Assess
Enable
Build
Sustain
Govern
Research
Resources
About
Contact
Governance July 20, 2026

Shadow AI at Investment Firms: Stopping Deal-Data Leaks Before They Happen

Author

Dr. Leigh Coney

Founder, WorkWise Solutions

Published

July 20, 2026

Reading Time

16 min read

TLDR: Shadow AI is staff using personal, unsanctioned AI accounts for real work, and at an investment firm the exposure is confidential deal and portfolio data leaving your control. People do it because the tools genuinely help, so a ban mostly pushes the activity into accounts you cannot see. The facts to build on: commercial plans (Claude Team, Enterprise, API; ChatGPT Enterprise and Team) do not train on your data, while consumer plans can unless the user opts out, which is why a pasted CIM is a problem. Retention is separate from training: Team and Enterprise chat keeps your data out of training but still retains conversations, so never assume "nothing is stored," and true zero-retention is an API or Claude Code configuration. For a fund the exposure is concrete: NDA breaches, MNPI handling, and Reg S-P customer-data rules with a June 3 2026 compliance date for larger entities. The fix is sanctioned tools plus a short, usable policy, so the safe path is the easy path rather than a prohibition that drives usage underground.

1. What Shadow AI Is, and Why It Is Everywhere

Shadow AI is employees using AI tools the firm has not approved, usually personal accounts on free or consumer plans, to do their actual work. An associate pastes a CIM into a personal ChatGPT to summarize it. An analyst drops portfolio-company financials into a free tool to reformat a model. It is the AI version of shadow IT, and it is happening at most firms right now whether or not anyone has said so out loud.

The activity is almost always well-intentioned, which is what makes it hard to see. Nobody is trying to leak anything. They are trying to finish faster, and the tool genuinely helps them do it. That is the whole tension: the behavior that creates the risk is also the behavior that makes people more productive.

The scale is easy to underestimate. AI assistants are now built into browsers, phones, email clients, and office software, so the tools are one tap away from every employee whether or not the firm sanctioned them. When something that useful is that available, some fraction of the team will use it on real work. Assuming it is not happening at your firm is usually a reporting gap, not a fact.

At an investment firm the data involved raises the stakes. A confidential CIM, a data room export, a set of management projections, sometimes material non-public information, are exactly the documents that should never sit in an employee's personal AI account. This guide covers why that is a real exposure and how to fix it without a ban that just moves the problem out of sight.

2. Why Smart People Paste the CIM

It helps to understand why careful people paste the CIM, because the fix depends on it. The productivity gain from a good AI assistant is large and well documented. The research quoted below found average productivity gains of about 14 percent, with the largest gains, around 34 percent, going to the least experienced workers. When a junior analyst can turn a two-hour summarizing job into fifteen minutes, they will reach for the tool that does it.

The personal account is often the closest one to hand. If the firm has not stood up a sanctioned tool, or has stood one up that is worse than the free version, the personal login wins by default. People route to whatever gets the work done, and a friction-free consumer app beats a clunky approved one every time.

There is a quality gap working against you too. The best consumer apps are genuinely excellent, and if the firm's approved option is an older model behind three logins, people will notice and route around it. The sanctioned tool has to be good enough that using it is not a sacrifice. Winning here is partly a procurement decision: buy the capable plan, wire up single sign-on, and make it the fastest way to get the work done.

This is why a prohibition alone tends to fail. Telling people not to use AI leaves the reason they use it fully intact, while stripping away your visibility into where they use it, which makes the exposure worse rather than better. The firms that actually reduce shadow AI compete with the personal account instead of banning it.

3. Why It Is a Real Exposure for a Fund

For an investment firm the stakes run higher than for a typical company, for three concrete reasons.

Deal data is usually NDA-bound. A CIM, a data room export, management projections: these come to you under confidentiality terms that never contemplated "pasted into a third-party AI account." A leak is a breach of the NDA before it is anything else, and the counterparty does not have to prove harm to be unhappy about it.

Some of it is material non-public information. Put MNPI into any external tool and you have created an information-handling problem that a regulator and your own compliance manual both care about, regardless of whether the tool trains on it.

Client and investor data is regulated. The Reg S-P amendments, with a compliance date of June 3 2026 for larger entities, tighten how advisers safeguard customer information and respond to incidents. A confidential document sitting in an employee's personal AI account is exactly the kind of unmonitored data path those rules are built to close.

Add a fourth pressure that is easy to forget: your own promises. Side letters and LP agreements often carry confidentiality terms about fund and portfolio information, and a leak through a personal AI account can put you offside with your investors, not only a deal counterparty. Reputation compounds the exposure. In a business built on being trusted with sensitive information, the story that a confidential document walked out through an employee's chatbot is the kind that follows a firm into its next fundraise.

None of this requires a breach in the Hollywood sense. It takes a hurried associate, a personal login, and a document that should never have left the firm's controlled tools.

4. The Data Facts, Stated Correctly

Here is the part people get wrong, and it matters because the wrong version is either falsely reassuring or needlessly alarming. These are the facts to build the policy on.

Commercial plans do not train on your data. Claude Team, Claude Enterprise, and the Anthropic API, along with ChatGPT Enterprise and Team, do not use your business inputs and outputs to train their models. That is the core reason a firm buys them.

Consumer plans can train on your data unless you opt out. Free and Pro consumer accounts may use your conversations to improve models unless you turn that setting off. This changed in 2025, and most people never touch the setting. The risk is direct: a personal account's default can feed your confidential document into model training.

Retention is a separate question from training. Even on a commercial plan that never trains on your data, conversations are still stored under standard retention settings. So the accurate statement is that Team and Enterprise chat keeps your data out of training while still retaining conversations. Anyone who tells you a Team or Enterprise chat means "nothing is stored" is overstating it.

True zero-data-retention is a specific configuration. Zero-retention is available as an API or Claude Code setup, where inputs and outputs are not persisted. A Team or Enterprise seat does not give it to you automatically. When the data is sensitive enough that retention itself is the concern, that is the configuration to ask for.

One newer wrinkle deserves a mention. Connecting an AI assistant to your live systems, through the Model Context Protocol or similar connectors, can be powerful and can also widen the data path when it is set up carelessly. The same rule applies: use sanctioned connections inside the firm's environment, with someone accountable for what data the assistant can reach, rather than letting individuals wire personal accounts into firm data.

The one-line version for staff: confidential firm data goes only on the firm's sanctioned commercial tools, never in a personal account, and when retention itself matters, use the zero-retention API path. For the full comparison, our guide on Claude Enterprise vs Team vs API lays out which plan fits which data.

5. Risky Habits and Safe Alternatives

Most shadow AI reduces to a handful of habits. Here is each one, why it is a problem, and the safe alternative that does the same job.

Risky habit Why it is a problem Safe alternative
Pasting a CIM or data room document into a personal ChatGPT or Claude account Confidential and often NDA-bound. On a consumer plan the content can be used to train models unless the user has opted out. Use the firm's commercial plan (Team or Enterprise) or an API workflow, where business data is not used for training.
Uploading portfolio-company financials to a free AI tool to clean up a model Same confidentiality exposure, plus you lose any audit trail of where the data went. A sanctioned tool with single sign-on, logging, and data controls.
Using a random browser AI extension to summarize a deal email Unknown data path and unknown sub-processors; the extension may send content anywhere. An approved assistant inside the firm's environment.
Sharing MNPI with any AI to get a quick read before it is public An insider-information handling problem regardless of the tool or its settings. No MNPI in any AI tool until it is public; wall it off explicitly in policy.
Assuming a Team or Enterprise chat means nothing is stored Commercial plans do not train on your data, but conversations are still retained under standard settings. Know the actual setting; use a zero-retention API or Claude Code configuration when the data demands it.
Banning AI outright to stay safe Drives usage into personal accounts you cannot see, which is worse than the problem you started with. Provide sanctioned tools plus a short usable policy so the safe path is the easy path.

Two rows in that table cause the most confusion, and they are the ones about training versus retention. People hear that the firm plan does not train on their data and mentally upgrade it to nothing being kept, which is a different and stronger claim. Keeping those two ideas apart is what lets you set the policy correctly: commercial plans solve the training problem, and the zero-retention API configuration is what you reach for when retention itself is the risk.

The through-line is that every risky habit has a safe version that is roughly as convenient. That is the whole strategy: make the safe path the easy path, so the personal account stops being the obvious choice.

6. The Fix Is Safe Tools Plus a Short Policy

The firms that actually reduce shadow AI make the safe path the easy path. Three moves do most of the work.

Give people sanctioned tools. A firm-provided commercial plan (Team or Enterprise) with single sign-on, logging, and data controls removes the main excuse for personal accounts, because the sanctioned tool is right there and it is better than the free one. If the approved option is worse than the consumer app, people go around it, so quality matters as much as approval.

Write a short, usable policy. One page, in plain language: which tools are approved, what data can go where, what never goes into any AI tool (MNPI until public, anything a specific NDA forbids), and who to ask when unsure. A policy nobody reads protects nobody, so length works against you.

Make the classification obvious. People leak data because they cannot tell in the moment what counts as sensitive. Give them a rule they can apply without calling compliance: firm and deal data goes only on the sanctioned tool, public information can go anywhere, and when in doubt, treat it as confidential.

The fourth quiet move is a short conversation. Tell people plainly why the rule exists: that a pasted CIM on a personal account can end up in training data, and that a leak is an NDA breach before it is anything else. People follow a rule they understand far better than one handed down without a reason. Ten minutes of context at a team meeting beats a policy PDF nobody opens.

Notice what is missing from that list: a ban. A prohibition is the move that feels safe and performs badly, because it drives the behavior into exactly the personal accounts you cannot monitor. Competing with the personal account beats forbidding it.

7. What Goes on the One Page

If you write only one thing this quarter, write the one-page policy. Here is what belongs on it, concretely.

The approved tools, named, with how to log in. Vague references to "authorized tools" send people back to Google.

The data rule: firm, deal, and portfolio-company data only on the approved tools, never in a personal account.

The hard stops: no MNPI in any AI tool until it is public, and nothing a specific NDA prohibits.

The retention note: the approved commercial tools keep your data out of model training but still retain conversations, so use the zero-retention path for the most sensitive material.

The when-in-doubt line: treat it as confidential and ask the named owner.

Set a date to revisit the page, because the tools move. New models, new plans, and new connectors show up every few months, and a policy that named last year's approved tool quietly becomes wrong. A quarterly ten-minute review keeps the one page honest, which is the difference between a living rule and a compliance artifact.

Keep it to a page, because a policy people can hold in their head is the one they follow. Many firms still have no written AI policy at all, so even a rough one-pager puts you ahead of a large share of your peers.

8. Where to Start

Start by finding out what is actually happening, without turning it into a witch hunt. Most shadow AI is well-intentioned people trying to do good work faster, so the goal is to redirect it. Ask the team which AI tools they reach for and why, and the answers tell you which sanctioned tools to stand up first.

For the portfolio-company version of this problem, our Secure AI Adoption engagement ($7,500 per company) puts sanctioned tools, a one-page policy, and the right data settings in place at each company, so staff have a safe path instead of a personal login.

For the firm itself, an AI Readiness Sprint ($12,500 flat for firms up to 20 people; the $30,000 Comprehensive Discovery Sprint for firms of 20 or more) baselines where confidential data is going today and hands back the policy, the tool choices, and the rollout plan. Either way the fix has the same shape: give people something good enough that the personal account stops being tempting.

"Access to a generative AI assistant increased worker productivity by about 14 percent on average, with the largest gains, around 34 percent, going to the least experienced and lowest-skilled workers."

Erik Brynjolfsson, Danielle Li, and Lindsey Raymond, National Bureau of Economic Research (2023)

Key Takeaways
  • Shadow AI is staff using personal, unsanctioned AI accounts for real work; at an investment firm the exposure is confidential deal and portfolio data leaving your control.
  • People do it because the tools genuinely help, so a ban mostly pushes the activity into personal accounts you cannot see.
  • The data facts, stated correctly: commercial plans (Team, Enterprise, API) do not train on your data; consumer plans can unless you opt out; that default is why a pasted CIM is a problem.
  • Retention is separate from training: Team and Enterprise chat keeps your data out of training but still retains conversations, so never assume "nothing is stored." True zero-retention is an API or Claude Code configuration.
  • For a fund the exposure is concrete: NDA breaches, MNPI handling, and Reg S-P customer-data rules with a compliance date of June 3 2026 for larger entities.
  • The fix is sanctioned tools plus a short, usable policy, so the safe path is the easy path instead of a prohibition that drives usage underground.
  • Many firms still have no written AI policy at all, and it is the cheapest governance gap to close first.

Frequently Asked Questions

What is shadow AI?

Shadow AI is employees using AI tools the firm has not approved, usually personal accounts on free or consumer plans, to do their actual work. Someone pastes a CIM into a personal ChatGPT to summarize it, or drops portfolio-company financials into a free tool to reformat a model. It is the AI version of shadow IT. The activity is almost always well-intentioned, which is what makes it hard to see: nobody is trying to leak anything, they are trying to finish faster. At an investment firm the problem is that the data involved is confidential, often NDA-bound, and sometimes material non-public information, so a helpful shortcut becomes a real exposure.

Is it safe to paste deal documents into ChatGPT?

It depends entirely on which account. On a personal free or Pro plan, no: those consumer plans can use your conversations to train models unless you have turned the setting off, so a confidential CIM can end up in training data. On a firm-provided commercial plan (ChatGPT Enterprise or Team, or Claude Team or Enterprise), the position is much better, because commercial plans do not train on your business data. One caveat people miss: commercial plans still retain your conversations under standard settings, so "does not train on it" is not the same as "nothing is stored." When the data is sensitive enough that retention itself is the concern, use a zero-retention API configuration. The simple rule for staff: confidential documents go only on the firm's sanctioned tools, never a personal login.

How do I stop employees using unauthorized AI tools?

Give them a better authorized option and a rule they can actually follow. A ban alone fails, because the productivity gain is real and people route around it into personal accounts you cannot monitor. What works is three moves: provide a sanctioned commercial tool with single sign-on and logging so the safe option is the convenient one; write a one-page policy that says which tools are approved and what data can go where; and give a dead-simple classification rule so people know in the moment what counts as confidential. Our Secure AI Adoption engagement ($7,500 per company) sets exactly this up at a portfolio company. The goal is to make the sanctioned path the path of least resistance.

Related Guides & Articles

Give your team a safe AI path

The fix for shadow AI is a safe path that is easier than the personal account. Our Secure AI Adoption engagement ($7,500 per company) sets up sanctioned tools, a one-page policy, and the right data settings at a portfolio company. For the firm itself, an AI Readiness Sprint ($12,500 flat for firms up to 20 people; the $30,000 Comprehensive Discovery Sprint for firms of 20 or more) baselines where confidential data is going today and hands back the tools, the policy, and the rollout plan.

Book a Call
Schedule Consultation