top of page

AI and confidential client information: the constraint that binds

  • 4 days ago
  • 3 min read

Updated: 3 days ago

Introduction


For accountants, solicitors, consultants, agencies, brokers, surveyors and anyone else holding client material under an obligation of confidence, this is the question that determines what is possible. The capability is attractive and largely irrelevant if the material cannot lawfully or contractually be processed through a third-party service.

What makes it difficult is that the obligations were not written with these tools in mind. Engagement letters and professional rules describe confidentiality in general terms, and applying them to a service that processes documents on infrastructure elsewhere requires a judgement rather than a lookup. Making that judgement deliberately, and recording it, is the difference between a defensible position and an assumption.


1. AI and confidential client information starts with what you already agreed


The obligations predate the technology.

Engagement letters, non-disclosure agreements, professional conduct rules and sector regulation. These describe what you may do with client material, and they apply regardless of whether they anticipated this.


2. Establish where the material would go


The factual question.

Which company processes it, in which country, on whose infrastructure, and which subprocessors are involved. Without this you cannot assess anything, and vendors vary widely in how clearly they answer.


3. Distinguish material that leaves from material that does not


The practical dividing line.

A tool operating within your own environment raises different questions from one sending documents to an external service. Both need assessing and they are not the same assessment.


4. Check whether the vendor may use it


The clause that decides many cases.

Whether content is used for training or improvement, and whether you can prevent it. For confidential client material, a vendor with no such right is in a materially different position from one that has it and offers an opt-out.


5. Consider whether consent is available and appropriate


Sometimes the cleanest route.

Some clients will readily agree, some have their own policies preventing it, and asking is itself informative about the relationship. Where consent is the basis you rely on, it needs to be specific rather than buried in standard terms.


6. Anonymise where it is genuinely possible


And be realistic about when it is not.

Removing names sometimes suffices and frequently does not, because the content itself identifies the matter or the person. Weak anonymisation is worse than none, because it produces false confidence.


7. Segment your use rather than deciding globally


The practical approach.

Internal drafting, research and general work can proceed while client-specific material is restricted. A blanket ban forgoes real benefit; a blanket permission ignores the obligation. Segmentation is what professional firms end up with.


8. Write down the assessment


The document that matters if questioned.

What was considered, what was decided, what the basis was, and who approved it. A recorded judgement is defensible; a practice that emerged without one is not.


9. Watch for informal use


The larger real exposure.

The considered firm-wide decision is rarely the problem. The problem is a member of staff pasting a client document into a personal account on a busy afternoon, and that is addressed by a clear rule and a usable approved alternative.

Professional confidentiality, legal privilege, data protection and sector regulation all apply here, they differ substantially by profession and jurisdiction, and guidance from professional bodies is developing quickly. For a regulated firm this is a matter for that guidance rather than general practice.


Conclusion


Start from the obligations you already have, because they apply whether or not they anticipated this.

Establish factually where material would be processed and by whom, distinguish tools that keep data within your environment from those that do not, check whether the vendor may use content for training, consider whether specific client consent is available and appropriate, be realistic about whether anonymisation actually works, segment your use rather than deciding globally, record the assessment and who approved it, and address informal use with a clear rule and a usable approved alternative.


Related reading


 
 
 

Comments


bottom of page