Client confidentiality

Can accounting firms use ChatGPT with client data?

Sometimes a firm may approve a specific AI service for a specific workflow. That is not the same as approving staff to paste client data into any chatbot.

Published by PrivateStride · Last updated August 11, 2026

The short answer

Do not begin with a blanket yes or no.

Begin with a written approval process for one defined service, one defined data class, and one defined workflow.

Turning off model training is useful, but it answers only one question. It does not by itself answer retention, access, disclosure, confidentiality, security, contractual, or professional-review questions.

Consumer ChatGPT accounts and business offerings do not use the same defaults. OpenAI says content from individual services may be used to improve models unless the user opts out. It says its business offerings and API do not use inputs and outputs for training by default. Your firm should still review the current terms and controls for the exact product before approval.

See how PrivateStride defines the data boundary

Five questions

Approve the workflow, not the brand name.

A useful review is specific enough that a staff member can tell what is permitted without guessing.

01

Which exact service and account?

A personal consumer account, a business workspace, an API, and a private deployment can have different terms, data controls, retention settings, and administrative features. The model name alone does not answer the risk question.

02

What exact information will enter it?

Classify the proposed inputs. Tax return information, personally identifiable information, financial records, credentials, workpapers, and de-identified examples do not carry the same risk. Include prompts, uploaded files, retrieved documents, outputs, logs, and support records in the data map.

03

Where does the information go?

Document where processing, storage, backups, monitoring, and support can occur. Ask who can access each copy, how long it remains, how deletion works, and whether any subprocessors are involved.

04

What use is the firm making of the data?

Summarizing a document for the same engagement is different from using client information for marketing, product improvement, benchmarking, or an unrelated service. Your advisers need the actual workflow, not the label “AI.”

05

Who reviews the output?

AI can produce plausible but incorrect work. Define the professional who checks facts, calculations, citations, tax positions, and tone before an output reaches a file or a client.

A practical boundary

Use three lanes instead of one vague rule.

The examples below are a starting point for policy design, not a legal classification for your firm.

LaneExamplePractical ruleRequired review
OpenPublic research or generic writing with no firm or client factsOnly in an approved service and accountNormal professional review
ControlledInternal templates, policies, and nonpublic firm materialOnly in the environment approved for that data classOwner, security, and records review
RestrictedTax return information, client records, credentials, or regulated dataNo use until the exact workflow is expressly approvedLegal, privacy, tax, security, and engagement review as applicable

An approval path

Make the safe answer easier to follow.

A policy that only says “do not use AI” leaves the work pressure in place. Staff may create their own workaround. Give them a place to bring use cases, a short response time, and a useful approved alternative.

Start with the acceptable-use policy
  1. Name an accountable AI owner and review group.
  2. Inventory the proposed data and every system boundary.
  3. Review terms, settings, retention, access, and subprocessors.
  4. Define human review and prohibited decisions.
  5. Pilot with synthetic or low-risk information first.
  6. Log approval, train the team, and reassess after changes.
See the PrivateStride implementation model

Sources and claims

Check current rules and current product terms.

AI services change. Recheck material settings, contracts, and data flows when the vendor or workflow changes.

Primary sources: OpenAI’s official explanation of how data may be used, the FTC’s Safeguards Rule guide, the IRS Section 7216 Information Center, and the NIST AI Risk Management Framework. Review the evidence standards behind PrivateStride’s own claims in our methodology.

Keep reading

Turn the policy into a working system.

These guides cover the decisions that sit next to this one.

The shadow AI guide

Find unmanaged use and replace it with a governed path.

Read the guide

IRC Section 7216 and AI

Frame the use and disclosure questions around tax return information.

Read the guide

Compare AI architectures

See how public, hosted, and on-premises options change the control model.

Read the guide

Capacity & AI risk assessment

Map the risk before you choose the tool.

In 30 minutes, we identify your highest-value workflows, likely shadow-AI exposure, and the controls a private AI program would need. The findings are yours to keep.

Book your audit 30 min · No preparation · Confidential