News and updates from Maple

AI acceptable use policies: what financial firms need in place before staff start using Copilot, Claude, ChatGPT or Gemini image

AI acceptable use policies: what financial firms need in place before staff start using Copilot, Claude, ChatGPT or Gemini

More than 80% of financial services firms are already using or adopting AI in some form, that's not a forecast, it's the current baseline according to the FCA's own chief executive, speaking earlier this summer. Chances are your staff are already using more than one of Copilot, ChatGPT, Claude and Gemini, whether there's a policy covering it or not, and increasingly we're seeing Claude specifically show up in client environments alongside the more obvious Microsoft tools.

That gap, adoption running ahead of governance, is where most of the real risk sits right now. Not exotic, futuristic AI risk, ordinary information security risk wearing a new coat: client data pasted into a public chatbot, a junior analyst treating an AI-generated summary as fact-checked without saying so, nobody quite sure who signed off on the new AI note-taking tool that's suddenly in every meeting.

Why "no policy" isn't actually a neutral position
Some firms hold off on an AI policy because they haven't formally "rolled out" AI yet. That's a misread of what's actually happening. Staff don't wait for permission, they find tools that make their job easier and use them, and different tools quietly end up in different teams. Without a policy, you don't have less AI use, you have the same AI use spread across more tools with no visibility, no boundaries, and no record of what was used for what.

What a proper AI acceptable use policy actually covers

  • Data classification: a clear, specific answer to "what can and can't go into an AI tool", especially client data, not a vague instruction to "be careful"
  • An approved tool list and sign-off process: someone specific reviews and approves new AI tools before they're used with work data, rather than finding out after the fact, and the list needs to name the actual tools in use, Copilot, Claude, ChatGPT, Gemini, and whatever shows up next
  • Human oversight where it matters: anything that touches a client decision, an investment view, or regulated advice needs a human checking it, not just an AI draft going straight out
  • Logging and an audit trail: a record of what AI tools were used for what, so you can answer for it later if a regulator, auditor or client asks
  • Staff training that's specific, not generic: the judgement calls people actually face, not a slide deck about "AI ethics" nobody remembers

What this looks like for financial services specifically
The FCA's stated approach is that AI is a technology, not a regulated activity, meaning the rules that already apply to your firm apply to how you use AI too, there's no separate AI rulebook waiting to arrive. But that's created real pressure of its own: the House of Commons Treasury Committee has told the FCA to publish practical guidance by the end of 2026 on how existing rules, including accountability under the Senior Managers and Certification Regime, apply when AI causes harm. In plain terms: if an AI tool gets something wrong and a client is affected, a named senior manager may be expected to answer for it, whether or not there's a specific AI policy on record, and regardless of which specific tool was involved.

If you have any EU exposure, the EU AI Act adds a second layer, though the timeline has recently shifted. High-risk system obligations, likely to catch credit scoring, underwriting and similar use cases, were pushed back from August 2026 to December 2027 following a political agreement in May. That's breathing room, not a reason to wait, the categories and expectations are already broadly known.

How we help
We help clients draft AI acceptable use policies that are specific enough to actually use, not generic templates lifted from elsewhere. That includes reviewing which tools are already in use across a business (often more, and more varied, than leadership expects), setting up the technical guardrails, like data loss prevention rules that stop sensitive information leaving through any of these tools, and building the staff training around real scenarios rather than abstract principles.

If you don't have an AI policy yet, the honest starting point is finding out what's already being used, and by who. That conversation is worth having now, while it's still a planning exercise rather than an incident review.