Answers

Can I use AI if I handle confidential client information?

Yes, and you start with the work that never touches the confidential part. Most of the hours AI gives back are in admin, drafting, and reporting, where no client data is involved. Where sensitive data is unavoidable, the boundaries are a design input, not a blocker.

This question stops more good projects than any technical problem does. Someone in a regulated field, or holding client files under a confidentiality obligation, assumes the whole category is off limits and closes the door.

It isn’t off limits. But the way in is narrower and more specific than the vendor marketing suggests, so here is the honest version.

Where do you start if your data is sensitive?

Start where the sensitive data isn’t.

Sit down and separate your week into work that requires confidential information and work that doesn’t. For most businesses, the second pile is much bigger than expected, and it’s where the hours actually are:

  • Drafting and formatting documents from templates you already own
  • Turning meeting notes into follow-ups
  • Marketing, content, and social production
  • Reporting on your own operational numbers
  • Research, summarising, and comparison work
  • The scheduling, chasing, and administrative churn around the real work

None of that requires a client name. In one engagement, weekly ad reporting went from two to three hours down to about five minutes, and no customer information entered the system at any point. Nearly every time-saving we build lands in this pile first, whatever industry the client is in.

Do that work first. It buys real hours, it builds your team’s judgment about what these tools are good at, and it does it without a single risk conversation.

Does AI train on the data you put into it?

It depends on the plan you’re on, which is exactly the detail people skip.

On consumer tiers, your content is often used to improve the vendor’s models by default, with an opt-out available. On business and enterprise tiers, the major providers exclude your data from training by default and put it in the contract. OpenAI documents this split across its own plan tiers, and Anthropic’s business plans take the same position.

So the practical answer is: check which plan you’re on before you check anything else. A team using free consumer accounts and a team on a business agreement are in genuinely different positions, even if they are using what looks like the same product.

What do you do about the work that does touch sensitive data?

Treat privacy as one of the design inputs, alongside the problem, the data, and what success looks like. When we scope a build, the constraints question is asked before anything gets built: what software can and can’t we use, and what are the security, privacy, and risk boundaries we build inside?

In practice, the answers usually look like one of these:

  1. Strip it before it goes in. Anonymise or code the identifying fields. The AI works on the structure of the problem, which is what it’s good at anyway, and never sees who it belongs to.
  2. Separate the channel. Dedicated accounts and inboxes for AI-assisted work, so the sensitive stream never mixes with it.
  3. Keep the human in the loop on purpose. Draft with AI, review before anything leaves the building. This is how we build client email triage: replies are drafted and waiting each morning, and a person approves every one before it sends.
  4. Build a tool that doesn’t use AI at all. AI is always available as the build tool. It doesn’t have to be in the finished product. A deterministic system that follows your rules with no model in the pipeline is often the right answer for a sensitive workflow, and it’s usually cheaper to run.

That last one is the option most consultancies won’t offer, because their business depends on the ingredient rather than the outcome.

Is anything actually secure?

No, and you should be suspicious of anyone who says otherwise. No online system is completely secure, and that has been true of your email, your file sharing, and your client portal for years. The question was never “is this risk-free.” It’s whether the risk is understood, proportionate to the value, and handled at least as carefully as the systems you already trust with the same information.

Held to that standard, a business-tier AI setup with clear rules is often more defensible than what’s happening in most organisations right now, which is staff quietly using consumer accounts because nobody has given them an approved option.

What should you have written down before you start?

Three things, and none of them take long:

  • Which categories of information may never enter an AI tool, named specifically
  • Which tools and plans are approved, and who owns the accounts
  • What has to be reviewed by a person before it goes anywhere

That’s an acceptable-use policy in its simplest form, and having one is what turns “we’re not sure we’re allowed” into a decision your legal and compliance people can actually sign off on.

If you’re sitting on this question and would rather have a straight conversation about your specific constraints, book a free readiness call. Twenty minutes, no pitch, and you’ll leave knowing which parts of your work are genuinely open.

Want this answered for your business specifically? Book a free readiness call.

Twenty minutes, no pitch. If it's not a fit, you still leave with clarity.