Is AI safe for client data? The accountant's straight answer
The honest answer to whether accountants can use AI with client data: yes, if you use business-tier tools and a handful of non-negotiable rules. The real risk is your process, not the model. We break down what ChatGPT, Claude and Copilot actually do with your data as at July 2026, what your confidentiality obligations require in the US, Australia and the UK, and the five rules that keep you on the right side of both.
Trent McLaren · 22 July 2026 · 10 min read
In this article
- How AI tools actually handle your data
- The tier table
- What the professional rules require of you
- The five non-negotiables
- What we'd still never put into any AI tool
- Frequently asked questions
- Can I put client data in ChatGPT?
- Does Claude train on my conversations?
- Is Microsoft Copilot safer than ChatGPT or Claude?
- Do I need client consent to use AI?
- What if staff have already pasted client data into free AI tools?
Part of our AI in accounting coverage. See the full AI for accounting firms guide →
Here is the straight answer, because you deserve one: yes, AI can be safe for client data, if you use the business tier of a mainstream tool and follow a handful of rules. The models themselves are not the risk. OpenAI, Anthropic and Microsoft all offer commercial terms under which your data is not used to train their models, is encrypted, and is handled to the same standards as the rest of your cloud stack: the one that already holds every client's payroll, bank feeds and tax file numbers.
The risk is process. It is a staff member pasting a client's full financials into a free ChatGPT account on their personal phone. It is a firm that never made a decision, so everyone made their own. Every documented AI data-leak story follows this shape, including the most famous one, where Samsung engineers pasted confidential source code and meeting transcripts into consumer ChatGPT in 2023 and the company banned the tools outright. The model didn't breach anything. People used the wrong tier of the tool with no rules in place.
So the question isn't really "is AI safe for client data?" It's "is your firm's AI process safe for client data?" That one you can actually control. Here's what you need to know, as at July 2026. We date-stamp that deliberately, because these terms change and any article that doesn't tell you when it was checked isn't worth trusting.
How AI tools actually handle your data
Three separate things get blurred together in this debate, and they carry very different risks. Untangle them and most of the fear dissolves.
Training is your data being used to improve the model itself. This is the scary one: in principle, information absorbed into training data could influence future model outputs. It is also the most avoidable one: every major vendor's business tier excludes your data from training by default, contractually. Training is a consumer-tier problem.
Retention is how long the provider stores your conversations. This is a different risk: retained data can be breached, subpoenaed or held under litigation. In 2025, a US court order in the New York Times case forced OpenAI to preserve consumer ChatGPT conversations (including deleted ones) for months (OpenAI says the preservation obligation ended in September 2025). Nothing was trained on; the data simply existed longer than users expected. Retention is why "I deleted the chat" is not a control.
Human review is provider staff reading conversations, usually for abuse and safety monitoring. All major providers reserve the right to review flagged content. Anthropic's current consumer policy, for instance, allows conversations flagged for safety review to be analysed regardless of your training preference. It's rare, it's targeted at policy violations, and it's another reason client identifiers don't belong in prompts.
Once you see these as three dials rather than one vague fear, the decision gets simple: pick the tier where all three dials are set in your favour.
The tier table
Here is where the major tools stand, as at July 2026. Terms change. Verify against the vendor's current documentation before you rely on this, and re-check annually.
| Tool and tier | Trains on your data? | What else to know |
|---|---|---|
| ChatGPT Free / Plus / Pro (consumer) | Yes, by default. "Improve the model for everyone" is on unless you switch it off in Data Controls. | Deleted chats are removed within 30 days unless legal requirements intervene. The NYT litigation hold showed that caveat has teeth. |
| ChatGPT Business / Enterprise (Team was renamed Business in 2025) | No, by default, contractually excluded. | SOC 2 audited, SSO, admin controls, workspace-level retention settings. |
| Claude Free / Pro / Max (consumer) | Depends on your setting. Since Anthropic's 2025 terms update, you choose whether chats may be used for model improvement. Check Privacy Settings rather than assuming. | With model improvement on, retention runs up to five years; off, roughly 30 days. Safety-flagged conversations may be reviewed regardless. |
| Claude Team / Enterprise (commercial terms) | No, by default. Commercial terms exclude training. | Admin controls, SSO, audit logs on Enterprise. |
| Microsoft 365 Copilot | No. Prompts, responses and Microsoft Graph data are not used to train the foundation models. | Grounded in your tenant; processing stays inside the Microsoft 365 service boundary and respects existing file permissions, which means bad internal permissions become Copilot's problem too. |
| API access with a zero-data-retention (ZDR) agreement | No. | ZDR means the provider doesn't store your inputs or outputs at all after processing. Negotiated on enterprise API agreements, on approval, for eligible endpoints. This is what the software vendors selling to your firm should hold, so ask them. |
Notice the pattern. The line isn't between vendors. It's between consumer and commercial terms at every vendor. A firm arguing about ChatGPT versus Claude while staff use free accounts of both has skipped the only decision that matters. We've covered the practical rollout side in our guide to what Claude actually costs and delivers for accounting firms.
What the professional rules require of you
One thing to say once, clearly: this is general information, not legal advice. Get counsel for your specific situation. With that said, the professional framing is refreshingly boring: your confidentiality obligations predate AI and apply to it without modification.
In the US, tax practitioners sit under IRC §7216, which restricts disclosure of tax return information to third parties without specific client consent, and the statute doesn't care whether the third party is an outsourcing firm or a chatbot. The AICPA Code (section 1.700.001) bars disclosing confidential client information without consent, and the IRS Office of Professional Responsibility has issued guidance confirming that Circular 230 duties (competence, diligence, confidentiality) apply squarely to AI use. The consistent theme: you remain fully responsible for the work and the data, whatever tool touched it.
In Australia, the Privacy Act's APP 11 requires reasonable steps to protect personal information from misuse and unauthorised disclosure, and the OAIC's guidance on commercially available AI products (issued October 2024) says the quiet part out loud: assess the product's data handling before personal information goes anywhere near it, and prefer settings where your data isn't used for training. Tax agents also carry confidentiality obligations under the TPB's Code of Professional Conduct. The UK position rhymes: UK GDPR plus ICAEW and ICO guidance pointing the same direction.
None of this bans AI. All of it bans carelessness. Which has always been the deal. As we've argued before, no AI is ever going to jail for you: the accountability stays with the human who signs.
The five non-negotiables
If your firm adopts these five rules, you can use AI on client work with a straight face in front of any regulator or insurer.
- Business tier only. No client-related work in consumer accounts, ever, including partners' personal Plus subscriptions. The commercial no-training terms are the entire foundation; everything else is built on them.
- No client identifiers in consumer tools. For the generic uses that survive rule one (drafting a template email, explaining a tax concept), nothing that identifies a client goes in. "A hospitality client with $2m revenue" is fine. Their name, TFN, EIN or actual ledger is not.
- Human review of everything. Every AI output that touches client work gets reviewed by a qualified human before it goes anywhere. This is a confidentiality control as much as a quality one: review is where you catch the model quoting something it shouldn't.
- Connector scopes read-only first. When you wire AI into your practice management, email or ledger, start with read-only access to the narrowest data set that does the job. Widen scopes deliberately, one approval at a time, never because a setup wizard suggested it.
- Write it down. An unwritten policy is a rumour. Which tools, which tiers, what data, who reviews, what happens when someone slips. One page covers it. Our companion piece, the one-page AI policy guide for accounting firms, gives you the template.
What we'd still never put into any AI tool
Even on enterprise terms with a signed ZDR agreement, some things stay out, not because the vendor will misuse them, but because the downside of any mishandling is unbounded and the upside of including them is roughly nil.
- Government identifiers: TFNs, SSNs, EINs, passport numbers. The model doesn't need them to do anything useful.
- Bank account numbers and payment credentials.
- Anything under active litigation, regulatory investigation or legal privilege: retention and discovery risks multiply here.
- Data a client has explicitly asked you to handle with extra care, whatever your terms technically permit. Their trust outranks your efficiency.
Redact, tokenise ("Client A"), or just leave it out. The analysis works fine without the identifiers, which tells you they were never needed in the first place.
Frequently asked questions
Can I put client data in ChatGPT?
On ChatGPT Business or Enterprise (where your data is contractually excluded from training by default), yes, subject to your professional obligations and your firm's AI policy, and in the US noting that §7216-protected tax return information generally needs client consent before any third-party disclosure. On Free, Plus or Pro accounts, no: as at July 2026, consumer conversations train the model by default unless you opt out, and even opted out, they're retained on consumer terms. The tier is the whole answer.
Does Claude train on my conversations?
On Claude's commercial products (Team, Enterprise and the API), no, not by default under Anthropic's commercial terms. On consumer plans (Free, Pro, Max), it depends on the model-improvement setting you chose when Anthropic updated its consumer terms in 2025: if it's on, chats can be used for training and retained for up to five years; if off, retention drops to about 30 days. Conversations flagged for safety review can be analysed regardless. Check your Privacy Settings rather than assuming, and for client work, be on a commercial plan so the question doesn't arise.
Is Microsoft Copilot safer than ChatGPT or Claude?
Not intrinsically, but its architecture suits firms already living in Microsoft 365. Copilot doesn't train foundation models on your prompts, responses or tenant data, and processing stays within the Microsoft 365 service boundary you've already risk-assessed. The catch: Copilot inherits your tenant's permissions, so if your SharePoint lets everyone see everything, Copilot will cheerfully surface it. It's comparable to the business tiers of ChatGPT and Claude on data terms; pick based on where your workflows live. Our AI for accounting firms hub compares the options in more depth.
Do I need client consent to use AI?
Sometimes, and the careful answer is jurisdiction-specific. Ask your professional body or counsel. In the US, IRC §7216 generally requires specific signed consent before tax return information is disclosed to third parties, and a cautious reading treats an AI vendor as a third party. In Australia and the UK, using a business-tier tool as a data processor under proper terms generally sits closer to using any other cloud software, but your privacy policy and engagement letters should say you use AI tooling. Transparency is cheap; discovering your clients feel misled is not.
What if staff have already pasted client data into free AI tools?
Assume it's happened. Surveys of shadow AI use suggest it almost certainly has. Don't run a witch hunt; that teaches staff to hide usage, which is worse. Instead: ask openly what's been used and for what, so you can size the exposure. Where the tool allows it, disable training and delete the relevant history (noting deletion isn't instant or absolute). Assess whether anything rises to a notifiable breach under your local scheme (in Australia, the Notifiable Data Breaches scheme; in the US, state rules) and get advice if identifiers were involved. Then fix the cause: give people a sanctioned business-tier tool and a one-page policy, because staff pasted data into free tools for the very good reason that the free tools were useful and you hadn't given them an alternative.
AIPractice Technology