IoniumMEMOS

MEMO · AUGUST 2026

The counterparty that happens to be software.

Organizations are careful about counterparties. A new broker, a vendor with access to the books, a hire who will see the client list — each gets some version of the same treatment: who are you, what will you do with what we give you, what happens if you misuse it. The discipline is so ordinary nobody names it. Which is why the current moment is strange. Organizations have been handing their information to a new class of counterparty, AI tools, largely without any of it.

The vetting that matters is not technical. For this purpose, understanding a tool has nothing to do with understanding how a model works. It means knowing, practically, what happens to what you give it: where the input goes, who can see it, how long it is kept, whether it trains someone else’s system, and what the provider’s terms actually say — the terms, not the landing page. Any diligence process would put those questions to a vendor holding sensitive material. They just have not caught up with tools that arrive through a browser tab and a personal credit card.

One profession has already written the standard down, and the document is instructive mainly for how unexceptional it is. In July 2024 the American Bar Association issued Formal Opinion 512, its first ethics guidance on generative AI. Competence, it says, means understanding at a practical level what a tool does with what it is given. Confidentiality duties apply in full to anything entered into an AI tool, the same as anything handed to any third party. Tools that learn from what users type need informed consent before protected information goes in, and boilerplate buried in an engagement letter does not count. Notably, the opinion bans nothing — no prohibition on cloud tools, no required architecture. A famously cautious profession looked at the newest technology in a generation and concluded that ordinary counterparty diligence already covers it. Provided, of course, that someone actually does the diligence.

The cost of skipping it has become a public record. Damien Charlotin, a research fellow at HEC Paris, keeps a database of court and tribunal decisions dealing with AI-fabricated citations and quotations in filings. It passed 1,800 decisions this summer, hundreds of them added in the first half of 2026, with fines, fee awards, and disciplinary referrals attached to named individuals. Nearly every entry is the same story: output trusted where the duty was to verify. Lawyers just happen to be the profession whose failures become published opinions. The same failure elsewhere — an invented figure in an investment memo, a confident error in a client deliverable, a sensitive document pasted into a tool that keeps it — is quieter, and no less real.

Treated as a working checklist, the whole thing comes down to four questions. Which tools are actually in use — the real inventory, not the sanctioned list. What each does with its inputs, at the level of retention and training. Which information may go where. And who keeps those answers current. An organization that can answer all four has done roughly what any client, regulator, or counterparty could ask of it. One more observation belongs in the build-or-buy file: where sensitive information never enters a third party’s system at all — because the work runs in an environment the organization controls, under terms that exclude training — most of these questions stop needing answers. Nobody requires that architecture. It is simply a fact about certain designs, and a legitimate weight on the scale.

The tools will keep changing, and this generation of guidance will age fast. The posture underneath it will not: understand what a counterparty does with what you give it before trusting it with what matters. Organizations have held people and firms to that standard for as long as there have been counterparties. Some of them are software now. That is the only new part.