How do I handle AI use in a business that works with confidential client information?
3 October 2026
How do I handle AI use in a business that works with confidential client information?
Treat an AI tool as an external processor that may receive, retain and transform client information, not as a private colleague. Start with a written client-data rule, an approved tool and narrow permissions. Redact or pseudonymise wherever possible, complete the appropriate supplier and data protection checks, and keep a person accountable for every output and disclosure.
Start with a clear rule: public AI tools do not receive client information
The safest usable rule is simple: staff may experiment with public or personal AI accounts only with public, fictional or fully sanitised information. Client names, email addresses, contract terms, case details, financial figures, call transcripts, health information, credentials and internal strategy stay out. That rule should cover pasted text, uploaded files, screenshots, voice recordings, browser extensions and integrations. A browser assistant that can read every open tab may have access to far more than the sentence an employee intended to summarise.
Confidentiality and data protection overlap, but they are not the same. A document can be confidential even if it contains no personal data. A client may also impose contractual restrictions that are stricter than UK GDPR. Legal professional privilege, professional conduct rules, non-disclosure agreements and sector requirements can add further limits. Your starting question is therefore not simply, 'Does the tool comply with GDPR?' It is, 'Are we permitted to disclose this material to this supplier for this purpose, and have we limited the disclosure to what is genuinely necessary?'
The Law Society of Scotland's generative AI guidance says confidential or client-sensitive information should not be shared with public generative AI systems and that documentation should have such information removed. That is a useful baseline beyond legal firms. It avoids the weakest control of all: asking each employee to interpret a long privacy notice while trying to finish urgent work.
Write the rule on one page. Include permitted tools, permitted data classes, prohibited data, who can approve an exception and where to report a mistake. Give staff an approved alternative, because a ban without a workable route usually creates shadow AI rather than safety.
Choose an approved workspace and check the supplier before uploading anything
A paid business plan is not automatically safe, but it usually gives you controls that a personal account does not: central administration, managed users, contractual terms, retention choices, single sign-on, access logs and clearer commitments about whether customer inputs are used for model training. Check the exact plan and configuration. Marketing pages are not a substitute for the contract, data processing agreement and current admin settings.
Record at least ten facts in your supplier review: the contracting entity, where data is processed, subprocessors, training use, retention period, deletion process, encryption, administrator controls, audit evidence and the exit process. Ask whether deleted conversations disappear from active systems immediately or move through a backup retention cycle. Check whether optional connectors allow the tool to search email, cloud storage or CRM records. Confirm whether users can create public links or install third-party extensions.
The ICO's guidance on AI and data protection covers accountability, governance, transparency, lawfulness, accuracy and fairness. It also notes that the guidance is under review following the Data (Use and Access) Act, so this is not a one-off compliance exercise. Schedule a supplier and settings review at least every six months, and whenever the vendor changes its terms, model, retention controls or integrations.
For a small firm, the internal work need not become an enterprise procurement programme. A focused assessment can be completed with a one-page use-case record, a supplier checklist, a data map and a short approval meeting. If external help is required, budget roughly £500 to £3,000 for a narrow tool and privacy review, or £1,500 to £5,000 for a tailored policy, staff workshop and approval process. Those are practical market estimates, not statutory fees. The cost increases when regulated advice, penetration testing or complex system integrations are needed.
Reduce the information before relying on security settings
Data minimisation is more reliable than hoping every later control works. If the task is to improve the tone of an email, remove the client's name, organisation, matter reference, unusual facts and signature block. If the task is to summarise a contract, ask whether the whole agreement is necessary or whether selected clauses will do. Replace identifiers with stable labels such as Client A and Supplier B, then keep the mapping outside the AI system.
Redaction must remove information, not merely hide it visually. Black rectangles placed over PDF text can sometimes leave the underlying text available for copying. Comments, tracked changes, document properties, filenames and image metadata may also reveal identities. Convert a clean copy, inspect it, search for names and reference numbers, and have a second person check high-risk material. Pseudonymised information can still be personal data when your business holds the key, so it remains subject to protection.
Use a simple three-level classification. Green information is public or fictional and may be used in an approved public tool. Amber information is internal or low-risk personal data and requires an approved business workspace plus a defined purpose. Red information includes privileged advice, health records, passwords, payment details, special category data, vulnerable-client information, trade secrets and unreleased transactions. Red information should be prohibited by default and allowed only through a specifically assessed system with named approval.
This discipline matters because ordinary cyber risk is already substantial. The UK government's Cyber Security Breaches Survey 2025/2026 found that 43% of businesses identified a cyber breach or attack in the previous 12 months, equivalent to about 612,000 UK businesses. It also found that 14% of businesses held personal data not protected by techniques such as anonymisation or encryption. AI should not become another uncontrolled route around the protections you already expect elsewhere.
Limit access, record use and keep a human accountable
Give the AI system the smallest permission needed for the task. A tool that drafts answers from an approved knowledge folder should not also have access to every employee's inbox, the finance drive and all historic client files. Create a dedicated service account where appropriate, restrict it to selected folders, use read-only access where possible and review permissions when staff change roles or leave.
Central administration and multi-factor authentication are basic requirements for confidential work. The 2025/2026 government survey found that only 47% of businesses used two-factor authentication, despite its value in reducing account takeover risk. Require it for administrators and users, prohibit shared accounts and ensure recovery methods belong to the business rather than an employee's personal phone or email address. Export or retain the logs you would need to investigate who submitted a file, which connector accessed it and what output was produced.
Keep an AI register with the tool, owner, purpose, data classes, client groups, permissions, supplier review date, human reviewer and next review date. For repeatable workflows, also record tests, known failure modes and the manual fallback. Logs should be proportionate: they should support accountability without creating a new permanent archive of confidential prompts and outputs. Set a retention period and restrict access to the register and operational evidence.
Human review is not a ceremonial glance. The reviewer must have enough subject knowledge to test facts, spot missing context, confirm that the output stays within the client's instructions and decide whether it is suitable to send. For high-impact work, use a two-person check or require the responsible professional to approve the final version. The person signing or sending the work remains accountable. AI does not take over the firm's duty of care, contractual responsibility or professional judgement.
Protect connected AI from prompt injection and excessive access
The risk changes when AI moves from a blank chat box to a connected assistant. A system that reads documents, websites, support tickets or email can encounter hidden or malicious instructions inside that content. Those instructions may try to make the system ignore its rules, reveal information or take an action. This is prompt injection, and it means you cannot treat retrieved content as trusted merely because it came from a familiar-looking document.
The National Cyber Security Centre's AI guidance warns that prompt injection can cause a model to reveal confidential information or trigger unintended consequences. The NCSC also stresses that security should run through the full AI lifecycle and that leaders need to understand the consequences if confidentiality, integrity or availability is compromised.
Put boundaries around connected systems. Separate retrieval from action, allowlist data sources, scan external content, require confirmation before sending messages or changing records, and block the model from returning documents outside the user's normal permissions. Test with deliberately hostile instructions before launch. Ask whether a malicious line in a client email could make the assistant search another client's folder, disclose a system prompt or send an unauthorised reply.
Do not accept the claim that the model 'only reads' information as sufficient protection. Reading is itself disclosure to the system and its suppliers. A read-only connector can still expose sensitive content in an answer, index information too broadly or make it available to the wrong user. Start with a small, isolated knowledge set and a limited staff group. Expand access only after reviewing logs, errors and user behaviour.
Prepare for mistakes before confidential work begins
Assume that someone will eventually paste the wrong material, grant an excessive permission or send an unchecked output. Your incident plan should tell staff to stop, preserve evidence and report quickly without fear of automatic punishment. Capture the account, tool, time, information involved, recipients, settings and actions already taken. Do not delete evidence before the responsible person has assessed what happened.
The first response is containment. Revoke shared links, remove connectors, suspend exposed accounts, rotate credentials where necessary and use the supplier's deletion or support process. Then assess impact. Identify whether personal data, privileged material, trade secrets or contractual information was involved, whether the supplier may retain it and whether another user or system could access it. Bring in the data protection lead, client relationship owner, insurer, legal adviser or regulator as appropriate.
Under UK data protection rules, a personal data breach may need to be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it if it is likely to risk people's rights and freedoms. That does not mean every mistaken AI prompt is automatically reportable. It means the business needs a documented, timely risk assessment rather than guesswork. Contractual and professional notification duties may be different and can apply even when UK GDPR reporting is not required.
Finish with prevention, not blame. Update the rule, tool configuration, training or workflow that allowed the event. If staff used an unapproved tool because the approved route was too slow, fix the route. If redaction failed, improve the checklist and verification. If permissions were too broad, narrow them and add a recurring access review. The honest objective is not to claim that confidential information can never leak. It is to make unsafe disclosure difficult, detection quick, impact limited and accountability clear.
Is This Right For You?
This approach is right for UK firms that hold client files, case notes, contracts, financial records, health information, commercially sensitive plans or other material covered by confidentiality obligations. It is especially useful when staff already use AI informally and the business needs a controlled route rather than an unrealistic blanket ban.
It is not right to connect AI to a whole document store simply because the supplier offers an integration. If you cannot identify the owner, lawful basis, permitted data, retention setting, access group, review process and manual fallback, keep the system away from confidential information. Use fictional, public or properly redacted material while you complete those controls. For legal, clinical, financial or other regulated work, obtain advice specific to your professional obligations before processing real client information.
Frequently Asked Questions
Can staff use ChatGPT with client information if we have a paid account?
Only if the exact business plan, contract, settings and use case have been approved. A paid account alone is not enough. Personal accounts should not receive client information, and even an approved workspace should get only the minimum data required.
Is anonymising a client's name enough?
Usually not. A matter can remain identifiable from dates, job titles, locations, unusual facts, reference numbers or document metadata. Remove indirect identifiers as well, and remember that pseudonymised data remains personal data when your business can reconnect it to the person.
Do we need client consent before using AI on their information?
Not always. Consent is only one possible lawful basis under UK GDPR and is often unsuitable in business or employment settings. You still need a lawful basis, transparency, contractual authority and compliance with professional confidentiality duties. Obtain specialist advice for sensitive or regulated uses.
Can we use AI to summarise confidential contracts?
Yes, but only in an assessed and approved environment, with authority to disclose the document to the supplier, suitable contractual protections, narrow access, appropriate retention settings and human legal review. For early testing, use a synthetic or properly redacted contract.
Should we tell clients that we use AI?
Be transparent where AI use is material to the service, affects how client information is processed or is required by your contract, privacy notice or professional rules. Do not hide a use that a reasonable client would consider important.
How often should we review an approved AI tool?
Review it at least every six months and sooner after a significant supplier, model, terms, integration or security change. Also review after an incident, an unexpected output or a change in the categories of client information being processed.
What should we do if someone has already pasted a client file into an unapproved tool?
Report it immediately, preserve the facts, contain access, use the supplier's deletion process and assess the information, retention, recipients and likely harm. Involve the responsible data protection, legal, client and insurance contacts. Consider ICO notification where the legal threshold is met.