Two family office colleagues review an AI tool and vendor terms, with confidential documents kept closed nearby.

Most family offices are already using AI, and the decision in front of them is not whether to begin. Someone has turned on a meeting assistant that joins calls and writes summaries, an analyst is pasting deal material into a chatbot to get a first draft, and a household coordinator is running travel plans through whatever came bundled with the phone. None of that was approved, because there was nobody to approve it and no rule saying it needed approving.

The useful way to hold the question is that adopting an AI tool means placing family information inside a system the office does not control, on terms it did not write. That is the same decision the office makes when it appoints a custodian, an accountant or a managed service provider, and it belongs to whoever holds that authority rather than to whoever is most enthusiastic about the tool. Our recommendation is to start with an inventory of what is already running, before writing a word of policy, because a policy written against an imagined future adoption governs nothing that is happening now.

What the tools keep

The United Kingdom’s National Cyber Security Centre set out the mechanics plainly when the first wave of general-purpose assistants arrived. A query typed into a public service “will be visible to the organization providing the LLM”, those queries “are stored and will almost certainly be used for developing the LLM service or model at some point”, and “the LLM provider (or its partners/contractors) are able to read queries, and may incorporate them in some way into future versions.” The NCSC’s guidance to organizations follows from that: do not include sensitive information in queries to public services, and do not submit anything that would cause a problem if it became public.

Two further risks in the same guidance matter more to a family than to a company. Stored queries “may be hacked, leaked, or more likely accidentally made publicly accessible”, and the operator may later be “acquired by an organization with a different approach to privacy than was true when data was entered by users.” A family office signs up to a tool for what it does this year and inherits whoever owns it in five.

This is a counterparty question, not a technology question

The instinct in most offices is to route AI to whoever is most technical. That produces an assessment of whether the tool works, when the question is whether the office is willing to have the material in it.

Canada’s Cyber Centre published a primer in May 2026 setting out ten security actions for organizations using AI, and the governance ones read like ordinary vendor management. It tells organizations to “Map and identify sanctioned and unsanctioned models operating on a network”, to “Apply allow and deny lists for AI solutions”, to “Classify and minimize personally identifiable information (PII) in prompts”, and that “Contracts with AI vendors should include explicit data usage, privacy, audit, and liability clauses.” The NCSC-UK makes the supply-chain point directly, telling those accountable that they should “understand your data, model and ML software supply chains and can you ask suppliers the right questions on their own security.”

None of this is novel governance. ISO/IEC 42001, the international management-system standard for artificial intelligence published in 2023, builds its requirements around impact assessment, lifecycle management and third-party supplier oversight, which is the vocabulary an office already uses for any other service relationship.

An office that has run a security review on its advisors already knows how to do this. The questions are the ones it puts to any counterparty holding family information: what the vendor retains, for how long, who inside the vendor can read it, whether the material trains anything, where it is stored, what happens on termination, and what the office is told when something goes wrong. The only genuinely new question is whether the material is used to improve a model, because that is the one commitment a conventional processing agreement was never written to cover.

Why the family’s information is the harder half

Corporate acceptable-use policy assumes the material at stake is commercial. A family office runs meetings that no such policy contemplates: a principal’s medical position ahead of a succession decision, a dispute between siblings over a trust, a philanthropic commitment that is not yet public, the terms of a divorce, a security assessment of a residence. A meeting assistant admitted to the calendar does not distinguish between those and a manager review, and the resulting transcript sits wherever the vendor puts it under terms nobody in the room has read.

The population is wider than the payroll, too. Household staff, family members and the office’s outside advisors all hold family information and all have their own devices and their own subscriptions. A rule that reaches only employees reaches perhaps half of the people who could put family material into a tool, which is the recurring shape of the household perimeter problem in a new setting.

We recommend a short written standard on what may never be entered into a general-purpose tool, expressed in the family’s own terms rather than in data-classification language: nothing about a principal’s health, nothing about a minor, nothing that identifies a residence or a travel movement, nothing under legal privilege, and nothing about a transaction that has not closed. A list a household coordinator can hold in their head governs more behavior than a taxonomy that needs interpreting.

Autonomy changes the calculation

The tools that write summaries are giving way to tools that take actions, and six cybersecurity agencies across five countries published joint guidance on those in 2026: the United States CISA and NSA, Australia’s ACSC, the Canadian Centre for Cyber Security, New Zealand’s NCSC and the United Kingdom’s NCSC. Its three headline instructions are worth reading as they are written. Organizations should “Begin with agentic AI use cases that are low-risk and non-sensitive”, should “Avoid granting broad or unrestricted access, especially to sensitive data or critical systems”, and should “Account for agentic AI security in your organization’s security model and risk posture.”

That last instruction is the one a family office is most likely to miss. A tool that can read the mailbox, move a file or initiate a payment is not a productivity purchase, and it sits inside the same control environment as the people who can do those things. An office that requires two humans to approve a transfer has not preserved that control if a tool acting for one of them can prepare and submit the instruction, which is why anything with authority over money belongs inside the transfer authorization rules the office already operates rather than alongside them.

The United States National Institute of Standards and Technology groups the risks of generative systems into twelve categories in its 2024 profile, among them confabulation, data privacy, information security, and value chain and component integration. Confabulation is the one to explain to the family in plain terms: these systems produce confident text that is sometimes wrong, so output that will inform a decision needs a named person who checked it.

What to build

The work is smaller than it sounds, and none of it requires a technical program.

  • Inventory what is running. Ask every person who touches family information which AI tools they use, including ones that came free with something else. Expect the list to be longer than anyone predicted, and treat nobody’s answer as a disciplinary matter, or the next inventory will be wrong.
  • Name the approver. One person decides whether a tool may hold family information. In most offices that is the executive who already holds vendor authority, not the person who understands the technology best.
  • Write the never list. Short, concrete, in the family’s language, covering health, minors, residences, movements, privilege and live transactions.
  • Decide the meeting-assistant rule before the next meeting. Whether a recorder may join, who announces it, who can object, and which standing meetings it may never enter. This is the most common tool in family offices and the least governed.
  • Put the retention and training questions in the contract. What is kept, for how long, who can read it, whether it trains a model, and what happens to it when the office leaves.
  • Require a human owner for anything that informs a decision. Not review of every output, but a named person accountable for the ones that matter.
  • Start any tool that can act, rather than only write, at the smallest scope that is useful, and widen it only when the office can see what it has been doing.

What to ask this week

Which AI tools are holding family information today, and who approved them? If a meeting assistant joined a call about a principal’s health last month, where is that transcript now and who can read it? Who in this office is allowed to decide that a new tool may be used? What have we agreed with our existing providers about whether our material trains their models? And if a tool produced an analysis that turned out to be wrong, whose name is on the decision that relied on it?

Where this sits

Assessing what a provider does with the family’s information is the same discipline as running a security review on your advisors, and deciding who holds the authority to approve a tool is one row in the wider accountability problem that most offices have never allocated.

Writing the standard, running the inventory and settling the approval route is work we handle through cybersecurity program development, and keeping it current as the tools change is what ongoing advisory is for.

Sources

National Cyber Security Centre (United Kingdom), ChatGPT and large language models: what’s the risk?, 14 March 2023

National Cyber Security Centre (United Kingdom), AI and cyber security: what you need to know, 13 February 2024, reviewed 31 July 2026

Canadian Centre for Cyber Security, Top 10 artificial intelligence security actions: A primer, ITSAP.10.049, May 2026

CISA, NSA, ASD’s ACSC, Canadian Centre for Cyber Security, NCSC-NZ and NCSC-UK, Careful Adoption of Agentic AI Services, 30 April 2026

National Institute of Standards and Technology (United States), Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1, 26 July 2024

ISO/IEC 42001:2023, Artificial intelligence management system