QuestionAI GovernanceImplementationprofessional services

What exactly leaves the firm's system when staff use AI?

3 August 2026
Answered by Rohit Parmar-Mistry

Short answer

A quick answer first, then the fuller context below.

What exactly leaves the firm's system depends on the tool, the integration and the logging settings. Treat prompts, files, outputs, metadata and support access as in scope until the vendor proves otherwise.

What this points to

This usually points to AI governance consulting

If this question reflects a real workflow, supplier, data or governance decision inside the firm, do not treat the answer as theory. Use it to decide whether you need a light assessment, a deeper audit, a controlled implementation path, governance support or recovery from a genuinely stalled AI attempt.

Detailed answer

The fuller context, trade-offs and practical steps behind the short answer.

What actually leaves the firm when AI is used

For a professional services firm, the right starting assumption is simple: more than the typed question may leave the firm's system. A user prompt can carry client names, matter facts, financial figures, file extracts, notes, email content and internal reasoning. If the tool accepts document upload, browser access, CRM data, meeting recordings or workflow integration, the data boundary widens again.

The practical question is not whether the vendor says the product is secure. The question is what data moves, where it is processed, who can see it, how long it is retained, and what evidence the firm can produce if a client, insurer, regulator or senior partner asks.

The safe answer: map prompts, files, outputs, logs and support access

When staff use AI, firms should check five data categories before approving the tool for client work. First, prompts and instructions: the text staff type, paste or dictate. Second, uploaded material: PDFs, spreadsheets, emails, contracts, case notes, call transcripts and screenshots. Third, outputs: drafts, summaries, recommendations, classifications and generated analysis. Fourth, metadata and logs: user IDs, timestamps, IP addresses, usage analytics, moderation events, error traces and audit logs. Fifth, human or subprocessor access: vendor support teams, model providers, cloud processors and any security or abuse-review process.

If any of those categories can contain confidential, privileged, personal or commercially sensitive information, the tool needs controls before routine use. That means approved use cases, data minimisation, retention checks, role-based access, review evidence and a route for exceptions.

Map AI data exposure before rollout

What to ask the vendor before approving the tool

Ask for plain evidence rather than broad assurances. The vendor should explain whether prompts, uploaded files and outputs are stored, used for training, reviewed by humans, shared with model providers, included in telemetry, or retained in backups. For regulated or client-facing work, the answer should be specific enough for procurement, compliance and delivery owners to act on.

Useful checks include: where processing occurs, whether data is encrypted in transit and at rest, whether customer data is logically separated, whether retention can be shortened or disabled, whether logs can be exported, whether support access is controlled, and whether subprocessors are listed. If the tool is embedded inside another platform, check both the application vendor and the underlying model or cloud provider.

How firms should set internal rules

Policies should turn the data map into day-to-day rules. Staff need to know which tools are approved, which data can be entered, which work must stay out of public or consumer AI tools, and when a human reviewer must sign off the result. A good rule is to treat client-identifiable data, special category personal data, privileged material, unpublished financial information and confidential strategy as restricted unless a named owner has approved the exact workflow.

The firm should also preserve an audit trail. For important client work, record the tool used, the data category involved, the reviewer, the final decision and any redactions or controls applied. This protects both quality and accountability: the firm can show that AI supported the work without handing responsibility to the tool.

Keep AI governance evidence current

A practical approval checklist

Before the tool is allowed near client work, create a short approval record covering the use case, data categories, vendor controls, retention settings, access model, human review step and escalation path. For higher-risk work, add a test run with synthetic or redacted data and check the logs afterwards. If the firm cannot explain what left the system during the test, it is too early to approve live use.

This approach keeps AI adoption useful without turning every experiment into a policy project. Low-risk drafting and internal summarisation can move faster when the data is non-sensitive. Client, regulatory, financial and legal work needs stronger gates because confidentiality, accuracy and evidence matter more than speed.

Conclusion

What leaves the firm's system is not a single field in a vendor questionnaire. It is the combined flow of prompts, files, outputs, logs, metadata, subprocessors and support access. Map that flow first, then approve tools only where the firm has a clear data boundary, a human review step and an audit trail it can defend.

Build controlled AI workflows for client work

FAQs

Direct follow-up answers written for searchers, buyers and internal decision makers.

Are prompts always stored by AI vendors?

No. Some enterprise settings reduce or disable retention, but firms should verify the contract, admin settings, audit logs and subprocessor terms before relying on that claim.

Can staff paste client data into a public AI tool?

They should not unless the firm has explicitly approved that tool and use case for the data category involved. Confidentiality and data protection duties still apply.

Do outputs count as firm data?

Yes. Outputs can contain client facts, analysis, assumptions and errors. They should be reviewed, stored and corrected under the same quality controls as other work product.

What is the minimum evidence a firm should keep?

Keep the approved use case, data category, tool configuration, reviewer, decision record and any retention or access settings that prove the workflow was controlled.

Need More Specific Guidance?

Every organisation's situation is different. If you need help applying this guidance to a specific process, book a discovery call or take the assessment first.