Insights · Opinion
Six questions partners should ask before staff use AI
Before staff use AI on client work, or soon after they start, a managing partner should be able to answer six questions: where the data goes, which plan the firm is on, who administers it, what the policy says, how outputs are checked and what clients are told. Where an answer is unclear, fix that before use widens.
- By
- Elias
- Published
- Updated
Why should partners ask these questions now?
Partners should ask now because AI use in a firm often starts before anyone decides anything. Someone tries a free tool on a file note, it saves time, and it spreads. These questions work before a formal rollout, and just as well as a check on use that is already happening.
The direction from regulators is clear. The OAIC recommends, as a matter of best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools (OAIC guidance on commercially available AI products). Professional regulators have said similar things, as the sections below show.
1. Where does our client data go?
Client data goes wherever the tool sends it, and that depends on the product, the plan and the settings, not the brand name. Find out where prompts and files are stored, where they are processed, how long they are kept and who at the vendor can see them.
Storage and processing can happen in different places, and the answer can change with each plan and each feature switched on. Microsoft’s documentation, for example, notes that Anthropic models available inside Microsoft Copilot are currently excluded from its EU Data Boundary and in-country processing commitments (Microsoft Learn). Connectors to email, SharePoint or Google Drive also widen what the AI can see. Our guide to where ChatGPT stores your data works through these questions for ChatGPT.
For some work, the right answer is that client data should not go into a public tool at all. That is what private AI and knowledge assistants are for.
2. Which plan are staff actually on?
The plan matters more than the product, because consumer and business plans handle data differently. The first thing to establish is whether staff use the firm’s business plan with work accounts, or personal accounts the firm cannot see or control.
As at September 2026, the vendors’ own documentation draws the line like this:
- ChatGPT: OpenAI says it does not train on data from ChatGPT Business, Enterprise or its API by default (OpenAI enterprise privacy). On Free, Plus and Pro, the “Improve the model for everyone” setting is on unless the user turns it off (OpenAI data controls).
- Claude: Free, Pro and Max users choose whether their chats are used for training. Claude for Work and the API sit under Anthropic’s commercial terms, which that choice does not cover (Anthropic).
- Copilot: Microsoft says prompts and responses in Microsoft Copilot, used by organisations under its enterprise terms, “aren’t used to train foundation models” (Microsoft Learn).
- Gemini: Google says Workspace does not use customer data to train models without the customer’s prior permission or instruction, on qualifying Workspace editions (Google Workspace privacy hub).
A personal account sits outside every control the firm has.
3. Who administers it?
A named person, inside the firm or at a provider working for it, should own the AI workspace the way someone owns Microsoft 365. That person controls single sign-on, who has a seat, which features and connectors are on, retention settings, and what happens when someone leaves.
Without an owner, settings drift. Vendors add features and change defaults, so a workspace configured correctly in March may not be in September. Our AI Setup service configures these controls and hands them to your administrator, with optional monthly admin if you would rather we keep them current.
4. What does our AI policy say?
The policy should tell staff, in plain language, which tools are approved, what client information may be entered, which tasks need partner review and who approves exceptions. If staff cannot summarise it in a sentence, it will not change what they do.
A good policy is short, specific to the firm’s work and backed by the tool’s settings, so the rules and the configuration say the same thing. Our guide to what an AI acceptable-use policy must cover sets out the clauses and links to our free template.
5. How are outputs checked?
Every AI output that reaches a client, a court or a regulator should be checked by someone qualified to do that work, and the firm should be able to show that it was. AI output is a draft, not advice.
Regulators expect the same. The joint statement from the Victorian, NSW and WA legal regulators says lawyers using AI to prepare documents “must be able and qualified to personally verify the information they contain” (Victorian Legal Services Board + Commissioner). The Tax Practitioners Board’s July 2026 guidance, TPB(GS) 55/2026, makes the same point for tax practitioners: they remain responsible for their services whether or not AI is used (TPB).
In practice, decide which outputs need review, by whom, and where that review is recorded on the file.
6. What do we tell clients?
Clients should hear how the firm uses AI from the firm, not discover it later. Decide what your engagement letters, privacy policy and client conversations will say, and make sure it matches what staff actually do.
Several obligations point the same way:
- The OAIC’s guidance recommends that privacy policies and notices give clear information about an organisation’s use of AI.
- The legal regulators’ statement refers to recording and disclosing to clients when and how AI has been used in a matter.
- The TPB’s guidance notes that entering client information into an AI tool can amount to disclosure to a third party, depending on how the tool is configured and used, which brings the Code’s client-permission requirement into play.
- From 10 December 2026, an APP entity’s privacy policy must describe the kinds of personal information used, and decisions made, where a computer program makes a decision, or does something substantially and directly related to making one, that could reasonably be expected to significantly affect someone’s rights or interests (OAIC consultation on automated decision-making). If AI screens enquiries or triages work, check whether that applies.
What should a partner do next?
Write the firm’s answer to each question on one page. Where you cannot answer, that is the work to do first: usually a business plan configured properly, a policy that matches it and a named person who runs it.
That is what AI Setup covers. If you would like to test your answers with us, book a free 45-minute discovery call.
This is general information, not legal advice.
