It’s likely that someone at your firm has already pasted a client’s information into ChatGPT, Claude, or Gemini to save time on a draft, a summary, or a tricky question. Not out of carelessness. Out of the same instinct that makes any of us reach for a faster tool. That’s shadow AI: AI use your firm never approved, sitting outside any policy you’ve written, on a device you already manage. The fix is knowing what’s actually being used, deciding what’s approved, and backing that decision with something more than good intentions.
Key takeaways
- Shadow AI isn’t a hypothetical. Staff are very likely already using consumer AI tools with client data, whether or not the firm has approved it.
- Pasting client tax data into a public AI tool touches the same territory as Section 7216 and the FTC Safeguards Rule, covered in depth elsewhere on this blog.
- Finding out what’s already in use starts with a short, non-punitive ask, not a surprise audit.
- A usable tool-vetting standard has three questions: where does the data live, is the vendor SOC 2 compliant, and what do the retention and deletion terms actually say.
- A written policy without technical backing relies entirely on someone remembering the rule at 4pm during a deadline crunch.
Table of Contents
Why shadow AI isn’t hypothetical for your firm
A five-person practice doesn’t have a compliance team standing between a new AI tool and a staff member’s next deadline. A large firm’s IT and legal departments vet a tool before anyone’s allowed near it with client data. A small firm usually finds out after someone’s already been using it for months.
It’s a structural gap: the review that happens automatically at a large firm has to happen deliberately at a small one, and deliberate is easy to skip when nothing’s gone wrong yet. The person who pasted a client’s return into a chatbot to draft a summary wasn’t trying to create an incident. They were trying to save twenty minutes on a Tuesday.
What’s actually at stake
Once client data goes into a consumer AI tool, the firm has lost visibility into where it went, who can access it, and how long it’s kept, and that’s before getting into the specific legal exposure.
Section 7216 governs when a firm can disclose or use a client’s return information, and the Circular 230 duties the IRS has attached to AI use add a separate layer of professional obligation on top of that, including an open question about whether AI use itself needs to be disclosed to the client. Both are worth reading in full rather than summarized here. What matters for this piece is simpler: the exposure isn’t theoretical, and it doesn’t wait for the firm to have a policy before it applies.
How do you find out what’s already being used?
Start by asking, not auditing. A short, explicitly non-punitive survey, five questions or fewer, catches more real usage than any technical scan, because people don’t hide a productivity shortcut when nobody’s in trouble for it.

Technical discovery fills in what people forget to mention. None of these sources is complete by itself, but together they usually surface more than firm leadership expects.
| Source | What it catches |
|---|---|
| A short staff survey | Tools people are already using but never thought to mention |
| Expense reports | Paid AI subscriptions nobody requisitioned through the firm |
| Browser extension reports | AI extensions installed on managed devices |
| Network traffic | Connections to known AI domains, where that visibility already exists |
Instead of guessing, the goal is a real inventory where the survey matters most. A technical scan tells you what happened on a managed device. It says nothing about the personal ChatGPT account someone’s using from their phone.
What does an approved-tool list actually look like?
Verito CEO Jatin Narang laid out his own standard for vetting an AI tool in Forbes: three questions, and none of them are answered by a sales page.
| Question | Why it matters |
|---|---|
| Where does the data live? | U.S.-based servers keep the data inside a jurisdiction your existing compliance obligations already cover |
| Is the vendor SOC 2 compliant? | An independent audit, not a marketing claim, of how the vendor actually handles data |
| What do the retention and deletion terms say? | Determines whether client data sits inside the vendor’s systems, or a training set, after the task is done |
Put the answer in writing. It doesn’t need to be long, but it needs to name which tools are approved, for which tasks, and with which data, so “probably fine” stops being the standard anyone’s working from. Two more items belong on the same list: update engagement letters to address AI use where it touches client work, and ask the firm’s E&O carrier directly whether AI-related errors are covered, since most firm owners haven’t asked and the answer isn’t always what they’d assume.
Where policy needs technical backing
A written policy works right up until someone’s under deadline pressure and the sanctioned tool is slower than the one they already know. That’s where the same category of control that blocks a phishing lure, network monitoring and content filtering, does double duty flagging or blocking traffic to AI tools that aren’t on the approved list.

That written policy doesn’t have to start from nothing, and it doesn’t have to be built alone. If your firm is working out where to start, that’s a conversation worth having directly.
Talk to us about building your firm’s AI policy →