Artificial intelligence (AI) is significantly expanding the range of tools available to advisors. Many of them use AI tools on a daily basis, as the Insurance Portal reported earlier this year. In fact, AI is profoundly transforming business practices at all levels of financial product distribution. But AI is not without risk.
The situation becomes more complex when advisors use AI tools without fully understanding their implications. AI is not only programmed to be helpful, but it also tends to want to please… Experts and regulators say we must be wary of it and adapt our practices accordingly. The issue is one of professional ethics: the professional responsibility of advisors is at stake.
The topic is attracting the attention of regulators. For example, Quebec’s Autorité des marchés financiers (AMF) published an online version of its Guideline for the Use of Artificial Intelligence last April. The guideline, which will come into effect on May 1, 2027, is intended for the financial services industry.
Furthermore, hiring an AI expert is not enough, as a panel at a recent roundtable of the International Association of Insurance Supervisors (IAIS) concluded. It is essential to learn how to work with this technology and, above all, to understand its risks. This warning also applies to advisors themselves.
A new guide
In June, the firms Virage Coaching, CY-clic, and the business law firm Bernier Beaudry published a free guide in French entitled IA générative : mode d’emploi pour conseillers financiers avertis (Generative AI: A User's Guide for Savvy Financial Advisors). The authors produced this guide, which is expected to be updated and published in English in the fall of 2026, knowing that many advisors have a poor grasp of the ethical risks associated with AI. In this context, AI represents both a human and a technological risk.
“The guide stems from our experience providing training to advisors,” explains Sophie Babeux, partner and executive business coach at Virage Coaching, in an interview with the Insurance Portal. “Two years ago, when we began writing the guide, AI was new. We didn’t know how to approach it. Some advisors weren’t using it correctly because the information lacked clarity. Many aspects of AI put them at risk in terms of professional liability…A guide was essential,” she said, “especially since many blind spots remain when using AI tools, particularly regarding the hosting and use of client data. And Bill 25 on the protection of personal information (Quebec legislation) adds another layer of complexity.”
“You have to be curious, almost obsessive, to understand which practices truly protect us as advisors, because some aspects of AI lack clarity,” Babeux continued. These include where the data is hosted, the difference between paid and consumer AI tools, the various versions of AI applications, and the contractual data protection agreements in related applications, such as Teams, which use AI.
There are notable differences between ChatGPT, Microsoft Copilot, Gemini, Claude, Perplexity, Guru, Adobe Firefly, DeepL, Otter.ai, Fireflies.ai, PinPoint, Cleo, Read AI, DeepL, Deepseek… And this list could be much longer.
Ethics
Quebec self-regulatory body, the Chambre de la sécurité financière (CSF), clarifies that, to date, there have been no disciplinary decisions related to the use of AI.
“As for the ethical obligations related to the use of AI by professionals, these are included in the fundamental principles of the code of ethics, notably the duty of competence (which includes technological competence), the duty of confidentiality and protection of personal information, as well as the duty of honesty and transparency,” writes Geneviève Fontaine, spokesperson for the CSF, to the Insurance Portal.
She adds that AI is just one tool among many; It does not replace professional judgment or the representative's responsibility. "Its use must always remain safe, transparent, and focused on the client's best interests," she underlines.
The CSF reiterates the obligation to document in detail all uses of AI, to keep technological skills up to date, to protect the confidentiality of personal information, to be transparent with clients, and to verify the accuracy of the results.
What is at risk?
Some uses of AI fall into a grey area and require active vigilance from the advisor, particularly the synthesis of drafting notes and the search for technical information.
Therefore, when recording a conversation, explicit consent from the other party is required, regardless of the platform used.
The generative AI guide specifies that written consent is a solid ethical safeguard, but verbal consent is acceptable, provided it is documented… in a recording.
Once the conversation is over, the AI will be used to transcribe and even summarize the exchange. The results, often surprising, must nevertheless be considered with caution. Before performing this transcription, it must be depersonalized by removing all sensitive information, especially if using an external AI tool.
The audio file of the conversation, as well as the AI-generated transcription, must then be kept in the client's file.
On the other hand, many advisors use AI applications to conduct technical information searches, such as determining the RRSP contribution limit for a given year. The effectiveness of AI in this area may be surprising, but it is essential to verify the results with another credible source, especially an official one, before sharing them with the client.
What is prohibited
The guide specifies four practices prohibited by professional ethics:
- submitting personal data to AI;
- automating the duty of care;
- altering documents;
- usurping someone's identity.
For most AI applications, users do not know where their data is stored. “In an ideal world, the hosting provider should be a Canadian company, with servers located within our borders,” explains Emeline Manson, founder of CY-clic and an expert in fraud prevention and cybersecurity, in an interview. There are several, but how can someone using AI know this? Is the application configured accordingly?
Moreover, it's necessary to go beyond this aspect by choosing never to submit personal information or complete statements to a public AI. This constitutes a data breach, punishable under Bill 25. In fact, some experts believe that such data should even be avoided in the first place when it comes to AI licensed to the company or firm to which the advisor is affiliated.
As for the automation of suitability assessments, the ethical guidelines are clear: it is forbidden to apply assessments generated by an AI tool without exercising professional judgment and analysis. Failure to do so is considered a breach of the duty to act in the client's best interests.
Finally, it is forbidden to create false documents, such as proof of income or signatures, or to alter documents in this way. It is also forbidden to clone the voice or image of a client or colleague without written consent. Violating these two prohibitions constitutes serious professional misconduct, or even a criminal act or fraud.
Depersonalizing yourself
Depersonalizing or anonymizing a document means removing all personal information: name, social insurance number (SIN), address, social media contact information, phone number, email address, medical data, etc. The temptation is to automate this process. Doing so with AI is a mistake, because as soon as text or data is copied into an AI tool, that technology will use that information. Depersonalization must be done manually. Good old copy-and-paste is the way to go.
The generative AI guide suggests three steps to achieve this. The first step is to remove the data from a word processor (Microsoft Word, Apple Pages, LibreOffice, OpenOffice) or a spreadsheet (Microsoft Excel, Apple Numbers, OpenOffice, LibreOffice Calc). Note: Google Docs and Google Sheets are not reliable for this task, as their servers are generally located in the United States or controlled by American companies, and therefore subject to US law.
The guide illustrates this point as follows: if the anonymized text appeared on a billboard, would it still allow the customer to be identified? If the answer is "yes," further anonymization is necessary.
Next, you copy and paste the data-redacted document into the AI application's interface. You then copy and paste the text provided by the application, re-entering the sensitive data into a secure, local document. It is at this stage that the accuracy of the information is verified, using the sources provided by the AI tool, but also with other sources deemed reliable by the advisor.
“Personally, I never copy and paste a document generated by AI,” comments Emeline Manson. “You have to think of AI as an intern who possesses a lot of knowledge but is constantly learning and needs supervision. A real person must always meticulously verify all information provided by the AI.”