AI and client confidentiality: what accountants and advisers must check
Generative AI is already in most firms, drafting client letters, tidying report sections, summarising a stack of statements. The productivity is real. The risk is that client financial data is confidential, often regulated, and a free chatbot is a processing arrangement nobody assessed.
You don't need to ban AI to handle this well. You need to be able to answer three questions about any tool before client data goes near it.
1. Where is the data processed, and on whose hardware?
"In the cloud" is not an answer your file should rely on. Ask which company operates the infrastructure and in which country. A UK region of a Big Tech cloud tells you the postcode of the servers, not who controls them. For client data you may be obliged to know both.
2. Who could be compelled to hand it over?
This is the question most firms skip, and it's the one that matters. Under the US CLOUD Act, a US-owned provider can be required to disclose data in its possession regardless of where that data is stored. So a US AI tool with a "UK data residency" setting still leaves the data within reach of a US legal order. That doesn't mean it will happen, it means your assessment of client confidentiality has to acknowledge it can. Our free AI privacy checker answers this for your current tools in two minutes, with no email and no tracking.
3. Does the tool train on your inputs?
If client figures and correspondence are used to improve a model, that is a use of confidential data your engagement terms almost certainly didn't permit. Many consumer tools train by default on free tiers and require an explicit opt-out; business tiers often don't train, but you should confirm which tier you're actually on and get it in writing.
Why this is a confidentiality issue, not just an IT one
Accountants and financial advisers owe duties of confidentiality to clients, and firms are expected to handle client data in line with data-protection law and their regulator's expectations. "A member of staff was using a free AI tool we hadn't assessed" is not a defence, it's the finding. A short written AI-use policy and one approved, assessed tool turn an invisible risk into a controlled, defensible process.
AI drafting that keeps client data in the UK
Hush AI drafts client letters, report sections and file notes under your review, on privately owned hardware, outside US CLOUD Act jurisdiction, never used for training, with a one-click audit trail for your compliance file. It does not give financial advice or make recommendations.
For finance firms Start a free trialHush AI (hush-ai.uk) is a private AI assistant for regulated professionals. It drafts under your review, not advice, not a decision-maker. This article is general information, not legal, regulatory or compliance advice; check your own obligations with your professional body and DPO.