STRATEDGE CONSULTING

Compliance and legal7 min read

Lawyers, notaries, accountants: using AI without breaching professional secrecy

What a law firm, notary office or accounting practice can do with AI without exposing client files: framework, architecture, permitted uses, usage charter.

Valentin Petitclerc · Published on September 1, 2026, updated on September 7, 2026

Regulated professions cannot paste a client file into a consumer AI tool. But they should not give up on AI either: their competitors are not giving up. The question of AI and professional secrecy is not a question of prohibition; it is a question of architecture and written rules. Between controlled hosting, compartmentalisation, pseudonymisation and a usage charter, here are the concrete rules we apply with the law firms, notary offices and accounting practices we equip.

The real risk behind consumer tools

The risk is not AI: it is copy-paste. A rushed associate pastes three pages of a client file into a consumer tool to "save time". At that instant, data covered by professional secrecy has left the firm, towards a service whose terms of use, server location and retention policy nobody has read.

Depending on the tool and its settings, that content may be retained, reviewed for moderation, sometimes used to improve models. The problem is not that a competitor reads it tomorrow; it is that the firm has lost control, and can no longer answer a client honestly when asked: "where is my data?"

Banning solves nothing: usage goes underground, and therefore invisible. We have seen firms where AI was "forbidden" and half the staff used it on their personal phones. The only serious answer is to provide a framework and tools that make the right move easier than the wrong one.

The framework: GDPR, the AI Act and professional duty

Three layers stack up, and they must be distinguished to avoid mixing everything.

LayerWhat it concretely requiresWho supervises
GDPRMinimisation, legal basis, a processing agreement (article 28) with every provider that touches the data, a register of processing, an impact assessment when the risk justifies itData protection authority
European AI ActAI literacy for staff since February 2025, transparency on generated content, reinforced obligations for high-risk usesNational authorities, European Commission
Professional dutySecrecy applies whatever the channel: email, phone, AI assistant. No "convenient tool" exceptionBar, chamber, professional body

GDPR first: process only what is necessary, have a clear legal basis, and sign an article 28 processing agreement with every provider that touches the data. A tool whose publisher refuses that agreement is not a tool for a firm.

The European AI Act next. For a firm, the most immediate obligation is literacy: staff who use AI systems must be trained on their limits. Then comes the ability to list your use cases and qualify their risk.

Professional duty last, and it is the strictest layer: professional secrecy has no "convenient tool" exception. Which is why the question to ask of every tool is not "does it perform?" but "can I demonstrate that secrecy survives it?"

The good news: the three layers converge on the same practical requirements, controlled hosting, compartmentalised access, traceability, human review. One architecture can satisfy all three.

An architecture that protects client files

What we install in firms rests on five principles.

  1. Hosting in the European Union, with providers under processing agreements, and models accessed through professional interfaces whose terms exclude training on your data.
  2. Compartmentalisation by file. An AI agent working on file A never sees file B, and access follows the firm's existing permissions: a staff member sees in the AI only what they already see in the case management system.
  3. Pseudonymisation before processing whenever the case allows. The AI reasons about "Mr X, employed since 2019", not about civil identities. Identities are reinserted in the final document, on the firm's side.
  4. Logging. Every processing step is dated, attributed, findable. That is what lets you answer a client or an audit without improvising.
  5. No client data ever trains a model, full stop. This is verified in the contract, not in the brochure.

And one rule across everything: human review before anything leaves the firm. AI prepares, a human signs. Our AI agents are built with this mandatory validation point on every sensitive decision.

Use cases that pass, and those that do not

Pass, inside the framework aboveDo not pass
Summarising large sets of documents to prepare a meetingPasting an identifiable client file into a consumer tool, whatever the goal
Drafting recurring letters and deeds from the firm's own templatesLetting AI issue an opinion that reaches the client without review
Research on public sources (statutes, case law, doctrine)Wiring an agent to the firm's inbox with no compartmentalisation
Sorting and prioritising incoming requestsUsing a free tool whose business model is the exploitation of your data
Transcribing and summarising internal meetingsRecording a client meeting without information or consent
Consistency checks on a deed (dates, amounts, names) before signatureEntrusting AI with a procedural deadline calculation without verification

In between lies a grey zone every firm must settle in writing: that is the role of the usage charter, a one-page document everyone signs, which replaces case-by-case debates.

The one-page usage charter

A good charter fits on one page and answers 6 questions.

  • Which tools are allowed, and which are forbidden, by name.
  • Which data may enter them: nothing identifiable outside compartmentalised tools, never an identity document, never health data outside a framework.
  • Who validates what goes out: the rule "AI prepares, a human signs" in black and white.
  • How the client is informed, when necessary, and with which wording.
  • What to do in case of an error or a leak: whom to notify, within what delay, which trace to keep.
  • How the charter evolves: a review every quarter, because tools change fast.

We provide this template in our one-day AI training, adapted to the firm's practice, with exercises on your own types of files.

Where to start without taking a risk

Start with an honest inventory: who already uses what, officially and unofficially. That diagnostic takes a few days and always surprises. Then set the usage charter, and equip one pilot use case, compartmentalised and measured: often file summarisation or the preparation of one recurring type of deed.

Train teams on their real files rather than generic examples, then measure: hours saved per week, shortened turnaround, rework rate. After a quarter, the numbers decide what comes next, not convictions.

StepIndicative durationDeliverable
Inventory of usesA few daysList of tools actually used, risks ranked
Usage charterOne weekOne-page document signed by the team
First compartmentalised agent2 to 3 weeksOne process in production, action log, human validation
Training on real filesOne dayPractice-specific prompt library, written framework
Measurement at one quarterOngoingHours saved, turnaround, rework

That is exactly the path we follow with the firms we equip, described on our page for regulated professions.

Questions to ask any AI vendor

Before a firm adopts a tool, the vendor should answer these questions in writing. The answers belong in the contract, not in a sales deck.

  1. Where is the data processed and stored, and can you name the hosting providers?
  2. Is our data used to train or improve your models, and is that exclusion written in the contract?
  3. How long are prompts, documents and outputs retained, and can retention be set to zero?
  4. Will you sign a processing agreement under article 28 of GDPR, and who are your sub-processors?
  5. Can access be restricted per file or per user, following our existing permissions?
  6. Is every processing step logged, and can we export those logs?
  7. Who at your company can read our content, under which conditions, and is that logged too?
  8. What happens to our data when we terminate, and within what delay is it deleted?
  9. Have you documented how your product fits the European AI Act, including transparency obligations?
  10. Can you provide references from firms subject to professional secrecy in our jurisdiction?

A vendor who answers all ten clearly is a vendor a firm can work with. A vendor who answers "it depends on the plan" to question two is not.

Frequently asked questions

When AI processes their personal data, information about processing and processors falls under GDPR. Beyond that, a clear mention in the engagement letter reassures and avoids misunderstandings. Nothing requires hiding it, everything argues for saying it simply.

Sources and references

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence
  2. CNIL, artificial intelligence: recommendations and practical guidance

TopicsProfessional secrecyLaw firmsGDPRAI agentsProfessional duty

ShareLinkedInEmail
Valentin Petitclerc

The author

Valentin Petitclerc

Founder of Stratedge Consulting, a custom digital systems agency in Paris and Lyon. More than 250 clients since 2022: law firms and notaries, SMEs, startups, groups. Written from what the team ships in the field.

LinkedIn

Apply this in your company

A 30-minute video call with a founder to look at your situation, then, if it helps, an Express Diagnostic at €500 excl. VAT, credited against the next step.

Book a discovery video call