Pivolt
AI

Why AI Policy Fails and Architecture Doesn't

Sep 202613 min read
Why AI Policy Fails and Architecture Doesn't

What Goes Out the Door at Eleven at Night

An analyst has to deliver performance commentary on twelve portfolios by market open. The platform exports the numbers, but the narrative is manual and takes forty minutes per portfolio. He opens ChatGPT on his personal account and pastes in the holdings, the returns by period, the attribution by asset class, and the allocation rationale the firm has used since 2019. He asks for the text. It comes back in ninety seconds, good enough to edit. He makes the deadline.

Nothing about this is irrational. The analyst solved the problem in front of him with the tool that worked, and nobody had ever told him clearly why he shouldn't. He copied no file, sent no email, installed nothing. He pasted text into a box.

Something else went with it. The firm's proprietary methodology, written out in structured form, by someone who understands it, including the parameters and the exceptions that only surface when a person has to explain a result. It went to a third-party system the firm has no contract with, with no record of what was sent and no defined retention.

This is shadow AI, and most firms have no idea of the volume. It doesn't show up in network logs because it happens on a phone or a personal laptop. It doesn't show up in DLP because there was no attachment. It doesn't show up in vendor audits because there is no vendor to audit. And it doesn't show up in internal surveys, because when compliance asks who has been using AI outside approved tools, the answer that comes back is always smaller than reality.

The problem surfaces later, and never at a convenient moment. It surfaces when an institutional client sends a due diligence questionnaire asking which third-party systems process their data. It surfaces when the firm has to demonstrate, in litigation or an examination, that it treated a particular piece of information as confidential. It surfaces when someone asks exactly what was sent, and the only honest answer is that there is no way to know.

The Damage Happens Even If Nobody Looks

When the subject comes up, the worry you usually hear is that AI labs keep hidden mechanisms for harvesting whatever is valuable in user conversations. The image is seductive and technically weak. GPU memory is volatile, recycled between requests, and the most expensive resource in the datacenter. Nobody would hide anything there. A technical reader dismisses the argument in the first paragraph, and dismisses the underlying concern along with it. That is the worst possible outcome, because the concern is legitimate.

The instinct is right and pointed at the wrong target. A wealth manager faces no meaningful risk of having its business copied from prompts. Nobody clones a family office by reading conversations, and what sustains an investment firm is relationships, track record, and licensing, not the allocation rationale. The risk is a different one. It is quieter, it depends on no intent whatsoever from the other side, and it materialises the moment the information leaves, even if no human being ever reads it.

Trade Secrecy Is a Status, Not a Property

The common intuition treats confidentiality as a characteristic of the information itself, the way a document is long or short. The information would be born secret, stay secret on its own, and stop being secret only if someone published it.

The law works differently. Both the Defend Trade Secrets Act in the United States and the EU Trade Secrets Directive condition protection on the holder's own conduct: there is a secret to protect only if the holder took reasonable measures to keep it secret. The information can be valuable, it can be unique, it can be the thing the whole firm rests on. Without the measures, there is nothing to invoke.

What counts as a reasonable measure is assessed from what the firm actually did, not what it wrote down. An internal policy signed on day one and never mentioned again carries limited weight. What carries weight is access control, a contract with whoever receives the information, and evidence that the firm knew where its data was going.

A methodology pasted into a consumer-tier service struggles to pass that test. The terms of those services frequently allow conversations to be used for model improvement, and they change by unilateral decision of the provider. The status can be extinguished at the moment of the paste. The harm is automatic and self-inflicted, and the firm only discovers it when it needs to prove otherwise, which is precisely the point at which it can no longer be fixed.

What a Firm Is Actually Pasting

The inventory is worth doing, because the list is more uncomfortable than the abstract discussion suggests.

The allocation thesis is the economic justification for the fee. If it circulates freely, what is left to justify the price is execution, which is easier to replicate. A family office's deal pipeline is the house's core asset and is frequently confidential under contractual obligation to third parties, which turns a leak into a breach. Fee structures and rebate policy are competitively sensitive, and in some markets their circulation raises a regulatory question on its own.

Then there is what does not belong to the firm at all. Client holdings, wealth composition, family structure, KYC material. Here the problem stops being about intellectual property and becomes one of data protection.

When What Leaks Isn't Yours

The moment personal data enters a prompt, the debate about third-party intent stops mattering. Even if the provider behaves impeccably, what happened was a transfer of personal data to a recipient the firm has no processor agreement with, without a documented legal basis, without an international transfer assessment, and without any record of what was sent.

Modern data protection regimes converge on this point. The firm is the controller and answers for the processing. Anyone processing on its behalf is a processor, and that relationship requires a contractual instrument with defined minimum content, which a personal account on a consumer service does not have. International transfer requires its own basis. And there is a practical aggravator under any of these laws: when a data subject exercises the right of access or erasure, the firm needs to know where their data sits. If part of it was pasted into systems nobody mapped, the answer to the data subject is incomplete by construction, and the firm has no way to complete it.

Add to that the impossibility of proving a negative. In an examination or a due diligence questionnaire, the question is not whether the firm believes nothing leaked. It is what evidence it has. A firm that kept no record has no evidence at all, and the absence of a record does not read as the absence of an incident.

Banning It Means Losing Twice

The most common corporate response is to restrict. Samsung did this in 2023, after finding engineers pasting proprietary source code into public AI tools. It is understandable and it is incomplete.

Restriction without a substitute does not eliminate the behaviour. It moves it beyond the firm's reach. The analyst from the first section still has the same deadline and the same forty-minute manual task. The difference is that he now uses a personal device and tells nobody, because telling someone has become a confession. The firm lost the productivity the ban cost it and lost what little visibility it had.

There is a worse second-order effect. Before the ban, the usage was debatable and could be corrected with guidance. After it, the usage is a policy violation, and policy violations do not get reported. The firm that banned AI ends up with less information about its own risk than the firm that did nothing.

The question that works better is not whether the firm uses AI, nor which tool it authorises. It is where the data stops.

Translating a fund term sheet, working through a BIS paper, researching a manager's track record, understanding the mechanics of an instrument: none of this carries the firm's own information and no sensible policy should get in the way. A policy that tries to cover everything loses credibility and stops being followed, and the line exists to separate, not to close.

What needs attention is the other list, and it is longer than most firms imagine. Portfolio narrative commentary. Answering why the portfolio fell this quarter. Market commentary tailored to each client's profile. Explaining a structured product in language the client will understand. Scenario simulation on the current allocation. All of these exist only on top of data that cannot cross the line, and all of them are exactly the kind of task where a language model genuinely helps. That is why the temptation does not go away with training.

The perimeter belongs to the data, not to the tool. Drawing that separation is a half-hour exercise with the people who actually do the work, and it produces a policy they will follow, because it doesn't stop them working.

What remains afterwards is the hard part, and it is where most governance programmes fail. Every task on the second list needs a contracted route, and that route has to be good enough to be the lazy choice. If the authorised route requires fifteen minutes of rewriting and the outside one requires none, the analyst uses the authorised route for what is comfortable and goes outside for the rest, now aware that he is violating policy and therefore telling nobody. Poorly executed partial coverage produces worse leakage than no policy at all, because it disappears from view.

The test is simple and does not depend on opinion. Take the second list, task by task, and time the authorised route against the chatbot, with the person who does that work every day. Don't survey, measure. Wherever the authorised route loses, there is a future leak already on the calendar, and the date depends only on the next tight deadline.

This is the gap Pivolt closes. Every task on the second list has a route inside the platform, on the portfolio it already administers, with nothing exported and nothing pasted.

How Many Boundaries the Data Crosses

A contracted route is the minimum requirement, and it is not the end of the conversation. Two routes can both sit under contract and still demand very different things from whoever answers for them. What separates them is how many boundaries the data has to cross for the task to happen, and what the firm has to stand behind at each crossing.

Before that, though, there is a simpler argument that holds for any arrangement. Pasting is not only risky. It produces worse work, and that is what lets a policy hold without surveillance.

Pasted Context Is an Unreconciled Extract

The analyst pastes what fits in the prompt and what he managed to export. The ten largest holdings, the quarterly return, the attribution by asset class. What stays out is whatever sat with another custodian, whatever would have required look-through into a structure, whatever didn't tie out and he left for later. The model answers very well about that extract and has no way of knowing what is missing, because nothing in the prompt signals an absence.

There is a second problem, less obvious and more serious. What the analyst pastes at eleven at night is an unreconciled snapshot. The consolidated position that goes into the official report has been reconciled daily against the sources, with an audit trail. The pasted one has not. When the narrative commentary is produced from one base and the report from another, the chance that the number in the text diverges from the number in the table is real, and the person receiving both is the client. That is an audit problem the paste creates, and nobody counts it when measuring the time it saved.

An open question about return and risk answered inside the platform runs against the entire consolidated portfolio, multi-custodian and multi-currency, with structures looked through and periods already reconciled. The answer is deeper because the context is complete, not because the model is better. And it comes from the same base that feeds the report, which removes the divergence at source.

Narrative Has to Be Born Attached to the Data

Generating a portfolio storyboard inside the platform removes the two manual steps that justified going outside in the first place, which are exporting and pasting. The text is produced on the current position, with the same period and methodology consistency the rest of the reporting already uses, and it returns to the same place it came from. What the analyst does next is edit, which is what he was already doing with the chatbot's output, without forty lines of client data sitting in a third-party system.

The limit of this is worth stating, and we covered it in Why an LLM Should Never Compute Your TWR: the model is excellent at explaining a number and terrible at producing one. The narrative should describe what the calculation engine determined, never replace it.

Why the Gap Closes: Request, Answer and Execution in One Place

The reason is architectural, not a matter of features.

Pivolt did not add AI on top of a portfolio system: the intelligence operates on the same consolidated, reconciled base that feeds the calculation and the report, and it reaches the entire lifecycle, from onboarding and CRM through planning, trading, reporting and billing. That is what removes the export, the paste and the number divergence, and no layer bolted on from outside reproduces it.

A good deal of the work also doesn't end with text. After the commentary comes the rebalance, the report, the order. When a request in plain language triggers the process inside the same system where the data already sits, the sentence and the action are the same thing, and what remains is a single record, with author, timestamp and scope.

It is the exact inverse of the scene in the first section, where nobody knows what was sent or by whom. And it is the difference that shows up least in a demo and most in an audit: every boundary the data crosses between request and execution is one more link to declare, contract, audit and explain to a regulator.

What Remains Is Contractual

Even inside the platform, data travels to a third-party model. That does not disappear, and claiming otherwise would be dishonest. What changes is that the transfer becomes a contracted one, with a declared chain of controller, processor and subprocessor, under negotiated terms rather than consumer terms, and with a trail. That is exactly the difference between a reasonable measure of secrecy existing and not existing.

Five questions are enough to verify this with any provider. Where inference happens, in which jurisdiction and with what isolation. Who is controller and who is processor, in writing. What the retention period is and how it can be verified. Whether the commitment sits in the DPA or only in public terms, which change by unilateral decision. And whether usage is recordable for the regulator, with author, timestamp and scope, in a form that survives a formal request.

Operational resilience regimes and the rising bar for third-party due diligence are all moving in this direction, and these questions are going to arrive regardless. Getting ahead of them costs an afternoon.

The decision is not whether the firm uses AI. It is knowing, with every query, which side of the line the data is on, and not forcing anyone to cross it in order to get their work done.

Put these ideas to work

See how Pivolt turns insight into automated, AI-native wealth management.

Talk to sales