Learn · AI Security

Staff sharing client data with AI

Short answer. When staff paste client information into AI tools, the firm can lose control of confidential data. The fix is a clear rule, an approved AI route that respects client boundaries, and a way to give AI the client context it needs without copying files into chats.

Last reviewed 24 September 2026

Why it happens

A manager needs to summarise a client’s correspondence before a meeting. A trainee needs to reconcile a messy spreadsheet. An AI tool would help, so they paste the client’s details in. They are trying to do good work quickly. Usually nobody told them not to, or they were told in a policy they have not read.

For firms that hold information on behalf of clients, such as accountants, solicitors, consultants and financial advisers, this is one of the most common AI risks.

What is actually at risk

  • Confidentiality. Professional firms generally owe duties of confidentiality to clients. Information disclosed to a third-party service may fall outside what the client expects.
  • Personal data. Client files often contain personal data about individuals. Under UK GDPR, the firm must process it lawfully, securely and for defined purposes.
  • Client separation. Files uploaded into a general AI chat can end up mixed with other clients’ work.
  • Contract terms. Engagement letters or client contracts may restrict how information is handled.
  • Accountability. Without a record, the firm cannot say what was shared, when or with which tool.

What not to do

  • Pretend it is not happening.
  • Rely on a long policy nobody reads.
  • Assume every AI account has the same data terms. They do not; check your provider’s current settings.
  • Punish people for being honest about what they have done.

A practical response

1. Set a simple rule

For example: client information may only be used in approved AI tools, through approved routes. Short, clear and easy to remember.

2. Provide the approved route

If staff have no approved way to use AI with client work, they will find their own. Provide business accounts with suitable terms, and connect them to client information properly.

3. Keep clients separate

Use an approach where an employee’s AI works within one client’s information at a time, and cannot draw in another’s.

4. Share the portion, not the file

Much of the time, AI needs a summary, a status or a handful of records, not the whole file. Give it the portion the task needs.

5. Record what happens

Keep a record of which client information was accessed by which AI, for whom.

6. Review incidents calmly

If sensitive information was shared inappropriately, assess it as you would any data incident. Consider whether it is a personal data breach under UK GDPR and whether it needs to be reported. Take advice where you need it.

How Kroy approaches it

Kroy gives staff a governed route: their AI connects to Kroy, and Kroy returns only the client information that person is entitled to, for the client they are working on. Internal notes, other clients and restricted data stay out of scope, and every retrieval is recorded. Staff get useful AI; the firm keeps its client boundaries.