Answers
Plain answers about AI and client information
What actually happens to a document, who checks the output, and what a firm can show afterwards. These describe how the work behaves. What your firm is obliged to do is not ours to say.
For what the regulators themselves have said, quoted and dated, read the reference page.
What actually leaves your firm when someone pastes a client document into a chatbot?
The whole document leaves, exactly as pasted, including every name, number and identifier in it. Where it goes next is governed by whatever terms that account is on. Your firm keeps no record of what was sent, by whom, or whether anyone checked the answer before it was used.
What is the difference between an in-house AI tool and a public-facing one?
A public-facing tool is one anybody can open and paste into. An in-house tool is one the firm has set up, configured and can describe. The useful part of the distinction is not where the model is hosted — it is whether the firm decided what the task is, who checks it, and what gets written down.
How do you show what an AI tool did with a client's information?
In most firms you cannot, because nothing was written down at the time. A run record fixes that by capturing metadata for every run — what kind of task it was, when, under which policy, with what outcome and who approved it — while never storing the content itself.
Who checks AI output before it goes to a client?
In most small firms, whoever generated the draft. That is the weak point: the person best placed to miss something is the person checking it. A workflow can declare the review step in advance, so the reviewer is decided by the firm rather than by whoever happened to be at the keyboard.
If details are taken out before sending, does that mean nothing leaves?
No, and anyone who tells you otherwise is overselling it. Replacing identifiers before routing reduces what leaves unnecessarily and makes that reduction automatic rather than dependent on someone remembering. It does not promise zero, and detection is not exhaustive.
Is an AI policy enough, or do you need something else?
A policy describes what people should do. A workflow is what they actually do. Both are useful and they are not substitutes: a firm can have a well-written policy, follow it in good faith, and still be unable to say what happened on any particular job.