under your firm's own Claude plan, and whether the whole setup fits your compliance program is your compliance officer's call.

None of this is legal advice. Regulations change, and your firm's specific obligations depend on facts a general article can't know. Talk with your compliance officer or securities counsel before changing how your firm uses ChatGPT, Claude, or any other AI tool.

Connor Florczyk, founder of Briefly

Connor Florczyk

Founder of Briefly. Before Briefly, he worked as a private wealth analyst on a top-performing team at Morgan Stanley, where he saw firsthand how much advisor time gets lost hunting for a client's own files.

See how Briefly keeps client files on your computer.

Briefly runs inside Claude Desktop and reads your firm's own files locally, so client data never has to leave your machine to get an answer.

Start now Or book a demo