Someone at your firm has already asked this question. Maybe not out loud, and maybe not to you.
They were staring down a client’s trial balance, or a set of statements that needed summarizing, or a memo that would take ninety minutes to write and twelve minutes to write with help. And they wondered — briefly, and then not so briefly — whether they could just paste it in.
Some of them wondered and stopped. Some of them didn’t.
You need an answer to this. Not a hedge, not a “we’re looking into it,” and not a blanket no that everyone quietly ignores. Here’s the honest one.
The Answer Depends on Which Door the Data Walks Through
“Can we use AI with client data” isn’t really one question. It’s a question about where the tool sits.
A personal account is a different product than a company tenant. Same model, same interface, materially different agreement. When someone signs up for an AI tool with a personal email and a personal card, they’ve quietly entered your firm into a consumer arrangement that nobody reviewed. Data handling, retention, whether inputs get used to improve the model, what happens if that account is compromised — all of it is governed by terms nobody at your firm has read, and none of it is under your control. For a CPA firm, that’s not a technology gap. That’s an operational continuity risk sitting inside someone’s browser tab.
A licensed business tenant is a different arrangement entirely. Data handling is contractual. Retention is defined. You own the tenant, you control access, and you can revoke it. Most importantly, you can describe it to a client who asks. If your firm already runs on Microsoft 365, you’re often closer to a defensible answer than you think — the tool may already be sitting inside the license you’re paying for, governed by an agreement you already control. This is the kind of thing our Microsoft-focused team walks Upstate firms through regularly: the difference between a tool your firm owns and a tool that’s merely being used inside your firm.
So the honest answer is this: it depends on whether your people are working inside something you control, or outside it. Right now, in most firms, the answer is some of both — and nobody knows the split.
The Three Questions Your Staff Cannot Currently Answer
Not because they’re careless. Because nobody has told them.
“Is this tool approved?” If your firm has never named one, every person is making their own call, every week — and making it differently each time.
“Is this specific piece of information okay to put in?” There’s a real difference between a redacted excerpt, a public filing, and a client’s complete general ledger. Your staff knows that instinctively. What they don’t have is a line — an actual, written line — telling them where it sits. Under deadline pressure, in the absence of a line, people guess.
“Who do I ask when I’m not sure?” This is the one that quietly matters most. If the answer is nobody, the default behavior when someone is unsure is to proceed and say nothing. That’s precisely the situation your firm can’t afford — the same way an unreported phishing email or an unmonitored account left open after an employee departs turns a small uncertainty into a real exposure. We see this pattern constantly across the businesses we support: the risk was never the technology. It was the silence around it.
Every one of these questions is answerable in a single sentence. None of them are answered at most firms today.
The Reflex to Ban It Is the Expensive One
Confidentiality is not negotiable in this business. Neither is the human relationship your clients are paying for — nobody wants to feel like their return was run through a machine.
But an outright ban doesn’t protect either of those things. It just moves the behavior to phones and home laptops, where you have zero visibility. And it hands a real advantage to the firm down the street that took the time to do this properly.
Because they are doing it properly, and here’s what it’s returning: hours back on document review, on research, on first-draft memos, on the reconciliation work that eats a senior’s afternoon and generates zero client value. That’s billable capacity currently being spent on tasks a properly governed tool could carry — during busy season, when you can’t hire your way out of the workload.
The firms getting this right didn’t compromise on confidentiality. They put a boundary around it, and then they moved. We won’t tell you that’s an overnight fix — change like this earns trust in small wins, not one big rollout. But the boundary itself doesn’t take long to build.
What You Actually Need in Writing
Less than you think. This isn’t a compliance program.
- One approved tool, named. Ideally the one already inside the license you’re paying for.
- One page stating what client information may go into it, what may never, and what must be reviewed by a person before it leaves the firm — written in plain language, because it has to be read on a busy Tuesday, not studied by counsel.
- One name — the person to ask when the answer isn’t obvious. It matters more than the policy itself. The firms we’ve worked with the longest, some since 2017, will tell you the relationship that holds under pressure is the one where people know exactly who to call and get someone by first name, not a ticket number. Your internal AI policy needs that same quality: a real person your staff can walk down the hall to.
- One sentence you can say to a client who asks your firm’s position on AI. You will be asked. Better to have the sentence ready before it happens.
That’s the whole document. It takes an afternoon. And the day it exists, your firm stops being a place where people are guessing, and starts being a firm working inside a boundary you set on purpose.
Get the AI Acceptable Use Policy Starter Kit
A one-page, plain-language policy your team will actually read — plus the sanctioned-tool checklist, the data-classification lines to draw, and the sentence to give a client who asks where your firm stands.
Built for firms handling confidential client information. Free, no obligation, no long-term commitment — just like the way we prefer to work with every client on our own list.
Questions before then? Call Palmetto Technology Group at (864) 552-1291 or email [email protected]. We’ve spent nineteen years helping Upstate businesses keep operating steadily while the tools around them change — this is the same conversation, just with a newer tool.