Every protection fact find is a conversation about dying.
Not in those words. But somewhere in it a client tells you what they have been treated for, what they take every morning, whether they smoke and how honestly, and what their mother died of and how old she was. It is the most private twenty minutes a broker ever spends with anybody, and the reason it happens at all is the thing nobody in the room says out loud. Death is guaranteed. Only the timing is uncertain.
So I asked an AI engine whether it could help run one.
July
It was careful. Among the considerations it listed was this:
"Be careful about entering personally identifiable or sensitive health information into AI systems."
Sensible. Then it set out a practical workflow, and step two reads:
"During the meeting, AI transcribes and summarizes the conversation."
The fact find is the health information. It warned me off putting health data into an AI system, then put an AI in the room while it was spoken aloud. It went further at the close and offered to build one:
"it's possible to build an AI-assisted fact-find that asks questions conversationally, produces compliant notes, and hands you a completed case file for review."
Not transcribing the conversation any more. Having it.
That was July. I wrote it up as a contradiction and left it there, and if the article had gone out on that it would have been wrong in a more interesting way than I expected.
This morning, twice
Two months later I put the identical question to the identical engine, in the identical words, logged out. Then I did it again a few minutes after that.
The first answer was better than July's. It framed AI as a co-pilot, it kept the adviser responsible for the regulated decision, and it said this:
"For a UK advice business, I'd also build in data protection, consent, audit trails, human oversight and clear boundaries around automated decision-making, particularly because protection fact finds can involve sensitive personal and medical information."
There it is, named outright. Sensitive personal and medical information, flagged as the reason to build controls. That is a genuinely better answer than the one I got in July, and it does not contradict itself: the caution frames the workflow instead of undoing it.
The second answer, minutes later, does not mention health in the caution at all.
Here is everything it says about controls:
"You'd want appropriate controls around things such as client consent, data protection, record keeping, accuracy, human oversight and the use of AI outputs."
No health. No medical. Nothing about sensitivity.
Health appears exactly once in that answer, and it appears here, in the list of things the AI should be doing:
"guiding the conversation through family, income, debts, existing cover, employer benefits, health/lifestyle, budget and objectives"
Alongside:
"turning a client conversation into structured fact-find notes"
Health has moved out of the warning and into the job description. In the space of a few minutes, on the same question, the most sensitive thing in the room went from being the reason to build controls to being one item in a list between employer benefits and budget.
Three answers, three positions
July. It warned against entering sensitive health information into AI systems, and then transcribed the meeting.
This morning, first draw. It named medical sensitivity outright, as the reason to build controls.
This morning, second draw. It listed health as a thing to ask about, and never mentioned it in the caution.
There was a fourth, an earlier July draw, and our note from that day records that it did not mention health data at all. I am describing it rather than quoting it because the transcript did not survive, which is its own small lesson about relying on what a tool told you once.
What this actually means for you
The useful finding is not that any one of these answers is dangerous. Read on its own, each is reasonable. The first September answer is genuinely good.
The finding is that there is no "what the tool says".
You cannot test it once in the quiet week and rely on it in the busy one. You cannot tell a colleague what they will get, because they will not get it. You cannot point at it afterwards and say this is what we were told, because the next person to ask was told something else.
If you had run this question in July, you would have come away believing the tool warns you about health data. If your colleague ran it this morning, they may have come away believing health is simply one of the things it asks about. Both of you would be describing the same tool accurately.
That is a different problem from the one everybody worries about. It is not that the machine is reckless. It is that there is nothing stable there to build a process on.
It is not only this question
The July capture covered six questions, all of them the kind a broker would actually type. Five of the six named a safeguard and then set out a workflow that removed it, in the same answer, a few hundred words apart.
On file notes: "Avoid pasting personally identifiable client information into public AI tools unless your firm's policy permits it." Then the worked example provides the AI with a transcript of a client meeting, which is personally identifiable client information.
On call summaries: "Review how the AI service stores, processes, and retains your data, especially if calls contain sensitive or confidential information." Then the recommended approach is "Transcript-based summarization, where you upload or paste a transcript after the call for AI to summarize."
On client emails: "Avoid entering sensitive personal or financial information unless you're using an approved, secure AI service that complies with your firm's policies." Then, for a better draft:
"Personalize quickly. Provide AI with: Client's first name, Loan or policy type, Current stage of the process, Any important deadlines, Desired tone (friendly, formal, reassuring). This helps produce a tailored draft in seconds."
These are single draws and I am not going to pretend otherwise. What today shows is that a single draw of any of them would probably not reproduce either.
The one that did not do it was worse
The sixth question was about chasing clients for their documents, and it broke the pattern by containing no data protection language at all. No consent, no storage, no retention.
What it did contain was a fully automated workflow, and a list of what you would be chasing:
"ID documents, Proof of address, Bank statements, Payslips, Tax records, Signed forms."
Close to a complete picture of a person's financial life, with an AI agent emailing, texting reminders, answering the client's questions about what is acceptable, and escalating only the cases that "genuinely need a human to step in".
The question carrying the most sensitive paperwork produced the answer with the least said about handling it.
The only thing that never changed
Across every answer here, over two months, on questions that agree with each other about almost nothing, one thing is constant.
An "approved, secure AI service". Whether "your firm's policy permits it". Following "your firm's data handling policies". Using "enterprise or compliant AI solutions where appropriate". Building in "audit trails, human oversight". Wanting "appropriate controls". Adding "compliance guardrails".
Approved by whom. Against what standard. Recorded where. Reviewed when, and by which named person.
Not one of them said. The words that carry the entire weight of the thing are the words that survive every redraw, and they are the ones with nothing behind them.
For a firm with a compliance function, "approved" points at a process somebody could go and look at. For an appointed representative, or a directly authorised firm of one to five, it points at nobody.
What I am not claiming
This is one engine. ChatGPT with search enabled, four draws, two months. It is not a survey, it is not a benchmark, and it says nothing about what a different tool would do.
Two draws cannot show a direction of travel. One September answer was better than July and one was arguably worse. That is variance, not improvement and not decline, and anyone telling you these tools are getting safer on the strength of two good answers is making the same mistake in the opposite direction.
Some of this was not written for you. One of the July answers closed by asking:
"If you mean a specific type of broker (for example, a mortgage broker, insurance broker, freight broker, customs broker, or business finance broker), I can suggest workflows tailored to that industry."
It had already given me the workflow. Whose job it was came afterwards, as an offer.
And two of the answers partly corrected themselves, which belongs here because a piece about hidden contradictions cannot hide the good bits. One suggested replacing identifying details with placeholders while drafting. Another closed by saying AI should be treated "as an assistant that prepares work for the broker to review, rather than as an autonomous decision-maker".
Where this leaves you
I am not going to tell you what an approval process should contain, or what belongs in a register, or how to make any of these workflows defensible. Those are real questions, they do not have a paragraph-length answer, and a piece that pretended otherwise would be doing the thing it has just spent two thousand words describing.
What I will say is that the tools will not flag this for you. Every one of these answers was fluent, reasonable and helpful. Not one mentioned that it might have said something different five minutes earlier.
So the question is not whether your AI tool mentioned data protection. It probably did.
It is whether you could show anyone what it told you, and whether that would still be true today.