Can You Put a Client’s Financials in ChatGPT? The Honest Answer Isn’t Yes or No — It’s Which Door the Data Walks Through

Can You Put a Client’s Financials in ChatGPT? The Honest Answer Isn’t Yes or No — It’s Which Door the Data Walks Through

Someone at your firm has already asked this question. Maybe not out loud, and maybe not to you.

They were staring down a client's trial balance, or a set of statements that needed summarizing, or a memo that would take ninety minutes to write and twelve minutes to write with help. And they wondered — briefly, and then not so briefly — whether they could just paste it in.

Some of them wondered and stopped. Some of them didn't.

You need an answer to this. Not a hedge, not a "we're looking into it," and not a blanket no that everyone quietly ignores. Here's the honest one.

The answer depends entirely on which door the data walks through

The question "can we use AI with client data" doesn't have one answer, because it isn't one question. It's a question about where the tool sits.

A personal account is a different product than a company tenant. Same model, same interface, materially different agreement. When someone signs up with a personal email and a personal card, they've entered into a consumer arrangement on your firm's behalf, and nobody reviewed it. Data handling, retention, whether your inputs get used to train the model, what happens if that account is compromised, who can retrieve anything later — all of that is governed by terms nobody at your firm has read. None of it is under your control.

A licensed business tenant is a commercial arrangement. Data handling is contractual. Retention is defined. You own the tenant, you control access, you can revoke it — and this is the part that matters most — you can describe it to a client who asks. If your firm runs on Microsoft 365, you may already be closer to a defensible answer than you think. Often the tool is already sitting inside the license you're paying for, through something like Microsoft 365 Copilot, rather than out on someone's personal account.

So the honest answer is: it depends on whether your people are working inside something you control, or outside it. Right now, in most firms, the answer is some of both — and nobody knows the split.

The three questions your staff cannot currently answer

Not because they're careless. Because nobody has told them.

"Is this tool approved?" If your firm has never named one, every person is making that call on their own, weekly. They'll keep making it, and they'll keep making it differently from the person at the next desk.

"Is this specific piece of information okay to put in?" There's a real difference between a redacted excerpt, a public filing, and a client's complete general ledger. Your people know that instinctively. What they don't have is a line — an actual, written line — telling them where it sits. Without that line, they guess. And they guess under deadline pressure.

"Who do I ask when I'm not sure?" This is the one that quietly matters most. If the answer is nobody, the default behavior when someone is unsure is to proceed and not mention it. That's the exact situation you can't afford.

Every one of those questions is answerable in a sentence. None of them are answered at your firm today.

The reflex to ban it is the expensive one

Confidentiality is not negotiable in this business. Neither is the human relationship your clients pay for — nobody wants to feel like their return was run through a machine.

But an outright ban protects neither of those things. It just moves the behavior to phones and home laptops, where you have zero visibility. And it hands a real advantage to the firm across town that took the time to do this properly.

Because that firm is doing it properly — and here's what it's returning: hours back on document review, on research, on first-draft memos, on the reconciliation work that eats a senior's afternoon and generates no client value at all. That's billable capacity you're currently spending on things a machine could carry, during the exact stretch of the year when you cannot hire your way out of it.

The firms getting this right didn't compromise on confidentiality. They put a boundary around it and then moved.

What you actually need in writing

Less than you think. This is not a compliance program.

One approved tool, named. Ideally the one already inside the license you're paying for.

One page that says what client information may go into it, what may never, and what must be reviewed by a person before it leaves the firm. Written in plain language, not counsel's language, because it has to be read by someone in the middle of a busy Tuesday.

One name — the person to ask when the answer isn't obvious. So "I wasn't sure" ends in a question, not a shortcut.

One sentence you can say to a client who asks what your firm's position on AI is. You will be asked. Preferably before it happens.

That's the whole document. It takes an afternoon. And the day it exists, your firm stops being a place where people are guessing, and starts being a place where people are working inside a boundary you set — the map they've been missing, not a rule they resent.

We've been the quiet infrastructure behind Wilmington and Kennett Square businesses since 1997, and the firms we work with tend to ask us this exact question the same week a client asks them. It's a solvable problem. It just needs to be solved on purpose, not by accident.

Get the AI Acceptable Use Policy Starter Kit

A one-page, plain-language policy your team will actually read — plus the sanctioned-tool checklist, the data-classification lines to draw, and the answer to give a client who asks.

Written for firms handling confidential client information. Free.

Get the Starter Kit →