Artificial intelligence is expanding the range of tools available to financial advisors, but it's also creating new professional liability risks that many don't fully understand. Quebec's financial regulator and industry experts are warning that advisors who use AI without grasping its ethical implications could face serious consequences, including disciplinary action and legal liability.
The stakes are high enough that Quebec's Autorité des marchés financiers (AMF) published its Guideline for the Use of Artificial Intelligence in April, with the rules taking effect May 1, 2027. The guidance applies to the entire financial services industry in the province.
Training alone won't solve the problem. A panel at a recent roundtable of the International Association of Insurance Supervisors (IAIS) concluded that hiring an AI expert isn't sufficient - professionals themselves must learn to work with the technology and understand its risks.
A practical guide for advisors
In June, Virage Coaching, CY-clic, and the business law firm Bernier Beaudry published a free French-language guide titled IA générative : mode d'emploi pour conseillers financiers avertis (Generative AI: A User's Guide for Savvy Financial Advisors). An English version is expected in fall 2026.
The guide grew out of the authors' work training advisors, many of whom had a poor grasp of the ethical risks associated with AI. "Some advisors weren't using it correctly because the information lacked clarity. Many aspects of AI put them at risk in terms of professional liability… A guide was essential," said Sophie Babeux, partner and executive business coach at Virage Coaching. She pointed to blind spots around data hosting and client information, which Quebec's Bill 25 on personal information protection complicates further.
Advisors need to understand the differences between tools like ChatGPT, Microsoft Copilot, Gemini, Claude, and Perplexity - where data is hosted, how paid and consumer versions differ, and what protections apply. "You have to be curious, almost obsessive, to understand which practices truly protect us as advisors, because some aspects of AI lack clarity," Babeux said.
What the code of ethics requires
Quebec's Chambre de la sécurité financière (CSF) confirmed there have been no disciplinary decisions related to AI use to date. But the existing code of ethics already covers it, according to Geneviève Fontaine, CSF spokesperson.
"As for the ethical obligations related to the use of AI by professionals, these are included in the fundamental principles of the code of ethics, notably the duty of competence (which includes technological competence), the duty of confidentiality and protection of personal information, as well as the duty of honesty and transparency," Fontaine said.
AI doesn't replace professional judgment. "Its use must always remain safe, and focused on the client's best interests," she said. The CSF requires advisors to document all AI use in detail, keep technical skills current, protect confidential information, be transparent with clients, and verify the accuracy of AI-generated results.
Grey areas require vigilance
Two common uses of AI fall into risky territory: synthesizing conversation notes and searching for technical information.
Recording a conversation requires explicit consent from the other party, regardless of platform. The guide recommends written consent as the safest approach, though verbal consent is acceptable if documented in the recording itself. After the conversation, any transcription must be depersonalized before being processed by an external AI tool. The audio file and AI-generated transcription should be kept in the client's file.
For technical searches - like determining an RRSP contribution limit - AI results must be verified against a credible official source before sharing them with a client. The tools are often surprisingly effective, but they're not reliable enough to trust alone.
Four prohibited practices
The guide identifies four practices forbidden by professional ethics:
- Submitting personal data to AI
- Automating the duty of care
- Altering documents
- Usurping someone's identity
Most AI applications don't disclose where user data is stored. "In an ideal world, the hosting provider should be a Canadian company, with servers located within our borders," said Emeline Manson, founder of CY-clic and an expert in fraud prevention and cybersecurity. But even with Canadian hosting, advisors should never submit personal information or complete statements to a public AI - that constitutes a data breach punishable under Bill 25.
Using AI-generated suitability assessments without exercising professional judgment is a breach of the duty to act in the client's best interests. Creating false documents, altering proof of income or signatures, or cloning a client's voice or image without written consent constitutes serious professional misconduct - potentially even a criminal act.
Depersonalization must be manual
Anonymizing documents means removing all identifying information: name, social insurance number, address, phone number, email, medical data, and more. The temptation to automate this with AI is a mistake - as soon as data is copied into an AI tool, the technology uses it. Depersonalization must be done manually.
The guide recommends a three-step process: remove sensitive data in a word processor or spreadsheet first (Google Docs and Google Sheets are unreliable for this because their servers are generally located in the United States), then copy the redacted document into the AI application, and finally paste the AI's output back into a secure local document, re-entering sensitive data and verifying accuracy against reliable sources.
Manson suggests a simple test: if the anonymized text appeared on a billboard, could the client still be identified? If yes, more work is needed. She also advises treating AI output with skepticism. "Personally, I never copy and paste a document generated by AI," she said. "You have to think of AI as an intern who possesses a lot of knowledge but is constantly learning and needs supervision. A real person must always meticulously verify all information provided by the AI."
Advisors who want to build practical AI skills can start with AI for Insurance training, which covers the specific risks and best practices for the sector. For a deeper look at the tools themselves, Generative AI and LLM courses explain how these systems work and where they're most likely to fail.
Why this matters for insurance professionals
Insurance advisors handle sensitive client data daily - medical records, financial statements, and identification documents. Every time that information touches an AI tool, it may be stored on servers outside Canada and used to train future models. The professional liability exposure is real: a single data breach under Bill 25 can trigger regulatory penalties, and a suitability assessment generated by AI without proper review could amount to a breach of the duty of care. Advisors should establish a documented workflow now - one that includes manual depersonalization, written consent for recordings, and verification of AI output against official sources - before regulators start testing compliance.
Your membership also unlocks: