Artificial Intelligence

A Guide to AI Confidentiality: What You Can and Can’t Upload

A practical framework for valuation analysts and forensic accountants who want AI’s efficiency without a confidentiality breach, a privilege waiver, or a professional standards violation.


Why This Matters Now

Every week, another valuation analyst pastes a client’s trial balance into a free AI chatbot to “save time.” Most of them have never read the terms of service for the tool they are using, and many are violating their confidentiality obligations without realizing it.

The problem is not AI. The problem is treating a consumer chatbot like a locked filing cabinet. This guide maps your existing professional obligations to concrete AI usage rules, so you can capture the efficiency gains while staying on the right side of your standards, your engagement letters, and—in litigation contexts—attorney-client privilege.

Part 1: Your Professional Obligations (Nothing New Here)

AI does not create new confidentiality duties. It creates new ways to violate the ones you already have.

Obligation Source

What It Requires

How AI Creates Risk

NACVA Professional Standards (confidentiality)

Member shall not disclose confidential client information without client consent

Uploading client data to a consumer AI tool may constitute disclosure to a third party

AICPA Code of Professional Conduct (confidential client information rule, ET §1.700)

Applies to CPA/CVA dual credential holders; no disclosure without specific consent

Same disclosure risk; consumer AI terms often permit the vendor to use inputs for model training

Engagement letters

Many contain data handling, subcontractor, and confidentiality clauses

An AI vendor may qualify as an undisclosed third-party service provider under your own contract

Attorney-client privilege/work product (litigation engagements)

Privilege can be waived by voluntary disclosure to third parties outside the privilege circle

Pasting privileged material into a tool that logs, stores, or trains on inputs is arguably a voluntary disclosure

State privacy statutes (varies)

Protection of personally identifiable information (PII)

SSNs, account numbers, and health information in source documents flow straight into AI inputs unless stripped or redacted

Court protective orders

Documents produced under a protective order have explicit handling restrictions

“Confidential/Attorneys’ Eyes Only” material in an AI tool is a potential order violation, not just an ethics issue

The one-sentence takeaway: If you could not e-mail the document to an unvetted outside vendor without client consent, you cannot paste it into an unvetted AI tool either.

Part 2: Not All AI Tools Are Equal—The Tier System

The single most important question is not which brand of AI you use, but which tier and under what terms.

 

Tier 1: Consumer/
Free

Tier 2: Paid Individual

Tier 3: Enterprise/
API with Zero Retention

Tier 4: Local/
On-Premise

Examples

Free chatbot accounts

Pro/Plus subscriptions

Enterprise plans, business API agreements, zero-data-retention addenda

Locally run open-source models (e.g., GPT4All, Llama on your own hardware)

Inputs used
for model training?

Often yes, by default

Varies; usually opt-out available; verify it

Contractually no

Never; data never leaves your machine

Data
retention

Indefinite or long-term

Limited, but logs typically exist

Contractually limited or zero

You control it entirely

Admin controls/
audit logs

None

None

Yes

Your own infrastructure

BAA/DPA availability

No

No

Often yes

N/A

Appropriate for client-identifiable data?

Never

No (even with training opt-out, retention and access terms are usually insufficient)

Yes, with review; read the actual agreement, don’t assume

Yes

Appropriate for anonymized data?

Risky; anonymization failures happen

Acceptable for well-anonymized data

Yes

Yes

Appropriate for general research/drafting (no client data)?

Yes

Yes

Yes

Yes

Practical rule of thumb: Consumer tools are for learning and generic drafting. Client work belongs on an enterprise agreement you have actually read, or on hardware you control.

Part 3: The Anonymization Table—What to Strip Before You Paste

“Anonymized” means a reader could not re-identify the client. Changing “Smith Plumbing LLC” to “the Company” while leaving in the city, revenue, and industry of a business with three competitors is not anonymization.

Data Element

Risk Level

Treatment Before Upload

Client/company names

High

Replace with generic labels (“the Company,” “Target Co.”)

Individual names (owners, spouses, employees)

High

Replace with roles (“Owner A,” “the non-titled spouse”)

SSNs, EINs, account numbers

Critical

Remove entirely; never merely relabel

Addresses and specific locations

High

Generalize (“a metro area in the Southwest”)

Exact revenue/financials of identifiable small businesses

Medium-High

Round or scale by a consistent factor; note the scaling privately

Industry + geography combined

Medium

Generalize one or the other for niche businesses

Case captions, docket numbers

Critical

Remove; these are trivially searchable

Dates of specific transactions

Medium

Shift consistently or generalize to quarter/year

Unique deal terms or contract language

Medium

Paraphrase rather than paste verbatim

Medical, criminal, or lifestyle details (dissolution work)

Critical

Remove or abstract heavily; these are both sensitive and identifying

The scaling trick for financial data: Multiply every figure by a consistent random factor (e.g., 1.37) before uploading. Ratios, trends, and anomaly patterns survive; the actual figures do not. Keep the factor in your workpapers, never in the AI conversation.

Part 4: The “Can I Paste This?” Decision Tree

Work through these questions in order. The first “stop” you hit is your answer.

START: I want to put something into an AI tool.

Q1: Does it contain ANY client-identifiable information, PII, or material from a litigation matter?

NO—PASTE FREELY (any tier). Generic prompts, public data, your own templates, published guidance = fair game.

YES ▼

Q2: Is the matter subject to privilege, work product protection, or a protective order?

YES—STOP. Consult engaging counsel before using any external tool. Local/on-premise processing may be the only safe option.

NO ▼

Q3: Am I using an enterprise-tier tool with a reviewed agreement (no training on inputs, defined retention, confidentiality terms)?

NO—STOP. Either anonymize fully per the table above, or do not upload. A training opt-out checkbox is not an agreement.

YES ▼

Q4: Does my engagement letter permit third-party service providers, or has the client consented to AI-assisted work?

NO/UNSURE—PAUSE. Update your engagement letter template and/or obtain written consent. (Do this once; it covers you forever.)

YES ▼

Q5: Even so, have I stripped what does not need to be there? (SSNs, account numbers, third-party names)

YES—PROCEED. Document the tool and tier used in your workpapers.

NO—Strip first, then proceed.

Part 5: Five Habits of the Compliance-Aware AI User

  1. Read one agreement. Pick your primary AI tool and actually read its data usage terms once. Thirty minutes now beats a disclosure incident later.
  2. Update your engagement letter template. Add a clause disclosing that AI-assisted tools operating under confidentiality agreements may be used in the engagement. Most clients will not blink; the ones who object are telling you something useful.
  3. Build an anonymization step into your workflow. Make “strip and scale” a checklist item before any upload, the same way you would redact before producing documents.
  4. Keep an AI usage log in your workpapers. Tool, tier, date, and nature of data uploaded. If your work is ever challenged in deposition, “I don’t know what I uploaded” is the worst possible answer.
  5. Default to the more restrictive rule. When NACVA standards, the AICPA Code, your engagement letter, and a protective order all apply, the strictest one governs. When in doubt, treat it as privileged.

The Bottom Line

AI is a leverage tool, not a filing system. Your confidentiality obligations did not change when chatbots arrived; only the number of ways to accidentally breach them did. Match the sensitivity of the data to the tier of the tool, redact like a professional (not like someone doing a find-and-replace on the company name), and document what you did. That is the whole game.

This guide provides general professional guidance, not legal advice. For litigation matters, coordinate AI usage with engaging counsel.


Colin Brown, CTO of Syncnet, helps consultants integrate AI into their practices.

Mr. Brown may be contacted by e-mail to cto@syncnet.com.

The National Association of Certified Valuators and Analysts (NACVA) supports the users of business and intangible asset valuation services and financial forensic services, including damages determinations of all kinds and fraud detection and prevention, by training and certifying financial professionals in these disciplines.