For professional services firms, the attraction of AI isn't difficult to understand. Whether your people work in legal, accounting, consulting, advisory, property or another knowledge-based profession, a significant part of their working day is spent finding information, reviewing documents, analysing data, preparing reports, drafting communications and sharing expertise.
Generative AI has the potential to make many of those activities faster. And your employees know it. The challenge for IT teams is that enthusiasm for AI doesn't necessarily arrive according to an implementation schedule. Employees can start experimenting with AI tools long before an organisation has decided which platforms it supports, what information can be shared with them, or how AI fits within existing security and governance frameworks.
For IT leaders, that creates an uncomfortable choice. Do you become the AI police, trying to restrict access until every risk has been addressed? Or can IT become the AI enabler — giving employees a safe way to use the technology while maintaining appropriate control over organisational and client information?
For most professional services firms, we think the second approach is where the opportunity lies.
Professional services firms have a lot to gain from AI
AI is particularly compelling for businesses whose primary asset is the knowledge and expertise of their people. Consider the potential applications.
Employees can use AI to summarise lengthy documents, prepare first drafts, analyse information, find answers within large collections of organisational knowledge, assist with research, capture meetings and automate repetitive administrative tasks.
Used appropriately, that could mean less time spent on low-value tasks and more time spent applying professional judgement, solving client problems and delivering valuable work.
So it's hardly surprising that employees want access. The difficulty is ensuring the organisation's security and governance practices evolve at the same speed.
1. You can't secure AI you don't know about
One of the first challenges facing IT teams is visibility. Your organisation might have an approved AI platform, an acceptable-use policy and clear guidance for employees.
But does that mean those are the only AI tools being used? Probably not. A staff member might use an online AI service to summarise a document. Another could install an AI meeting assistant. Someone else might experiment with a browser extension, while another team signs up for an AI-powered SaaS application using a corporate account.
None of these decisions necessarily comes from bad intent. Usually, people are simply looking for a faster way to get their work done. But collectively they can create a new form of shadow IT: Shadow AI.
For IT teams, the first question therefore isn't simply "How do we secure our approved AI platform?" It's also: "Do we know where AI is already being used across the organisation?"
2. AI can amplify information-access problems you already have
Introducing an enterprise AI platform doesn't necessarily create entirely new security problems. Sometimes it exposes old ones.
Take Microsoft 365 Copilot as an example. Copilot works within a user's existing Microsoft 365 permissions. If someone can legitimately access particular information, Copilot can potentially use that information when responding to them.
On the surface, that sounds reassuring. But consider an organisation that has accumulated years of SharePoint sites, Teams workspaces, shared folders and legacy permissions.
Does every employee still have access only to the information they genuinely need? Are old project folders still shared more broadly than intended? Are confidential client documents appropriately classified? Do former team members retain access to areas they no longer require?
AI can make existing information considerably easier to find, summarise and connect. In other words, AI doesn't just test your AI security. It tests the quality of the security foundations underneath it.
For IT teams preparing for broader AI adoption, identity, access, permissions, data classification and information governance therefore become part of the AI conversation.
3. Client confidentiality raises the stakes
Professional services firms don't only hold their own sensitive information. They hold their clients' information too. Depending on the organisation, that could include contracts, financial records, strategic plans, legal documents, commercially sensitive correspondence, intellectual property, employee information or details of transactions that haven't yet become public.
Clients provide that information because they trust the firm to protect it. That makes questions around AI particularly important. What information can employees provide to an AI service? How does that service process the information? Where is it stored? Who can access it? Is it used to train models? What happens to prompts and outputs? And what controls exist to prevent sensitive information being used inappropriately?
The Australian Signals Directorate's guidance on engaging with AI recommends that organisations assess the security risks associated with AI systems and apply appropriate mitigations when using both internally and externally hosted services.
The important point isn't that sensitive information means professional services firms shouldn't use AI. It's that the value and sensitivity of the information they hold makes deliberate AI governance essential.
4. An AI policy is important — but it isn't an AI strategy
Creating an acceptable-use policy is a sensible part of AI governance. But a policy can't be the only control.
If employees can see obvious productivity benefits from AI but the organisation doesn't provide them with practical, approved ways to access those benefits, some will inevitably look for alternatives. That's where IT has an opportunity to move beyond saying "Don't use that."
Instead, the conversation becomes: "Here's what you can use, here's how you can use it safely, and here's what you shouldn't share." That requires a combination of technology, governance and education.
It could include approved AI platforms, identity and access controls, data-loss prevention, appropriate information classification, monitoring, user education and clear processes for assessing new AI applications.
The objective isn't to remove every conceivable risk. It's to create enough visibility and control that employees can innovate without the organisation flying blind.
5. The next challenge is AI that can act, not just answer
There's another reason IT teams need to establish these foundations now. AI is rapidly moving beyond chat interfaces that simply answer questions. AI agents can increasingly interact with applications, access organisational information and perform tasks on behalf of users.
That creates enormous potential for automation — but it also changes the security equation. An AI assistant that can summarise a document presents one level of risk. An AI agent that can access systems, retrieve information and take actions presents another.
The Australian Signals Directorate has recently urged organisations adopting agentic AI to consider what could go wrong, assess how those scenarios could affect operations and maintain ongoing visibility and assurance over their AI investments.
For IT leaders, concepts such as least-privilege access, strong identity controls, monitoring and human oversight become even more important as AI moves from providing information to taking action.
IT doesn't need to be the department that says no
There is a temptation with any rapidly evolving technology to wait until all the risks are understood. With AI, that may not be realistic.
Employees are interested. Vendors are embedding AI into existing platforms. Business leaders are looking for productivity gains. And the technology itself continues to evolve.
The more useful question for IT leaders may therefore be: What needs to be true for us to say yes?
-
Do we know which AI tools are being used?
-
Do we understand where our sensitive information resides?
-
Are our identity and access controls appropriate?
-
Have we reviewed legacy permissions and oversharing?
-
Can we provide employees with sanctioned alternatives to consumer AI tools?
-
Do employees understand how to use AI responsibly?
-
And do we have enough visibility to recognise when something isn't working as intended?
-
Those questions turn AI security from a roadblock into an enabler.
Because ultimately, the organisations that benefit most from AI may not be those that adopt every new tool first. They'll be the organisations that create an environment where their people can experiment, innovate and become more productive without compromising the trust their clients place in them.
For professional services IT teams, that's an opportunity to lead.
Tags:
Professional Services
12 August 2026, 13:15:27 GMT+09:30
Comments