AI and Client Confidentiality: What Professional Services Firms Must Get Right

Law, accounting, and advisory firms hold privileged and confidential material, and the duty of confidentiality applies no matter which tool you use. Here is what to get right.

Professional services firms run on trust. Law firms hold privileged communications, accounting firms hold sensitive financial detail, and advisory firms hold the confidential plans clients share in confidence. That trust is backed by a professional duty of confidentiality, and that duty does not change when a new tool enters the workflow.

AI can be a genuine asset in these firms. But adopting it responsibly means treating client confidentiality as the first design constraint, not an afterthought.

The duty applies regardless of the tool

It is easy to think of an AI assistant as just another piece of software. From a confidentiality standpoint, it is better understood as a place where privileged and confidential material might be sent, processed, and possibly retained. The obligation to protect that material follows it wherever it goes, so the tool has to meet the same standard you would demand of any other channel for client information.

If you would not paste a client's confidential file into an unknown third-party service, the same caution applies to an AI tool whose data handling you have not reviewed.

Engagement letters and client consent

Clients increasingly want to know how their information is handled, and the use of AI is becoming part of that conversation. This is worth addressing directly rather than leaving it implied.

  • Consider whether your engagement letters should address the use of AI tools in delivering the work.
  • Understand your professional and ethical guidance on client consent for new technologies.
  • Be prepared to answer, in plain terms, how a client's confidential material is protected.
  • Recognize that some clients or matters may call for stricter handling or opting out entirely.

Getting ahead of these questions signals diligence rather than raising alarm.

Matter-level access controls before AI

An AI assistant sees what the person using it can already see. In a firm, that makes matter-level access control the foundation of safe adoption. If confidential files for one client are broadly accessible across the firm, an assistant simply makes that oversharing faster to exploit.

Before enabling AI, confirm that access to sensitive matters is scoped to the people who are actually working on them. Ethical walls and need-to-know boundaries have to be enforced in the system, not just on paper, because the assistant will respect exactly the permissions it finds.

Vendor terms on training and retention

Two clauses in a vendor's terms deserve your direct attention: whether your inputs are used to train the provider's models, and how long your data is retained. For confidential client material, the answers you generally want are that your data is not used for training and that retention is limited and under your control.

Business and enterprise tiers usually offer these protections where consumer tiers do not. Read the terms for the specific service and tier you plan to use rather than assuming the brand name guarantees it.

Keep a record of what the terms said and when you reviewed them. If a client or a regulator ever asks how you protected confidential material, being able to point to the specific data-handling terms you relied on is far stronger than a general assurance that you were careful.

Practical next steps

Confirm matter-level access controls are enforced, review the training and retention terms of any AI tool touching client material, address AI use in your engagement and consent practices, and standardize on tiers that protect confidential data. A managed services partner can help you sequence this work so it aligns with your professional obligations rather than cutting against them.