This article sets out general principles for professional services firms. It is not legal advice, and it does not replace guidance from your regulator or your own advisers on your specific obligations.
Why is silence the riskier choice?
Many firms have drifted into using AI on client work without ever deciding whether to mention it. A proposal gets a first draft from a chat assistant. A long document is summarised before a fee earner reads it. A client letter is tidied by a writing tool. Nobody told the client, because nobody decided anything.
The trouble with silence is that it turns an ordinary working method into a secret. Clients can ask suppliers directly whether AI is involved in their work, and it is an obvious question for a procurement form or a panel review. If the honest answer is yes, and the client learns it from a form, a document property or a stray phrase in a draft rather than from you, the conversation is no longer about AI. It is about why you did not say.
Trust in professional services rests on the client believing they know how their work is done and who is responsible for it. Disclosure protects that. Concealment, even accidental concealment, undermines it.
What do professional duties require?
The useful starting point is that existing professional duties still apply, whatever tools are used. Bodies such as the SRA, ICAEW, ACCA, RICS and the FCA all hold firms to standards of competence, confidentiality, supervision and honesty with clients. None of those change because a draft was produced by software.
In practice that means four things. The firm remains fully responsible for the work, so output must be checked by someone competent to check it. Client confidential information must be protected, which means knowing where it goes when it enters a tool. Personal data must be handled lawfully under UK GDPR and the Data Protection Act 2018. And the firm must not mislead the client about how the work was done or what it cost to do.
Whether any of that amounts to a specific duty to disclose depends on your regulator, your sector and the work. That is a question for your own compliance function or advisers. The safer default, while the position settles, is to be open.
What should an engagement letter say?
An engagement letter or terms of business is the natural place to explain AI use, because it is where the client already expects to learn how the firm works. The wording does not need to be long. It needs to be accurate. Most firms will want to cover:
- That AI is used, and for what. For example, drafting routine correspondence, summarising documents or preparing first drafts of reports. Be specific enough to be meaningful, general enough to stay true as tools change.
- That a person is responsible. A named or identified person reviews and approves anything that goes to the client. AI drafts; people approve.
- What happens to the client's information. Whether it leaves the firm's own systems, whether any provider can use it to train their models, and that it is handled under the same confidentiality terms as any other supplier.
- How the client can raise concerns or ask that AI is not used on their matter.
If your firm is rebuilding how it produces engagement documents, scope documents and engagement letters covers how that wording can be held once and kept current, rather than edited by hand in every letter.
What about the client's own terms?
Disclosure runs in both directions. Larger clients often set their own rules for suppliers: outside counsel guidelines in legal work, supplier codes and data handling schedules elsewhere. Some restrict AI use entirely. Others permit it only with approved tools, or require notice before client information is processed.
Those terms override your default approach. Before AI touches a matter, someone needs to check whether the client has said anything about it, and the answer needs to reach everyone working on the file. A firm that tells clients it uses AI responsibly, then breaches a client's specific restriction because nobody read the panel terms, is in a worse position than one that said nothing.
What actually builds client trust?
Clients do not, on the whole, want to audit your tools. They want to know three things: that their information is safe, that a qualified person stands behind the work, and that they are not paying for effort that did not happen. Disclosure that answers those questions reassures. Disclosure that is vague or defensive worries.
The strongest position is being able to describe the process concretely. Not "we may use AI tools", but "first drafts of your monthly report are prepared from your records by a system we control, and every report is reviewed and signed off by your engagement manager before it is sent". That sentence is only honest if the process genuinely works that way, which is why the review step has to be built in rather than hoped for. Reviewing AI output on client work covers how to make that check reliable.
Firms that use consumer tools informally find this hard to describe, because there is no process to describe. Firms that have rebuilt a specific job, with defined inputs, controlled tools and a named reviewer, can explain it in a paragraph. That is one more reason to rebuild processes deliberately rather than let tool use spread on its own.
Where should a firm start?
Find out what AI use already happens on client work; the answers may surprise you. Write the internal rules first, using a guide such as writing an AI policy, then write the client-facing wording from those rules so the two cannot contradict each other. Check your data position against data protection and AI on client work. And take advice from your regulator's guidance or your own advisers before the wording goes into live terms.