A general counsel at one of your longstanding corporate clients forwards a vendor-security questionnaire before renewing the engagement. Buried in the third section is a question your firm has never had to answer before: Describe the controls you use to prevent client confidential information from being entered into public AI tools, and provide evidence those controls are effective. The retainer depends on the answer, and "we have a policy prohibiting it" is no longer going to clear the bar.
This is the new reality for outside counsel. Clients that adopted AI governance for their own staff are now extending the same scrutiny to their advisors. They know their firms are using ChatGPT, Claude, and Copilot for research, first-draft memos, and document review — Cyberhaven found in 2025 that 82.8% of legal documents entered into AI tools go to non-corporate accounts. The client's question is no longer whether their counsel uses AI. It's whether counsel can prove the client's data isn't leaking through it.
Why a policy is the wrong answer to this question
The instinct is to point to the firm's acceptable-use policy — a signed acknowledgment that lawyers and staff won't paste client material into public tools. But a sophisticated client reads that answer for what it is: an assertion of intent, not a demonstration of control. Their own governance program has already taught them the gap between the two.
The numbers behind that skepticism are stark. LayerX found in 2025 that 77% of AI users paste data into prompts, and 82% of that pasted content comes from unmanaged personal accounts. Gartner's 2026 survey reports that 88% of employees with enterprise AI access also use personal AI tools for work. A policy governs the managed account the firm can see; it does nothing about the articling student who opens ChatGPT on a personal login at 11 p.m. to summarize a diligence bundle. The client understands this because it's true inside their own organization too.
So when the questionnaire asks for evidence of effectiveness, a policy PDF answers a different question than the one being asked. The client wants to know what happens at the moment a lawyer or staff member actually tries to paste a client's term sheet into a prompt box — not what the handbook says they shouldn't do.
What the client is actually testing for
Strip the security jargon away and the questionnaire is asking about the same professional duties the firm already carries: confidentiality, solicitor–client privilege, and the newer duty of technological competence. The client is checking whether their counsel has done reasonable due diligence on a tool that now touches nearly every matter.
The sharpest version of the question is about supervision. Whatever a junior associate, articling student, or assistant produces, a partner signs it and owns the risk. If a staff member drops a client's confidential financial model into a public tool to get a faster summary, that content becomes subject to the provider's terms of use — which can grant broad rights to retain and process it, potentially by sub-processors elsewhere. Once submitted, it cannot be recalled. There is nothing left to control after the fact. The courts are beginning to treat these disclosures as consequential: in U.S. v. Heppner (S.D.N.Y., Feb 2026), documents created with a public GenAI tool were held not protected by attorney-client privilege — an early signal, not settled law, but a directional one clients are watching.
What the client wants to see, then, is threefold: that the firm knows where AI risk concentrates across its people, that sensitive client data is actually stopped before it reaches a public tool, and that there's a record showing the safeguard is working. That third element is the one policies can't produce.
Turning the answer into evidence
Consider two firms answering the same questionnaire. The first writes: Our staff are prohibited by policy from entering client data into unauthorized AI tools. The second writes: We run a control that inspects prompts before submission and redacts client-identifying and confidential information, so it never reaches the public tool. Our administrators have visibility into AI usage and policy events across the firm, and we retain a record that sensitive data was caught before it left our control.
Only the second answer is evidence. It maps to what regulators and clients recognize as reasonable safeguards — and it aligns with the direction of enforcement generally, where demonstrable diligence can reduce exposure when something goes wrong. It also flips the framing from defensive to reassuring: instead of promising restraint, the firm can tell the client, credibly, "we keep your data out of public AI tools, and we can show you the record." That's a client-trust signal, not just a compliance checkbox.
Crucially, the record has to be the right kind of record. It should capture the policy event — that something was flagged and stopped — never the content of what a lawyer typed. A log that reproduces prompt contents would recreate the confidentiality problem it's meant to solve. The evidence a client is entitled to is that the control fired, not a transcript of the near-miss.
And it works only if lawyers don't route around it. A control that simply blocks everything gets abandoned within a week under filing pressure. A redact-and-allow approach — where client identifiers are swapped for realistic placeholders so the AI answer still comes back useful — keeps the research and drafting workflow intact while the sensitive data stays behind. This is the principle Sanitized AI is built on: act at the prompt, redact before submission, and turn each flagged moment into evidence the firm did its due diligence.
The question to answer before the client asks it
The firms that will answer these questionnaires cleanly are the ones treating client AI-security scrutiny as inevitable rather than exceptional. Before the next renewal cycle, ask: if a corporate client demanded evidence today that client data cannot reach a public AI tool through your firm, what would you send them — a policy, or a record?
If the honest answer is a policy, that's the gap to close this quarter. If you'd like to see what an evidence-based answer looks like in practice, request a demo and we'll walk through it with your matters in mind.