5 min readSanitized AI Team

Answering the Client AI-Security Questionnaire: What Outside Counsel Needs to Show

AI GovernanceComplianceRiskData PrivacyDLP

A general counsel forwards your engagement letter back with an attachment: a fourteen-question AI-security questionnaire, due before they'll release the matter file. It asks which AI tools your firm permits, how you prevent client data from being entered into public ones, and what happens when someone does it anyway. The partner who won the pitch now has to answer questions about controls no one at the firm has ever documented — and "we tell our associates not to" is not going to survive the follow-up.

This is arriving faster than most firms expected. Clients — especially in-house teams at technology companies, financial institutions, and regulated healthcare organizations — have started treating their outside counsel the way they treat any other vendor with access to their crown-jewel information. If a client already runs an AI governance program internally, they will expect the firm holding their privileged files to run one too. The questionnaire is the moment your informal posture becomes a discoverable, contractual representation.

What the questionnaire is really testing

The surface questions are about tools and policies. The real question underneath is whether the firm has visibility and control over where client data goes once it enters a lawyer's browser. A client sophisticated enough to send the questionnaire knows the answer isn't a tool list — it's an account of how the firm handles the gap between policy and behaviour.

That gap is well documented. Gartner's 2026 survey found that 88% of employees with enterprise AI access also use personal AI tools for work, and Cyberhaven's 2025 analysis found that 82.8% of legal documents entered into AI tools go to non-corporate accounts. So when a client asks "do your staff use ChatGPT with our data," the honest answer for most firms is: someone probably has, on a personal login the firm can't see, and the firm has no record either way. A questionnaire response that claims otherwise without evidence is a representation the firm may not be able to stand behind.

The strongest answers reframe the question from prevention by prohibition to demonstrable diligence. Clients don't actually believe you can stop every associate from ever touching an AI tool. They want to know that when it happens, sensitive data was caught before it left the firm's control — and that you can show it.

The scenario the questionnaire is built to catch

Picture the matter after you've won it. A litigation associate is under deadline on a document review. She pastes a batch of the client's internal emails into a public AI tool to get a fast summary of who-knew-what-when. The prompt works beautifully. It also just moved the client's confidential communications outside the firm's control — into a tool where, once submitted, the content becomes subject to the provider's terms of use, which can grant broad rights to retain and process it. There is no recall button. The associate never thought of it as "sending client data to a vendor," because there was no upload dialog, no attachment, no security prompt. Just a text box.

Now map that back to the questionnaire. The client asked how you prevent exactly this. If your answer is a policy document, the associate's paste already went around it. If your answer is a ban, she used her personal account and the firm has no log of the event at all. The only answer that actually corresponds to what happened is one where the sensitive content was identified and redacted before the prompt reached the tool — because after submission there is nothing left to control.

This is why bans read as weak on a questionnaire and why they fail in practice. A prohibition that people route around produces no record and no protection. What a sophisticated client is looking for is a control that acts at the point of entry and leaves a trail proving it acted.

Building an answer you can actually stand behind

Three things turn a questionnaire from an awkward exercise into a competitive advantage.

First, visibility. You cannot represent what you can't see. A firm that can describe its AI usage — where prompts are going, where policy violations cluster, which practice groups carry the most exposure — is answering from evidence rather than hope. Note the boundary that matters for privilege: the record should capture the policy event, not the contents of what the lawyer typed. You want proof that a control fired, not a second copy of the client's confidential material sitting in a log.

Second, data-level protection that survives real behaviour. The control has to catch client PII, financial data, and privileged content across the tools people actually reach for and the files they upload, and it has to do so before submission. Crucially, it should let the sanitized prompt through — redacting the sensitive pieces while keeping the answer useful — so lawyers get their result and don't feel pushed back onto a personal account to get their work done.

Third, in-the-moment education. Every time a risky prompt is stopped with a plain-language explanation of what was flagged and why, the associate learns the boundary in the exact moment it mattered. Over time that produces something a questionnaire loves: a measurable record that your people are getting better at safe AI use. That record is also directionally useful if a firm ever needs to show it took reasonable steps to prevent a disclosure — evidence of safeguards, framed as diligence, not as a guarantee of any particular outcome.

This is the principle Sanitized AI is built on: protect the data at the moment of the prompt, teach the person while it's happening, and keep a record of the policy event so the firm can show its work — regardless of which tool the lawyer reached for.

The question to ask before the next questionnaire arrives

Don't wait for a client to define your AI posture for you. This quarter, pull the questionnaire you'd least want to receive and answer it honestly, in writing. If any answer is "we have a policy" with no way to show it was followed, that's the gap a client will find first. The firms that treat the AI-security questionnaire as a client-trust signal — something they can hand a client proactively — will win the matters the firms still relying on a ban quietly lose.

If you want to see what a demonstrable, evidence-backed answer looks like in practice, request a demo or an intake conversation.

See how Sanitized AI stops sensitive data from leaving the prompt box.