AI Can Carry the Analysis, Not the Duty

Discussion of AI in professional services tends to focus on capability. In fiduciary businesses the more consequential question is governance: which tools are approved, who reviews the output and whether the work can be explained later. Laura Fuhr sets out what advisers should be asking their Gibraltar counterparties.

Laura Fuhr

September 14, 2026

-

3

min read

In July 2026, the Gibraltar Financial Services Commission announced a dedicated Technology Supervision team, citing digital resilience, cybersecurity, information governance and the growing adoption of artificial intelligence. The signal was clear enough. How a firm uses technology is moving from an operational matter to a supervisory one.

Most discussion of AI in professional services still centres on capability. What can the tool do, how much time does it save, who gets it first. Those are adoption questions. In a fiduciary business, the harder question is governance: who is accountable for an AI-assisted output, how was it reviewed, and could we explain any of it a year later if asked?

At Acquarius we took the governance question first. We have a written AI policy, a risk register entry for AI use and a defined list of approved tools, each risk assessed and approved at board level before anyone uses it. Our AI committee meets twice a month, and we run AI clinics where teams talk through what has worked and what has not. It is simply the order the work requires.

Adoption and governance are different questions

Adoption asks what a tool can do. Governance asks what the firm will permit it to do, who signs off, and what evidence remains afterwards.

The reason is specific to fiduciary work. A trustee’s duty of care cannot be delegated to software. Where we exercise a discretion or approve a distribution, responsibility sits with named individuals and, ultimately, with our board. AI can support the analysis behind a decision. It cannot hold the duty.

Why we put governance before scale

The sequence matters more than the technology. Where a tool is approved after teams have built it into their habits, governance becomes an exercise in catching up. We would rather set the boundary first and widen it deliberately.

Our AI committee therefore looks at opportunities, emerging risks, live workstreams and regulatory change, and reports to the board. We assess tools before approval rather than regularising them after adoption. None of this is novel governance. It resembles the way we would handle any other operational risk, which is the point.

The greater risk is plausibility, not obvious error

The AI risk most often discussed is inaccuracy, but obvious errors are the easier problem because they are visible. The greater risk in a fiduciary setting is an output that is coherent, well expressed and wrong in a way only a qualified reader would catch.

Take a summary of a trust instrument prepared to support a distribution decision. A model may produce a fluent account of the trustee’s powers that omits a consent requirement or misreads the effect of a later deed of variation. Nothing about it looks wrong. It reads like competent work, which is why it can pass unchallenged.

The control here is not the tool but the experience of the reviewer. We rely on qualified practitioners who know the underlying instruments well enough to interrogate an answer rather than accept it, and where an output cannot be verified against source documents it does not proceed.

Confidentiality, data protection and external assurance

We hold sensitive personal and financial information about families, beneficiaries and underlying assets. Introducing a new processing tool into that environment is a data protection decision before it is a productivity decision, and Gibraltar’s framework, supervised by the Gibraltar Regulatory Authority, applies in the ordinary way.

We therefore put AI tools through external information security and data protection assessment, carried out with RightCue, before approving them for use. Advisers acting for EU-connected clients should also consider how the EU AI Act applies to outputs used within the Union, though it does not apply directly in Gibraltar.

Training and culture do the daily work

Policies set boundaries. Behaviour determines whether those boundaries hold on an ordinary afternoon under time pressure.

In our AI clinics, teams share what has worked, where a tool has produced something unreliable, and which tasks it should not be used for. Members of our AI committee attend workshops and seminars in Gibraltar and further afield, and feed what they learn back into those sessions. We are after professional scepticism applied consistently, alongside curiosity that does not shade into overconfidence.

I looked at workflow-level controls, including prompting, documentation and escalation, in People, process, prompting in practice, published in May 2026.

Why this matters in practice

Advisers instructing a Gibraltar trustee or corporate services provider rely on that firm’s internal controls whether or not they have examined them. AI raises the stakes, because it changes how quickly work moves through a firm and how easily it can be reconstructed afterwards.

That is most relevant to private client lawyers, tax advisers and family offices who retain the client relationship while a fiduciary provider administers the structure. Four questions cover most of it:

•      Is there a written AI policy, and who owns it at board level?

•      Which tools are approved, and what assessment preceded approval?

•      What human review applies before an AI-assisted output informs a decision?

•      Can the firm evidence how a particular piece of work was produced?


A firm that cannot answer is not necessarily using AI badly. It may simply not know how AI is being used across its teams, which is itself the governance issue.

Key takeaways

•      Adoption asks what AI can do. Governance asks what a firm permits, who is accountable and what evidence remains.

•      Fiduciary responsibility cannot be delegated to a tool, however capable that tool becomes.

•      Policy, risk assessment, approved tool lists and board oversight belong before wider use, not after it.

•      The principal risk is a plausible but incorrect output accepted without challenge, which makes reviewer experience the real control.

•      Data protection assessment is a prerequisite in a fiduciary environment, and training determines whether written controls hold in practice.

Working with Acquarius

We work alongside legal, tax and advisory professionals rather than in place of them, and our approach to AI mirrors our approach to structures. Define accountability first, document what was done, and keep judgement with people qualified to exercise it.

If you are reviewing AI governance within your own arrangements, or within the providers you instruct, I am happy to discuss how we have approached it. Drop me an email at enquiries@acquarius.gi to arrange a call.

Key Contacts
Oliver Andlaw
Chief Executive Officer
Get in Touch ->
Laura Fuhr
Team Leader Trust & Company Management
Get in Touch ->
Denise Bonavia
Client Accounting
Get in Touch ->
Related Insights