How to use AI in professional services without exposing confidential data
Professional services firms handle client records, privileged material, personal information and commercially sensitive documents. This guide provides a controlled way to define one use case before any real data is introduced.
Why the risk begins before a prompt is submitted
The prompt is only one part of the information flow. Review connected sources, attachments, logs, history, outputs and the systems where results are saved. Removing a name may not prevent identification from a file or surrounding facts.
A useful scope is: “An authorised team will prepare a first-pass internal summary of these approved document types for professional review.” This is easier to test than a broad objective such as “use AI across the firm”.
- Purpose and intended result
- Authorised users and accountable reviewer
- Permitted sources and data categories
- Destination, retention and deletion
- Allowed actions and a safe manual fallback
1. Classify information and use cases
A simple classification helps staff make consistent decisions. It may separate public, internal, confidential and highly restricted information. Credentials, tokens, keys, highly sensitive case material and unnecessary data should be prohibited by default.
Classification does not replace legal or professional analysis. It helps distinguish early tests using public or synthetic content from tasks requiring a specific assessment.
- Public or approved for publication
- Internal and non-public
- Confidential or personal information
- Restricted information subject to specific controls
2. Define permitted, prohibited and approval-based use
A usable policy should name approved tools and accounts, permitted uses without personal data, activities requiring approval and information that must never be submitted.
It should also make accidental disclosure easy to report. Prompt reporting helps the firm respond; a punitive culture may delay action.
Prudent default: do not send passwords, client documents, personal data or confidential configurations in an initial enquiry.
3. Assess the provider and the full data flow
Answers should be supported by contracts, technical documentation and actual configuration rather than marketing language. No single certification makes a service suitable for every category of information.
- Are inputs or outputs used to train or improve models?
- What is retained in prompts, files, logs and abuse-monitoring systems?
- Where is information processed and which subprocessors are involved?
- Are individual accounts, MFA, roles and activity logs available?
- Can connectors be limited to a matter, folder or approved data set?
- Can read and write access be separated and important actions require approval?
- How are incidents, export, deletion and service exit handled?
4. Minimise, redact and pseudonymise carefully
Use the least information needed: remove irrelevant fields and pages, replace identifiers when identity is unnecessary, use extracts rather than full files and prefer synthetic data during design.
Visual black boxes are not reliable redaction if underlying text remains. Metadata, comments, tracked changes, file names and hidden cells may also disclose information. Pseudonymisation is not automatically anonymisation when reidentification remains possible.
- Restrict retrieval to an approved scope
- Separate instructions and client content where possible
- Check the output and destination before saving
- Avoid unnecessary copies and retention
5. Limit identities, permissions and connections
Avoid shared accounts, enable MFA where available and assign privileges by role. An assistant connected to a repository should see only the approved scope; read-only access is preferable when writing is unnecessary.
For every connector, record what it can read, which actions it can perform, how access is revoked and what happens when a person changes role or leaves.
6. Make human review an operational control
A fluent answer can still be incomplete or wrong. Reviewers need access to sources, visibility of AI-assisted content and authority to verify facts, dates, amounts, calculations and citations, edit or reject an output and stop an action.
Review intensity should follow potential harm, not the apparent confidence of the text. Client communications, deadlines and professional interpretations require proportionate checks and a clearly accountable person.
- No autonomous professional advice
- No external communication without approval
- No consequential decision based only on AI output
- Sources and assumptions available for review
7. Run a controlled pilot
The first project should be narrow, reversible and measurable. Use public or synthetic information until the workflow is understood.
- Choose one bounded task and accountable owner.
- Document permitted and prohibited information.
- Review terms, data flows, settings and permissions.
- Prepare ordinary examples, exceptions and errors.
- Measure quality, review time and problems against the current method.
- Test access removal, deletion and manual fallback.
- Decide whether to expand, revise or stop.
When to involve specialist advisers
Seek privacy, contractual, security or professional advice when the use case involves special-category data, large repositories, employee information, international transfers, profiling, decisions affecting people or high-privilege integrations.
This guide provides general organisational criteria and does not determine whether a particular processing operation is lawful or appropriate.
Kreluna is in active development. Availability, integrations and safeguards are confirmed before any proposed pilot.
Decision record before using an AI tool
Complete this sequence for each use case. If an answer is missing, defer loading real data.
- Purpose and owner
Define the outcome and the person accountable for the final decision.
- Data and necessity
List category, source and why each piece of information is required.
- Provider and data path
Record contract, hosting, retention, training, subprocessors, transfers and deletion.
- Controls and incident
Set access, review, logs, safe stop and the response to exposure or an incorrect output.
Confidential-data questions
Does a business account make every upload safe?
No. Contract terms, configuration, data flow, access and the use case have to be assessed together.
Is pseudonymised data anonymous?
No. If a person can be relinked using additional information, the data remains personal and GDPR still applies.
When is a DPIA needed?
That depends on the processing and risk. The controller should assess it with the DPO or competent advisers where appropriate; this guide does not make an automatic determination.
Institutional sources and further reading
- European Commission — GDPR principlesPurpose limitation, data minimisation, retention, integrity and confidentiality.
- EDPB — Opinion on AI modelsData-protection considerations for AI-model development and deployment.
- NIST — AI Risk Management FrameworkResources for governing, measuring and managing AI risks.
Start with one defined use case
Describe the objective, current workflow and general type of information involved. Do not send credentials, personal data or confidential documents in an initial message.