Why client data in AI tools needs a clear answer
When a fee earner, adviser or support team member pastes client material into an AI tool, the practical question is simple: where does that information go, who can see it, and what evidence does the firm have that it stayed under control?
The answer depends on the tool, the account tier, the contract and the firm's own operating rules. A public chatbot used through a personal or free account is very different from an approved enterprise service with a data processing agreement, retention controls and audit logs. The risk is not that every AI tool is automatically unsafe. The risk is using a tool without knowing which of those conditions applies.
The safest practical answer for client data
Client data should only go into AI tools that the firm has approved for that type of information, after checking data processing terms, retention settings, training use, access controls, location of processing, auditability and human quality review. If those points are unknown, the safe rule is: do not enter confidential, privileged, personal or commercially sensitive client material.
For professional services firms, this is not only an IT preference. It connects to confidentiality, legal privilege where relevant, UK GDPR duties, professional conduct expectations, insurance position and the firm's ability to explain how work was produced. The firm needs a record of the decision, not an informal habit that varies by team.
Map where client data touches AI tools
What can happen to the data
In a typical AI workflow, client data may be transmitted to the provider's systems, processed to generate an answer, retained for a defined period, scanned for safety or abuse monitoring, and sometimes made available for human review. In some consumer or lightly governed settings, prompts may also be used to improve models unless settings or terms prevent that.
Those behaviours vary by provider and tier. A consumer account may offer limited contractual protection and little audit evidence. An enterprise or legal-specific tool may provide stronger commitments on training exclusion, retention, access, regional processing, subprocessors and logging. The firm should verify those points directly rather than relying on a brand name or a sales summary.
The governance checks before staff use AI with client material
Before approving an AI tool for client work, the firm should answer these questions in writing:
- What categories of client data may be entered, and which are prohibited?
- Is the provider acting as a processor, controller or independent service under the relevant terms?
- Is there a data processing agreement, and does it cover subprocessors, security, retention and deletion?
- Can prompts or uploaded files be used for training, safety review or product improvement?
- In which regions is the data processed and stored, and can the firm evidence that position?
- What logs, admin controls and review trails are available if a client or regulator asks?
- Who signs off outputs before they influence client advice, filings, valuations, reports or communications?
The aim is a controlled operating model. Staff should know which tools are approved, which data is allowed, what review is required and where to raise exceptions.
Put AI usage rules under active governance
How this applies in legal and regulated professional services
Law firms and adjacent professional services teams have extra reasons to be careful. Client confidentiality and privilege can be harmed by careless disclosure. Personal data may trigger UK GDPR obligations, including lawful basis, transparency, data minimisation, security and international transfer checks. The SRA Code and similar professional standards expect competent supervision, confidentiality and accountability for work delivered to clients.
That does not mean firms should ban AI outright. It means they should separate low-risk uses from restricted uses. Drafting a generic checklist from public information is different from uploading a client's evidence bundle, contract, claim chronology, financial model or board paper. The approval rules should reflect that distinction.
A workable policy for teams
A practical policy can be short, but it must be specific. It should name approved tools, permitted data classes, prohibited material, required redaction, review steps, logging expectations and escalation routes. It should also explain what staff should do when a client asks whether AI was used.
For many firms, the best starting point is an inventory: which AI tools are already being used, by whom, with what data, for what purpose and under which terms. That gives leadership a fact base for deciding where AI can improve work safely and where controls need to be tightened.
Conclusion
Client data in AI tools is manageable when the firm treats it as a controlled workflow, not an individual experiment. The minimum standard is clear tool approval, data classification, contractual review, audit evidence and human accountability for the final output. Without those controls, confidential and personal data should stay out of the tool.
Implement a controlled AI workflow
Need a safer AI route for your firm?
If this article reflects a live decision in your practice, the useful next step is to map the workflows, confidentiality risks, supplier controls and governance gaps before tools spread informally.