A workable AI use policy for a consulting firm fits on a page and answers one question per data class: which AI tool tier, if any, may process it. The load-bearing rule is that client-confidential data may only be sent to AI with the client's written authorization — or through an architecture where the model never receives the confidential values at all. The template below is free to copy; adapt the bracketed parts to your firm.
Why a permissioned policy beats a ban
The evidence is consistent: employees adopt AI faster than employers approve it, and most hide it. A blanket ban doesn't remove the usage — it removes your visibility of the usage, pushing it onto personal devices and consumer tools, which is the most expensive place a breach can happen. A short permissioned policy — "these tools are fine for this data; client-confidential data follows this rule" — governs the behavior that's already occurring instead of pretending it isn't.
The template
Copy the sections below into your firm's document system. Replace bracketed text; delete what doesn't apply. Keep it to one or two pages — a policy people can't remember isn't one they'll follow.
1. Purpose
"[Firm] supports the use of AI to do better work faster. This policy sets out how to do that without breaching client confidentiality, privacy law, or our professional obligations. It applies to everyone who handles client or firm data."
2. Data classes
Sort information into these classes; when in doubt, treat it as the stricter one.
- Public — published, non-confidential, or fully synthetic.
- Firm-internal — your own non-client material (methods, templates, internal notes).
- Client-confidential — anything covered by an NDA or engagement terms: client data, unpublished results, pricing, strategy, the client's identity where confidential. Removing names does not move data out of this class.
- Regulated personal data — PII/PHI subject to HIPAA, GDPR, PIPEDA, Law 25.
3. Tool tiers
| Tier | Examples | What it protects |
|---|---|---|
| A · Public AI | Consumer ChatGPT, free chatbots | Nothing — assume anything entered is disclosed |
| B · Enterprise AI | ChatGPT Enterprise, Copilot, Claude for Enterprise (firm-licensed), with a signed BAA, advanced auditability and privacy certification | Vendor-side: no-training, retention controls — protects the firm↔vendor relationship |
| C · Cloaked / architectural | Tools where confidential values are removed on-device before the model sees them | The value itself — the model never receives it, so no disclosure occurs |
4. The rules
- Public data — not just any tier. Out of respect for the client relationship and to maintain traceability, we use enterprise-grade AI even for public data.
- Firm-internal data — Tier B or C. Not Tier A.
- Client-confidential data — Tier C by default. Tier B only with the client's written authorization for that specific system. Never Tier A.
- Regulated personal data — Tier C, and only where the relevant privacy law and any data-processing agreement allow it.
- Always: a human reviews AI output before it reaches a client; AI involvement is disclosed where the client or a regulator expects it. Complete audits — including exchanges with the AI and the protected values — are always available on request, and traceability and auditability are maintained for 7 years in line with regulated-industry standards.
5. Records
"For client deliverables, keep a record of material AI assistance sufficient to explain it later — which tool tier, and for Tier C, the audit trail the tool produces. We keep client authorizations (for Tier B on client-confidential data) with the engagement file."
6. Owner & review
"This policy is owned by [name/role] and reviewed every [6/12] months, or when a major tool or regulation changes. Questions and exceptions go to [contact]."
Adapting it
The one line not to soften is the client-confidential rule. Everything else can flex to your firm's risk appetite, but "enterprise licence ≠ client consent" is a legal reality, not a stylistic choice — it's the gap that turns an approved tool into an unapproved disclosure. If most of your work is client-confidential, Tier C is not an edge case; it's the main path, and the policy should read that way.
Frequently asked questions
Does a consulting firm need an AI use policy?
Yes. Employees are already using AI — surveys put concealed use above 50% — so the choice is between an explicit policy and an unwritten one enforced by individual judgment. A short, practical policy that tells people which tools are allowed for which data prevents both reckless use and blanket bans that push usage underground.
What should an AI use policy for consultants cover?
At minimum: which data classes may go into which tool tier; the rule that client-confidential data requires either client authorization or an architecture where the model never receives it; a prohibition on public/consumer AI for any client data; a record-keeping expectation; and a named owner. It should be one or two pages, not a manual.
Can we just ban AI instead?
A ban is a policy, but usually an ineffective one: it doesn't stop use, it stops disclosure of use. The measurable outcome of blanket bans is shadow AI on personal devices, which carries the highest breach cost. A permissioned policy — clear allowed tiers — protects confidentiality better than a prohibition nobody follows.
How does this template handle client NDAs?
It treats client-confidential data as its own tier with a hard rule: it may only be processed by AI when the client has authorized the specific system in writing, or when the confidential values never reach the model (client-side cloaking). This mirrors the legal reality that enterprise AI terms bind the vendor to you, not you to your client. However you proceed, use the data safely and make sure you have auditability and traceability — your relationship and reputation depend on it.
This guide is general information about how AI tools interact with confidentiality obligations. It is not legal advice, and it does not create any professional relationship. Confidentiality agreements vary — review your own agreements with qualified counsel before relying on any framework described here.
Work with AI on data you can't share with it.
Untraceable cloaks confidential values on your computer before any AI model sees the text — the model never receives the secret at all.