When should clients be told that AI was used?
Short answer
A quick answer first, then the fuller context below.
Clients should be told that AI was used when it affects advice, judgement, confidentiality, scope or the way their work is delivered. Keep disclosure proportionate, but record the tool, review and final human decision on the file.
What this points to
This usually points to AI governance consulting
If this question reflects a real workflow, supplier, data or governance decision inside the firm, do not treat the answer as theory. Use it to decide whether you need a light assessment, a deeper audit, a controlled implementation path, governance support or recovery from a genuinely stalled AI attempt.
Detailed answer
The fuller context, trade-offs and practical steps behind the short answer.
When clients need to be told that AI was used
Clients do not need a technical explanation every time a firm uses software. They do need a clear disclosure when AI changes the risk profile of the work, touches confidential material, shapes advice, affects professional judgement or changes what the client thought they were buying.
For professional services firms, the practical test is simple: would a reasonable client, regulator or file reviewer expect to know that an AI-enabled tool influenced the work? If the answer is yes, disclose it in plain English and keep the evidence of human review.
The safest answer is proportionate disclosure plus a file note
The safest approach is to tell clients when AI use is material, not to turn every internal tool into a long disclaimer. Material use usually includes uploading client information, using AI to draft or analyse advice, relying on AI to summarise evidence, or using an external tool where retention, training, security or access settings matter.
That disclosure should say what the tool was used for, what it was not used for, and who remained accountable for the final judgement. The firm should also keep a short audit trail showing the approved tool, the data entered, the reviewer, the checks completed and any changes made before the work reached the client.
Check where AI use needs disclosure and evidence
What counts as material AI use?
AI use is likely to be material when it touches client confidential information, personal data, privileged material, regulated advice, audit evidence, valuation work, claims handling, financial recommendations or any output that a client may rely on. The question is not whether the model is impressive. The question is whether the tool affected the work in a way that creates a confidentiality, quality, accountability or expectation risk.
Examples include using a public AI tool to summarise a client file, asking an assistant to draft advice from matter facts, processing client calls through an AI transcription service, or using an embedded AI feature inside a practice, CRM, document or workflow platform. Even when the tool is approved, the firm still needs a controlled process for disclosure and review.
How to decide what the client should be told
Use a short decision tree. First, did client data or client context enter the tool? Second, did AI influence advice, judgement, drafting, evidence analysis or a client-facing deliverable? Third, would the client reasonably expect a human professional to have done that part of the work unaided? Fourth, do the contract, engagement letter, professional rules or regulator guidance require a particular standard of transparency?
If the answer to any of those questions is yes, use a concise disclosure. Avoid vague claims that AI was used safely. Say what happened: for example, that an approved AI-enabled tool helped summarise source documents, that no client data was used for model training under the configured terms, and that a named professional reviewed the output before it informed the final advice.
What the internal record should contain
The file note matters because disclosure without evidence is weak. A good record states the tool or system used, the purpose, the category of information entered, the data protection or confidentiality control, the reviewer, the checks made, and the final professional decision. It should also record when AI was considered and rejected because the data or judgement risk was too high.
This record does not need to be bureaucratic. It can be a structured field in the matter file, workflow system or approval log. The important point is that the firm can prove human review, data discipline and accountability if a client, insurer, regulator or internal quality reviewer asks later.
Build an AI disclosure and review operating model
How this differs by professional context
Law firms should pay particular attention to confidentiality, privilege, client consent, SRA expectations and whether AI use affects advice or client communication. Accountancy, audit and advisory firms should focus on independence, evidence quality, review trails and whether AI influenced conclusions. Financial services and insurance teams should connect disclosure decisions to Consumer Duty, SM&CR accountability, complaints risk, claims handling, underwriting judgement and data protection.
The common thread is control. Clients do not need theatre around AI. They need confidence that sensitive information was handled properly, that the work was reviewed by a competent human, and that AI did not quietly replace professional responsibility.
A practical disclosure rule for firms
Create three categories. Category one is low-risk internal productivity, such as formatting non-confidential notes, where no client disclosure is usually needed. Category two is controlled assistance, such as summarising approved documents or drafting first-pass text, where disclosure may be needed depending on the matter and file note. Category three is high-risk or client-material use, where disclosure and senior review should be mandatory before the work proceeds.
Review the categories quarterly, because embedded AI features change quickly. Procurement, IT, risk and fee-earners should agree which tools are approved, which data is allowed, and which client communications require a disclosure line.
Conclusion
Tell clients about AI use when it affects their data, the substance of the work, the delivery model or the professional judgement they are relying on. Keep the wording short, but make the control real: approved tools, human review, a clear file note and an escalation route for higher-risk matters.
FAQs
Direct follow-up answers written for searchers, buyers and internal decision makers.
Do we need to tell clients every time staff use AI?
No. Low-risk internal productivity use may not need client disclosure. Disclosure becomes important when AI touches client information, shapes advice, affects judgement or changes the service the client expects.
Can an engagement letter cover AI disclosure?
It can help, but it should not replace matter-level judgement. Engagement wording should set the baseline, while the file note records the actual tool, purpose, controls and review for material use.
Who should approve disclosure decisions?
A named accountable professional should approve the decision for the matter, supported by risk, IT or data protection input where the tool or data sensitivity requires it.
What if the AI tool is built into software we already use?
Treat embedded AI features like any other third-party AI vendor. Check settings, retention, training use, access logs, sub-processors and whether client data can be excluded before relying on the feature.
Need help implementing this?
If this question points to a live process, policy or supplier decision, the next step is usually to turn the answer into a controlled plan. These services are the most relevant starting points.
AI governance consulting
Create policies, approval routes, ownership and controls that teams can actually use day to day.
AI governance consultingSecure AI implementation
Put privacy, supplier review, data boundaries, testing and staff guidance into the implementation plan from the start.
secure AI implementationAI Risk & Efficiency Audit
Map real workflows, AI use, data exposure, opportunity value and governance controls before buying or building more tools.
book the AI Risk & Efficiency Audit