Guide · Law & accounting

AI and client confidentiality: a practical guide for law and accounting firms

The duty of confidentiality did not change because the tools did. What changed is how many places client information can end up in a single afternoon.

Updated September 2026

In short

Professional confidentiality means taking reasonable care over who can see client information, and that applies to AI tools too. In practice: know where client data goes when you use AI, choose where the model runs by how sensitive the matter is, keep AI agents’ access narrow and logged, never let an agent send email or move money without a person’s review, and follow your professional body’s guidance. This guide is practical, not legal advice.

Where client data actually goes

Using AI on a matter can put client information in more places than people expect:

  • The AI provider, if the model runs in the cloud.
  • Chat histories and shared workspaces in the AI tool.
  • Agent tools and plugins that fetch documents or email on the model’s behalf.
  • Logs, exports and copies made while testing a workflow.

Choose the model by the matter

Several bar associations and accounting bodies have published guidance on AI: understand the tool, protect confidential information, supervise the output, and be open with clients where required. A workable rule for a small firm is to decide per matter.

For highly sensitive matters, use a model that runs on your own hardware, or keep identifying details out of the prompt. For routine work, a business plan of a cloud model with no-training commitments may be acceptable under your rules. Write down which applies to what.

Email is the riskiest door

Client email is where confidential information and untrusted input meet. A message can carry instructions aimed at an AI agent, and an agent that can send can be tricked into forwarding documents. Give AI assistants a connection that can read and prepare drafts, but cannot send, delete or forward. A person reviews and sends.

Practical rules for the firm

  • Keep the credentials to client systems out of plain-text files and out of agents’ reach.
  • Give each agent only the access its task needs, and revoke it when the task ends.
  • Where possible, let agents see client names as placeholders rather than real values.
  • Nothing leaves the firm (emails, filings, payments) without a person’s review.
  • Keep a record of what each agent accessed, in case a client or regulator asks.

Checklist

Firm checklist

  • We know which AI tools touch client information, and on which plans.
  • Sensitive matters use a local model or keep identifying details out of prompts.
  • AI assistants can read and draft email, but cannot send it.
  • Agents’ access to client systems is limited, logged and revocable.
  • We have read our professional body’s current guidance on AI.

How the MoltenRock apps help a firm

The MoltenRock apps run on your Macs and keep credentials, email access and the record under the firm’s control. They do not run the AI model, and they make no legal or compliance claims for you.

Questions

Can lawyers and accountants use AI at all?

Many professional bodies say yes, with care: understand the tool, protect confidential information and supervise the output. Check your own body’s current guidance.

Is a cloud AI model a breach of confidentiality?

Not automatically. It depends on the provider’s terms, your rules and the matter. For the most sensitive work, a local model or keeping identifying details out of the prompt is the cautious choice.

Should AI draft client emails?

Drafting is fine if a person reviews and sends. Do not give an AI tool the ability to send on the firm’s behalf.

Do we need client consent?

Some rules require informing or asking clients in certain cases. Follow your professional body’s guidance and your engagement terms.

This guide is general information for professional firms, not legal advice. Rules differ by country and profession; check your professional body’s current guidance.

More guides