content snare

Is ChatGPT safe for client data? What accounting firms need to know

Written by
Drazen Vujovic
|
Reviewed by
James Rose
|
Last Updated
September 9, 2026
|
8 mins
Quick summary
ChatGPT itself isn't the risk, pasting client financials into it is. Public AI tools can train on and retain what you paste, and APES 110's own language on using client data for AI training makes the confidentiality problem explicit. The fix is a clear firm AI policy paired with a secure channel for exchanging sensitive documents with your clients.

Someone on your team has almost certainly pasted a client's financials into ChatGPT this month. Not out of carelessness, just because it's faster than doing the summary by hand, and it works. That's the real starting point for this conversation, not some hypothetical risk down the track.

The AI debate in accounting tends to focus on whether the output is accurate. That's the wrong worry, or at least not the first one. The bigger risk is what happens to the input, the data leaving your firm the moment it's typed into a public chatbot.

You can put a policy in front of your staff, but you can't put one in front of your clients. So the real question isn't "is ChatGPT safe", it's what your accounting firm can actually control, and what to do about the part it can't.

Is ChatGPT safe for client data What accounting firms need to know

Where does your client's data actually go?

"Public" is doing a lot of work in "public AI tool," and it's worth being specific about what that means for an accounting firm, because the mechanics matter more than the anxiety around them.

When you paste a client's financials into a consumer chatbot, that input can be used to train future versions of the model, unless the provider's terms say otherwise. Paying for a subscription doesn't automatically fix this. A personal ChatGPT Plus account, for instance, still trains on your conversations by default, you'd need to actively turn that off in settings.

The tiers that genuinely change the picture are business or enterprise plans with a data processing agreement in place, and those are a different product entirely from what a staff member or client is signing into on their own account. Unless your firm has specifically set that up, "I'm on the paid version" doesn't mean anything from a confidentiality standpoint.

Related: Getting started with AI in accounting

Once information's been used for training, it doesn't come back out as a document you can point to. It becomes a pattern the model learned from, which is a strange kind of exposure: nobody's looking at a specific client's numbers, but the client's information stopped being something only your firm holds the moment it left your systems.

Two leak points running in opposite directions

The data doesn't just leave your firm one way. It leaves through your staff, pasting a client's numbers into a chatbot to save ten minutes on a summary. And it leaves through your clients, pasting the return or report you just sent them into the same kind of tool to sanity-check it before they come back to you.

Different people, different motives, same outcome: information that was supposed to stay inside a professional relationship is now sitting inside a system neither of you controls.

Is ChatGPT safe for client data? What accounting firms need to know

Your staff, doing it for speed

The first leak point is internal, and it's less about recklessness than convenience. A junior wants a quick summary of a set of financials before a meeting. Someone's drafting a client email and pastes in the numbers for context. It's not a policy failure so much as a habit that formed the same way spellcheck did, because it's genuinely useful and nobody thought to stop and ask where the text just went.

Accountants themselves are conflicted about this. The time saved is real and hard to argue with, but so is the discomfort: feeding a client's financials into ChatGPT or Claude can look a lot like a breach of confidentiality once you think it through, and some in the profession treat a leak this way as something closer to gross negligence than an honest mistake.

Your clients, doing it for a second opinion

The second leak point is harder to manage, because it isn't happening inside your firm at all. Clients are increasingly taking the return you prepared, or the advice you gave them over email, and running it through AI themselves, then coming back with questions that sound less like "can you explain this" and more like a challenge to your judgement.

You didn't put their data into the chatbot. They did, with their own information, which is entirely their right. But the effect on your practice is the same either way: a client's numbers are now sitting inside a system you have no relationship with and no visibility into, and the conversation you're about to have with them is shaped by whatever the AI told them first.

Practitioners describe a particular kind of frustration on Reddit: a client who won't be bothered opening a letter from the tax office will happily paste their return into ChatGPT, without pausing to consider that their name, income, and account details are now sitting somewhere that could expose them to identity theft.

What the rules actually say

Here's where "is ChatGPT safe" stops being a vibe and turns into an actual compliance question, because the answer isn't only PR risk. It's already written into the rules you work under. In Australia, the relevant clause sits inside APES 110, the profession's Code of Ethics:

"The circumstances in which a Firm or employing organisation seeks authorisation to use or disclose Confidential Information, include where the information is to be used for training purposes, in the development of products or technology, in research or as source material for industry or other benchmarking data or studies."

Read that back with a chatbot in mind. Pasting client data into a public AI tool without authorisation is, in the Code's own language, using confidential information "in the development of products or technology."

The US lands on the same conclusion by a different road. IRC 7216 makes it a federal offence for a tax preparer to disclose or use a client's tax return information without consent, and that covers feeding it into a third-party AI tool just as much as it covers selling a mailing list. Different code, different country, same answer: the client's data doesn't leave the engagement without their say-so.

Note

Neither rule was written with AI in mind, but neither needs updating to apply to it. "Confidential information" and "tax return information" don't care what the third party is.

What you can control

Accounting practices can't stop clients from using AI on their own data, but staff behaviour is a different story. This is the half of the problem you actually have leverage over, and most of the fix comes down to writing down what's already understood informally and making sure everyone's working from the same rules.

  • Name the tools that are actually approved, and say so in writing. If nobody's told staff "not the free tier of ChatGPT," someone will use it.
  • Spell out what can never be pasted in: client names, TFNs, account numbers, anything that identifies a real person or transaction.
  • Update engagement letters to cover AI use explicitly.
  • Assign someone to vet new AI tools before staff start using them informally.

None of this is complicated, and none of it requires new technology, just a policy that exists on paper instead of living in everyone's individual judgement. The harder problem is the one on the other side of the relationship, the part a policy can't reach.

Related: The future of accounting: Practical AI applications for productivity

What you can't fully control

A policy works because you can enforce it. You can require training, audit who's using what, and discipline someone who breaks the rules. None of that applies to a client sitting at their own kitchen table with their own return open in a browser tab.

Telling clients not to use AI is roughly as effective as telling them not to Google their symptoms before a doctor's appointment, and about as likely to be followed. However, you can still do a couple of things to mitigate the risks.

1. Say something before it comes up

A line in the engagement letter or the first client meeting, noting that AI tools can misread figures or miss context specific to their situation, costs nothing and means you're not starting from a defensive position when they arrive with a chatbot's opinion already formed.

2. Treat the AI-sourced question as useful information

If a client's pushing back on your advice because ChatGPT told them something different, that's usually a sign the original explanation didn't stick, and it's worth fixing the explanation rather than just correcting the AI.

Note

Neither of those closes the leak. What closes it, or at least narrows it, is giving clients somewhere better to put their information than a chatbot in the first place.

Content Snare: A safer place to share accounting client data

Is ChatGPT safe for accounting client data?

Content Snare is a secure client portal built for exactly this kind of exchange: instead of a client emailing a return back and forth or pasting a report into a chatbot to make sense of it, they get a single link, no login required, where documents move through an encrypted channel built for professional services.

It's ISO 27001 certified, uses military-grade encryption, and gives each firm its own per-company encryption keys, so client information stays inside a system built to hold it, not wherever a client happened to paste it. Here are a few Content Snare features that really stand out in this particular area:

  • Confidential fields: Sensitive answers stay hidden from view once submitted, and only unlock with a password when someone actually needs to see them
  • Instructions built into the request itself: Your clients don't need to guess what you're asking for or improvise an explanation elsewhere
  • Automated reminders: Nobody's chasing a client by email, which is often how sensitive documents end up loose in inboxes to begin with
  • Templates built for Australian accounting workflows: You don’t need to build a secure request from scratch, it’s easier to customise the existing form

Sydney-based NGR Accounting put it plainly when describing their own switch:

“What our clients like is that the documents are being uploaded safely. That’s really important from a cybersecurity perspective. You can email documents, but it’s not 100% safe. Uploading those documents to Content Snare gives us that extra security around personal information.”

None of this stops a client from opening ChatGPT on their own time. What it does is remove the reason they'd reach for it with your documents in the first place, because the easier and safer option is already sitting in their inbox.

Stop the improvising

Give clients a safer place to send their documents

Collect tax documents and sensitive information through one secure, ISO 27001 certified request, so nothing sensitive ends up in a chatbot or an inbox.

Start My Trial
Free trial
Stop chasing clients for documents
Content Snare automates the collection process so you can stop chasing and get back to work.
Start My Trial
About the author
Drazen Vujovic
Writer

Dražen Vujović is a journalist and content writer. More importantly, he is a father of two and a long-distance runner.

Explore

lockcrossmenuchevron-uparrow-right