All answersM22 Answers · updated September 2026

How can a UK family office use AI safely with confidential data?

Short answer

A family office can use AI safely with confidential data when the tool is a business tier that does not train on your data, you know where data is stored and processed, permissions are enforced before an answer is retrieved rather than only when it is shown, every question and answer is logged, and a person approves anything before it leaves the office. M22 Consultancy builds permission-aware systems on these lines, UK GDPR-native, with a human approving anything that matters and the client owning what is built.

A family office can use AI safely with confidential data if five things are true: the tool is a business tier that does not train on your data, you know where data is stored and processed and for how long, people can only retrieve what they are already allowed to see, every question and answer is logged, and a person approves anything before it leaves the office. The model matters less than the route your data takes. It is also the standard M22 Consultancy builds to when it puts an AI system over a client's own records.

The actual risks

  1. Training on your data. Consumer plans can be used for training; Anthropic's consumer terms let Free, Pro and Max users choose, and keep data for five years if they opt in. Business tiers say they do not train on business data by default.
  2. Retention. Prompts, files and answers are stored for a period and can be held longer where the law requires. Know the number for each tool.
  3. Access across family members and entities. An assistant connected to everything will answer anyone about everything unless permissions are enforced when it retrieves, not only when it displays. Microsoft says Copilot only surfaces data a user has at least view permission for, so loose SharePoint permissions become loose answers.
  4. Staff pasting into consumer chatbots. In a Censuswide survey of 2,003 UK employees for Microsoft in October 2025, 71% had used unapproved consumer AI tools at work and 22% had used them for finance-related tasks.
  5. Jurisdiction. Sending personal data to a separate organisation outside the UK is a restricted transfer under UK GDPR, which needs adequacy regulations or a safeguard such as the International Data Transfer Agreement, plus a transfer risk assessment.

What the business tiers say about your data

From each vendor's own documentation, checked September 2026. Terms change, so confirm against your contract.

ToolTraining on business dataUK or EU residency
ChatGPT Business and Enterprise; OpenAI APINot by defaultUK data residency for eligible Enterprise, Edu and API customers
Claude Team and Enterprise; Anthropic APINot by default, unless you send feedbackUS storage by default; regional processing available via Amazon Bedrock or Google Cloud
Microsoft 365 CopilotPrompts, responses and Graph data not used to train foundation modelsEU Data Boundary for EU customers; Microsoft expects UK in-country processing by the end of 2026
Gemini in Google WorkspaceNot used for training outside your domain without permissionData regions of US or Europe only, no UK option

This is why M22 is model-agnostic: it builds on whichever of these fits a client's residency and governance needs, for example Claude, ChatGPT or Microsoft Copilot, and can move the underlying model later without rebuilding the system around it.

The controls that matter more than the vendor

  • Permission-aware retrieval. The system checks who is asking before it fetches anything, mirroring entity and family-branch access. Test it with a junior login before anyone relies on it.
  • Answers with sources. Every answer cites the document it came from, so a person can check it in seconds.
  • Audit logs. Who asked what, what was retrieved and what was answered.
  • Human approval before anything leaves the office. Emails to banks, payment instructions, filings and messages to family members wait for a named person's yes. See human-in-the-loop automation.
  • A one-page policy. Which tools are approved, which classes of data may go into them, and who to ask.

UK GDPR and the ICO

A family office that decides why and how personal data about family members, staff and counterparties is used is the controller under UK GDPR; an AI vendor processing that data on its behalf is a processor. The ICO says that in the vast majority of cases, using AI involves processing likely to result in a high risk to individuals, which triggers the legal requirement for a data protection impact assessment (DPIA). It also expects you to evaluate a third-party AI tool's trade-offs as part of due diligence. M22 is UK GDPR-native, which means this assessment is built into how it scopes a system, not bolted on afterwards.

A first 90 days

  1. Days 1 to 30. Ask staff, without blame, which AI tools they already use. Classify data into public, internal and family-confidential tiers. Choose one business tier, sign its data processing agreement, set retention, and turn on single sign-on and multi-factor authentication.
  2. Days 31 to 60. Complete a DPIA for the first use. Tidy folder and mailbox permissions by entity and family branch before connecting any AI to them. Pilot one low-risk job, such as meeting notes, with a small group and logging switched on.
  3. Days 61 to 90. Read the logs and the errors. Decide whether to connect more sources through permission-aware retrieval, and set a quarterly review of tools, retention and access.

How does M22 handle this?

M22 Consultancy builds the Company Brain: a permission-aware hub over a firm's files, email, meetings and numbers, where people only get answers from material they are allowed to see and every answer carries its sources back to the document it came from, an approach described on the work page. A named person approves anything that matters before it acts. It is UK GDPR-native and model-agnostic, and the client owns the code, data and documentation, so the system does not depend on M22 remaining the supplier. Before any of that, the AI Audit, a fixed fee from £1,500 and sized to the business, maps where confidential information actually moves today, so permissioning is designed around how the office really works rather than guessed at.

If confidentiality is the question you need answered before anything else, the fastest way to test a supplier's approach is to ask for a live demonstration with two different logins. For a straight answer on how M22 would map your permissions, book a thirty-minute call at m22.group/contact.

Questions people also ask

How much does M22's AI audit cost?

From £1,500, a fixed fee agreed before day one. There is no set length: it is sized to the business, and it maps the real handoffs, including where confidential information moves, before anything is built.

Does M22 work with family offices on confidential data?

Yes. M22 Consultancy works with UK businesses in every sector, family offices included, and builds permission-aware systems as standard, not as an add-on, for any client with confidential records to protect.

Who owns an AI system M22 builds over confidential records?

The client does. Code, data and documentation belong to you, not M22, and the system is model-agnostic, so changing the underlying model later does not mean starting again.

Is ChatGPT Enterprise safe for confidential family office data?

It can be, if configured properly. OpenAI says it does not train on ChatGPT Enterprise data by default, admins control retention, and eligible customers can store data in the UK. You still need tidy permissions, a DPIA, a data processing agreement and a clear policy.

Do we need a DPIA before using AI in a family office?

Almost certainly. The ICO says that in the vast majority of cases, using AI involves processing likely to result in a high risk to individuals, which legally requires a data protection impact assessment.

Written and maintained by M22, a London-based AI consultancy. Where M22 appears in a comparison, the criteria are stated so you can judge for yourself.

More answers