Why does the IT provider answer a different question from the one you asked?

A firm of twenty to two hundred people rarely has its own head of IT. It has a managed service provider who looks after laptops, mailboxes, backups, patching and the occasional disaster. That relationship works well for what it was set up to do. It was not set up to decide how your firm handles privileged client information inside a new category of software.

So when a partner asks "is it safe to use AI on client files?", the provider hears a technical question and gives a technical answer: the tenancy is secure, the data is encrypted, nothing leaves the platform. All of that may be true and still leave your real question untouched. The real question is who can see what, what is kept, for how long, and whether you could prove any of it to a client who asked.

The questions below are the ones worth putting in an email, with a request for written answers. Written answers can be filed, quoted and relied on. A helpdesk conversation cannot.

Where does the data actually go?

Start with the plumbing, because every other answer depends on it.

  • When someone uses an AI feature in our environment, which company processes that content, and in which country is it processed?
  • Which sub-processors are involved, and where is the current list published?
  • Is any of our content used to train or improve a model, by anyone in the chain? Which clause says so?
  • Are prompts and outputs retained, and for how long? Can we see them, export them or delete them?
  • Does any of this change between the licence tiers we hold? Some protections apply to one plan and not another.

That last point catches people out. Firms often hold a mix of licences across the team, and the terms that apply to a fee earner's account may not be the terms that apply to a support colleague's. If the provider cannot tell you which protections attach to which seat, nobody in the firm can give a client a straight answer either. Our guide to data protection in AI client work sets out how these answers map onto your obligations as a controller.

Who can see what once AI starts searching the files?

This is the question that matters most and gets asked least. An assistant that searches across your document store does not create new access. It surfaces what a user technically had access to all along and never found. In most firms, technical permissions are looser than the confidentiality the firm actually practises. A folder was opened to the wider team during a busy month and never closed. An old matter sits in a shared area. Nobody noticed, because nobody went looking.

Ask directly:

  • Does the AI respect our existing file and mailbox permissions exactly, with no exceptions?
  • Can it reach shared mailboxes, archived sites, chat history or recorded meetings?
  • How do we test what a specific user can retrieve, before we switch this on for everyone?
  • If we need information barriers between teams working on opposing sides, how are those enforced in the AI layer?

Run the test with a real account, not a demonstration account. Pick one person from each team and ask the assistant for something it should not be able to find. The results of that test tell you more about your readiness than any supplier briefing.

Can we prove afterwards what happened?

At some point a client, an insurer or a regulator will ask a version of this question: was our information put through an AI tool, and can you show us. You need to be able to answer with records rather than recollection.

Ask what is logged, who can read the logs, how long they are kept and whether you can get them out without raising a support ticket every time. Ask whether the logs record which documents were used to answer a prompt, not just that a prompt happened. Ask whether an administrator can view the content of individual prompts, because if they can, that is a confidentiality consideration of its own inside your firm.

Your professional indemnity insurer is likely to ask about supervision and records before it asks about the technology. Firms that have the evidence to hand have a much shorter conversation.

Who turned this on, and what happens next time a default changes?

Ask which AI features are already active in your environment today. Many firms find that the answer is more than they expected, because features arrive switched on with a platform update and nobody is watching the release notes. Then ask the follow-up: what is your process for telling us before a new AI capability becomes available to our staff, and can we require that nothing is enabled without our sign-off?

Ask what the provider can and cannot block. They can usually control what runs on a managed laptop. They cannot stop someone pasting a draft into a personal account on their phone. That gap is where shadow AI lives, and it is closed by a clear policy and a better official option, not by a firewall rule. If you have not written the policy yet, start with our guide to writing an AI policy.

Where does their responsibility end and yours begin?

Be explicit about this, in writing, before anything goes live. The provider is responsible for configuration, access control and the terms of the platforms they resell to you. The firm remains responsible for deciding what client work may touch these tools, for supervising the output and for the advice that leaves the building. A named person signs off anything that goes to a client. No IT contract transfers that.

It also helps to say plainly what you are not asking them to do. An IT provider is not the right party to choose which of your processes should be rebuilt, or to redesign how a report gets written. That is a question about how the work flows, not about which licence to buy, which is the point we make in a tool is not a process. Firms that do run their own managed services will recognise the distinction immediately: see IT and managed services.

What do you do with the answers?

File them, date them and review them when the contract renews. They become the evidence base for three separate conversations: the policy you give your own team, the answer you give a client who asks how their information is handled, and the renewal form your insurer sends you.

They also change what you say to clients. A firm that can describe its controls in two sentences is in a far stronger position than one that avoids the subject, which is the argument in telling clients you use AI.

Then come back to the point of all this. Controls make AI safe to use. They do not make it useful. Usefulness comes from picking the one job that eats the week and rebuilding it, which is what the audit is for. Ten questions, about three minutes, and it names the process to tackle first.