Someone at your firm has already pasted a client contract, a draft settlement agreement, or a spreadsheet of financial records into ChatGPT or Claude this week. Not maliciously — they were trying to save time, summarize a document, or draft an email faster. But they almost certainly did it from a personal, free, or individually-billed account with no connection to your firm’s security controls, no oversight from IT, and no contractual protection over what happens to that data next.
This is shadow AI: employees adopting consumer AI tools faster than firms can govern them. For a law firm, accounting firm, or other professional services business handling privileged and regulated client data, it’s one of the fastest-growing gaps in an otherwise well-managed security program — and most firms don’t know it’s happening until an incident, an audit, or a client questionnaire forces the question.
Why Personal AI Accounts Are a Different Risk Category Than “Shadow IT”
Firms have dealt with shadow IT for years — an employee signing up for an unsanctioned file-sharing tool or personal cloud storage. Shadow AI is worse for one structural reason: the data doesn’t just sit somewhere ungoverned, it becomes an input the AI provider may process, log, or in some cases use to improve their models, depending on the account tier and settings in effect at the time.
Consumer-tier ChatGPT and Claude accounts — the free and individually-billed plans employees sign up for with a personal email — are built for individual convenience, not enterprise data governance. Key gaps that separate them from enterprise/business-tier deployments:
- No firm-level data protection agreement. Enterprise and business AI plans typically come with contractual terms excluding customer data from model training and defining data retention limits. Consumer accounts operate under standard consumer terms of service, which are not a substitute for the vendor agreements compliance frameworks require.
- No admin visibility or control. IT and compliance have no console showing what was entered, by whom, or when. If a breach or a client complaint requires answering “what data left our environment,” a personal AI account produces no audit trail your firm can access.
- No centralized offboarding. When an employee leaves, IT can disable their email and VPN access in minutes. Their personal ChatGPT or Claude account — and anything stored in its conversation history — is invisible to that offboarding process entirely.
- No enforced MFA or SSO. Personal accounts are secured by whatever password and recovery email the employee chose, not your firm’s identity provider or conditional access policies.
What’s Actually at Risk When Client Data Goes Into a Personal AI Account
Privilege waiver. For law firms, sharing privileged client communications or work product with a third-party AI service — outside the firm’s controlled environment and without a governing data agreement — creates a credible argument that attorney-client privilege or work product protection has been waived. Courts are actively litigating how AI tool use intersects with privilege; firms shouldn’t wait for controlling precedent before treating this as a live risk.
HIPAA and regulatory exposure. A consumer AI account is not a business associate under HIPAA, and typically has no Business Associate Agreement available at that tier. Entering PHI into a personal ChatGPT or Claude account to draft a client email or summarize a file is very likely a HIPAA Security Rule violation, regardless of intent — the same logic that applies to any unauthorized third-party disclosure of PHI.
Compliance and audit failures. SOC 2, CMMC, and cyber insurance underwriting all expect documented control over where sensitive data flows. An environment where employees can freely paste client data into ungoverned AI tools is a finding waiting to happen in any of those reviews — and, per Kyber’s own guidance on cyber insurance underwriting, insurers are increasingly specific about the technical controls they expect to see.
Data permanence you can’t undo. Once sensitive data has been submitted to a third-party AI service, your firm has limited ability to guarantee its deletion, especially if it was retained for abuse monitoring, safety review, or — depending on account settings — model improvement. There is no equivalent to shredding a document or wiping a device.
Inaccurate work product treated as fact. Separate from data exposure, AI models generate plausible-sounding but incorrect information — including fabricated case citations, misstated figures, and confidently wrong summaries. Attorneys have already faced court sanctions for filing AI-generated briefs with invented citations. Ungoverned use compounds this risk because there’s no firm-level review step requiring verification before AI output reaches a client or a filing.
Why “Just Ban It” Doesn’t Work
Some firms respond to these risks by prohibiting AI tools outright. In practice, this doesn’t eliminate the risk — it just removes visibility into it. Employees under deadline pressure will use whatever tool helps them finish faster, policy or not, and a ban with no enforcement mechanism produces exactly the same ungoverned usage as having no policy at all, minus the ability to say you addressed it. The firms that actually reduce risk build a systematic plan that enables safe, monitored AI use instead of pretending it isn’t happening.
What a Systematic AI Governance Plan Actually Includes
An AI acceptable use policy with clear data classification rules. A written policy defining exactly which data categories can never be entered into an AI tool (PHI, privileged client communications, financial account data, personally identifiable information of clients or employees) and which categories are permissible with an approved, governed tool. Vague guidance like “use AI responsibly” doesn’t give employees a decision they can actually apply.
Enterprise or business-tier AI accounts provisioned through the firm. Business plans for ChatGPT and Claude support SSO through your existing identity provider, contractual exclusion of firm data from model training, admin-level visibility into usage, and centralized deprovisioning tied to the same offboarding process as email and VPN access.
Vendor risk review before any AI tool is approved. The same due diligence applied to a new software vendor — data processing terms, retention policy, subprocessor list, security certifications — should apply before an AI tool is added to the approved list, not after employees are already using it.
Technical controls that catch what policy alone won’t. Data loss prevention rules and network-level monitoring can flag or block sensitive data patterns — client account numbers, PHI identifiers, privileged document markers — headed to unapproved AI endpoints, providing a backstop for the inevitable cases where a written policy gets forgotten under deadline pressure.
Employee training specific to AI risk, not folded into generic security awareness. Most phishing-focused security training never addresses AI tool use at all. Employees need concrete, firm-specific examples: what’s safe to ask an approved AI tool, what data can never go in regardless of the tool, and how to verify AI-generated work product before it reaches a client.
Logging and audit trail for compliance and incident response. If a regulator, auditor, or opposing counsel later asks what data your firm shared with AI tools, a governed deployment can answer with records. An ungoverned one cannot — and “we don’t know” is a materially worse position in any compliance review or breach investigation.
How Kyber Security Builds AI Governance Into Your Existing Compliance Program
AI governance isn’t a separate initiative bolted onto your security program — it’s an extension of the same risk assessment, policy development, and monitoring work Kyber already provides for HIPAA, CMMC, and SOC 2 alignment. Firms that have already built a compliance foundation with Kyber are typically a short step away from AI governance, not starting over.
AI risk assessment. We identify where AI tools are already in use across your firm — sanctioned or not — and map the specific data types at risk against your regulatory obligations.
Acceptable use policy development. A written, firm-specific AI policy defining approved tools, prohibited data categories, and required review steps for AI-assisted work product, developed as part of the same policy framework covering your other compliance obligations.
Enterprise AI deployment and SSO integration. We configure business-tier ChatGPT or Claude accounts tied to your existing identity provider, so AI access follows the same provisioning and offboarding controls as every other firm system.
vCISO oversight. For firms without a dedicated security executive, Kyber’s vCISO service extends to AI governance — setting policy, reviewing new tool requests, and reporting on AI-related risk alongside the rest of your security program.
Security awareness training that covers AI specifically. Ongoing, tracked training that gives employees a clear, practical standard for what belongs in an AI conversation and what never does.
Frequently Asked Questions
Is it ever safe to use ChatGPT or Claude for work at all?
Yes, with the right account tier and governance in place. Enterprise and business plans offer contractual data protections, admin controls, and SSO integration that consumer accounts do not. The risk isn’t AI itself — it’s employees using personal, ungoverned accounts with no firm oversight or data protection agreement.
Can pasting client information into ChatGPT actually violate HIPAA?
Yes, in most cases. A consumer AI account is not a business associate and typically has no Business Associate Agreement in place. Submitting protected health information to a personal AI tool is very likely an unauthorized disclosure under the HIPAA Security Rule, regardless of the employee’s intent.
Does using AI tools put attorney-client privilege at risk?
It can. Sharing privileged communications or work product with a third-party AI service outside a controlled, contractually governed environment creates a credible basis to argue privilege was waived. Courts are still actively addressing how AI use interacts with privilege doctrine, which makes proactive governance more important, not less.
What’s the difference between a personal and a business AI account?
Business and enterprise tiers of ChatGPT and Claude typically include contractual exclusion of customer data from model training, defined data retention terms, admin-level usage visibility, and SSO integration with your identity provider. Personal accounts operate under standard consumer terms with none of those protections or controls.
How do we find out if employees are already using personal AI accounts?
An AI risk assessment reviews network traffic patterns, surveys staff usage, and evaluates existing device and browser policies to identify where AI tools are already in use. Most firms are surprised by how widespread usage already is once they look.
How long does it take to stand up an AI governance program?
For a firm starting from no formal AI policy, an initial risk assessment and written acceptable use policy typically takes two to four weeks, with enterprise AI account deployment and SSO integration following in parallel. Full rollout, including staff training, is generally achievable within 60 days.
Bring Your Firm’s AI Use Under Control
Kyber Security helps professional services firms govern AI tool use with the same rigor applied to HIPAA, CMMC, and SOC 2 compliance — enterprise deployment, written policy, and ongoing oversight.
Cybersecurity Guidance for Fairfield County Businesses
Kyber Security is a Trumbull, CT-based managed IT and cybersecurity provider serving businesses throughout Bridgeport, Stamford, Norwalk, and the rest of Fairfield County. Talk to us about your security strategy.
