← Back to blog
AI governance

Shadow AI in professional services firms: how to capture the upside without risking client data

Many professional services firms do not have an AI program yet. But that does not mean AI is absent. Staff may already be using public AI tools to summarize emails, draft replies, interpret documents, or answer process questions. The real issue is not malicious behavior; it is useful productivity behavior happening before the firm has data boundaries, review rules, and approved workflows.

Why shadow AI shows up in accounting first

Accounting firms are full of repeatable knowledge work: document requests, missing-item follow-up, status summaries, internal checklists, client-service emails, reconciliations, payroll cycles, and month-end coordination. Those are exactly the tasks where generative AI feels immediately helpful.

They are also tasks that routinely touch confidential business records, taxpayer information, payroll data, HR details, bank statements, and personally identifiable information. IRS guidance for tax professionals emphasizes safeguarding taxpayer data, written security planning, staff awareness, and controls. FTC Safeguards Rule guidance similarly pushes financial-information handlers toward risk assessment, access control, and service-provider oversight. AI should be evaluated through the same operating-risk lens.

The leadership mistake: treating AI as only an IT tool

The partner question is not simply which chatbot to approve. It is how the firm wants work to move. If staff use AI to draft a client response, summarize a document request, or find an SOP, the firm needs to know what data was used, what output was created, who reviewed it, and what decisions AI was not allowed to make.

That makes shadow AI an operations issue, a training issue, a data-governance issue, and a client-trust issue. IT can help select tools and enforce access controls, but firm leadership has to define acceptable workflows.

A practical policy should separate use cases, not just tools

A useful AI policy should not say only “approved” or “not approved.” It should describe categories of use. Low-risk examples may include drafting generic internal text, brainstorming non-client-specific process improvements, or summarizing firm-authored SOPs. Higher-risk examples include anything involving client tax records, payroll data, bank information, medical information, investment information, or client-facing output.

The safest policy language is operational: AI may draft, classify, summarize, compare, and route inside approved workflows. Humans approve. AI does not make final tax, accounting, payroll, legal, compliance, filing, payment, eligibility, or client-advice decisions.

How to find shadow AI without creating fear

If leadership frames the exercise as a hunt for policy violations, staff will hide usage. A better approach is to ask where people are trying to save time. The goal is to identify workflow pain and then create safer approved paths.

A short confidential survey or practice-team discussion can surface useful patterns: drafting emails, summarizing long documents, building Excel formulas, explaining software errors, or writing client request lists. Each pattern can be mapped to data sensitivity and review requirements.

The 90-day pilot that replaces unmanaged experimentation

The best response to shadow AI is not a broad firm-wide chatbot. Start with one workflow where staff already feel pain and leadership can define boundaries. Client document intake, SOP lookup, weekly status briefs, and missing-item follow-up are strong candidates because they are repetitive, measurable, and naturally reviewable.

In a 90-day pilot, success should be measured by accepted drafts, reduced cycle time, fewer missing handoffs, and reviewer confidence. The firm should also measure control: no prohibited data use, no unsupervised client communication, and clear logs for sensitive workflow steps.

How to talk to staff about shadow AI

The conversation should start from reality: staff are looking for leverage because the work is repetitive and deadlines are real. Ask where AI has been helpful, where people are unsure, and where they wish the firm had an approved tool. That framing turns shadow AI discovery into process improvement instead of discipline.

Then publish a short interim rule: do not paste client financial, taxpayer, payroll, HR, health, investment, or personally identifiable information into unapproved public AI tools. Bring candidate use cases to leadership so the firm can convert the useful ones into approved workflows.

How to evaluate this as a 90-day pilot

A useful AI pilot should be narrow enough that the firm can describe it in one sentence. If the description requires a long list of exceptions, the scope is probably too broad. Start by naming the workflow, the business owner, the source systems, the reviewer, the prohibited actions, and the success metric.

The best pilots have both business evidence and control evidence. Business evidence shows whether the workflow saved time, reduced cycle time, improved visibility, or removed repetitive follow-up. Control evidence shows whether the workflow stayed inside approved data boundaries, preserved human review, escalated uncertainty, and avoided prohibited actions.

What buyers should ask before approving a vendor or internal tool

Accounting-adjacent firms should be careful not to confuse a polished demo with a controlled operating model. The firm should ask the same questions it would ask of any sensitive-data process: what data is used, where it is processed, who has access, what the vendor retains, what humans review, and what evidence remains if a client or partner asks how the workflow worked.

A simple operating standard

For most first pilots, the standard can be plain English: AI may draft, classify, summarize, route, compare, and retrieve from approved materials. Humans approve. AI may not make final professional judgments, send unsupervised sensitive communications, approve payroll or payments, alter client records, file returns, give regulated advice, or decide compliance outcomes.

This boundary is not anti-AI. It is what makes adoption practical. It gives staff a useful approved path while giving partners a workflow they can explain to clients, insurers, advisors, and internal reviewers.

How to turn the article into an internal action item

Pick one recurring workflow and schedule a 45-minute internal review. Bring one partner or owner, one operations/practice leader, one frontline reviewer, and one person who understands the source systems. Walk through five recent examples of the workflow and mark where time was lost, where sensitive data appeared, where judgment was required, and where a draft or summary would have helped.

At the end of that session, the firm should be able to answer three questions: is this workflow worth improving, can it be safely constrained, and who would review the first version? If those answers are clear, the firm has a strong candidate for a private, human-reviewed AI pilot.

Want to turn this into a controlled pilot?

Firmdesk runs 90-day private AI workflow pilots for professional services firms. The goal is one narrow workflow, approved data boundaries, human review, and measurable operating value.

Request pilot discovery

Related Firmdesk resources

Sources and further reading