April 24, 2025
Client Consent Basics for AI-Assisted Work
Confidentiality obligations did not change when AI tools arrived. What changed is that a new category of third party, the AI vendor, now potentially touches client information, and that triggers the same consent questions a firm would ask about any other third party.
The baseline obligation
Sharing client information with any third party, including a software vendor, generally requires either client awareness or confidence that the arrangement falls within the ordinary course of engaging support services under existing terms. Firms should not assume AI tools are automatically covered by old contract language written before those tools existed.
What to actually tell a client
Plain language, in the engagement letter or a related communication: what tools are used, what categories of information they touch, and what protections are in place. Clients generally do not object to a firm using modern tools; they object to finding out after the fact that they were not told.
Where firms most often get this wrong
Adopting a tool firm-wide and only updating client-facing language months later, or never, is the most common gap. The fix is straightforward: update standard language once, at the point of adopting a new category of tool, rather than treating it as a one-off decision buried in an internal memo nobody outside the tech team reads.
A short script for the client conversation
Most clients respond well to a brief, direct explanation: we use AI-assisted tools for research and first drafts on engagements like yours, under an agreement that keeps your information out of any public model training, and every deliverable is reviewed by a named person before it reaches you. This is a short paragraph, not a long disclosure, and it tends to build confidence rather than raise concern, because it demonstrates the firm has already thought through the question the client might otherwise have to ask.
Handling a client who wants more detail
A small number of clients, particularly in regulated industries, will ask follow-up questions beyond the short standard explanation, which specific tools, whose infrastructure, what certification. Having a slightly longer, more technical version of the disclosure ready for this smaller group, without needing to lead with it for every client, keeps the standard conversation short while still being fully prepared for the clients who need more detail.
A short note on how often this conversation actually needs repeating
Once a client has been told, plainly, what tools are used and how their information is protected, that disclosure does not need to be repeated at the start of every single engagement with the same client, as long as nothing material has changed. A brief mention at the outset of the relationship, refreshed if the tools or terms change, is proportionate.
A short note on the difference between a policy and a habit
A written confidentiality policy and an actual team habit of checking sources and disclosing tool use are related but distinct, and a firm can have a good policy on paper while the daily habit has quietly lapsed. Periodically observing, rather than just asking, whether the described practices are actually happening in a sample of real client work is a more reliable check than trusting that a written policy alone is being followed.
The gap between the two tends to widen quietly during busy stretches, when a policy that everyone agreed to in principle gets treated as optional under deadline pressure. Checking in on the habit specifically during a firm's busiest periods, not just its calmest ones, gives a more honest read on whether it actually holds.
A final word on treating this as an ongoing practice, not a one-time project
Confidentiality practice around AI tools is not something a firm finishes and moves past. New tools get adopted, new client types raise new questions, and staff turnover means the habits described here need periodic reinforcement rather than a single rollout. Treating this as a standing, lightly maintained practice, revisited on a regular calendar, is more realistic than treating it as a project with a defined end date.
Key takeaways
- Sharing client information with an AI vendor is a third-party disclosure question, like any other vendor.
- Old contract language should not be assumed to already cover new AI tools.
- Tell clients plainly what tools are used and what information they touch.
- Update client-facing language at the point of adoption, not months later as an afterthought.
Questions, answered
What is the short answer on Client Consent Basics for AI-Assisted Work?
Using AI tools on client accounts raises consent questions that predate AI but are easy to overlook in the rush to adopt new tools.
What are the key takeaways?
Sharing client information with an AI vendor is a third-party disclosure question, like any other vendor. Old contract language should not be assumed to already cover new AI tools. Tell clients plainly what tools are used and what information they touch. Update client-facing language at the point of adoption, not months later as an afterthought.
How does VIPMarketing approach confidentiality?
VIPMarketing runs in a private, hosted workspace. You own every document and record, and none of it trains a model or serves anyone else.