Your analysts already paste case data into AI tools. Give them a governed door

Vasco Alexandre
September 15, 2026

The question is no longer whether compliance teams will use AI tools on customer files. They already do, mostly by copying a case summary into a chat window and pasting the answer back. The real choice is between a channel nobody can see and a channel you govern, and we think only the second is defensible.
In Microsoft and LinkedIn's 2024 Work Trend Index, published in May 2024, 78% of people using AI at work said they bring their own AI tools to work. Compliance teams are not an exception. They are knowledge workers with long documents, repetitive writing and too many open tabs, which is exactly the profile those tools were built for.
A paste is the least compliant way for data to move
Think about what happens to a case when an analyst copies it into an AI tool.
- Identity is lost. The AI tool does not know who is asking, so it cannot know whether that person should see this file.
- Permissions are lost. A member restricted to one space can paste a case from it into a conversation that lives forever outside it.
- Provenance is lost. The pasted text no longer says which value came from a register and which one the customer declared.
- The trail is lost. Nobody can later say which data left the system, when, and for what.
Every one of those four is something a compliance team is paid to protect. The copy and paste workflow strips all of them, quietly, many times a day.
Banning it removes the visibility, not the use
The instinctive response is a policy: no customer data in AI tools. It is a reasonable sentence to write and a hard one to enforce. The work does not get smaller, the AI tool is one tab away, and the people under the most pressure are the ones most likely to use it anyway. What the ban reliably produces is use that nobody reports.
So the better question is not whether, but on what terms.
Four conditions before an AI tool touches a compliance file
1. It acts as a named person, with that person's permissions. No shared service account, no key with more rights than the human using it. If you cannot approve a case in the console, your AI tool cannot approve it either.
2. It is checked on every call, not once. Membership, MFA, SSO and IP restrictions verified again at each request. A connection approved in January should not still work in March for someone who left in February.
3. Writes are labelled, and confirmation stays on. The AI tool should know which actions read, which change data and which delete it, and should ask before anything that approves, rejects or emails someone. Reading is cheap to get wrong. Writing is not.
4. Nothing to leak, and revocable at once. Sign-in through the browser with the person's own account, so there is no API key to create, store, paste into a config file or rotate. Revoking the connection should cut access on the very next request.
A fifth follows from the first four: the AI tool should read from the system of record, with its sources, instead of from a snapshot someone pasted last week.
What we decided not to do
Two choices are worth stating, because they are the ones people ask about.
Configuration stays in the console. An AI tool connected to Dotfile can read templates, controls, risk settings and AML screening profiles, and explain why a case was routed the way it was. It cannot change them. Explaining a setup from a chat is safe and useful; changing a risk engine from a chat is a different level of risk, and we would rather be slow on that one.
No new chat window to adopt. Teams already have the AI tool they like. Asking them to switch to ours for compliance work would recreate the copy and paste problem in reverse. The better design is to make the compliance system reachable from the tool they already use, on the compliance system's terms.
Accountability does not move
None of this changes who is responsible. The firm owns the decision whatever tool was open when it was made. What governed access changes is the answer to the question a supervisor will eventually ask: who did what, with which data, under which permissions. With copy and paste, nobody can answer it. With a governed connection, the answer is the same as for any other action in the system.
That is why we built the Dotfile MCP the way we did: your AI tool acts as you, with your permissions, checked on every call, and you can cut it off in one click.

Ready for Anywhere?
Verify any business, enter any market, defend every decision. Every signal orchestrated, every decision traceable, from one platform.



