Back to News & Insights
Security July 21, 2026 4 min read

Your Staff Is Already Using AI. The Question Is Whether You Know.

AI arrived at your firm before any policy did. Why a ban backfires, and the four-part governance that keeps client data under your control.

Somewhere in your firm this week, someone opened a free AI chatbot and pasted in a piece of client work. Not out of malice. They were buried, the tool was right there, and it helped.

I'm not guessing. This is how AI arrives at professional firms. It doesn't come through procurement, and it doesn't wait for a policy. It comes through the side door, one convenient decision at a time. By the time leadership sits down to write the rules, the habits are already formed.

Adoption never asks permission

The pattern looks the same almost everywhere:

  • Free accounts. A staff member signs up for a consumer chatbot with a personal email. It saves them an hour on the first day. They never mention it in a meeting.
  • Browser extensions. An AI writing helper, a summarizer, a "meeting assistant." Installed in thirty seconds, sitting on top of everything that person reads and types.
  • Features you already own. The software your firm has run for years ships an update, and the AI features arrive switched on. Nobody chose them. Nobody reviewed them. They're just there.

None of these people think of themselves as taking a risk. They think of themselves as keeping up. The uncomfortable part is that they're not wrong to want the help. The tools genuinely work. That's why the quiet adoption keeps spreading.

Why this lands harder on a CPA or law firm

If you ran a landscaping company, this would be a modest problem. You don't. You run a firm whose entire value rests on what clients trust you to hold.

When client data goes into a consumer AI tool, it leaves your control. You can't get it back, and you can't tell a client where it went. Whatever the tool's terms say, that data now sits on infrastructure you don't govern, under an agreement your firm never signed.

Your obligations don't pause for any of that. If you're an accounting firm, you answer to IRS Publication 4557 and the written information security plan that goes with it, and to the NIST-aligned expectations behind them. If you're a law firm, you carry confidentiality duties and privilege. Privilege, in particular, is unforgiving: it protects communication you control, and arguments start the moment you can't show you controlled it.

None of those frameworks care that the tool was convenient. Convenience is not a defense you get to raise.

The ban reflex, and why it backfires

The reflex answer is a ban. I understand it. It's still the wrong call.

A ban doesn't stop the behavior. It relocates it. The work moves to personal phones, personal laptops, personal accounts, the places where you have no visibility and no controls at all. You trade a risk you could see and manage for one you can't. And you hand your most capable people a reason to stop telling you what tools they use, which is the opposite of what governance needs.

You also give up the upside. The firms that come out ahead over the next few years won't be the ones that held AI at the door. They'll be the ones that let it in on their terms.

What "on your terms" actually means

Governance here isn't a binder. It's four things, and none of them are complicated.

A short AI-use policy people actually follow. If the policy takes longer to read than the task it governs, nobody reads it. One or two pages: what's allowed, what isn't, who to ask.

An approved-tools list with enterprise data terms. The same capabilities your staff found on their own, procured properly, under contracts that say your data isn't training material and doesn't leave your control.

Bright lines on data. A plain list of what never goes into any AI tool, on any account, ever. Client identities, return data, privileged material, whatever your lines are. Short enough to memorize.

Controls mapped to what you already answer to. You don't need a new framework. You need your AI use mapped to Pub 4557, to your WISP, to the NIST-aligned controls your firm already claims. When a client or a regulator asks, the answer is already written down.

This is what our AI Governance & Guardrails work builds: the policy, the list, the lines, the mapping. Built to be used, not filed.

Where I stand on the tools

So you know where this counsel comes from: I'm not warning you off AI. My firm builds with it every day. The website you're reading was built with it. I think these tools are the most useful thing to happen to professional work in a long time, and I think firms that use them well will out-execute firms that don't.

That's exactly why the guardrails matter. You don't put brakes on a car to make it slower.

Your staff already answered the question of whether your firm will use AI. The question left on the table is whether it happens with your knowledge and under your terms, or without either.

If you'd rather answer it deliberately, the AI Readiness & Alignment Assessment is where I'd start: a straight read on what's actually in use at your firm, what it exposes, and what to do about it.

Join the conversation

Straight talk welcome. Comments are moderated — no pitches, no spam.

Comments load once the Hyvor Talk Website ID is set in article.html.