Quick answer (updated August 2026): AI for professional services starts with a data rule, not a tool list. Small law, CPA, and agency firms should sort each task into three tiers before choosing software: no client data, confidential client data, and privileged or statutorily protected data. That decision determines whether a consumer, business, or zero-retention enterprise tool is appropriate.

Why client-confidential firms need a different playbook

Adoption is no longer the question. A U.S. Chamber of Commerce/Teneo survey of 3,870 small businesses found 58% used generative AI in 2025, up from 23% in 2023. But the Federal Reserve Banks’ 2025 Small Business Credit Survey (6,525 employer firms) found that while 46% of small firms use AI, just 7% of those users have fully integrated it. The gap is widest where client confidentiality is on the line.

A law firm, CPA practice, or agency is not a bakery with a chatbot. You hold information that courts, licensing boards, and client contracts require you to protect, and in February 2026 a federal court showed what happens when that information meets a consumer AI tool (more below). The answer is not to avoid AI. It is to decide, before you pick any tool, which data can touch which tier of tool. The general playbook is in our small-business AI guide; this article is the professional-services version, where the data gate comes first.

The 3-tier rule: what client data can touch which tool

Every AI decision in a professional firm reduces to one question: what is in the prompt? Classify the data first and the tool choice follows. Here is the whole rule at a glance.

Tier What is in the prompt Tool class that fits Setup requirements Example tasks
1: No client data Public law, templates, marketing, internal how-tos Consumer tools (free or ~$20/mo) None beyond common sense Draft a blog post, summarize a new regulation, build a checklist
2: Confidential client data, not privileged or statutorily covered Client names, matter facts, financials under NDA Business/team tiers Training off, defined retention, administrator controls, SSO Engagement letter assembly, intake summaries, billing narrative cleanup
3: Privileged or statutorily protected data Legal advice and strategy, tax return information, material nonpublic client data Enterprise or API deployments with zero data retention Written no-training and zero-retention commitments, counsel-reviewed contract Litigation strategy memos, tax workpaper analysis, due-diligence review

Tier 1: no client data, consumer tools are fine

If the prompt contains nothing a client gave you in confidence, a consumer chatbot is a fine tool. Drafting marketing copy, summarizing a published rule change, writing a job description, building internal templates: none of this implicates privilege or confidentiality rules. This matters because Tier 1 is where a firm should start practicing. Skills built on public-data tasks transfer directly to the gated tiers, and the St. Louis Fed found workers who use generative AI already report saving about 2.2 hours per week on average. The discipline to maintain: no client names, no matter facts, no numbers from a client file, ever, in a consumer tool. If a prompt would need redaction to be safe, it belongs in a higher tier.

Tier 2: confidential client data needs business tiers with training off

Most day-to-day client work sits here: information you must keep confidential under professional rules or contracts, but which is not privileged legal strategy or statutorily fenced tax data. The tool answer is a business or team tier where the vendor states your data is not used for training by default, retention is defined and controllable, and an administrator governs accounts. OpenAI’s published enterprise privacy commitments and Anthropic’s commercial terms both take training off the table for business customers; that is the floor, not a luxury. One caution for lawyers: the duty of confidentiality is broader than privilege and covers nearly everything about a representation, so when in doubt, treat the task as Tier 3. Two settings to verify before rollout: training toggled off where a toggle exists, and retention windows documented in writing.

Tier 3: privileged and covered data gets zero-retention only

Privileged communications, litigation strategy, tax return information, and material nonpublic client data get the strictest treatment: enterprise or API deployments where the vendor commits contractually to zero data retention and no training. These commitments exist and are published. Thomson Reuters states CoCounsel user content is not used to train its products or the underlying models, and Harvey states it does not use inputs, outputs, or uploaded documents to train models and requires zero data retention from its model providers. The reason this tier is non-negotiable became concrete in the New York Times litigation against OpenAI: a May 2025 preservation order swept consumer chat logs into a litigation hold, while by OpenAI’s own account zero-data-retention API traffic was never covered (the going-forward hold was lifted in October 2025). Retained data is discoverable data.

What United States v. Heppner changed (February 2026)

In United States v. Heppner, No. 25-cr-503 (S.D.N.Y. Feb. 2026), Judge Jed Rakoff held that documents a criminal defendant created by prompting the consumer version of Claude were protected by neither attorney-client privilege nor the work product doctrine. “Because Claude is not an attorney,” the court wrote, that alone disposed of the privilege claim. The court also found the chats were not confidential, because the consumer privacy policy allowed the vendor to collect inputs and outputs, use them for training, and disclose them to third parties. Sharing the outputs with his lawyer afterward did not rescue them.

Read carefully, the decision maps directly onto the tier rule: commentators, including White & Case’s April 2026 analysis, note that counsel-directed use of an enterprise-grade platform that bars retention and disclosure is far more likely to preserve protection. For the full legal-vertical treatment, see is ChatGPT safe for legal work.

The professional rules behind the tiers

Law firms: ABA Formal Opinion 512

The ABA’s Formal Opinion 512 (July 2024) is the anchor. Before putting information relating to a representation into a generative AI tool, lawyers must evaluate the risk that it will be disclosed to or accessed by outsiders. For self-learning tools that could expose client information through their outputs, informed client consent is required first, and the opinion warns that boilerplate consent buried in an engagement letter is not sufficient. On fees, the opinion is blunt: hourly lawyers “must bill for their actual time.” At least five state bars have added their own guidance as of mid-2026: California (2023) warns against putting confidential client information into tools lacking adequate protections, Florida’s Opinion 24-1 (2024) permits use with confidentiality safeguards and recommends informed consent, New York’s bar task force (2024) declined to mandate consent, D.C.’s Opinion 388 (2024) ties competence to understanding the technology, and Texas Opinion 705 (2025) requires protecting confidential information and verifying outputs.

CPA firms: AICPA 1.700.001 and tax-data gates

CPAs start from a stricter default than lawyers. The AICPA Confidential Client Information Rule (ET §1.700.001) provides that a member in public practice shall not disclose confidential client information without the client’s specific consent, and confidential means essentially everything not public. Feeding client financials into an AI vendor that retains or trains on inputs is plausibly a disclosure under that rule, before you even reach the separate federal restrictions on tax return information. The practical consequence: a CPA firm’s Tier 2 looks like other firms’ Tier 3. Client-identifying tax and financial data belongs in deployments with written no-training and retention commitments, with consent language handled in the engagement letter. Where AI shines for accountants right now is the words around the numbers: engagement letters, billing narratives, client memos, and workpaper summarization. The full data-gate treatment is in our AI for CPA firms guide.

Agencies: the contract is your bar rule

Marketing, design, and consulting agencies have no licensing board, but they signed the equivalent: NDAs, MSA confidentiality clauses, and increasingly client AI riders that restrict what vendor tools can touch client material. An unannounced product launch, a client’s customer list, or nonpublic financials in a consumer chatbot is a contract breach waiting for a discovery request. The same three tiers apply, driven by contract instead of statute. Public-facing creative work with no client confidential input is Tier 1. Work product containing client-confidential material is Tier 2 on a business tier with training off. Embargoed launches, M&A-adjacent work, and anything a client’s own policy restricts is Tier 3. Two agency-specific additions: check each client contract for AI-disclosure or consent clauses before onboarding a tool, and keep AI-generated drafts labeled internally so human authorship questions in deliverables are answerable later.

Five workflows where the hours are

Once the tiers are set, point the tools at the work that eats the most non-billable time. Five workflows show up in nearly every professional firm.

Workflow Typical tier What AI does well
Document drafting and review 2–3 First drafts, clause comparison, style cleanup
Engagement letters and proposals 2 Assembly from approved templates, scope language
Client intake and conflict checks 2 Structured intake summaries, name-sweep prep for conflicts
Research summarization 1–3 (depends on inputs) Condensing rules, cases, and guidance into memos
Billing narratives 2 Turning time entries into clear, client-ready descriptions

The evidence for the drafting-heavy rows is strong. A controlled experiment published in Science (Noy and Zhang, 2023, 453 college-educated professionals) found generative AI cut time on professional writing tasks by 40% while quality rose 18%. Intake deserves special attention in law: CallRail’s January 2025 analysis of 1.1 million business calls found law firms miss 28% of inbound calls, so pairing AI intake summaries with fixing phone coverage is often the higher-value move. Conflict checks and final documents stay human-reviewed in every case.

The math: what five hours a week is worth

Here is why professional firms have the clearest AI business case of any vertical we cover: the hourly rate makes the arithmetic legible. As an illustration, not a promised result: suppose one professional recovers 5 hours a week and bills at a realized $300 per hour. Counting only 48 working weeks, that is $72,000 a year of freed capacity (5 × $300 × 48) for one person. The measured baseline is smaller but real: the St. Louis Fed’s 2.2 hours per week is what average users report today, before any deliberate workflow redesign.

Two honesty rules keep the math clean. First, per ABA Formal Opinion 512, recovered time is not billable time; the gain shows up as more matters handled, faster turnaround, or better margins on flat-fee work. Second, count conservatively: round hours down, round tool costs up. A structured way to find where your firm’s hours actually hide is what an AI opportunity assessment is for. We sell no software and take no commissions, so the prescription is whatever the numbers support.

A model firm AI policy, sketched

Most firms need one page, not a binder. A workable policy has eight parts:

  1. Scope and tool inventory. Which AI tools are approved, at which tier, for whom. Everything else is unapproved by default.
  2. The data rule. The three tiers above, stated in one paragraph, with your firm’s examples.
  3. Client consent. When consent is required (self-learning tools for lawyers, confidential-information disclosure for CPAs, contract clauses for agencies) and where the approved language lives.
  4. Verification. No AI output reaches a client, court, or regulator without professional review. Name who signs off.
  5. Billing. Actual time only; AI-saved time is not billed.
  6. Settings baseline. Training off, documented retention, SSO or managed accounts, offboarding included.
  7. Shadow-AI amnesty. Staff are already using personal tools: MIT Project NANDA’s preliminary 2025 research (52 interviews, 153 leader surveys, 300+ deployments reviewed) found workers from over 90% of companies surveyed regularly used personal AI tools for work. Invite disclosure without penalty, then route those use cases to approved tools.
  8. Ownership and review. One named owner; policy reviewed on a set cadence as bar and AICPA guidance evolves.

Have your own counsel review the final policy; this sketch is a starting structure, not legal advice.

Bottom line

Bottom line: sort every AI task by what is in the prompt: no client data (Tier 1, consumer tools), confidential client data (Tier 2, business tiers with training off and controlled retention), privileged or statutorily covered data (Tier 3, zero-retention enterprise only). United States v. Heppner (S.D.N.Y. 2026) shows the cost of skipping the gate. Done right, the measured floor is about 2.2 recovered hours per professional per week, and 5 hours at $300 per hour is roughly $72,000 a year of capacity, as an illustration.

This article is general information for business owners, not legal advice, and does not address any specific matter. Consult your own counsel, state bar, or licensing authority before adopting AI tools that touch client data.

Sources

  • U.S. District Court, S.D.N.Y., United States v. Heppner, No. 25-cr-503 (JSR), opinion, February 2026: courtlistener.com
  • Harvard Law Review Blog, “United States v. Heppner,” 2026: harvardlawreview.org
  • White & Case, “Attorney-client privilege and work product in the age of generative AI,” 2026: whitecase.com
  • American Bar Association, Formal Opinion 512, “Generative Artificial Intelligence Tools,” 2024: americanbar.org
  • AICPA, Code of Professional Conduct, ET §1.700.001: pub.aicpa.org
  • State Bar of California, COPRAC Practical Guidance on Generative AI, 2023: calbar.ca.gov; The Florida Bar, Ethics Opinion 24-1, 2024: floridabar.org; NYSBA AI Task Force Report, 2024: nysba.org; D.C. Bar, Ethics Opinion 388, 2024: dcbar.org; State Bar of Texas, Opinion 705, 2025: legalethicstexas.com
  • Federal Reserve Banks, 2026 Report on Employer Firms (2025 Small Business Credit Survey), 2026: fedsmallbusiness.org
  • U.S. Chamber of Commerce / Teneo Research, Empowering Small Business, 2025: uschamber.com
  • CallRail, From Conversations to Conversions, 2025: callrail.com
  • Federal Reserve Bank of St. Louis, “The Impact of Generative AI on Work Productivity,” 2025: stlouisfed.org
  • Noy & Zhang, “Experimental evidence on the productivity effects of generative artificial intelligence,” Science, 2023: pubmed.ncbi.nlm.nih.gov
  • MIT Project NANDA, The GenAI Divide: State of AI in Business 2025 (preliminary), 2025: report PDF
  • OpenAI, “Enterprise privacy at OpenAI,” 2026: openai.com; OpenAI, “How we’re responding to The New York Times’ data demands,” 2025: openai.com
  • Anthropic, Commercial Terms of Service, 2025: anthropic.com
  • Thomson Reuters, CoCounsel security FAQ, 2026: thomsonreuters.com; Harvey, “Security,” 2026: harvey.ai