
By Mark O'Malley, Founder and Managing Director of DSC.
A family office may already be using AI, even if there is no documented AI Policy & Strategy in place. AI often appears quietly, perhaps through a principal's subscription, an executive's personal account, employee drafts, meeting assistants, or browser extensions.
Users rarely act with bad intentions; they simply want to work faster.
However, when AI is used without approval, governance, security oversight, or monitoring, it becomes Shadow AI — technology operating without visibility or control.
The main concern is not whether families should use AI, but whether they are using it in a controlled and governed way.
When useful tools create unseen exposure
Often, family office principals, executives, and staff sign up for AI subscriptions directly, without involving technology, cybersecurity, or governance advisers. Most choose free $0 plans, while others pay out of pocket to solve immediate problems.
Whether free or paid, almost every Shadow AI account we have reviewed lacked organizational policies or technical controls to prevent family office information from being shared with consumer AI services outside the governed environment.
Risks also appear when AI connects to inboxes, finance platforms, documents, photo libraries, calendars, or meetings. Like any personal software account, a personal AI subscription makes it difficult for the office to manage configuration, data retention, connected applications, and plug-ins. It also raises the question of what happens to family office information retained in these applications when a user leaves or changes roles.
Client scenario #1:
A family office principal and executive believed existing policies meant no Shadow AI was in use. Our audit identified 11 instances: six on desktop computers and five on mobile devices. None had organizational controls governing family office data, and more than three-quarters were using free accounts. One Shadow AI instance was used by the CFO, a role with access to some of the office's most sensitive financial systems and information.
The risk becomes clear when you look at information, permissions, and provider practices, especially when data moves outside managed systems or adviser controls.
Why family offices are different
Family office teams are often small, with many part-time roles. Their responsibilities often span investments, banking, legal matters, tax, succession, identity, residences, travel, and health. Private family information is shared among principals, executives, employees, family members, and advisers.
Client scenario #2:
A mature, large family office selected and set up ChatGPT on their own without configuring the necessary back-end policies or ongoing monitoring. After a mobile app update, users were completely logged out of the office-managed ChatGPT subscription. They kept entering sensitive information without realizing they were outside the governed workspace. Since authentication status, policy exceptions, and usage logs were not proactively monitored, the issue was not found quickly.
Approving a platform is not the same as governing it. This is why AI must be secure by design and monitored in operation.
Traditional cybersecurity is still important, but it does not answer every question about AI. For example: What information is entered? Is it kept or used for training? What can the tool access? Who checks its output and stays accountable?
A blanket ban on AI is unlikely to work
A strict ban can drive AI use out of sight. Without an approved option, users may pick whatever is easiest. Good governance should allow helpful use within clear boundaries.
A practical guide: four ways a family office can adopt AI
Family offices often ask us whether they should use 'private AI' or governed enterprise AI. The best choice depends on their IT systems, the sensitivity of their information, and their current level of cybersecurity maturity.
The safest option is not always the most private one; it is the one that can be managed well. Poorly maintained private AI can increase risk, and weak enterprise permissions can make things worse. Responsibilities for configuration, monitoring, log review, exception reporting, and incident response should be explicitly assigned, while the family office retains overall accountability.

Before selecting an AI architecture, ask:
What business benefit are we seeking?
What information must AI access?
What risk are we addressing?
What is our current cybersecurity maturity across the systems AI will connect to, and can we operate the chosen architecture safely?
A practical governance response
Having the right architecture does not replace the need for good governance.
Start by discovering current AI use throughout the office.
Document the AI Policy & Strategy. Define requirements, objectives, ownership, and risk appetite.
Approve platforms and use cases. Approval must be purpose-specific, and consequential outputs must remain subject to qualified human review and accountability.
Define information boundaries. State what AI may process and which data or systems are prohibited.
Govern identity and access. Use enterprise accounts, MFA, and controlled integrations.
Monitor and report continuously. Review logs, policy exceptions, configuration changes, and emerging Shadow AI.
Maintain an AI Governance Register. Through a structured change management process, record each tool or agent, its purpose, owner, users, connections, information classification, and review cycle.
Visibility before control
Family offices do not have to choose between innovation and confidentiality. However, they cannot manage technology they do not know is in use. Before selecting an AI architecture, the first questions should always be: Where is our information already going today, where is it stored, and who controls it?
-
Mark O'Malley is Founder and Managing Director of DSC, an Australian technology, cybersecurity, and Secure AI governance firm working with family offices across Asia-Pacific. DSC establishes governed AI environments and proactively monitors technology risk.


