“One day the AIs are going to look back on us the same way we look at fossil skeletons on the plains of Africa. An upright ape living in dust with crude language and tools, all set for extinction.” Nathan, Ex Machina Financial Services
If you can overlook the examples of The Terminator, Ex Machina, 2001 A Space Odyssey, Upgrade, Avengers 2, Smart House, War Games, Stealth, Westworld and Electric Dreams, the increasing relevance of Artificial Intelligence (AI) is tremendously exciting.
In financial services, AI represents an incredible opportunity for financial advisers to transform their advice practices, optimise their performance, improve efficiency, enhance client engagement, and uncover advanced data insights. We’ve explored the role of AI in financial advice in previous articles, such as Guide for Advisers and Licensees: Navigating AI in Financial Services, The Future of Advice in a Changing Regulatory Environment, and Curated Content: AI and Ethics, but it’s time to go deeper.
This article will address our previous articles’ questions and provide a practical guide for advisers about managing this transformative technology. Before we begin, let’s clarify some terms because it’s essential for you to understand what AI encompasses. AI can refer to a variety of systems, including integrated applications like Microsoft Copilot and Grammarly, which assist with office productivity tasks, or more advanced large language models (LLMs) such as OpenAI’s GPT or Anthropic’s Claude, which can generate human-like responses based on vast datasets. Common types of AI models include:
- Machine Learning (ML): ML models learn from data to identify patterns and make decisions. Examples include predictive analytics tools that can forecast market trends.
- Large Language Models (LLMs): LLMs, like GPT, are trained on extensive text datasets to generate text, summarise information, or assist in customer service interactions.
- Generative AI: These AI systems, such as DALL-E or generative chatbots, create new content based on input data.
- Natural Language Processing (NLP): NLP is used for language-based tasks such as transcription or chatbots, helping automate customer interactions. AI refers to software capable of performing tasks that traditionally require human intelligence, such as data analysis, pattern recognition, and natural language processing. You might already be using AI in tools like Grammarly and Zoom—applications that employ AI for grammar suggestions, noise suppression, and real-time transcription. However, while AI integration brings many benefits, it also introduces complex legal and regulatory risks that you must manage carefully.

The Role of AI in Financial Advice: Benefits and Risks
Can AI truly revolutionise your financial advice practice without compromising compliance?
“If you are handing over part of your business to AI, you are responsible for what it does.” – Gabor Lukacs
If LinkedIn posts reflect reality, financial advisers across Australia are increasingly using AI to enhance efficiency and improve client service. I don’t want to kill the vibe, but interest does not always correlate with use, particularly in industries that are often reactionary and risk-averse. However, the team at Assured Support has been working with licensees and advisers who recognise and want to embrace the opportunities AI presents. Thankfully, they understand that alongside these opportunities lie potential risks that must be addressed.
As you start to grapple with the opportunities it presents, you need to understand how these benefits come with inherent risks:
- Client Profiling and Risk Assessment: AI can analyse vast amounts of client data to generate personalised advice based on behavioural patterns and financial histories. However, there’s a significant risk of biased algorithms, which could lead to discriminatory or inaccurate recommendations.
Recent research from King & Wood Mallesons highlights the risks associated with generative AI and the potential for privacy pitfalls, notably when AI lacks transparency or inadvertently uses sensitive data without adequate safeguards. These risks are particularly pronounced in client profiling, where algorithmic bias can lead to unfair outcomes.
- Automation of Administrative Tasks: Automating routine tasks such as fact-finding or compliance reporting can save you significant time. However, automating tasks that involve sensitive client data comes with risks. Sensitive data in financial advice can include personally identifiable information (PII) such as names, addresses, dates of birth, tax file numbers, financial details, and health information. Breaches of this data can lead to significant reputational damage, financial penalties, and loss of client trust. As such, careful management of this data is crucial to avoid severe consequences for both advisers and their clients. A case in point occurred when an Australian fintech firm, Clearview AI, breached Australians’ privacy by “scraping their biometric information from the web and disclosing it through a facial recognition tool.”.
The Office of the Australian Information Commissioner (OAIC) has issued guidance on the privacy implications of using commercially available AI products, emphasising the need for compliance with Australian Privacy Principles (OAIC, 2024). You must ensure your AI tools are used in a manner consistent with these principles, particularly when handling client data.
- Predictive Analytics for Market Trends: AI models can forecast market movements and help you proactively adjust client portfolios. However, reliance on predictive analytics without human oversight can lead to overconfidence in AI outputs.
- AI-Driven Virtual Assistance: AI-driven chatbots and virtual assistants can provide your clients with 24/7 information. However, recent cases have shown that such systems can sometimes overstep their boundaries by offering financial advice without proper regulatory oversight. In a recent example, an Air Canada chatbot inadvertently provided incorrect advice to a client, resulting in the airline being held liable for the misinformation.
Key Regulatory and Legal Considerations
“A number of uses of AI are low-risk. However, the use of personal information in AI systems is a source of significant community concern and depending on the use case, may be a high privacy risk activity. The OAIC, like the Australian community, therefore expects organisations seeking to use AI to take a cautious approach to these activities and give due regard to privacy in a way that is commensurate with the potential risks. — Office of the Australian Information Commissioner (OAIC)”
Privacy and Data Protection (APP 6, 10, 11)
The use of AI in financial advice presents challenges, especially regarding compliance with Australian Privacy Principles (APPs), as outlined in recent guidance from the Office of the Australian Information Commissioner (OAIC).
The OAIC has published specific resources detailing these requirements, which can be accessed here: Guidance on Privacy and the Use of Commercially Available AI Products.
Key Takeaways from the OAIC’s Guidance
1. Privacy Obligations for Input and Output Data
Privacy obligations apply to any personal information you input into an AI system, as well as the output data generated by AI (where it contains personal information). When adopting a commercially available product, you should conduct due diligence to ensure it is suitable for its intended uses. This should include:
- Considering whether the product has been tested for such uses.
- Evaluating how human oversight can be embedded into processes.
- Assessing the potential privacy and security risks.
- Understanding who will have access to personal information input or generated by the entity when using the product.
2. Updating Privacy Policies and Notifications
You should update your privacy policies and notifications with clear and transparent information about your use of AI. This includes ensuring that any public-facing AI tools (such as chatbots) are clearly identified as such to external users such as clients. Establishing policies and procedures for using AI systems is critical to facilitating transparency and ensuring good privacy governance.
3. Complying with APP 3 for Generated or Inferred Personal Information
If your AI systems are used to generate or infer personal information, including images, this is considered a collection of personal information and must comply with APP 3. You must ensure that:
- The generation of personal information by AI is reasonably necessary for your functions or activities and is only done by lawful and fair means.
- Inferred, incorrect, or artificially generated information produced by AI models (such as hallucinations and deepfakes) concerning an identified or reasonably identifiable individual constitutes personal information and must be handled under the APPs.
4. Secondary Use of Personal Information (APP 6)
If personal information is being input into an AI system, APP 6 requires you only to use or disclose the information for the primary purpose for which it was collected unless you have consent or can establish that the secondary use would be reasonably expected by the individual, and is related (or directly related, for sensitive information) to the primary purpose. A secondary use may be within an individual’s reasonable expectations if it was expressly outlined in a notice at the time of collection and in your business’s privacy policy.
5. Avoiding the Use of Personal Information in Publicly Available Generative AI
As a matter of best practice, the OAIC recommends that you do not enter personal information, particularly sensitive information, into publicly available generative AI tools due to the significant and complex privacy risks involved.
Cybersecurity Standards and AI Adoption
AI technologies can introduce cybersecurity risks, particularly when not aligned with standards such as ISO 27001, which governs information security management systems. ISO 27001 provides a framework for ensuring the confidentiality, integrity, and availability of data, which is critical when deploying AI in a regulated industry like financial advice. However, many AI systems rely on third-party data processing, which can conflict with the strict controls required by ISO 27001.
In the ASIC v RI Advice case, ASIC highlighted the importance of licensees maintaining robust cybersecurity and data protection measures. AI tools that do not comply with ISO 27001 or similar cybersecurity standards can introduce significant risks, especially when sensitive client data is processed via third-party servers. You must ensure that your AI systems adhere to strong access control and encryption protocols and undergo regular security audits to meet regulatory requirements.
Mitigating Legal and Regulatory Risks
Conducting AI Due Diligence
“When looking to adopt a commercially available product, organisations should conduct due diligence to ensure the product is suitable to its intended uses.” — Office of the Australian Information Commissioner (OAIC)”
Before adopting any AI tool, you should perform comprehensive due diligence:
- Testing for Suitability: Not all AI tools are suitable for financial advice. Ensure that any AI system has been rigorously tested for its intended purpose, including real-world applications and stress testing for potential failures.
- Understanding Limitations: Identify the boundaries of your AI tool, particularly for tasks involving compliance risks. For example, an AI system used for client profiling should be reviewed to ensure it doesn’t inadvertently discriminate based on age, gender, or other protected attributes.
- Mitigating Bias: You should incorporate mechanisms to check for and correct biases in AI tools. Bias in algorithms can lead to unfair or inaccurate advice, which can expose you to compliance breaches and reputational harm.
Embedding Human Oversight
” Businesses should update their privacy policies and notifications with clear and transparent information about their use of AI, including ensuring that any public-facing AI tools (such as chatbots) are clearly identified as such to external users such as customers. — Office of the Australian Information Commissioner (OAIC)”
AI should assist rather than replace your judgment:
- Accuracy Checks: When using AI to generate insights or recommendations, your oversight is essential. Regularly verify the outputs of AI systems, particularly for high-stakes tasks like client risk profiling or portfolio management.
- Explainability: You must be able to explain AI-driven decisions to both clients and regulators. Tools like Google’s AI Explainability 360 can help ensure transparency in AI decision-making processes.
Practical Steps for Incorporating AI
Successfully incorporating AI into your financial advice practice requires careful planning and execution. Each step is crucial for mitigating risks and ensuring AI enhances your services rather than creating compliance or operational issues.
To ensure successful AI adoption without increasing legal or regulatory risks, you should consider the following steps:
- Pilot Programs for Specific Use Cases: Rather than implementing full-scale AI from the start, small pilot programs should be initiated. For example, AI can automate basic administrative tasks, like client communications or data entry, before scaling to more complex applications.
- Incremental Integration: Introduce AI tools in phases. Start by using AI to automate client reports, and as the system proves reliable, it will gradually expand its use to client profiling or risk assessments.
- Auditing and Monitoring Tools: To monitor the performance of AI systems, specific tools like DataRobot for model management, Microsoft Azure AI for risk monitoring, and IBM OpenPages for tracking compliance are used. These tools offer compliance monitoring and risk management capabilities to help ensure that AI remains within regulatory boundaries.
- Testing and Validation: Set up systems to rigorously test AI-generated insights. For instance, regularly audit the system’s performance against compliance standards using tools like Splunk to monitor logs and identify anomalies that could indicate a security or compliance breach.
- Training and Capacity Building: Ensure that your team is trained to understand AI’s capabilities and limitations. For example, you should train advisers to recognise when AI recommendations deviate from best practice and require human intervention.
- Continuous Risk Assessment: Regularly assess your AI systems for potential compliance risks, such as bias, inaccurate predictions, or security vulnerabilities. Use tools like OpenAI’s GPT for compliance assessments to review and validate AI outputs that comply with privacy and data protection standards.
“As a matter of best practice, the OAIC recommends that organisations do not enter personal information and particularly sensitive information into publicly available generative AI tools due to the significant and complex privacy risks involved.” — Office of the Australian Information Commissioner (OAIC)
Risks of Not Incorporating AI
Ignoring AI integration also has its risks. If you do not adopt AI, you risk falling behind competitors who are leveraging technology to enhance efficiency and client experience. Missing out on the opportunities AI provides could mean your business appears outdated and struggles to keep up with the rapidly changing market. Competitors who embrace AI will attract more clients with faster, more personalised services, while those who resist change may face increased operational costs, inefficiencies, and ultimately reduced profitability. Failing to embrace AI could lead to inefficiencies, lower-quality advice, and, ultimately, a significant loss of market share.
Moreover, clients are increasingly expecting the convenience and insights that AI-powered solutions can provide, and you need to integrate AI to meet these evolving demands. The financial consequences of missing the AI adoption wave include losing high-value clients to more tech-savvy competitors, stagnating business growth, and an inability to scale effectively. Balancing AI adoption with robust risk management will help mitigate these risks and position your firm as a forward-thinking, client-focused leader in the industry. Start by conducting a comprehensive risk assessment, or consider reaching out to experts for a consultation to guide you through adopting AI effectively and safely.
The Future of AI in Financial Advice
While AI might become ubiquitous across industries, there is no certainty about its exact role in financial advice. It could evolve in various directions, from replacing human involvement in digital advice models to serving traditional models in innovative ways. AI might handle lower-value clients autonomously, making financial advice accessible and cost-effective for a broader audience. Alternatively, it could act as a para-planner, supporting you in a subordinate capacity by handling research, preparing recommendations, and automating administrative tasks. AI might be integrated as a partner in a more advanced role, driving the development of advice strategies and managing client relationships by providing deeper insights. It could also serve as a purely supportive thinking tool, freeing up your time to focus on high-value, human-centric aspects of your practice. You need to deliberate on your preferred approach to integrating AI, considering the technology available, your licensee’s requirements, and your client base’s specific needs and expectations. This reflection will ensure that AI adoption aligns effectively with your overall business model, enhancing rather than detracting from the quality of your services.
Artificial intelligence is a powerful tool for modernising financial advice, but its use comes with significant legal and regulatory responsibilities. You can harness AI’s full potential while minimising risks by conducting due diligence, embedding human oversight, and staying compliant with privacy and cybersecurity laws. As AI continues to evolve, staying informed about regulatory changes and best practices will be vital to delivering high-quality advice safely. You should aim to lead the charge in the thoughtful and responsible adoption of AI, positioning yourself at the forefront of innovation in financial services.
For expert guidance on integrating AI into your financial advice business, see more about evolving technologies and compliance on Assured Support.
If you enjoyed this, we recommend that you read:
Navigating AI in Financial Services
The Future of Advice in a Changing Regulatory Environment
Curated Content: AI and ethics
FAQ
1. What are the main benefits of using AI in financial services?
AI offers financial advisers significant benefits, including enhanced efficiency, client engagement, data insights, and performance optimisation. For example, AI-driven tools can automate administrative tasks, improve client profiling accuracy, and provide predictive analytics for market trends. Integrating AI effectively can help advisers deliver more personalised, timely advice, enhancing the overall client experience.
2. How can financial advisers manage the risks associated with AI?
Managing AI risks requires a proactive approach. Advisers should conduct due diligence on AI tools, implement human oversight, and regularly audit AI-generated insights for accuracy and compliance. Ensuring data privacy and transparency is essential, especially when handling sensitive client information. Advisers can mitigate risks by establishing clear AI usage policies and staying updated on regulatory requirements.
3. What privacy regulations impact the use of AI in financial services?
Privacy regulations, such as the Australian Privacy Principles (APPs), set strict standards for using personal data in AI systems. These guidelines cover both data input and output, emphasising the need for consent, transparency, and data protection. Financial advisers must ensure that their AI tools comply with these regulations, especially for client profiling and data analysis.
4. How can advisers prevent AI-driven bias in financial advice?
Bias in AI can lead to unfair client recommendations. To prevent this, advisers should regularly evaluate AI algorithms for biases, such as those based on age, gender, or other protected attributes. Implementing bias-checking mechanisms and using diverse data sets for training AI models can help reduce discriminatory outcomes and ensure more equitable advice.
5. What steps should advisers take when introducing AI tools?
Introducing AI into financial advice practices should be done in phases. Advisers can start with pilot programs focused on non-sensitive tasks, such as automating routine communications. Gradual expansion to complex applications, combined with regular risk assessments and staff training, helps ensure that AI enhances services without introducing compliance issues.