Does Your Security Consultant Use AI?

Cody Shultz July 15, 2026

As I’ve written about in previous blogs, corporations, private equity firms, family offices, and law firms stand much to gain by conducting an Independent Security Study. The potential tax benefits under IRS Section 132 for protecting their executives are becoming more well known, and we’ve seen a significant increase in requests for the ISS in the first half of the year.

Many clients, particularly those of high net worth, want to know how their sensitive data is protected, given that the ISS reports on their digital exposure, risks while traveling, as well as security vulnerabilities at their home and office. In the hands of the wrong people, or inadvertently leaked, having this information could spell disaster that results in physical or reputational harm. This is a particularly important question to address, especially as the use of artificial intelligence increases.

How Does AI Introduce Risk to Executive Security?

As reported earlier this year, an engineer at Meta inadvertently exposed sensitive user and company data when they followed guidance from an AI agent. One study “found that 57% had entered confidential information into AI platforms such as ChatGPT, Google Gemini, and Microsoft Copilot.” Another survey also revealed  “77% of employees paste data directly into GenAI tools, with more than 50% of those paste events containing corporate information.” Executives are right to question if their security providers use AI, how they use it, and what safeguards are in place to limit or prevent their most personal details from being submitted to AI tools. As has been said before, the Internet has a long memory, and true white-glove service requires integrity, discretion, and maintaining a high degree of trust.

Can AI-Generated Security Recommendations Create Risk?

Not only is there a risk that a security consultant may inadvertently expose sensitive client information through their use of AI, but also there is a risk that the security recommendations from the ISS are AI-generated as well. Discerning clients are right to question if a nascent security company, or a consultant who only recently began conducting Independent Security Studies, has the right experience to produce a report that is defensible to the IRS. Artificial intelligence can help smaller firms produce reports quicker and cheaper than other providers, but it comes with significant risks. For example, AI may be able to produce good recommendations to improve an executive’s security posture. That does not mean it is the best recommendation, nor may it be reasonable for that company or that particular executive.

Human-generated Subject Matter Expertise

More established firms such as Guidepost, who have    produced numerous IRS 132 audits, are backed by subject matter experts with decades of experience and thus able to produce recommendations that take into account factors such as corporate culture, geography, and executive lifestyle. Ask your security consultant if they have an AI use policy and how AI is used as part of the ISS process. While various factors may limit a company’s ability to share the policy itself, not having a set policy is an immediate red flag.

At the end of the day, AI is a helpful tool across a wide variety of applications, but misuse can create vulnerabilities that did not exist before. Trusted security advisors to those with significant wealth should help reduce risk, but choosing the wrong advisor can have the inverse effect and introduce risk. Independent Security studies, by their nature, are a repository of sensitive, personal information, and must be protected. If you are considering the many tax benefits available under IRS Code Section 132, be sure to ask how the consultant protects your information, what their AI-use policy is, and the real-world experience of those conducting the ISS.

And yes, I wrote this blog entirely without the help of AI!

MSU Institutional Assessment + RA
MAGELLAN Monitorship
Empire/Liberty Review