All guides AI Governance for RIAs 8 min read

Is ChatGPT Safe for Client Financial Data? What RIAs Need to Know

Consumer ChatGPT can retain and train on anything you paste into it, with no data processing agreement available. This guide walks through the tier distinction that creates Reg S-P exposure, a three-question vendor test, and a decision table for what client data can go where.

Whether ChatGPT is safe for client data comes down to one thing: which tier you are on. Consumer ChatGPT (free and Plus accounts) can retain your inputs and use them to train OpenAI's models. No data processing agreement is available at those tiers. Pasting a client's name alongside their portfolio value is a Reg S-P problem on the spot.

OpenAI's enterprise tiers are different. They contractually prohibit training on your organization's conversations and offer a data processing agreement covering client nonpublic personal information (NPI). The AI model is the same; the legal relationship is not.

That distinction has real consequences: 82% of RIA AI users rely on generative AI (Schwab/Logica, n=533, Jan 2026), and most of them are using accounts with no executed DPA. The tier you are on is the compliance control.

Why the tier matters

OpenAI's products split into two compliance categories:

Consumer tiers (free and Plus): Inputs may be used to improve OpenAI's models unless you opt out in settings. That opt-out is a setting, not a contract. The underlying agreement does not bind OpenAI from changing its data use practices, and no DPA is available at these tiers. You cannot document vendor oversight of client NPI because there is no vendor-oversight contract to point to.

Enterprise tiers (Team and Enterprise): Conversations are contractually excluded from model training. A DPA covering NPI is available on the Team tier and included on the Enterprise tier. Once you have that DPA executed, the contract names what OpenAI can and cannot do with your clients' data.

That is not a minor gap. One tier gives you a documented safeguarding commitment; the other gives you nothing contractual. And yet 78% of RIAs have no written AI policy governing which tier is approved for which data (ISS Market Intelligence, n=466, June 2025), which means most AI-using advisors are deciding this in the moment, with nothing to back them up.

Three questions before entering client data in any AI tool

Reg S-P requires RIAs to safeguard client NPI from unauthorized disclosure. Amended Reg S-P, with a compliance deadline of June 3, 2026 for smaller advisers (under $1.5B AUM), adds explicit vendor-oversight and incident-response requirements. Before entering any client data into an AI tool, answer these three questions:

1. Does the vendor contractually prohibit training on your firm's data? A toggle in your account settings is not a contract. You need it in writing, in the service agreement: the vendor will not use your inputs to train or improve its models. Without that language, the safeguard holds only until the vendor decides otherwise.

2. Is there a data processing agreement (DPA) that specifically covers client NPI? The DPA is what makes Reg S-P's vendor-oversight requirement enforceable. It names what the vendor can do with the data you share, how it is stored, and who can access it. Without one, you have no documented safeguarding commitment to show an examiner.

3. Does the vendor contractually commit to incident-response notification timelines? Amended Reg S-P requires you to notify affected customers of covered security incidents. That chain starts with your vendor notifying you. You need contractual language committing them to report a breach promptly. Without it, you may not find out until after the fact.

If any answer is "no" or "unknown," client NPI does not go into that tool.

A yes/no decision table: what data goes where

This table applies the three-question test to the most common use cases. "With DPA" means you have actually executed the agreement, not merely that a DPA is offered by the vendor.

What you are pasting Consumer free/Plus Team or Enterprise (with DPA executed)
Anonymized market analysis: no client identifiers Low risk — no NPI Yes
Internal templates: no client data included Low risk — no NPI Yes
Public regulatory filings or earnings reports Yes Yes
Client name linked to any financial detail No Yes
Account numbers or balances No Yes
Tax documents, estate plans, beneficiary info No Yes
Meeting notes that reference a client by name No Yes
Form ADV or compliance draft language without client-specific data Yes Yes

"Low risk — no NPI" on consumer tiers still means no DPA and no contractual prohibition on training. The risk is lower without client identifiers in the mix, but that governance gap cannot be papered over when an examiner asks how you govern AI use of firm data.

What ChatGPT does not handle for you: Rule 204-2

Even on an enterprise tier with a DPA in place, ChatGPT does not produce records in the form Rule 204-2 requires. Rule 204-2 requires retaining both the AI-generated output and the underlying source material (the notes, transcript, or data you fed in) for five years, with the first two years readily accessible.

ChatGPT's conversation history does not get you there. You cannot export it in a compliant format, it is not write-protected, and it cannot be produced on short notice for an SEC exam. If an advisor uses ChatGPT to draft a meeting summary from a client transcript, both the transcript and the draft need to land in the compliance archive before they go to the client. A browser tab does not count.

The fix is a workflow, not a different tool. Whatever comes out of ChatGPT goes into your archiving system: Smarsh, Global Relay, or a comparable platform. An advisor-focused AI note-taker that archives directly to one of those systems does this automatically. A copy-paste into a personal email does not.

The SEC's 2026 examination section on Emerging Financial Technology directs examiners to assess whether your controls around AI-assisted advice are consistent with your regulatory obligations. "We use ChatGPT Enterprise" is not a control. The archiving workflow is the control.

Compliant alternatives for client-data work

For general-purpose AI drafting, ChatGPT Enterprise and Team (with DPA executed), Anthropic's Claude for Work, and Google Workspace with a DPA all contractually exclude training on your data. For an RIA, the real question is which one your compliance vendor can connect to your archiving system.

Microsoft 365 Copilot is its own governance problem, with specific settings that determine whether it holds up under SEC scrutiny. The Microsoft 365 Copilot compliance guide for RIAs covers what those settings are and how to configure them.

For client meeting data, purpose-built advisor AI note-takers are easier to defend than a correctly configured general-purpose enterprise tool. They are built around Rule 204-2 retention from the start and pipe outputs directly into archiving platforms. The tradeoff is price and how much you can customize the workflow.

Before any of this holds up at an exam, you need a written AI policy that names which tools are approved for which data. Without it, you are back to making the call in the moment, one paste at a time. The RIA AI Policy Starter Template gives you the structure to document approved tools, data-handling rules, and the vendor due-diligence section that records your DPA status for each tool you deploy.

Frequently Asked Questions

Does ChatGPT train on data you paste into it?

On consumer tiers (free and Plus), yes, unless you have turned off training in your account settings. That setting is not a contract: OpenAI can change it, and it does not create a binding commitment you can show an examiner. The Team and Enterprise tiers contractually exclude your organization's conversations from model training. If you are on a consumer tier and have already pasted in client data, that data has likely been processed. Switching to an enterprise tier and executing a DPA stops it going forward; it does not retroactively remove what has already been ingested.

Does using client PII in ChatGPT violate Reg S-P?

On a consumer tier: yes. Reg S-P requires safeguarding client NPI from unauthorized disclosure and establishes vendor-oversight requirements for any third party that handles NPI. Consumer ChatGPT has no DPA, so there are no documented safeguards to show an examiner. On an enterprise tier with a DPA executed, you are in a defensible position: the contract names what the vendor can and cannot do with your clients' data. The DPA is not optional. Without it, the enterprise tier does not close the compliance gap either.

What data can never go into a consumer chatbot?

Any data that qualifies as client nonpublic personal information under Reg S-P: client names linked to account values, balances, or positions; account numbers; Social Security or tax identification numbers; estate plans or beneficiary designations; tax documents; and meeting notes or communications that identify a specific client and their financial situation. The format does not matter. What matters is whether the data is not publicly available and ties to a specific client's financial relationship with your firm. When in doubt, strip the identifier before pasting.

How does ChatGPT use affect books-and-records compliance?

ChatGPT does not satisfy Rule 204-2 recordkeeping requirements on its own, and using it without a downstream archiving step creates a gap. Rule 204-2 requires retaining both the AI-generated output and the underlying source material for five years, with the first two years readily accessible. ChatGPT's conversation history cannot be exported in a compliant format, is not write-protected, and cannot be produced quickly for an exam. Any AI-generated document that becomes part of a client record needs to go into your compliant archiving system. An advisor AI note-taker that routes outputs directly to Smarsh or Global Relay handles this automatically. A manual copy-paste into an email does not.

What are compliant alternatives for client-data AI work?

The main options: enterprise-tier general-purpose AI tools (ChatGPT Enterprise, Claude for Work, Google Workspace) with a DPA executed and covering NPI; Microsoft 365 Copilot with the governance configuration appropriate for SEC-registered advisers (see the Copilot compliance guide for the specifics); and purpose-built advisor AI tools designed around Rule 204-2 and SOC 2 certification, particularly for meeting-note workflows. For any of these to hold up at an exam, you need a written AI policy documenting which tools are approved for which data. The RIA AI Policy Starter Template includes the vendor due-diligence section that records DPA status, training-prohibition language, and incident-response commitments for each tool your firm deploys.