Written by 7:31 pm AI Workflows • 2 Comments

What Small Accounting Firms Should Never Put Into an AI Tool

What Small Accounting Firms Should Never Put Into an AI Tool

An accountant needs help interpreting a client document. The fastest move is obvious: upload it to an AI assistant and ask for a summary.

The document contains the client’s name, tax information, bank details, payroll data, and information about other parties.

The accounting question may be simple. The data decision is not.

The useful question is not whether an AI model is “safe.” It is what data you are sending, through which product and account configuration, under what controls, and against which professional obligations.

A practical classification

CategoryExamplesDefault stance
Do not submitPasswords, API keys, private keys, authentication credentials, MFA codes, system access tokensAbsolute. These belong nowhere near a general-purpose AI tool.
Restricted client dataClient tax returns or source documents with identifiers, payroll files, bank statements with account numbers, unredacted workpapers, engagement letters with pricing, unpublished financials, client correspondence containing PIIUse only through firm-approved configurations and after the firm has addressed confidentiality, contractual, technical, and jurisdictional requirements.
Check firstPartially redacted client data, internal firm templates that still contain client-specific numbers, draft memos that reference live client factsRisk depends on residual identifiers, tool configuration, and firm policy.
Generally lower riskFully anonymized or synthetic data with no residual identifiers, public statutes, published guidance, public filings, generic process questions with no client factsStill subject to firm policy, but the confidentiality exposure is materially lower.

Why product tier matters more than model name

The same model family can present different data-handling profiles depending on the product and account.

Consumer and personal tiers (ChatGPT Free, Plus, and Pro; Claude Free, Pro, and Max; consumer Gemini) currently operate under terms that, by default, allow use of inputs for model improvement unless the user has opted out, with limited contractual protections and weaker administrative controls.

Related: THE TEST: We Gave Five AI Systems the Same Month-End Variance Analysis

Business and enterprise tiers (ChatGPT Team/Business and Enterprise; Claude Team/Enterprise and commercial API; Gemini in Google Workspace or via Vertex AI under enterprise terms) generally state that customer content is not used to train models by default and provide stronger contractual, retention, and administrative controls.

These distinctions are based on published product terms at the time of writing and can change. They do not make any specific tool automatically suitable for confidential client information. Suitability still depends on the data being sent, the exact configuration in use, the firm’s policies, jurisdictional requirements, and the professional rules that apply to the engagement.

Professional context

Existing confidentiality obligations continue to apply. Using a third-party AI service can trigger the same confidentiality and third-party-service considerations that already apply when client information leaves the firm’s direct control. The practitioner remains responsible for the data and for the work product regardless of the tool used.

Firms therefore need a documented approach that covers:

  • Which tools and tiers are approved
  • What categories of data may enter those tools
  • What consent or engagement-letter language is required
  • How outputs are reviewed before use

Absent that framework, individual staff decisions become the firm’s risk.

Practical starting rules for a small firm

  1. As a default firm policy, do not place client-identifiable data into consumer AI accounts unless the firm has explicitly reviewed and approved that use.
  2. Use client data only in firm-approved tools and configurations that have been reviewed for the specific type of data and use case.
  3. Prefer redaction or anonymization whenever the task does not require live identifiers.
  4. Keep credentials and access secrets completely out of AI tools.
  5. Document the decision process so the firm can show it applied professional judgment rather than convenience.

Closing note

This is not a compliance determination for any specific product or jurisdiction. The point is narrower: firms need to evaluate the data, product tier, settings, contractual protections, and professional obligations together rather than relying on a model name or an “enterprise” label.

Visited 9,000 times, 1 visit(s) today
Get practical research on AI, accounting workflows, and software.
Close