Using AI With Client Data: What to Check First
Before your team pastes client records into an AI tool, check where the data goes, who can see it and which rules apply. A plain checklist for small businesses.
Somebody on your team is probably already using an AI tool at work. They paste in an email to tidy it up, a spreadsheet to summarize, a set of notes to turn into a report. Most of the time that is a good thing. The question worth asking is what happens when the thing they paste in is a client's tax return, a patient's care notes or a buyer's financial details.
You can still use AI on client work. You just need to know where the data goes before it goes there.
Where your data actually goes
When you type into an AI tool, the text is sent to the provider's servers to be processed. What happens next depends on the product and the plan you are on:
- Is it stored? For how long, and can you delete it?
- Is it used to train models? Some consumer plans may use conversations for training unless you switch it off. Business and enterprise plans often exclude it by default. Read the current terms for the exact plan you use, because they differ and they change.
- Who at the provider can see it? Most providers allow limited human review for safety or abuse checks. The terms will say when.
- Where is it processed? This can matter if you have clients in the UK or EU, or contracts that specify where data may be held.
A free personal account that an employee signed up for on their own is the riskiest setup, because the business has no control over its settings and no record of what went in.
The rules that may already apply to you
Most of the obligations around AI and client data are ones you already have. A few that come up often with the businesses we work with:
- Healthcare. If you handle protected health information under HIPAA, any vendor that receives that information on your behalf generally needs a Business Associate Agreement with you. If an AI provider will not sign one for the product you are using, patient information should not go into it.
- Tax and accounting. In the US, tax preparers fall under the FTC Safeguards Rule, which requires a written information security plan. The IRS also publishes guidance for preparers on protecting taxpayer data (Publication 4557). An AI tool that touches client records belongs inside that plan.
- Clients in the UK or EU. Data protection law there expects you to know which processors handle personal data and on what terms.
- Your own contracts. Some client agreements and NDAs limit sharing with third parties, and an AI provider can count as one.
This is a starting point for a conversation with your compliance adviser, and it does not replace one. The point is that the question "can we put this into an AI tool?" usually has an answer already, in rules you follow today.
A simple checklist before you roll it out
- Pick approved tools and plans. Choose a business plan with clear data terms, and make it the one people use.
- Turn off training on your data where the plan allows it, and confirm the retention settings.
- Sign the agreements you need. A BAA for health data, a data processing agreement where your clients' privacy law expects one.
- Write a one-page AI policy. What can go in (drafting, general research, internal templates), what needs care (client names, figures) and what never goes in without an approved setup (medical records, Social Security numbers, bank details).
- Remove identifiers when you can. Many tasks work just as well with "Client A" and rounded figures.
- Keep a person on the final output. AI drafts. A qualified person checks and sends.
- Revisit it every few months. Terms, products and your own use will all change.
When a custom setup makes sense
If client data is central to the work, the better answer is often a system built for it: an assistant that runs inside an account your business controls, answers from your own approved documents and logs what it does. That is how a RAG-based assistant is usually set up, and it is the same approach we take with an AI receptionist that handles patient or client inquiries. You decide what it can see, what it can say and when it hands over to a person.
How we work
At Pinn.Media we build AI tools for healthcare agencies, CPA firms and other businesses that hold sensitive information, and the data questions come first: what goes in, where it is processed, what is kept and who signs off. Book a discovery call and we will help you work out which of your tasks can use AI safely today, and what it would take to do the rest.
One team, from identity to intelligence.
Brand, software, AI, and growth from a single team, not separate vendors.
Book a discovery call