The 10 Rules of AI Governance, Before Someone Pastes Client Data Into ChatGPT
Right now, somewhere in your firm, someone has a ChatGPT tab open. They’ve pasted in a client’s financials, or a draft contract, or a file note, and asked it to “tidy this up.” They think they’re being efficient. They have no idea they just handed confidential client information to a third party you’ve never assessed, under terms nobody read.
That’s not a hypothetical. It’s the single most common way professional firms are leaking client data in 2026, and most directors can’t even see it happening. There’s no breach alert, no ransom note, no server down. Just staff quietly routing your clients’ confidential information through tools you never approved.
You don’t need a 40-page AI policy to fix this. You need a short list of rules everyone actually follows. Here are the ten we give our clients.
1. Don’t put client data into public AI tools. Full stop.
If information is covered by an NDA, by legal professional privilege, or by your duty of confidentiality to a client, it does not go into ChatGPT, Gemini, Claude, or any other public AI tool. Not “anonymised first.” Not “just this once.” It doesn’t go in.
The legal ground here is shifting under your feet. The Privacy Act reforms that passed in December 2024 handed the OAIC sharper enforcement powers, a new tiered penalty regime, and, for the first time, wrote automated decision-making into Australian privacy law. From late 2026, organisations have to disclose in their privacy policy where they use personal information in systems that make or substantially help make decisions affecting people. If you’re feeding client data into AI you can’t even account for, you are nowhere near able to answer that question.
Your client’s NDA was written for a world of filing cabinets and email. It does not cover their data becoming training fodder for someone else’s model. The moment you’re unsure whether something should go in, you already have your answer.
2. Know every AI tool in your stack
You can’t govern what you can’t see. Most firms have no idea how many AI tools their staff are actually using, because the tools arrived one signup at a time: a free transcription app here, an AI note-taker bolted onto Teams there, a browser plugin someone installed on a Friday afternoon.
Every one of those is a connection out of your business and a potential data leak. Audit them quarterly. Not “when we get a chance,” which means never. Put it on the calendar like you would a BAS deadline. Who’s using what, what data it touches, and whether it should still be there.
3. Treat every OAuth connection like a physical key
When a tool asks “Connect to Google Drive?” or “Allow access to your Microsoft 365?” and someone clicks yes, that’s not a small permission. It’s often full read access to everything in that account. You just gave an app you’ve never vetted a key to the building.
Those connections don’t expire on their own, and nobody ever goes back to check them. Review them monthly, not once a year when you finally remember. Revoke anything you don’t recognise or no longer use. This is the same discipline as managing one clean identity for every login, which we cover in One Identity, Zero Passwords.
4. Treat AI browser extensions as hostile until proven otherwise
This one isn’t theoretical, and it’s recent. In January 2026, two Chrome extensions branded around ChatGPT and DeepSeek were caught quietly siphoning users’ full AI conversations, browsing URLs, and authentication tokens off to an attacker’s server every 30 minutes. Combined, they had over 900,000 installs. Microsoft’s own telemetry found the wider campaign active across more than 20,000 business tenants.
The lesson: “Featured” on the Chrome Web Store means nothing. A five-star rating means nothing. An AI extension sits inside the browser where your staff are logged into your email, your practice management system, and your client files, and it can read all of it. The safe default is to block them by policy and whitelist the rare exception, not the other way around.
5. Classify the data before the AI call, not after
Rule one tells you what never goes in. This is the habit that makes it stick: before anyone uses AI on a piece of information, they should know what that information is.
Make it a simple gut check. If a staff member is hovering over the paste button thinking “should I really put this in?”, that hesitation is the answer. Don’t. The few seconds it takes to ask “is this public, internal, or confidential?” is the entire difference between a productivity win and a notifiable breach.
6. Remember that free AI isn’t free, you’re paying with data
When a powerful AI tool costs nothing, your inputs are the price. On the free and consumer tiers of most AI tools, what you type in can be retained and used to train the model. Your client’s confidential data is not a freebie you get to hand over to subsidise a tool you didn’t pay for.
The fix is straightforward and it’s the same one we recommend for almost every firm: use the paid, business-grade versions with proper data protection terms, where your inputs aren’t used for training and the data handling is contractually defined. Microsoft 365 Copilot inside your own tenant is a very different proposition to a staff member’s personal ChatGPT account. One is governed. The other is a leak waiting for a headline.
7. Verify every output before it leaves the building
AI is confidently wrong on a regular basis. It invents case citations, fabricates statistics, and misreads documents while sounding completely authoritative. Lawyers in multiple jurisdictions have already been sanctioned for filing AI-generated submissions citing cases that never existed.
For a professional firm, an unchecked AI output isn’t a typo risk, it’s a liability one. Courts are increasingly asking whether AI was used. Your professional indemnity insurer cares enormously about how you produce advice. A human who is accountable signs off on every AI-assisted output before it reaches a client or a court. No exceptions, no “it looked right.”
8. Make the approved path faster than the shortcut
Here’s the uncomfortable truth about shadow AI: staff don’t reach for unapproved tools to be reckless. They reach for them because the approved option is slow, painful, or doesn’t exist. If getting a tool sanctioned takes three weeks of emails, someone will sign up for the free version in three minutes and never tell you.
You will not win this with a ban. You win it with speed. Give people a clear, fast way to get a useful AI tool approved, and a sanctioned tool that’s genuinely good enough to use. When the safe path is also the easy path, shadow IT dries up on its own. Convenience is the control.
9. Put AI into your incident response plan
When something goes wrong, and with this much new tech moving this fast, assume it’s when, not if, you need to already know the answers. Which AI tools have access to client data? Which OAuth tokens grant the deepest reach? Who revokes them, and how fast?
If your incident response plan still pretends AI doesn’t exist, it’s out of date. The middle of a breach is the worst possible time to be working out which connections to kill first. Map it now: every AI integration, what it can reach, and the exact steps to cut it off. A plan you’ve never updated for AI is a plan that fails on the day you need it.
10. Train your team, because a policy nobody understands protects nothing
In 2023, Samsung learned this the hard way. Within less than 20 days of allowing staff to use ChatGPT, engineers had leaked confidential source code and internal meeting notes into it across three separate incidents. These weren’t careless people. They were skilled engineers who didn’t grasp that “paste into ChatGPT” meant “send to a third party’s servers.” Samsung banned the tools company-wide shortly after.
That’s the whole problem in one story. Your people aren’t trying to hurt the firm. They simply don’t see the risk, because nobody showed them. Knowledge without policy is useless, and policy without knowledge is worse, because it gives you false comfort. Short, plain-language training that explains why these rules exist will stop more leaks than any document gathering dust on the shared drive.
What you should do this week
- Ask the honest question: what AI tools are your staff actually using right now? Don’t assume zero. Find out.
- Review your OAuth connections in Microsoft 365 and Google Workspace. Revoke anything you don’t recognise. This is the fastest way to close the widest hole.
- Write the one-page version of these rules and put it in front of your team. One page they’ll read beats forty pages they won’t.
- Pick a sanctioned, business-grade AI tool so staff have a safe, fast option instead of a personal account. Make the right path the easy one.
- Add AI to your incident response plan, even if it’s just a list of every integration and how to switch it off.
Used well, AI is a genuine advantage for a small firm. Used blind, it’s an uncontrolled export of your clients’ most sensitive information. The difference is governance, and governance is just a short list of rules people actually follow.
If you want a straight read on what your team is really using and where the exposure sits, that’s exactly the kind of thing a Technology Business Review starts with. Book a conversation and we’ll tell you where you stand. No sales pitch, just a straight answer.
Not sure if your IT is actually working?
A Technology Business Review is an independent look at your current setup, no provider switch required. You get the findings either way.
More on this: Managed IT articles · Managed IT Services