Both of these tools are already inside your firm, whether anyone approved them or not. Somebody on your team drafts client letters with ChatGPT at home. Somebody else has Copilot sitting in their Outlook because the firm’s Microsoft license turned it on. The comparison people usually reach for is which one is smarter, and that is the least useful question you can ask. The useful questions are mechanical: where each one runs, what it can see, what it keeps, and what kind of work it is actually built for.
Where each one runs
ChatGPT runs on OpenAI’s servers, and for most advisors it runs under a personal account. Whatever gets typed into it leaves the building. That is not sinister; it is just what a cloud chat service is. The terms that govern what happens next belong to the plan the account is on, and a personal account was never negotiated by your firm.
Copilot runs inside the Microsoft 365 tenant your firm already administers. The same identity, licensing, and permissions that govern your mail and files govern it. Questions and answers stay inside Microsoft’s commercial cloud boundary, under an agreement your firm actually signed. For a compliance officer, that is a genuinely different position, and Copilot deserves the credit for it.
What each one can see
ChatGPT starts blank. It knows a great deal about the world and nothing about your firm: not one client, not one account, not one meeting note. The only way it learns anything is when someone pastes it in, which is why the strip-the-names ritual exists. An advisor wants help rewriting a review letter, knows the client’s name should not go into the box, and scrubs the details by hand. It works, it costs minutes every time, and the tool is permanently answering a redacted version of the question.
Copilot sees what the signed-in person can already open in Microsoft 365: their mail, their calendar, the files in OneDrive and SharePoint, the Teams threads they belong to. That scope is real and it is enforced by the platform, not by the model’s good intentions. But the scope ends where Microsoft 365 ends. Your CRM is not in it. Your portfolio platform is not in it. The custodian’s data feed is not in it.
What each one keeps
On consumer ChatGPT plans, conversations can be retained and, depending on the account’s settings, used to improve future models. Business plans promise otherwise. The honest summary is that retention is decided by the vendor’s terms and the account’s settings, and unless someone at your firm has read the terms for the exact plan your people are using, nobody at your firm knows the answer. For a personal account used at a kitchen table, nobody even knows the question was asked.
Copilot’s story is cleaner: prompts and responses stay in your tenant, your existing retention policies apply to them, and Microsoft’s commercial terms keep your content out of foundation-model training. Your administrator can answer a retention question with a setting rather than a shrug. That difference matters more than any benchmark.
Where each one fits
ChatGPT is excellent at work that needs no client records at all: explaining a concept, rewriting a paragraph, pressure-testing an argument, drafting the first version of anything general. Copilot is excellent at work on your own documents and mail: summarize this thread, draft a reply from this memo, find the version of the deck we sent in March. Neither of those strengths is small, and a firm that banned both outright would just be pushing them into the shadows.
The question neither answers
Now ask something an advisory firm actually needs: which households hold the fund we’re replacing, and when did each of them last have a review? Holdings live in your portfolio system and the custodian’s data. Reviews live in your CRM. ChatGPT has never met either system. Copilot stops at the edge of Microsoft 365, and neither your CRM nor your custodian lives there.
Neither tool is broken. Each is answering exactly to its boundary. But the questions that run a firm cross those boundaries constantly, and answering them takes a different shape of system: standing connections to the records, a database the firm owns, rules about who sees what enforced in code, and a receipt on every number so a person can check the answer against the source. That is the job RIAI was built for, and it is a different job than either of these tools ever claimed.