Financial data rarely leaks through the AI tool itself. It leaks through the everyday habit of exporting, copying and forwarding files. Banning AI tools treats the symptom, not the cause. The real fix is governed, permissioned access, so there's no reason to export a copy in the first place.
Almost every board conversation about AI in the finance function starts the same way. Is it actually safe to let this near our numbers?
It's a fair question to ask. It's just usually aimed at the wrong thing.
The moment financial data really becomes exposed rarely has much to do with which AI tool someone happened to use. It happens earlier than that, at the point someone exports it in the first place.
Follow the file, not the tool
Picture a finance officer pulling this quarter's numbers into a spreadsheet to answer a quick question. That spreadsheet gets emailed to a colleague for a second opinion. It sits on a laptop that goes home every evening. A copy gets attached to a message because something's urgent and the file server feels too slow for the moment. Somewhere along the way, a chunk of it gets pasted into whatever AI tool happens to be open in another tab, because typing out a proper request feels like it'll take too long.
None of this is careless. It's just what working quickly actually looks like inside most finance teams, not-for-profit or otherwise. Six months on, though, nobody in the organisation could really say where that data ended up, or how many copies of it exist by now.
For a for-purpose organisation, what's usually sitting inside those files isn't trivial. Think participant or client information tied to NDIS or other individualised funding packages. Donor records and giving history. Grant figures that haven't been reported to funders or the board yet. The board commentary someone drafted honestly, then quietly softened before it actually went out.
None of that needs a clever attack to leak. It just needs the ordinary path a spreadsheet takes once it wanders outside the system it was meant to stay inside.
The fix isn't banning AI tools
The instinctive response is to lock everything down, to restrict access to AI tools altogether. It treats the symptom rather than the cause though. Exporting, copying, forwarding and pasting is a habit that's been around long before AI showed up. Ban one destination and the same behaviour just finds a new one.
The real fix sits in the architecture, not in policing behaviour. Give people governed, properly permissioned access to the data they actually need, and there's simply no reason left to export a copy in the first place. When access is scoped properly, a staff member sees only what they're meant to see, works with it inside the system it belongs to, and nothing new gets created that anyone has to keep track of.
The principle we build every implementation around: one governed source of truth, accessed under proper permissions, rather than a dozen exported copies scattered across inboxes, laptops and personal devices.
Where this fits into the work we do
This is exactly why governance and privacy guardrails sit inside our data remediation work from the start, rather than getting bolted on afterwards. Before any system rollout or AI tooling goes anywhere near live data, we scrub personally identifiable donor and participant information out of open memo fields, partition restricted funds properly, and build audit trails that align with what the ACNC expects. The data itself ends up structured to be safely accessed, not just hoped to behave.
A clean, well-governed data foundation isn't really a compliance box to tick. It's what actually decides whether using AI safely is a genuine, defensible practice, or just a policy document nobody follows.
If you couldn't say with confidence where your organisation's financial data actually lives, or who holds copies of it, that's worth talking through before any new tool gets introduced.
Contact us