5 min readSanitized AI Team

What the CPA Confidentiality Duty Means When Client Data Meets Generative AI

ComplianceData PrivacyAI GovernancePIIData Security

A senior on your tax team is reconciling a client's investment income at 9 p.m. The numbers don't tie out, so she copies three columns of the client's brokerage statement — names, account balances, a SIN in the header row — into ChatGPT and asks it to find the discrepancy. She gets a clean answer in thirty seconds and closes the file. She did good work. She also just disclosed a client's financial identity to a third party, and neither she nor the firm has any way to recall it.

This is the tension that generative AI creates for every accounting, tax, and audit practice in Canada. The confidentiality duty in your provincial CPA code isn't new, and it isn't ambiguous: information obtained in the course of a professional engagement stays confidential unless the client consents or the law compels disclosure. What's new is how easily that duty is breached by someone doing nothing more than trying to work faster.

The duty didn't change, but the exposure did

CPA confidentiality obligations were written for a world of paper files, locked cabinets, and clearly bounded disclosures. You knew when information left your control because it left in an envelope or an email you could point to. A public AI tool collapses that boundary. Once a prompt is submitted, the content becomes subject to the provider's terms of use — which can grant broad rights to retain it, process it through sub-processors elsewhere, and use it to improve the provider's models. There is no envelope to intercept and no recipient to call.

The irreversibility is the part that matters most. A misdirected fax can sometimes be shredded on the other end. A prompt cannot be un-submitted. That's why the confidentiality analysis has to move earlier than most firms assume — the decision point isn't "how do we handle a leak," it's "how do we stop client data from reaching the tool in the first place," because after submission there is nothing left to control.

And the volume is real. Cyberhaven's 2025 research found that the sensitive share of corporate data going to AI tools rose to roughly 35 percent, up from about 11 percent two years earlier. LayerX's 2025 data shows 77 percent of AI users paste data into prompts, and 82 percent of that pasted content comes from unmanaged personal accounts. For an accounting firm, "sensitive data" and "the content of a prompt" are frequently the same thing: a return, a valuation, a client's financials.

Why busy season makes this worse, not better

The confidentiality duty applies year-round, but the conditions that produce breaches spike during busy season. Deadline pressure, volume, junior staff working late, and the sheer repetitiveness of reconciliation and review work are exactly the conditions under which someone reaches for the fastest available tool. Gartner's 2026 survey found that 88 percent of employees with enterprise AI access also use personal AI tools for work — meaning even firms that provisioned an approved tool still see client data flowing into unmanaged accounts.

Consider a common scenario: an audit associate is testing a sample of transactions and wants to summarize a client's general ledger extract to spot anomalies. The extract includes vendor names, dollar figures, and in some rows, personal information about the client's contractors. Pasted into a public tool, that's not one confidentiality question — it's a disclosure spanning the client, the client's counterparties, and individuals whose PII the client entrusted to your firm. Netskope's 2025 telemetry puts a number on how routine this is: the average organization logs roughly 223 sensitive-data policy violations per month in GenAI apps, and regulated data accounts for 54 percent of them.

A firm-wide ban feels like the clean answer. It isn't. Gartner reports that 69 percent of organizations suspect or have evidence of prohibited public GenAI use. Bans push the activity onto personal devices and personal accounts, where the firm has no visibility at all — replacing a governance problem with a blindness problem.

Confidentiality is a data problem, so the control has to be at the data

The more durable approach treats confidentiality as a data-level obligation rather than a tool-level one. It doesn't matter which AI tool a staff member reaches for; what matters is whether client-identifying financial information leaves the firm's control. That reframing points to three things a firm can actually do.

First, catch sensitive data — SINs, account numbers, client names tied to financial figures, valuation data — before a prompt reaches the AI tool, so the disclosure never happens. Redacting the sensitive elements while letting the analytical question through means the associate still gets her reconciliation help; the client's identity just doesn't go with it.

Second, make each near-miss a teaching moment. When a prompt is stopped, an explanation of what was flagged and why turns an abstract policy into concrete, in-the-moment training. Over a busy season, that's how a firm's staff measurably get better at handling AI — instead of learning the rule only after a breach.

Third, give partners visibility into where AI risk concentrates across the practice, recorded as a policy event rather than a transcript of what anyone typed. That distinction matters: you want evidence that a control is working, not a second copy of the confidential data you were trying to protect.

This is the principle Sanitized AI is built on — that the confidentiality duty is best honoured by acting on the data before submission, not by policing tools after the fact.

The question to answer before your next filing deadline

Here's the one thing worth resolving this quarter: if a member of your staff pasted a client's return into a public AI tool tomorrow, would anything stop it, and would anyone know? If the honest answer is no, the confidentiality duty you already carry is running on trust alone. It doesn't require a ban or a policy memo nobody reads — it requires a control that meets the data at the point where it would otherwise leave your firm.

If you'd like to see what that looks like for an accounting, tax, or audit practice, request a demo and we'll walk through it with your workflows in mind.

See how Sanitized AI stops sensitive data from leaving the prompt box.