Prudex AI

Plain answers

Can your firm use AI without client data touching a public model?

Prudex AI · September 1, 2026 · 3 min read

This is the first question most regulated firms ask about AI, and it deserves a direct answer: yes. A firm can run serious AI systems without client data ever reaching a public model in the way the question fears. But the answer depends on distinctions that vendor marketing tends to blur, so it is worth being precise.

The distinction that matters: consumer tools vs business APIs

When people picture client data "going into the AI," they usually picture a consumer chat window. That picture is right to worry about. Consumer AI products carry consumer terms, and depending on settings, what goes in may be retained or used to improve the product. An advisor pasting a client's statement into a free chat tool is a compliance incident, not a workflow.

Business API access is a different arrangement. At the major providers, data sent through the business API is not used to train models by default, retention is limited and contractual, and the terms are written for exactly this concern. The same company can offer both; the terms are what differ. So the first honest reframe of the question is: it is not about whether AI is involved, it is about which door your data walks through.

Whose account, whose contract

The second piece is who holds the provider relationship. When a system runs on your own AI provider account, under your own key, the handling of your data is governed by a contract between your firm and the provider, and you can read every word of it. You are not relying on a vendor's summary of somebody else's terms.

This is how we build every system: the client owns the AI account. It also means that if you ever part ways with your builder, the provider relationship, like the system, stays with you.

Where the system itself runs

Model terms are half the story; the other half is where the application and its data live. A single-tenant deployment in your own environment means the finished system, its records, and its stored documents sit in accounts your firm controls. There is no multi-tenant platform holding a copy of your client base, because there is no platform at all. For firms whose information cannot leave their walls, fully private deployments go further still.

The quiet option: scope the data out

The cleanest answer to "how is client personal information protected" is often "the system never handles it." A surprising amount of high-value work, research synthesis, document drafting from templates, internal knowledge retrieval, can be built so that client identity is not part of the workflow at all. Where a system genuinely must handle personal information, that should be agreed explicitly and in writing before the build starts, not discovered in an audit.

Five things to verify, whoever you work with

  1. Business API or consumer product? Ask which specific access tier the system uses, and read that tier's data terms.
  2. Whose account? If it is not yours, ask why not.
  3. Where does the system run? Your environment, or a platform holding many firms' data?
  4. Is personal information in scope? If yes, where is that written down?
  5. Is any of this verifiable? Terms you can read beat assurances you have to trust.

A firm that gets five satisfactory answers has not eliminated risk, nothing does, but it has moved the question from faith to paperwork, which is where compliance lives.

Our own practices on all five are documented on the trust page, and walking through them for a specific system your firm has in mind is a good use of a complimentary consultation.