Artificial intelligence · Client confidentiality
Your staff are already using AI. The question is whether anyone told them which tool.
Client data is leaving practices through a route nobody has written a policy for: an ordinary copy and paste into a free AI tool, by someone trying to finish faster.
There is a conversation we now have in almost every practice we take on. It goes like this. We ask which AI tools the firm permits. There is a pause. Someone says "we haven't really decided". Someone else says, more quietly, that they think a couple of people use one.
Nobody is doing anything wrong on purpose. That is exactly why it is worth writing about.
What actually happens
It is 8pm. A member of staff has a forty-page document to get through — a set of accounts, a lease, a consultant's letter. They open a free AI tool, paste the document in, and ask for a summary. They get one. It is good. It saves them an hour, and they go home.
The work was fine. The instinct was fine. What is not fine is what just happened to the data:
- It left your environment. Whatever controls you have — your firewall, your access rules, your hosted desktop — stopped applying the moment that text was pasted into a browser.
- You cannot recall it. There is no equivalent of "recall message". You cannot audit it, you cannot delete it from the other side, and in most cases you cannot prove what happened to it.
- You are still responsible for it. The client gave their information to your practice. Your obligations to them did not transfer to a website.
⚠ The bit that catches practices out
Free and consumer tiers of AI services frequently reserve the right to use what you type to improve their models. Business and enterprise tiers generally do not — but that is a difference in the terms you signed up to, not a difference in the product your staff see. The screen looks identical either way.
Two obligations, not one
This is where it stops being a technology question, and practices tend to think about only half of it.
Data protection
Under UK GDPR your practice is the controller of client personal data. Any third party processing that data on your behalf is a processor, and Article 28 requires a written contract governing what they may do with it. When a member of staff pastes client data into a tool the firm has never assessed, no such contract exists. Nobody chose that processor, nobody reviewed its terms, and nobody recorded it.
That is a gap in your records as much as a gap in your security. If you were asked today to list every place client personal data is processed, an unapproved AI tool would not appear on the list — and that is precisely the problem.
Professional confidentiality
Separately, and often more immediately, there is your professional duty. Confidentiality is one of the five fundamental principles in the ICAEW Code of Ethics, alongside integrity, objectivity, professional competence and due care, and professional behaviour. It does not carve out an exception for tools that are convenient. Legal and healthcare practices carry equivalent duties under their own regimes.
A client who discovered their affairs had been pasted into a public tool would not be reassured by an explanation about model training policies. They would ask why it happened at all.
Why banning it does not work
The instinct of a lot of firms is to prohibit AI outright. We would gently push back on that, for a practical reason rather than an ideological one.
A ban does not stop people using AI. It moves it onto personal phones, where you have no visibility at all.
The work pressure that made the tool attractive at 8pm does not disappear because a policy says no. What disappears is your ability to see it. A prohibited-but-used tool is strictly worse than an approved one, because at least the approved one was chosen deliberately.
What good looks like
This is not an expensive problem to fix. It is an unaddressed one. Three things close most of the gap:
- Name one approved tool. A business-tier account, set up so that your inputs are not retained for model training, under terms the practice has actually read. One tool, chosen on purpose, beats five chosen by accident.
- Write it down — half a page is enough. Which tool is approved, what may go into it, what must never (client identifiers, anything under legal privilege, anything you would not email unencrypted), and who to ask when someone is unsure. A verbal "be careful" is not a policy and will not help you explain yourself later.
- Tell people why. Staff follow rules they understand and route around rules they do not. Five minutes explaining the difference between a free tier and a business tier does more than a paragraph in a handbook nobody opens.
Worth adding, if you can: a record of which tools are in use, reviewed occasionally. The list changes faster than most policies do.
Questions worth asking this week
- If someone needed to summarise a long client document today, would they know which tool to use — and would they be right?
- Does the practice have a written AI policy, and has anyone read it since it was written?
- Could we list every third party currently processing our client data, and do we have a contract with each of them?
- If a client asked us directly whether their information had been put into an AI tool, could we answer with confidence?
If the honest answer to any of those is no, that is not unusual and it is not a crisis. It is a half-day of work that nobody has got round to. The firms that address it now will find it a much smaller job than the firms that address it after a client asks.
Frequently asked questions
Is it against UK GDPR to put client data into an AI tool?
Not automatically. It depends on the tool, its terms, and whether your practice has assessed and documented it. The problem with ad hoc use is that the practice remains the data controller while nobody has reviewed the processor, agreed a contract under Article 28, or recorded that the processing happens at all.
Are paid AI tools safer than free ones?
Generally the business and enterprise tiers offer stronger commitments — most importantly that inputs are not used to train the provider's models — but this varies by provider and changes over time. The terms are what matter, not the price, so read them for the specific tier you are on rather than assuming.
Should we just ban AI in the practice?
Blanket bans tend not to hold, because the workload pressure that makes AI attractive does not go away. In practice a ban usually moves the activity onto personal devices, where the firm has no oversight. Naming one approved tool gives you a defensible position and visibility at the same time.
What should an AI policy for a practice cover?
At minimum: which tools are approved, what categories of information may and may not be entered, how client identifiers should be handled, who to ask when someone is unsure, and who reviews the list. Half a page is enough for most practices.
Does confidentiality apply to AI tools?
Yes. Confidentiality is one of the five fundamental principles of the ICAEW Code of Ethics and applies regardless of the technology involved. Solicitors and healthcare practitioners carry equivalent duties under their own professional regimes.
Not sure what is already in use across your practice?
We will help you see which tools your people are actually using, set up an approved one properly, and draft the half-page policy that goes with it. If you already have this covered, we will tell you so.
Book a free consultation →
