AI Just Exposed This Firm's HR Secrets — Here's How to Avoid It

John O'Connell of The Oasis Group on the AI mistakes already putting wealth management firms at risk — and the boring, overlooked use cases quietly paying off.

A wealth management firm turned on Microsoft Copilot, connected it to SharePoint, and assumed their HR directory was safe. It wasn't. Employees could ask Copilot directly who was on a performance improvement plan — and it answered.

That's the story John O'Connell, Founder and CEO of The Oasis Group, opens with on this episode of The Modern Financial Advisor Podcast. John has spent 2026 doing little else but talk to wealth management and RIA leaders about AI — 20-plus keynotes, a standing gig as Schwab's AI speaker, and a monthly AI WealthTech Map tracking 110+ firms — and he joins host Mike Langford to lay out exactly where the industry is getting AI right, where it's quietly exposing itself to risk, and what a financial advisor should actually do about it starting this week.

Connect with John O’Connell on LinkedIn and The Oasis Group

What You'll Learn in This Episode

  • John's five-camp framework for AI adoption in wealth management: Vanguards, Roadrunners, Tasmanian Devils, Bison, and Ostriches — and where most firms actually fall

  • How a Microsoft Copilot and SharePoint permissions gap exposed one firm's executive salaries and HR records

  • Why "vibe coding" an AI tool without a developer review can open the door to SQL injection attacks and runaway token bills

  • Why the best first AI use case in your firm is the most boring task, not the flashiest one

  • How AI can help new financial advisors reach "escape velocity" faster, using FINRA's own retention data

  • Why "written by advisors for advisors" should raise your guard, not lower it

Why This Matters for Financial Advisors Right Now

Is AI actually a cybersecurity risk for financial advisors? Yes — and the risk usually isn't the AI model itself, it's the permissions sitting underneath it. John's central warning in this episode is that AI tools inherit whatever access model already exists in a firm's systems. If a SharePoint folder is "hidden but not secured," a chatbot layered on top of it doesn't know the difference — it just answers the question. That's exactly what happened to the firm John describes: Copilot didn't break any rules. It followed the access permissions that were already quietly broken.

This matters for every firm in Mike's audience because the fix isn't exotic. John's advice: before you plug any AI tool into existing software, ask where your data actually goes, who can access it, and whether your permissions model would survive someone asking the wrong question. He also makes the case that free AI tools carry a second risk most advisors haven't priced in — firm data like fee schedules can end up used for training or debugging outside the United States the moment it's typed into a free tool.

The episode also tackles a tension every RIA principal feels: the AI tools are moving fast, but most RIAs are small businesses with no developer on staff. John's answer is refreshingly unglamorous — don't start with your flashiest, most client-facing idea. Start with the task your team hates most. Let AI document that workflow, iterate on it, and build comfort before anyone touches a client-facing use case. And if a vendor pitches a custom-built AI tool, John's advice is blunt: get a professional developer to pressure-test it before it goes anywhere near client data, because the kind of vulnerability that leaked over two million people's financial information in the real-world MOVEit breach started with exactly the kind of overlooked "what if" question most non-technical teams never think to ask.

Finally, John and Mike connect AI directly to one of the industry's most persistent problems: advisor retention. FINRA data shows 85% of financial advisors quit before year five — right around the point most successful advisors say it finally "clicked" for them. John's take: firms that use AI to compress the 7-to-9-year runway to owning a book of business, instead of just automating tasks for existing producers, are the ones that will fix this.

"You gave your people a chainsaw, turned it on, and you're asking them to juggle with it and not hurt anybody. That's probably not gonna work out well."
— John O'Connell, Founder & CEO, The Oasis Group

Resources Mentioned in This Episode

Related Episodes

Frequently Asked Questions

What are the biggest AI security risks for financial advisory firms?
The biggest risk isn't the AI tool itself — it's inherited permissions. AI tools like Microsoft Copilot answer based on whatever access controls already exist in a firm's systems. If those permissions have gaps, AI can surface sensitive data (like HR records or executive salaries) that was never meant to be visible, simply because it was "hidden" rather than properly secured.

What's the best first AI use case for a financial advisory firm?
According to John O'Connell, it's not a client-facing use case — it's the most boring, most-dreaded task in the firm. Starting with low-stakes internal workflows (like summarizing email threads or formatting recurring documents) builds comfort with AI before extending it to anything client-facing.

How can AI help new financial advisors succeed faster?
FINRA data shows 85% of financial advisors quit before their fifth year — right around when most successful advisors say they finally felt it click. AI can compress that learning curve by teaching new advisors firm processes, financial planning basics, and client conversation triggers much earlier in their careers.

Mike Langford
Founder & CEO of finservMarketing. Financial services industry veteran with over 20 years of experience in both retail and institutional segments. Early pioneer in the use of social media and digital marketing for financial advisors.
Next
Next

Why "Curation Over Accumulation" Is the New Private Markets Playbook for Advisors