AI & platforms
AI in financial and investment advisory: What Copilot, ChatGPT and Claude actually deliver today.
The debate on AI in financial and investment advice is dominated by two overstated pictures. One promises the imminent replacement of the adviser. The other deems AI unsuitable in a regulated setting by definition. Both fall short, and both divert attention from the genuinely interesting finding.
Financial institutions already deploy AI on a large scale. In the joint 2024 survey by the Bank of England and the FCA, 75 per cent of surveyed firms stated they already used AI productively. The main benefit areas they named were data analysis, AML and fraud detection, and cybersecurity. What these figures do not show, but practice confirms, is that the greatest leverage currently lies not in automated investment decisions but in quality-assured preparatory work: research, structuring, documentation and internal processes.
The central question is therefore not whether AI should be used, but how it is planned strategically, embedded in a privacy-compliant way and anchored in processes before the first tool goes live.
Strategy first
A common mistake is entry via the tool. A model is evaluated, a pilot started, and only then it turns out that approvals are missing, data access is unclear and no one knows who is liable for the outputs. What looked like an efficiency gain becomes a governance problem.
The sound approach works the other way round. Which processes should AI support, and why? Which data flow in, under what conditions, and who is accountable for what the system outputs? Only when these questions are answered can a sensible choice be made as to which tool fits which use case. An AI strategy in a financial context is not an IT document. It is a governance document.
IOSCO names in this connection governance, data quality, bias, transparency, monitoring and outsourcing as core requirements. Not regulatory formalities, but the structure without which AI does not scale in an advisory context.
Data protection as a precondition
Before an AI tool goes live in a financial institution, one question arises that in practice is often asked too late: what happens to the data entered into the system?
In an advisory context that means client data, portfolio information, internal analyses, contractual documents. All data that fall under regulatory protection, are often classified as professional secrecy and are subject to strict requirements in many jurisdictions. Anyone who enters this data into an external language model without having clarified beforehand whether and how it is processed, stored or used for model training is not only negligent, they risk regulatory consequences.
The three large platforms address this point differently, but all with clear limits. Microsoft explains that Copilot operates within the Microsoft 365 service boundary and only accesses content for which the respective user is authorised. OpenAI explains for ChatGPT Enterprise that enterprise data are not used for training by default and are transmitted and stored encrypted. Anthropic explains the same for commercial Claude products. What all three providers share: responsibility for what is entered lies with the user, not the provider.
Data protection is therefore not a question the IT department clarifies after rollout, but a prerequisite that must be answered before the first productive use, legally, technically and organisationally. Which data classes may enter the system, which may not, how is that ensured and who monitors compliance? Without answers to these questions, every use of AI in finance remains an open risk.
Workflows: where the real work begins
A strategy on paper and a legally signed-off privacy concept are necessary but not sufficient. The decisive step is translation into concrete flows: who enters what into the system? Who reviews the output? Who approves before a result goes external? Where does model responsibility end, and where does the adviser’s begin?
Well-designed AI workflows in an advisory setting are narrowly enough defined to limit sources of error, documented enough to be audit-ready, and open enough to be reviewed and corrected by experienced staff. A workflow that envisages AI-generated results flowing without specialist review into client communication or investment recommendations is not an efficient process. It is an uncontrolled risk.
The boundary lies not in the tool but in the process. A market commentary drafted internally with AI support, then professionally reviewed and revised before it goes out, that is a clean workflow. An automatically generated investment proposal that flows unfiltered into a client document is not.
Copilot: strong in the existing workflow
Microsoft Copilot matters where banks, wealth managers or family offices already work intensively with Outlook, Teams, Excel, Word and SharePoint. Copilot accesses work-related sources, files, emails, chats and meetings, and supports users directly in familiar applications. In Outlook it prioritises inboxes and drafts replies; in Teams it summarises meetings and extracts tasks; in Excel it analyses and visualises data.
For many institutions, the privacy-relevant advantage is decisive: Copilot operates within the existing Microsoft 365 permission structure. Anyone without access to a file does not see its content via Copilot either. That makes integration into existing security architectures comparatively straightforward, but it assumes the permission structure itself is cleanly defined. An institution that does not manage file rights properly exports that problem straight into the AI workflow.
In practice Copilot delivers the greatest benefit in internal, process-close use cases: meeting materials, KYC processes, credit memos, internal reports and compliance documents. Anyone already deep in the Microsoft ecosystem finds the most direct entry here, provided flows are defined before the tool is rolled out.
ChatGPT: strong on research, synthesis and analysis
ChatGPT is particularly interesting when information from several sources needs to be brought together, evaluated and turned into a solid first draft. ChatGPT Enterprise offers admin controls, a knowledge base from internal sources, data analysis, file uploads and in-depth research capabilities. OpenAI explains that enterprise data are not used for training by default and are transmitted and stored encrypted.
In practice, a question that is often underestimated arises: what may be entered at all? For market commentaries, public company data or general scenario analyses the answer is often simple. As soon as client-related information enters the picture (names, portfolio composition, tax facts), it becomes more complex. Clear internal rules on which data classes may flow into external models and which may not must be part of the workflow, not left to each employee’s personal judgement.
For research-heavy teams the potential remains substantial. Market commentaries, company analyses, initial scenario comparisons, drafts for investment committees, structured preparation of quarterly figures: all can be prepared much faster with ChatGPT. The strength lies not in the final recommendation but in a high-quality working version that is then professionally reviewed and refined. That is not a weakness, it is the right point of use.
Claude: strong on long documents and complex knowledge bases
Claude is attractive above all where extensive documents, complex text corpora and sensitive internal information play a central role. Claude Enterprise enables secure connection to enterprise knowledge; customer data are not used for training commercial products by default. Current models work with very large context windows; for certain models Anthropic documents up to one million tokens, while Anthropic itself notes that accuracy and retrieval quality can decline as context size grows.
For document-intensive workflows the benefit lies in rapid structuring and compression of large volumes of information: annual reports, due diligence materials, participation agreements, foundation and trust documents, regulatory texts. Here, too, the question of which documents may enter the system must be answered in advance. Contractual documents with client references, internal valuation models or confidential due diligence materials fall into categories that require their own classification and approval, however comfortable the context window is. A large context window replaces neither specialist review nor the data protection decision.
What research shows
The most robust evidence for the benefits of generative AI comes from knowledge and assistance tasks. An NBER working paper by Brynjolfsson, Li and Raymond showed productivity gains averaging 14 per cent among call centre agents. A study by Noy and Zhang (2023, Science) found that ChatGPT reduced processing time on professional writing and knowledge tasks by an average of 40 per cent and improved output quality by 18 per cent. For advice-adjacent work that is immediately relevant because a large share of high-quality financial advice consists of research, structuring, wording and condensation.
In the narrower financial context, evidence is more nuanced. Some work shows language models can extract relevant signals from headlines and financial texts. Others stress limits in concrete financial planning, risks of bias and still limited reliability on numerical tasks. Bias, calculation errors and spurious precision are not fringe issues in regulated advisory, they are risks that must be addressed through sound workflows, specialist review and documented approvals.
What this means for banks, asset managers and family offices
Copilot, ChatGPT and Claude are not interchangeable tools, and the choice between them is not the genuinely hard decision. Harder and more consequential is the clean mapping of strategy, data protection, workflow and tool that must precede deployment.
Copilot is especially strong in the Microsoft-close workflow and in permission-bound everyday processes. ChatGPT is especially strong as a flexible surface for research, analysis and knowledge work. Claude plays to its strengths mainly on long documents and complex knowledge bases. None of these platforms should be integrated as an uncontrolled black box into a client-facing advisory process, and none replaces the upstream decision on which data may flow, who approves outputs and how deviations are documented.
AI in financial and investment advice is not tomorrow’s topic. Its greatest short-term lever lies not in replacing the adviser but in better, faster and more consistent preparatory work. Anyone who deploys Copilot, ChatGPT and Claude wisely gains time for what remains scarce and decisive in demanding advice: judgement, accountability, understanding the client and trust. Anyone who deploys them without strategy, without a privacy concept and without defined workflows scales errors, bias and spurious precision, and overlooks that the real risk lies not in the model but in the missing structure behind it. Digital positioning and client communication remains a separate strategic field.