Where your firm's data actually goeswhen your team uses public AI
Your staff are already pasting client work into chatbots. Here is what happens to it after they hit enter, and why your engagement letter still has your name on it.
17 AUGUST 2026 · 4 MIN READ
There is a conversation happening in your firm that you are not part of.
Someone in your team has a document due. It is long, it is tedious, and there is a tool that will summarise it in nine seconds. They open a browser tab, paste it in, and get their answer. It works. So they do it again tomorrow, and they tell a colleague, and by the end of the quarter it is simply how work gets done.
Nobody did anything malicious. Nobody broke a rule, because there probably was not one. But something left the building, and it is not coming back.
The part most owners get wrong
The instinct is to treat this as a technology question — which tool, which settings, which toggle in the admin panel. It is not. It is a question about where a copy of your work now lives, and who is permitted to read it.
When your team member hit enter, that document did not go to an AI. It went to a company. A company with its own retention schedule, its own jurisdiction, its own security posture, its own commercial pressures, and its own definition of what counts as a breach worth telling you about.
You controlled the first stage. You have no visibility into any of the three that follow, and no mechanism to reach back into them.
Three things that are true regardless of the vendor
You cannot see what left. There is no log on your side. If a partner asks next year what client material has been shared with third-party AI services, the honest answer is that you do not know — not approximately, not in outline. You do not have the data to construct an answer.
You cannot get it back. Deletion requests operate on the copy the vendor acknowledges holding. Backups, derived indexes, cached inference, and material already reviewed by a human sit outside that. "Deleted" is a claim about one system, made by the party with the least incentive to define it broadly.
You are still the one who signed. This is the part that matters commercially. Your client signed an engagement letter with your firm. Your regulator licensed your firm. Your professional indemnity policy names your firm. A vendor's terms of service is a contract between your employee and a third party, and it transfers exactly none of your obligations anywhere.
Why banning it does not work
The reflex response is a policy: no AI tools with client data. It gets circulated, everyone acknowledges it, and the problem appears to be solved.
It is not solved. It has become invisible.
The pressure that drove the behaviour has not changed — the document is still long, the deadline is still tomorrow, and the tool still works. What changes is that usage moves to personal accounts, personal devices, and personal phones, where you have no policy reach at all. You have not removed the exposure. You have removed your ability to see it.
This is the same pattern every firm went through with file sharing fifteen years ago. Blocking the corporate account did not stop anything. Providing a sanctioned alternative did.
What a fixed version actually looks like
The workable answer is not less AI. Your competitors are not using less of it, and the productivity difference is real. The answer is AI your team can use freely because the material never leaves your control in the first place.
Concretely, that means the model runs on a machine inside your network. Staff use it the way they use any chat tool — same interface, same speed, same habits. The difference is architectural rather than contractual: there is no outbound connection from the inference layer, so there is no vendor to trust, no retention policy to read, and no jurisdiction to worry about.
- Every request stays on hardware you own or lease
- A complete log of who used what, held by you
- Access grantable and revocable per person and per department
- Evidence you can hand a client or a regulator on request
- No per-question pricing, so nobody is discouraged from using it
The last point does more work than people expect. When AI is metered per use, staff quietly ration it, and the ones who need it most are usually the ones least willing to spend the budget. Removing the meter removes that friction entirely.
The question worth asking this week
Not "should we allow AI." That decision has already been made for you, by the people doing the work.
The question is: if a significant client asked tomorrow what of their material has been shared with third-party AI services, could you answer?
If the answer is no, that is the exposure. Everything else is detail.
Comments
A short note. No account required.
Loading
If this was useful.
Short notes on private AI, data risk, hardware, and cost — when they are ready. No deck, no pitch, no follow-up sequence.