For a law or accounting firm, confidentiality is the product AI can leak
The work is documents, review and judgement, which AI eats through. But confidentiality is what clients pay for, and one paste into a public chatbot is one breach of it. Control the data first.
On paper, legal and accounting firms are built for AI. The work is documents, correspondence, review and judgement, which is precisely the material these tools are good at. If you were designing a business to benefit from AI, it would look a lot like a professional firm.
There’s one catch, and it’s the whole business. Confidentiality is the product. A client isn’t just paying for the advice, they’re paying for the certainty that their affairs stay private, and for a lawyer that certainty carries the weight of privilege and a duty older than any software. Leak a client’s material once and no amount of efficiency was worth it. So secure AI in a firm doesn’t start with prompts or use cases. It starts with one question, asked before anything else: who controls the data when the AI touches it?
The breach usually starts with a helpful staffer
Picture the most likely first incident, because it’s already happening in firms that haven’t got ahead of it. A junior pastes a client’s letter into a free public chatbot to tidy the wording. A bookkeeper drops a set of figures in to reformat them. Nobody meant any harm, and client material has just left the building for a system the firm doesn’t control, can’t audit, and in some cases feeds someone else’s model.
Now scale that across a season. An accounting practice in the run-up to BAS and year-end has every junior under deadline pressure and a queue of work that AI shortcuts nicely: reformatting figures, drafting cover letters, summarising loan documents, turning a client email chain into a file note. Under that pressure the free chatbot stops being a temptation and becomes a certainty. The only open question is whether client material moves through a channel the firm controls and can audit, or one it can’t even see.
Vendor terms have improved, and some tools now promise not to train on your inputs. But “the terms are probably fine” is not a professional standard, and it’s not what you’d tell a client if they asked where their file went. The answer is an approved path that’s easier than the risky one: a controlled assistant that only ever sees approved internal material or the documents for a matter, with permissions and logging wrapped around it. Ban the public tools by all means, but a ban with no sanctioned alternative just drives the behaviour where you can’t see it.
Start where a wrong answer costs an hour, not a client
Plenty of useful work is low-stakes. Precedent and policy search across the firm’s own material. Summarising a matter file. Drafting standard correspondence for a fee-earner to check. Building a file chronology. Cleaning up invoice narratives. Tax research support. Triaging a new intake enquiry. In all of it, the assistant prepares the work and stops. The lawyer or accountant still owns every word of advice that leaves the firm.
The hours recovered are not small. A matter-file summary that used to eat an afternoon comes back in minutes and takes half an hour to check properly, and multiplied across the routine work of a mid-sized practice that’s a meaningful slice of every week, recovered without touching anything a client would consider sensitive.
That boundary is the point. The tool does the reading and the fetching and the first draft. A qualified person does the judging, the same as always, just faster to the part that needs them. Where firms get burned is letting the assistant’s output slide out the door as if a human had stood behind it. The efficiency is real, and the accountability doesn’t move an inch.
Permissions, or the ethical wall the AI walked straight through
Here’s the risk that’s specific to firms and that generic tools quietly create. Your document system has matter permissions, client boundaries, and in some cases an ethical wall between teams acting on opposite sides of a matter. Bolt a generic AI assistant across everything and it can flatten all of that in a week, cheerfully answering a question about a matter the person asking was never allowed to open.
If someone can’t open a matter in the document system, they must not be able to ask the AI about it either. That means retrieval enforces the same permissions, walls and roles the firm already relies on, down at the data layer, not as a setting in the chat window. This is the question to put to any vendor before anything else, and to keep pushing on until the answer is about the retrieval and not the interface. A tool that looks helpful while dissolving your access controls isn’t a productivity gain, it’s a professional conduct problem with a friendly face.
Where the model runs decides most of the risk
Once a firm accepts that staff will use AI regardless, the question that deserves partner-level attention is architectural: where does the model run, and what does the provider keep? The options sit on a spectrum. At one end, public consumer tools, where the terms are consumer terms and the data path is whatever it is this quarter. In the middle, enterprise agreements with no-training clauses, retention controls and audit logs a firm can put in front of its insurer. At the far end, a private setup where the model runs on infrastructure the firm controls and matter material never leaves it.
Most firms don’t need the far end for everything, and paying for it everywhere is its own mistake. A sensible split runs general drafting and research on a well-configured enterprise service and reserves the private setup for the material that would make the managing partner sweat: disputed matters, market-sensitive clients, anything behind an ethical wall. For some clients, where the data physically lives stops being a preference and becomes a requirement, and Australian hosting has to be provable rather than assumed. Government and listed clients increasingly write that expectation into engagement terms. What no firm should accept is fog. If nobody can answer “where did that document go when the assistant read it” in one sentence, that’s the gap to close before the next use case, not after.
Run a hostile hour before it touches live matters
Before any assistant gets near current files, give it a hostile hour on a closed matter. Load the matter, then have someone from the wrong side of an ethical wall try to reach it through the assistant: directly, then sideways, with the kind of oddly worded question a curious staffer might actually type. Ask it for case citations and check every single one against the database, because the plausible fake is the one that ends up in a filing. Feed it a document with a known error and see whether the summary repeats the error as fact. Then pull the logs and confirm they’d let you reconstruct the session six months later, because one day you’ll need to.
Wiring the assistant into the document system so the permissions hold is integration work, not prompt writing, and it’s where the budget should go first. An hour of hostile testing tells you more than any vendor deck, and if the tool fails the wall test, the pilot is over. If it passes, the test itself becomes evidence: the file you show the professional indemnity insurer, and the more careful clients, when they ask what the firm is doing about AI. They will ask.
Write the review step down and teach it
A draft from a model still needs a person checking the accuracy, the tone, the legal or financial reasoning, the client context, and whether the citations it produced are real rather than plausible. Models invent case citations and confidently misstate a rule, and the one thing worse than doing the research yourself is filing something that only looked researched.
So decide up front which outputs are fine as internal notes and which need a partner, manager or specialist signing off before they go anywhere near a client. Then spell that review process out and actually train it, rather than assuming people will infer the right caution from the vibe. On the sensitive matters, log it too: who used the assistant, which matter or document set they searched, what came back, what got produced. Match the logging to the risk, and when a question surfaces months later, that trail is how you reconstruct what actually happened.
None of this is about being timid with the technology. Start on internal knowledge and low-risk drafting, test it on real files rather than a demo, get the permissions tight, train the people using it, and move to the touchier workflows once you’ve got evidence it behaves. A firm can absolutely take on useful AI without gambling the one thing clients are paying for above everything else. It just has to build the confidentiality in first, not bolt it on after the first scare. If you want that done properly, tell us how your matters and permissions are structured and we’ll design around them.
Related reading
An AI risk register for small business: keep it short and useful
A short AI risk register gives leaders a way to say yes carefully instead of blocking every useful idea.
Your staff are putting client data into AI. You own the fallout
Shadow AI can turn a harmless time-saving shortcut into a privacy breach, client trust problem and regulator headache.
Data sovereignty for Australian AI projects: the questions to ask
The word sovereignty is vague until you ask where the data lives, who can access it and what the vendor is allowed to do.
Turn the thinking into a plan.
Send the process, risk or idea. We will help you work out what is worth doing first.