Your Firm’s AI Use May Be Moving Faster Than Your Controls

Robot finger touching digital lock

A managing partner does not need to approve a new AI platform for AI risk to enter the firm.

A staff member pastes a client email into an AI tool to clean up the wording. A CAS manager uses AI to summarize a client’s financial notes before a meeting. A tax team member asks an AI assistant to explain a confusing client document. Someone uses a browser extension, plug-in, note taker, transcription tool, or AI meeting assistant because it saves time and “everyone is doing it.”

None of this feels reckless in the moment.

That is the problem.

For CPA, CAS, and financial consulting firms, the most immediate AI risk may not be a hacker using AI to attack the firm. It may be the firm’s own AI use creating client-data exposure before leadership has visibility, rules, controls, and evidence. DigiCert’s AI Trust Outlook describes a broader problem of AI adoption moving faster than accountability and governance.

Diagram showing staff AI use leading to client data exposure before leadership has visibility or controls.
AI risk often enters through ordinary productivity decisions, not obvious security events.

This is the uncomfortable question: Are we already using AI in ways that involve confidential client data, but managing that use mostly through assumption?

AI Risk Is Now a Governance Problem

Most AI conversations start in the wrong place. They focus on AI-powered phishing, deepfakes, malware, or attackers moving faster.

Those risks are real. But they are not the only issue.

Inside a professional service firm, AI risk often starts with ordinary work:

  • A person is under deadline pressure.
  • A client file is long.
  • A memo needs to be summarized.
  • A meeting transcript needs to be cleaned up.
  • A spreadsheet needs to be interpreted.
  • A proposal needs to be drafted faster.

AI becomes attractive because it removes friction. But if the firm has not clearly defined what tools are approved, what client data can be entered, what retention settings apply, who owns exceptions, and what evidence exists, then AI use becomes a quiet client-data exposure channel.

The issue is not whether people are trying to do something wrong. Usually they are trying to be more productive.

The issue is whether leadership can govern what is happening.

The Real Risk Is the Gap Between Use and Visibility

A firm may have good people, good intentions, and a decent IT environment — and still have an AI governance gap.

That gap usually shows up in five places:

  1. Tool visibility — leadership does not know which AI tools are being used.
  2. Data rules — employees are unclear about what client data may or may not be entered.
  3. Access control — AI tools or agents may connect to email, documents, calendars, or cloud storage without adequate review.
  4. Evidence — the firm cannot quickly show what controls exist.
  5. Ownership — exceptions are not formally reviewed, accepted, or corrected.

This is where AI becomes a Cyber Defensibility issue.

Cyber Defensibility is not about claiming the firm has eliminated AI risk. It is about being able to show that client-data protection is being actively managed — with visibility, controls, evidence, exceptions, and ownership.

Circular AI governance control loop with visibility, rules, controls, evidence, exceptions, and ownership.
AI governance becomes defensible when leadership can see the tools, rules, evidence, exceptions, and owners.

The Research Points in the Same Direction

DigiCert’s AI Trust Outlook makes the core problem clear: organizations are putting AI-powered systems into use while accountability, identity, traceability, and governance are still catching up.

KnowBe4’s research on agentic AI and human behavior points to the human side of the same issue: AI agents and employees are increasingly becoming part of the same work layer, while unapproved or ungoverned AI use creates another area organizations need to manage.

For a CPA or advisory firm, the practical meaning is simple: the AI problem is not just “will attackers use AI against us?” It is also:

Can we prove our own firm is using AI responsibly around confidential client data?

That question matters because client trust is not based only on intent. A client does not care that an employee was trying to save time if confidential information ends up in the wrong place. A cyber insurer, regulator, or large client reviewing a security questionnaire will not be satisfied with “we told people to be careful.”

They will want evidence.

A Simple AI Defensibility Test

Leadership does not need to start with a 50-page AI policy. Start with five questions:

  1. Can we list the AI tools currently approved for firm use?
  2. Can we explain what types of client data employees may not enter into public or unapproved AI tools?
  3. Can we show whether AI tools have access to email, SharePoint, Google Drive, practice management systems, client portals, meeting recordings, or document repositories?
  4. Can we identify who owns AI exceptions when productivity pressure conflicts with confidentiality risk?
  5. Can we produce evidence that these rules are communicated, monitored, and reviewed?

If the answer is unclear, the firm may not have an AI technology problem yet. It has an AI visibility problem.

And visibility problems tend to become evidence problems at the worst possible time: after a client question, insurance renewal, due diligence request, incident, or employee mistake.

Checklist of five AI defensibility questions for CPA and advisory firm leadership.
A quick leadership test: could your firm prove AI use around client data is governed?

The Prudent Move Is Not to Ban AI

Banning AI may sound decisive, but in many firms it is not realistic. People will use tools that help them work faster, especially when the official process feels slow or restrictive.

The better move is to govern AI use like other client-data risks:

  • Define approved tools.
  • Define prohibited data use.
  • Review connected apps and permissions.
  • Create exception handling.
  • Train staff around real workflow examples.
  • Maintain evidence.
  • Review the issue with leadership on a cadence.

This should not live only in IT. AI use touches operations, client service, HR, compliance, legal, and leadership judgment.

The right question is not, “Are we using AI?”

The right question is, “Can we prove our AI use is being governed before confidential client data is exposed?”

Next Step

Start with a quick self-check.

IT Assure’s Client Data Protection Quick Check helps firm leadership evaluate whether client-data protection is mostly assumed or supported by visible controls and evidence.


Take the Quick Self-Check

If the answers raise concern, the next step is a Cyber Defensibility Review. The review is designed to help leadership understand where control gaps, evidence gaps, or ownership gaps may exist — including risks created by AI, SaaS sprawl, vendor access, identity, backup, and client-data workflows.


Book a Cyber Defensibility Review

AI may help your firm move faster.

But client trust still requires discipline.

Speed without governance is not innovation. It is exposure waiting for a reason to become visible.

Sources