Can You Put a Client’s Financials in ChatGPT? Nearly Half Your Staff Already Has — Here’s the Honest Answer for South Shore Firms

By Secure Networks

Someone at your firm has already asked this question. Maybe not out loud, and maybe not to you.

They were staring down a client’s trial balance, or a set of statements that needed summarizing, or a memo that would take ninety minutes to write and twelve minutes to write with help. And they wondered — briefly, and then not so briefly — whether they could just paste it in.

Some of them wondered and stopped. Some of them didn’t. Nationally, nearly half of employees admit they’ve already uploaded sensitive company information into an AI chat, and up to 65% are using AI tools their employer never approved. For a South Shore firm of a dozen or twenty people, that’s not a fringe risk. That’s most of your staff, guessing on their own, every week.

You need an answer to this. Not a hedge, not a “we’re looking into it,” and not a blanket no that everyone quietly ignores. Here’s the honest one.

The answer depends entirely on which door the data walks through

The question “can we use AI with client data” has no single answer, because it isn’t one question. It’s a question about where the tool sits.

A personal account is a different product than a company tenant. Same model, same interface, materially different agreement. When someone signs up with a personal email and a personal card, they’ve entered into a consumer arrangement on your firm’s behalf without anyone reviewing it. Data handling, retention, whether inputs can be used to improve the model, what happens if the account is compromised, who has the ability to retrieve anything — all of that is governed by terms nobody at your firm has read, and none of it is under your control.

A licensed business tenant is a commercial arrangement. Data handling is contractual. Retention is defined. You own the tenant, you control access, you can revoke it, and — this matters more than anything else here — you can describe it to a client who asks. If your firm runs on Microsoft 365, you’re closer to a defensible answer than you think. Secure Networks has spent years helping South Shore businesses set up and license Microsoft 365 correctly, and often the safer tool is already sitting inside the plan you’re paying for. It just isn’t turned on, or nobody’s told your team it’s the approved option.

So the honest answer is: it depends on whether your people are working inside something you control, or outside it. And right now, in most firms, the answer is some of both, and nobody knows the split.

The three questions your staff cannot currently answer

Not because they’re careless. Because nobody has told them.

“Is this tool approved?” If your firm has never named one, every person is making their own call, weekly. They will keep making it, and they will keep making it differently.

“Is this specific piece of information okay to put in?” There is a real difference between a redacted excerpt, a public filing, and a client’s complete general ledger. Your people know that instinctively. What they don’t have is a line — an actual, written line — telling them where it sits. In the absence of a line, they guess, and they guess under deadline pressure.

“Who do I ask when I’m not sure?” This is the one that quietly matters most. If the answer is nobody, then the default behavior when someone is unsure is to proceed and not mention it. That is precisely the situation you cannot afford, especially under Massachusetts data privacy law, where the safe practice is to keep raw client information — names, account numbers, financial detail — out of free, public AI tools entirely and inside a licensed, controlled workspace instead.

Every one of those questions is answerable in a sentence. None of them are answered at your firm today.

The reflex to ban it is the expensive one

Confidentiality is not negotiable in this business. Neither is the human relationship your clients pay for — nobody wants to feel like their return was run through a machine.

But an outright ban does not protect either of those things. It moves the behavior to phones and home laptops, where you have no visibility at all. And it hands a real advantage to the firm across the rotary that took the time to do this properly.

Because they are doing it properly, and here’s what it’s returning: hours back on document review, on research, on first-draft memos, on the reconciliation work that eats a senior’s afternoon and generates zero client value. That’s billable capacity you’re currently spending on things a machine could carry — during busy season, when you cannot hire your way out of it.

The firms getting this right didn’t compromise on confidentiality. They put a boundary around it and then moved. As a local partner working with firms across the South Shore and Southeastern Massachusetts, we’ve seen the difference a single afternoon of clear guidance can make.

What you actually need in writing

Less than you think. This is not a compliance program.

One approved tool, named. Ideally the one already inside the license you’re paying for.

One page that says what client information may go into it, what may never, and what must be reviewed by a person before it leaves the firm. Written in plain language, not counsel’s language, because it has to be read by someone in the middle of a busy Tuesday.

One name — the person to ask when the answer isn’t obvious. So that “I wasn’t sure” ends in a question rather than a shortcut.

One sentence you can say to a client who asks what your firm’s position on AI is. You will be asked. Preferably before it happens.

That’s the whole document. It takes an afternoon. And the day it exists, you stop being a firm where people are guessing, and start being a firm where people are working within a boundary you set.

Get the AI Acceptable Use Policy Starter Kit

A one-page, plain-language policy your team will actually read — plus the sanctioned-tool checklist, the data-classification lines to draw, and the answer to give a client who asks.

Written for firms handling confidential client information. Free.

Questions before then? Call Secure Networks at (508) 418-3245 or email [email protected]. We’ve been the local IT team for the South Shore’s nonprofits, healthcare practices, and professional service firms for more than 20 years — we’re here when you need us.

Leave a Comment