Executive briefings · AI security research
Insights
Written for the partners of regulated firms. Every regulatory claim is checked against the document itself, because most published errors in this market are scope errors rather than factual ones.
Featured
Start here · Copilot for regulated firms, in reading order
- 01Copilot Does Not Leak. It Reveals.Why an assistant finds what staff could always open, and what to check first.
- 02Governed Copilot vs ClaudeWhat differs when Claude runs inside Copilot, row by row, and where a prompt goes.
- 03Claude's Microsoft 365 ConnectorWhat it reads, where the content goes, and who turned it on.
- 04Governed vs Ungoverned CopilotThe same license, set up or switched on, and the five questions that tell you which you have.
- 05The Copilot Change LogWhat Microsoft changed, dated, with the setting it touches and what it means for a regulated firm.
Published briefs
AI governance · Copilot series, 5 of 5The Copilot Change LogWhat Microsoft changed in Copilot, dated, with the setting it touches and what it means for a firm that holds client data. Newest first.Read →
AI governance · Copilot series, 4 of 5Governed vs Ungoverned CopilotThe same product on the same license. What differs is what it can read, which AI models it may use, and whether anyone can show what was decided. A plain guide for partners who are just starting to ask.Read →
AI governance · Copilot series, 3 of 5Claude's Microsoft 365 ConnectorIt sees only what each person can open. What matters more is who consented, from which Claude plan, and where the content goes next: one consent covers the tenant, every Claude plan can use it, and what it reads is kept with the chat.Read →
AI governance · Copilot series, 2 of 5Governed Copilot vs ClaudeCopilot can already run Claude, on by default for most commercial customers outside the EU and UK. What differs for a regulated firm is the contract, the controls and where the data goes, row by row, and the five questions to answer first.Read →
Microsoft 365 · Copilot series, 1 of 5Copilot Does Not Leak. It Reveals.Microsoft 365 Copilot surfaces to a user exactly what that user could already open. The exposure was already there; the assistant only makes it findable. Five checks before a rollout, and what to keep as the record.Read →
AI governanceEnterprise-Approved AI: What Circular 230 Now Asks You to ShowOPR Alert 2026-19 applies six Circular 230 sections to AI-assisted tax work. Most of the coverage has been about hallucinations. The section that reaches the partners is 10.36, it asks for procedures to be documented, and the term it turns on is never defined.Read →
Professional conductWhat are a law firm’s duties when client information goes into an AI tool?ABA Model Rule 1.6(c) asks for reasonable efforts against inadvertent disclosure, and Formal Opinion 512 applies it to generative AI. What reasonable means here, and what the firm has to be able to show.Read →
SEC Reg S-PWhat does an affiliated investment adviser add to a CPA firm’s obligations?A second safeguards regime on the same systems, with a different examiner. 17 CFR 248.30 reaches the adviser, the FTC Safeguards Rule reaches the practice, and one set of controls has to answer both.Read →
AI governanceCan I put client tax data into ChatGPT?Not into a personal account, without each client’s consent. What 26 U.S.C. 7216(a) treats as a disclosure, why the vendor’s training policy does not decide it, and what consent has to look like.Read →
FTC SafeguardsHow long does a firm have to notify the FTC after a data breach?Thirty days. 16 CFR 314.4(j) sets the clock from discovery of a notification event, not from the end of the investigation, and 314.2(m) decides what counts as one.Read →
Cyber riskWhat a Cyber Insurance Application Actually AsksWe filled out our own before handing one to a client, and could not answer four questions. Not because the controls were missing, but because the record proving they ran did not exist.Read →
