Skip to main content

Industry

Agents and Client Confidentiality in a Professional Services Firm

How a law, audit or consulting firm keeps matter level separation when one AI agent serves several clients, and what belongs in the engagement letter.

Written by Sicherhaven

Your firm acts for two companies in the same sector. One agent helps both teams draft documents. A partner asks the obvious question: what stops something from client A showing up in work for client B?

The short answer for client confidentiality with AI agents is that separation has to live in the retrieval layer, not in the model's manners. An agent should be scoped to one matter at a time, with the record set it can read fixed before the request runs, so there is no route by which client B's context can reach a client A answer even if someone asks for it.

Where the leak actually happens

People worry about the wrong thing first. The common fear is that a model memorises one client's data during use and repeats it later. With a private model you run yourself, that is a training question you control, and you simply do not train on client material.

The realistic leak is duller. It is retrieval. An agent that answers a question by searching across everything the firm holds will happily pull a precedent, a template, a fee note or a set of assumptions from a matter the asking team has no right to see. Nothing is remembered. Something is fetched. Tracing every place a copy appears when an agent reads a record makes that easier to see.

The second realistic leak is drafts. A summary written for one client sits in a shared folder because that was the fastest place to save it. The agent indexes the folder. Now the summary is a source.

Scoping by matter, not by person

Most firms already have matter level access rules for people. Extending them to agents is the whole job, with one change in emphasis.

For a person, permissions are a fence. They can see the folder or they cannot. For an agent, permissions need to be a fence and a shortlist. The agent should not merely be blocked from reading other matters, it should be told which matter this request belongs to before it starts, and search only there.

The difference matters because agents are good at finding things. A person who lacks context gives up. An agent with a broad index and a vague brief goes looking, and the wider the index, the more likely it turns up something adjacent and useful and forbidden.

Practical shape:

  • Every agent request carries a matter identifier. No identifier, no run.
  • The searchable set is derived from that identifier, not from the user's full entitlements.
  • Firm wide material that is genuinely shareable, such as house style, standard clauses and jurisdiction notes, sits in its own store that any matter may read.
  • Anything client specific lives only under its matter.

Conflicts and information barriers

If your firm operates information barriers, an agent is a new hole in them unless it is treated as a party to the barrier. That means the barrier list controls agent scope as well as human scope, and the agent's activity is visible to whoever monitors the barrier.

Worth stating plainly to whoever owns risk in your firm: an agent that can read across barriered matters is a barrier failure whether or not anything leaks. The exposure is in the capability, not only in the incident.

Rules on conflicts, privilege and client consent vary by jurisdiction and by regulator, and professional bodies are still publishing guidance. Take the specifics to your own compliance function rather than a blog post. Regulated clients ask much the same things themselves, as a bank's questions before an agent touches customer records show.

What to write into engagement letters

Clients increasingly ask, and the ones who do not ask will ask later. It is easier to have language ready than to retrofit it.

Points worth covering, subject to your own legal advice:

  • That the firm may use AI tools in delivering the engagement, described in general terms rather than by product name, so the letter does not go stale.
  • Where client material is processed and stored, and whether it leaves the firm's control.
  • That client material is not used to train models.
  • That output is reviewed by a qualified person before it reaches the client.
  • Who is responsible for the work. This should be the same answer as before, which is the firm.
  • Any right the client has to object, and what happens if they do.

Keeping the record

If a dispute arrives, the useful evidence is a log showing which matter each agent run was scoped to, what it read, what it produced, and who approved it. That log needs to survive longer than the matter, because complaints tend to arrive later than the work.

SicherOne is built around agents working on one shared set of records with a human approving output before it ships, and private models can be self hosted, which is often the deciding factor for firms that cannot send client material to an outside service. The trade offs between self hosted and vendor hosted models are worth walking through with whoever owns compliance. The scoping and barrier decisions above are still your firm's to make. The tooling can enforce them, but it cannot decide where your walls go.

The honest summary

Confidentiality with agents is not a new discipline. It is your existing matter separation, applied to something that searches faster and more literally than any junior ever did. Get the scoping right and most of the rest follows. Leave it broad and no amount of careful prompting will save you.

← All posts

We're building the future of community events and financial wellness

See how Eventify and WealthWise change the way people find events and manage money.

Get Started