| At a Glance: – Employees are already using AI tools, whether your firm has approved them or not. – This is known as Shadow AI: the use of AI applications outside your firm’s approved technology and IT compliance processes. – The biggest risk isn’t the AI itself. Its sensitive client information being shared with tools your firm doesn’t control. – A simple AI policy, approved tools, and the right Microsoft security settings can dramatically reduce your risk while still allowing employees to benefit from AI. |
AI Isn’t the Problem. Unmanaged AI Is.
Most RIAs are talking about AI. Some are actively rolling out Microsoft Copilot. Others are experimenting with ChatGPT, Claude, Gemini, or specialized financial planning tools.
But behind the scenes, some employees are using AI without telling anyone.
They might paste an email into ChatGPT to improve the wording, upload a spreadsheet to an AI tool for analysis, ask an AI assistant to summarize meeting notes, or generate marketing content using a personal account.
They’re not trying to bypass security, they’re simply trying to be more productive.
This growing phenomenon has a name: Shadow AI.
The Risks to an RIA
RIAs are unique in that Shadow AI isn’t just a data governance issue. It’s also a regulatory and fiduciary one.
Advisory firms routinely handle personally identifiable information (PII), financial account information, tax documents, investment strategies, and other sensitive client data. If employees enter that information into an AI service that hasn’t been reviewed, your firm may have little visibility into:
- Where the data is stored
- Whether it is retained
- Whether it is used to improve future AI models
- Who has access to it
- Whether it complies with your firm’s security requirements
Saving a few minutes can unintentionally create significant risk for the firm.
Shadow AI Is Bigger Than ChatGPT
When people think about Shadow AI, they often think about ChatGPT. But it’s just one example.
Employees don’t need IT to install software or request approval before using AI. They access browser-based AI services, use personal accounts, install browser extensions, or simply start using the AI features that are built into the business applications they already use.
That’s what makes Shadow AI difficult to manage. It isn’t one application. It’s dozens of AI capabilities appearing across the software your employees use every day.
The big question is “Do we knows which AI tools employees are using, how they’re using them, and what client information they’re sharing?”
Your RIA firm needs to think beyond simply blocking AI websites. Create a consistent approach to AI usage, define what information can be shared with AI tools, and provide employees with approved solutions that meet the firm’s security and IT compliance requirements.
Signs Shadow AI May Already Exist
If you’re not sure whether employees are using unauthorized AI, ask yourself:
- Do employees know which AI tools are approved?
- Is there a written AI usage policy?
- Can users access public AI tools from company devices?
- Are browser extensions monitored?
- Do employees understand what client information should never be entered into AI?
- Does IT have visibility into AI usage across the Microsoft environment?
If several of these answers are “no,” there’s a good chance Shadow AI already exists.
Five Steps To Minimize Shadow IT Risk
1. Create an AI Usage Policy
Employees need clear guidelines.
Define:
- Approved AI tools
- Prohibited uses
- Types of information that can never be entered into AI
- Review and approval processes for new AI applications
2. Give Employees an Approved Option
If employees need AI to do their jobs, provide a solution that meets your firm’s security requirements.
People are far less likely to seek unauthorized tools when an approved alternative is available.
3. Protect Your Microsoft Environment
Identity, permissions, data classification, conditional access, device management, and data loss prevention become even more important once AI enters the picture.
The AI tool you choose for your RIA firm should inherit the good security you have in your Microsoft environment.
4. Train Employees
Employees don’t need to become AI experts.
They simply need to understand:
- Which AI tools are approved
- What information can and cannot be shared
- When to involve IT before adopting a new AI application
Clear guidance can prevent many of the risks associated with Shadow AI.
5. Review AI Like Any Other Technology
New AI tools should go through the same review process as any other software.
Questions should include:
- Where is data stored?
- What security certifications exist?
- Can administrators manage users?
- Are audit logs available?
- Does the tool integrate with your identity platform?
If you wouldn’t approve software without asking these questions, AI shouldn’t be any different.
AI Adoption Doesn’t Have to Mean Losing Control
AI is becoming another standard business tool, much like email, cloud storage, or video meetings.
Trying to prevent employees from using AI entirely is unlikely to succeed.
Instead, successful firms will focus on giving employees secure, approved ways to use AI while maintaining the governance, security, and IT compliance expectations that already exist within the business.
That’s how firms reduce Shadow AI—not by saying “no” to AI, but by making the right way the easiest way.
Need Help Building an AI Strategy for Your RIA?
Whether you’re evaluating Microsoft Copilot, reviewing your Microsoft 365 security posture, or creating your firm’s first AI usage policy, RIA WorkSpace helps advisory firms adopt AI without compromising security or IT compliance.
Schedule a discovery call to discuss how your firm can take advantage of AI while keeping client data protected.