TerrierTerrier

Shadow AI in Professional Services: The Client Data Risk Law Firms, Accounting Firms, and Financial Advisors All Share

Last updated: June 2026


Law firms, accounting firms, and financial advisory firms are experiencing the same problem from three different angles. Employees are using consumer AI tools — ChatGPT, Claude, Otter.ai, Grammarly — with client data, without firm approval, and without understanding what happens to that data once it enters those tools. The firm doesn't know it's happening. The client doesn't know it's happening. And the regulatory and ethical consequences differ by industry, but the root cause is identical.


The Scenario That Plays Out the Same Way at Every Firm

A junior employee has a deadline. They have a tool that can help them meet it in four minutes instead of two hours. They use it.

At a law firm, it is an associate drafting a motion. Client name, case facts, legal strategy go into a ChatGPT Plus prompt. ChatGPT Plus terms allow training on user inputs by default. In February 2026, a federal court ruled in United States v. Heppner that documents prepared this way were neither attorney-client privileged nor protected work product.

At an accounting firm, it is a staff accountant summarizing a client's tax return or audit workpapers in Claude.ai. Revenue figures, entity structures, and personal financial data enter a consumer AI system. The firm's confidentiality obligations under AICPA ET §1.700.001 don't pause because the tool was convenient.

At a financial advisory firm, it is an advisor using an AI meeting recorder to transcribe a client planning session. Account balances, Social Security numbers, investment strategies — all now in a third-party system the firm never approved, never audited, and cannot account for under Regulation S-P or FINRA's recordkeeping standards.

The employee wasn't being reckless. They were being efficient. The problem is that nobody told them the rules, and the firm didn't know the tool existed.


Why the Stakes Are Different in Each Vertical — and Why the Root Cause Is the Same

Law Firms: Privilege and Ethics Exposure

The Heppner ruling is the sharpest point of urgency for law firms. In February 2026, Judge Rakoff of the Southern District of New York held that a defendant's AI chat exchanges — prepared on a consumer-tier platform whose terms allow data retention — were not privileged and were subject to discovery. The ruling turned on the platform's terms of service, not on the sensitivity of the content.

ABA Formal Opinion 512 (July 2024) established the national ethics framework: lawyers may use AI, but their duties of competence, confidentiality, and supervision remain in force. More than 35 state bar associations have built on that framework with their own guidance. Courts are increasingly sanctioning attorneys for unverified AI citations. New York's 22 NYCRR Part 161, effective June 1, 2026, requires attorneys to certify that court submissions contain no fabricated AI content.

The exposure for a law firm: privilege waiver, ethics violations, court sanctions, and malpractice claims — all from tools most managing partners don't know their associates are using.

Accounting Firms: Confidential Client Information in AI Training Pipelines

Accounting firms handle some of the most sensitive financial information in existence — individual tax returns, corporate audits, estate plans, business valuations. The AICPA Code of Professional Conduct's Confidential Client Information Rule (ET §1.700.001) requires members to protect this information and prohibits disclosure without client consent except in specific circumstances.

Consumer AI tools do not meet that standard. A staff accountant who pastes a client's financial data into a consumer AI tool to get a summary or check their work has potentially exposed that data to a system that retains it, may use it for model training, and cannot guarantee it against disclosure. The CPA did not intend a violation. But intent is not the standard.

The additional risk for accounting firms: clients whose financial data enters an AI training pipeline may never be notified. Unlike a data breach, there is no incident detection mechanism — just ongoing exposure that accumulates with every use.

Financial Advisory Firms: A Regulator Actively Looking

The regulatory heat is sharpest in financial services. FINRA's 2026 Annual Regulatory Oversight Report — published in December 2025, earlier than usual in response to member firm feedback so firms could incorporate findings into their 2026 compliance planning — included for the first time a dedicated section on generative AI. It was explicit: existing rules on supervision, recordkeeping, communications, and fiduciary duty apply to AI tools exactly as they apply to any other technology.

The SEC added "Emerging Financial Technology" to its 2026 Examination Priorities. In practice, examiners are now reviewing firms' AI-related policies, procedures, and client disclosures as part of standard audits.

Regulation S-P — which requires written policies to protect the privacy of consumer financial information — has new incident response requirements. The smaller-firm compliance deadline was June 3, 2026. Using consumer AI tools with client financial data without adequate oversight creates exposure under that rule specifically: if client data enters a consumer AI system and is retained or used without authorization, that is exactly the kind of privacy incident Reg S-P is designed to prevent.

FINRA Regulatory Notice 24-09 clarified that supervision, recordkeeping, and communication standards apply to AI tools. An advisor using an unapproved AI meeting recorder on a client call, or a consumer AI tool to draft client communications, is operating outside those standards without realizing it.


The Common Denominator

Three industries, three different regulatory frameworks, three different sets of consequences. But one identical root cause:

The firm does not know what AI tools its employees are using with client data.

Not because employees are hiding it — most of them are not. Because consumer AI tools require no procurement approval, no IT setup, and no budget conversation. An employee creates an account in 30 seconds, charges $20 to their expense report under "productivity tools," and starts using it. The firm's Google Admin logs show the OAuth connection was made. The corporate card shows the charge. Nobody is looking at either one with this question in mind.

The result: every professional services firm currently has a gap between its written confidentiality obligations and the actual data handling behavior of its staff. The firms that close that gap proactively — by finding what's in use and building governance around it — are the ones that avoid the incident. The firms that discover it after a client asks, after an examiner asks, or after a court ruling makes it relevant are the ones managing a crisis.


The Solution: Find It, Evaluate It, Govern It

Step 1 — Find what's actually in use

Two sources cover the visible layer of shadow AI:

Google OAuth audit: Admin Console → Reporting → Audit and investigation → OAuth log events. Set the date range to 90 days. This shows every tool any employee has connected using their work Google account — including every AI tool they signed into with "Sign in with Google." Filter the App Name column for AI-related names. The list will include tools the firm never approved and may never have heard of.

Card and expense statement review: Pull 90 days of corporate card transactions and expense reimbursements. Search for: OPENAI, ANTHROPIC, OTTER, FIREFLIES, GRAMMARLY, PERPLEXITY, JASPER, RUNWAY, MIDJOURNEY, GITHUB. Any recurring AI charge that did not go through formal procurement is shadow AI — and it is potentially processing client data right now.

These two sources together give you the visible inventory. They do not capture tools employees access on personal accounts with personal cards — that layer requires a written policy and direct conversation with staff.

Step 2 — Evaluate what's safe and what isn't

Not all AI tools are equal. The distinction that matters for professional services firms is between consumer-tier and enterprise-tier, and it comes down to the contract.

Consumer-tier tools (ChatGPT Free, ChatGPT Plus, Claude.ai personal, most free-tier tools) typically allow the provider to retain inputs, use them for model training, and disclose them as permitted by their privacy policy. These tools are not appropriate for client data in any professional services context.

Enterprise-tier tools (ChatGPT Enterprise, Claude for Enterprise, legal-specific tools like Harvey or CoCounsel, financial services AI tools built for compliance) typically include zero data retention, prohibition on training on user inputs, SOC 2 certification, and a signed data processing agreement. These can be appropriate for client work — if the firm has actually reviewed and signed the agreement.

For each tool found in the inventory: does it have an enterprise agreement with these protections? If yes, it can be evaluated for approval. If no, it should not be used with client data regardless of how the employee has been using it.

Step 3 — Build a governance layer

A written policy does not need to be long. It needs to answer three questions clearly:

Which tools are approved for client work? Name them. "Use AI responsibly" is not a policy.

What is prohibited? At minimum: inputting client data into any consumer AI tool without an enterprise data processing agreement.

What happens if someone violates the policy? A policy without enforcement is a suggestion.

For law firms: the ABA, Virginia Bar, Illinois ARDC, Texas Bar, and North Carolina Bar have all published model AI policies — use one as your starting document rather than writing from scratch.

For accounting firms: the AICPA has published AI guidance. Start there and have ethics counsel adapt it for your jurisdiction.

For financial advisors: FINRA's Regulatory Notice 24-09 and the 2026 Oversight Report are the reference documents. Your compliance officer should lead this process.


How Terrier Fits

Terrier handles Step 1 — the inventory — which is where most firms get stuck. It connects to your Google Workspace and cross-references your corporate card transactions to surface AI tools connected to work accounts and AI subscriptions on the company card, without accessing email content, client files, or any confidential information.

The output is the list you need before you can evaluate, approve, or prohibit anything. For professional services firms across all three verticals, the process is the same: run the inventory first. Everything else follows from knowing what's actually there.

terrierops.com — free to scan your first month.


One Thing You Can Do Right Now

Open your Google Admin Console → Reporting → Audit and investigation → OAuth log events. Set the date range to 90 days. Look for AI tool names in the App Name column.

That list is your firm's actual AI footprint — not the tools you approved, not the tools you think your team uses. The actual tools, connected to actual work accounts, potentially processing actual client data.

Whatever you find there is the starting point for the conversation your firm needs to have. In some firms, the list is short and the conversation is easy. In others, it is the beginning of a real governance project. Either way, you need to know what's on it.


Frequently Asked Questions

Q: Is this a problem specific to large firms or does it affect small firms too?

It is more acute at small and mid-size firms. Large firms have IT departments, procurement processes, and compliance officers who catch unauthorized tools before they spread. A 40-person law firm, a 15-person accounting practice, or a boutique RIA typically has none of that. One person making one productivity decision creates exposure that the entire firm carries — and there is no internal mechanism to catch it.

Q: What is the actual risk if an employee uses ChatGPT with client data once?

It depends on what data was input and what the tool's retention policy was at the time. In the worst case — sensitive privileged communications, a consumer tool with active retention — the exposure is real. In a lower-stakes case — general drafting assistance, no client-identifying information — the risk is lower. The problem is that employees are not making this assessment before they act. They are using whatever is available. The firm's job is to make the assessment in advance, through policy, so employees don't have to make it under deadline pressure.

Q: For financial advisory firms, what specific rules apply to AI tool use?

No new AI-specific regulations have been enacted as of mid-2026. The SEC and FINRA are applying existing rules to AI use. The most relevant: FINRA's supervision rules (firms must supervise how technology is used in the business), Regulation S-P (written policies to protect consumer financial information), recordkeeping requirements (FINRA Rule 4511 — communications and records must be retained, which may include AI-assisted client communications), and fiduciary duty (for RIAs, AI-generated advice must still be in the client's best interest and supervised by a qualified professional). FINRA's 2026 Annual Oversight Report and Regulatory Notice 24-09 are the practical starting points.

Q: For law firms, how does the Heppner ruling affect everyday AI use?

The Heppner ruling was specifically about a defendant who used a consumer AI tool on his own, without attorney direction. Civil courts have since distinguished the ruling and generally protected AI work product in ordinary litigation contexts. The practical lesson for law firms is not that all AI is dangerous — it is that consumer-tier AI used with privileged or confidential client information, without enterprise data protections, creates discoverable records and potential privilege exposure. Enterprise-tier tools with contractual data protections are a different analysis. The policy question is knowing which category each tool falls into.

Q: We have a privacy policy. Does that cover this?

A client-facing privacy policy describes how the firm handles data it collects. It does not govern what tools employees use internally or what happens to client data when it enters a third-party AI system. A shadow AI policy addresses the internal behavior — which tools employees may use, under what conditions, with what data. The two documents address different things and one does not substitute for the other.

Q: How do we tell clients about our AI use?

The standard is converging across all three industries toward transparency when AI materially affects the services delivered. For law firms: an AI clause in the engagement letter is the recommended approach (ABA Formal Opinion 512, Model Rule 1.4). For accounting firms: AICPA guidance similarly points toward disclosure when AI affects the nature of the service. For financial advisors: if AI tools are used in client-facing communications or advice, disclosure in the firm's Form ADV or client agreement is appropriate, and FINRA's supervision rules require firms to track what tools are in use. When in doubt, disclose. The clients who object to responsible AI use are rare; the clients who object to finding out after the fact are not.


Terrier identifies AI tools connected to your firm's Google Workspace accounts and surfaces AI subscriptions on your corporate card — without accessing email content, client files, or any confidential information. It is the inventory layer before the governance layer. terrierops.com