Skip to content
Pylon Digital

Knowledge base

AI security and privacy guides for firms

These AI security and privacy guides help Australian law, accounting and advisory firms use AI without losing control of client information. They explain where tools such as ChatGPT keep your data, what the Australian Privacy Principles mean for AI use, how to set up business plans securely, and what an AI acceptable-use policy must cover.

Last updated:

5 guides in AI security & privacy

What does this topic cover?

This topic covers the security and privacy questions partners should settle before AI touches client work: which tools staff are using, where those tools keep data, what Australian privacy law expects, and what rules staff should follow. The guides are written for managing partners and practice managers, not security specialists, and they focus on decisions a firm can make itself.

What is shadow AI, and why start there?

Shadow AI is staff using AI tools the firm has not approved or configured, often personal accounts on free plans. It is the right place to start because a firm cannot secure tools it does not know about. Shadow AI in professional firms explains how to find out what is in use and move people onto approved tools.

Where does our data go when staff use AI?

It depends on the tool, the plan and the settings, not just the brand. Consumer and business plans of the same product can differ on how long data is kept, what administrators can see and whether inputs can be used to train models, and processing locations vary by vendor and plan. Where does ChatGPT store your data? sets out the position as at September 2026 and the alternatives for firms that need more control.

What do the Australian Privacy Principles mean for AI use?

The Australian Privacy Principles set how organisations covered by the Privacy Act 1988 collect, use, disclose and protect personal information. The OAIC’s guidance on commercially available AI products says privacy obligations apply to any personal information entered into an AI system, and to AI output that contains personal information. AI and the Australian Privacy Principles translates the principles that matter most for AI into plain English, with examples from professional firms.

What should an AI acceptable-use policy cover?

An AI acceptable-use policy should say which tools are approved, what information must never go into them, who reviews AI output before it reaches a client, and how staff report a mistake. Keep it short enough that people read it. AI acceptable-use policy: what it must cover walks through each clause and links to our free template.

How does Pylon Digital handle client data?

Our security and data residency page explains how client data in the systems we build and run is stored, who has access, and how the AI providers we use handle your data. For work that cannot go into public tools, Private AI and knowledge assistants store client data in fully GDPR-compliant data centres, and your firm chooses which matter and client documents they can search.

This is general information, not legal advice.

Questions

Frequently asked questions

Is it safe for staff to use free AI tools with client information?

No, not without controls the firm has checked. Free and personal AI accounts sit outside the firm's admin controls, so the firm cannot see what was shared, set how long it is kept or remove access when someone leaves. Settings on personal accounts can also allow conversations to be used to improve the vendor's models. Move staff onto a business plan the firm administers, or a private assistant.

Do we need an AI acceptable-use policy?

Yes, if anyone in the firm uses AI for work. A short policy tells staff which tools are approved, what information must never go into them, who checks AI output before it reaches a client, and how to report a mistake. Without one, each person makes their own rules, and the firm cannot show what it expected of staff if something goes wrong.

Secure by design. Set up correctly. Fully managed.

Talk to us before you commit to anything

Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.

Book a free 45-minute discovery call