For professional services firms, the appeal of artificial intelligence is easy to understand. Employees spend much of their time finding information, reviewing documents, analysing data, preparing reports and communicating with clients. AI can help with many of these activities, giving people more time to apply their judgement and expertise.
Adoption is not always waiting for a formal business decision. Employees can access generative AI tools through a browser, install meeting assistants, enable features within existing software or subscribe to new applications using a work email address.
In many firms, experimentation has already begun. That creates an important leadership question: How can the firm capture the productivity benefits of AI while protecting the confidential information that clients have entrusted to it?
AI adoption may be moving faster than governance
A firm may have an approved AI platform and an acceptable-use policy. That does not necessarily mean employees use only approved tools or understand what information they can safely provide to them.
Most unsanctioned use does not begin with poor intent. A consultant wants to summarise a long document. A finance professional wants help drafting a client update. A project team tests an AI meeting assistant. Someone uses a free online tool because it produces an answer quickly.
Each decision can appear harmless in isolation. Together, they can leave the firm with little visibility over which tools are being used, what information is entering them and how that information is processed.
This is often described as Shadow AI. A blanket prohibition may feel like the safest answer, but it can push useful experimentation further from view. Employees need clear boundaries and practical, approved ways to use AI. Otherwise, the policy and everyday behaviour may quickly move apart.
Client confidentiality raises the stakes
Professional services firms hold information that belongs to other organisations and individuals. Depending on the profession, that information might include:
- Financial records
- Contracts
- Commercial plans
- Intellectual property
- Personal information
- Project documentation
- Confidential correspondence
Clients provide that information because they expect the firm to handle it with care. If an employee copies client material into an AI service that the firm has not assessed, several questions arise:
- Where is the information stored?
- Who can access it?
- Is it retained?
- Can it be used to improve the service?
- What happens to the prompts and outputs?
Leaders do not need to become AI security specialists. They do need confidence that someone within the organisation has considered these questions before sensitive information is placed into a new service.
This is why AI governance belongs in a broader conversation about client trust. A firm’s approach to AI should reflect the same professional obligations that already shape how employees handle documents, correspondence and advice.
AI can expose information problems that already exist
Some of the most important AI risks do not begin with the AI tool itself. They begin with how information is already organised and shared. A firm may have years of documents spread across SharePoint sites, Teams workspaces, shared drives, email and specialist applications.
Access often accumulates over time. Employees change roles, project teams disband and external parties retain permissions longer than intended. AI makes information easier to find, summarise and connect. That can improve productivity, but it can also make existing oversharing more visible.
An employee may receive an accurate answer based on information they technically have permission to access but no longer need for their role. Before expanding AI across the firm, leaders should ask whether the information environment underneath it is ready. Clear ownership, appropriate access and regular permission reviews create a stronger foundation for safe adoption.
A policy cannot carry the whole strategy
An AI policy is useful. It can explain which tools are approved, what information employees must not share and where they should go for guidance. It also gives managers a consistent basis for discussing responsible use.
However, a policy cannot provide visibility, correct excessive permissions or secure an application. It also cannot deliver the productivity benefits that employees and business leaders expect from AI.
Responsible adoption needs a combination of governance, technology and education. Employees need approved services that suit the work they are trying to perform. The firm needs appropriate identity, access and information controls. People also need examples that make the rules meaningful in their day-to-day roles.
The objective is not to eliminate every possible risk before anyone can begin. It is to create enough oversight and control for the firm to make informed decisions and respond when something changes.
Leadership needs to define the conditions for saying yes
AI adoption should not become the sole responsibility of IT. Technology teams can assess platforms and implement controls, but business leaders understand the client obligations, work practices and professional consequences involved.
A practical governance model should answer several questions:
- Who owns the firm’s approach to AI and approves new use cases?
- Which AI services may employees use for business activities?
- What organisational and client information must not be entered into those services?
- How will new applications and embedded AI features be assessed?
- Are existing access and information-sharing practices appropriate?
- How will employees receive practical guidance and raise questions?
- How will the firm monitor adoption and review decisions as the technology changes?
These decisions do not need to be perfect on the first attempt. They need clear ownership and a process for review. AI services will continue to change, and features may appear inside platforms the firm already uses. Governance therefore needs to operate as an ongoing business discipline rather than a one-time policy project.
Client trust and AI innovation can support one another
Professional services firms do not need to choose between innovation and confidentiality. With suitable foundations, AI can help employees work more efficiently while the firm maintains control over sensitive information.
The starting point is visibility. Leaders need to understand how employees are already using AI, where the most valuable use cases exist and which information those activities involve. From there, the firm can provide approved tools, strengthen information controls and give employees practical guidance.
This approach also helps the organisation prepare for the next stage of AI. Newer systems can increasingly retrieve information, interact with applications and perform actions on a user’s behalf. As AI moves from answering questions to completing tasks, clear access boundaries and human oversight will become even more important.
Clients trust professional services firms because of the judgement and care their people apply. A considered approach to AI can protect that trust while allowing employees to benefit from useful new capabilities.
Questions for your leadership team
If AI use is already growing within your firm, these questions can help start the internal discussion:
- Do we know which AI tools employees are using today?
- Have we defined what client and organisational information can be shared with AI services?
- Can employees access approved tools that meet their practical needs?
- Are our Microsoft 365 permissions and information-sharing practices ready for broader AI adoption?
- Who approves new AI use cases and reviews them over time?
- Do employees know where to ask for guidance before trying a new service?
The answers will show whether the firm is actively governing AI or relying on individual employees to make decisions on its behalf. Establishing that visibility now gives the organisation a better chance of realising AI’s benefits without weakening the confidence clients place in it.
Tags:
Professional Services
10 September 2026, 14:57:00 GMT+09:30
Comments