Most of the firm leaders I talk to are still framing AI as a question they haven't answered yet. They're deciding whether to adopt AI, which tools to vet, and what policies to put in place. That framing is reasonable. It's also probably behind where their employees already are.

The term for this is shadow AI. It follows the same pattern as shadow IT, which most compliance and security professionals know well. When an organization doesn't provide the tools its people need to do their jobs, those people find tools on their own. They're not trying to circumvent the firm. They're trying to get work done. But the end result is the same: AI use is happening inside your organization without oversight, without defined data boundaries, and without any way to audit what's going in or what's coming out.

Consumer AI tools are free, powerful, and accessible from any phone or browser. Anyone with an internet connection can pull up ChatGPT and use it before the first morning meeting. That's not a future state. That's the current reality for most firms, whether leadership has acknowledged it or not. The firms waiting to see how AI develops should understand: the development is already underway inside their own organizations.

 

What Makes AI Use Safe

The difference between shadow AI and governed AI use isn't the capability of the tool. It's whether the firm has visibility into how the tool is being used.

When I think about what safe AI use looks like inside an organization, I come back to three criteria: observable, reportable, and safe. Observable means your firm can see what tools employees are using and in what context. Reportable means there's a record — that if something goes wrong, you can reconstruct what happened. Safe means the use operates within defined boundaries around what data can be used as input.

Shadow AI fails on all three. You can't supervise what you can't see. You can't respond to an incident you don't know is happening. And there are no data boundaries because nobody established them.

 

The Alternative Isn't "No"

A lot of firm leaders respond to the shadow AI problem by trying to ban AI. I understand the instinct. But banning AI doesn't eliminate shadow AI — it just removes the incentive for employees to tell you when they're using it. If anything, a blanket prohibition makes the problem harder to manage, because now the behavior is underground.

A better approach is to give employees a sanctioned path. That doesn't have to be a complex program. For a firm that's still figuring out its AI strategy, a basic policy is enough to start: employees may use open AI tools for general, non-sensitive tasks, but client information, proprietary firm data, and intellectual property stay out. Full stop. You can build from there. The policy that works best tomorrow can start as a page in the employee handbook today.

Part of building that sanctioned path is thinking carefully about whether the tools you're sanctioning are open or closed AI. The distinction matters in a specific way that goes beyond basic data control. Open AI models train on user inputs — which means once an employee puts client, sensitive, or proprietary data into an open model, that data is permanently out of your control. You can't take it back. The toothpaste doesn't go back in the tube. Closed models run in a controlled environment where data stays within defined infrastructure. And critically, if an employee makes a mistake and enters something they shouldn't have, that data can be deleted. For firms handling client information, moving to closed models at cost isn't just about better control over what goes in — it's about having a recoverable error state if something goes wrong.

The point isn't perfection. It's getting from "I don't know what's happening" to "I've established some boundaries, and employees know what those boundaries are." That's the difference between unmanaged risk and managed risk.
 

Financial decision making
AI Resources for Advisory Firms

Build the Policy Before Employees Build Their Own Path

Orion's AI Resource Hub brings together practical guidance on governance, security, and acceptable use — built for firm leaders who need a starting point, not a textbook.

A Threat You May Not Be Thinking About

There's a second dimension to AI security that doesn't get enough attention in the governance conversation: the external threat.

AI isn't only a tool your employees are using. It's a tool bad actors are using to come after your firm. Research on AI-enabled vulnerability detection has made clear that the time and effort required to find and exploit security gaps is decreasing as AI hacking tools improve. Firms that aren't thinking about the incoming threat environment aren't just behind on AI adoption — they're behind on their overall security posture.

My advice to firms evaluating technology partners and AI vendors: ask the question directly. What is this organization doing about AI-enabled threats — not just internal governance, but defense against externally targeted attacks? SOC 2 certification and ISO certifications are a reasonable baseline. The security posture of a vendor's leadership on this issue is also worth understanding. Any security team worth trusting should be able to answer that question clearly.

 

Start Where You Are

I've talked with firms at every stage of AI adoption, and the ones that have handled this well share one thing in common: they didn't wait until they had a complete program before doing anything. They started with something basic, learned from it, and expanded.

If your firm is still in the experimenting phase, that's fine. But experimentation without even minimal guardrails is how you end up in a situation where something goes wrong and you have no way to show the firm acted responsibly. That's a hard position — for your clients, for regulators, and for your team.

Start with the basics. Understand and monitor what tools your team is using. Define what data types can go into which environments. Document your policy, train your team on it, and monitor compliance. As AI continues to evolve and your use cases grow, you can adjust your policy and practices to keep pace. What you can't do is ignore the AI revolution and hope for the best.

Go Deeper on AI Governance

Know What Your Firm Is Working With

From data governance to external threat posture, Orion's Trust Center surfaces the security information firm leaders need to make informed AI decisions.