Why most AI policies stall
Someone senior asks whether the team can use AI on client work. The answer comes back as a question: is the material confidential?
And there the conversation dies, because in a professional firm almost everything feels confidential. A blanket yes is reckless. A blanket no is ignored within a month, because people quietly paste things into a chat window anyway and nobody hears about it until something goes wrong.
The failure is in the question. “Is this confidential” is not decidable. What follows is a set of questions that are.
The five questions
Run any document type through these. If you answer no to all five, it can almost certainly go to a cloud AI service under a normal enterprise agreement. If you answer yes to two or more, it belongs in an environment you control.
1. Does it contain material belonging to someone who has not agreed to this?
Client files, candidate applications, patient records, supplier contracts. The person who owns the confidentiality is usually not the person deciding to paste it into a tool. That asymmetry is the whole issue, and it is not resolved by the tool being secure.
2. Would we have to disclose it if we were asked where it was processed?
Some engagement letters, professional standards and regulatory regimes require you to be able to answer that question. “On that machine, in that room” is an easier answer to give than one that depends on a contract clause and a region setting.
3. Does it reveal how we work, rather than what we produced?
Firms guard their outputs and casually expose their methods. Internal checklists, pricing logic, review criteria, escalation rules and templates are frequently the most commercially valuable material in the building, and they are exactly what gets pasted into a chat window to make a task faster.
4. Would a competitor learn something material from it?
Deal pipelines, pricing structures, unpublished research, strategy papers, board material. Not usually regulated, often more damaging than the material that is.
5. Does it involve a person who could be harmed by it being seen?
Grievance notes, performance records, safeguarding matters, medical information, immigration paperwork. The consequence lands on someone who never chose to be part of the decision.
The worked list
This is the pattern in most professional and advisory firms. Your list will differ, and it should be written down rather than assumed.
| Document type | Usual call | Why |
|---|---|---|
| Published marketing material | Cloud | Already public |
| General research and background reading | Cloud | Nothing proprietary |
| First drafts of internal, non-sensitive writing | Cloud | Low stakes, high volume |
| Anonymised or synthetic data for testing | Cloud | The identifying material is gone |
| Client onboarding and identity files | Keep it in | Belongs to someone else, often regulated |
| Beneficial ownership structures | Keep it in | Both confidential and regulated |
| Audit working papers | Keep it in | Professional standards, disclosure exposure |
| Payroll and HR records | Keep it in | Individuals who did not choose this |
| Board papers and strategy | Keep it in | Competitive harm |
| Draft contracts under negotiation | Keep it in | Belongs to a counterparty as well as to you |
| Internal SOPs, checklists, pricing logic | Keep it in | Your method is the asset |
| Meeting recordings involving clients or staff | Keep it in | Consent rarely covers this |
The question this is not
This is not an argument that cloud AI providers are unsafe. They are not, and enterprise agreements from serious providers offer meaningful contractual protection, dedicated capacity and no-training commitments.
The better framing is the one that survives contact with a sceptical audience: the question is not whether cloud enterprise AI is insecure. The question is whether every company workflow should have to leave the company’s environment in order to use AI.
For a large share of workflows, the answer is that it is perfectly fine. For the ones on the right-hand column above, the answer is usually that it is unnecessary, and unnecessary exposure is difficult to justify after the fact.
What to do with the “keep it in” pile
Having a list is not a policy. Three moves turn it into one.
Give people a route, not just a rule. A prohibition without an alternative produces quiet non-compliance. If the onboarding team cannot use the cloud assistant, they need something that does the job in an environment you control, or they will use the cloud assistant anyway.
Start with one process, not the whole list. Take the single most expensive item, map it end to end, and prove the value there before extending. Cases per year, multiplied by hours per case, multiplied by a loaded hourly cost, gives you the number the project should be measured against. It is usually far more interesting than any software price.
Keep a human at the decision points. Nothing in the right-hand column should be fully automated. AI assists these workflows; it does not replace the professional judgement that signs them off. Exceptions should route to a person by design, not by accident.
Six questions worth asking any AI vendor
A vendor with a clear architecture will answer all six without hesitating.
- Where exactly is inference processed in the deployment you are proposing? Ask them to name the machine.
- Which specific workflows run in that mode, and which do not? Most platforms have exceptions, and the exceptions are the answer.
- What is the cost when usage triples?
- What stops working if our internet connection drops?
- Who administers users, and what happens when someone leaves?
- What did you have to say no to in the last twelve months? A vendor who cannot name a workload they turned down has not been asked hard questions yet.
Where Estha for Mac fits
Estha for Mac is built for the right-hand column. It is a private AI platform for Apple Silicon where AI inference runs locally on your Mac, either on a single machine or on a Mac on the local network that colleagues connect to. For supported workflows, the document does not need to be sent to an outside AI service to be processed.
It is deliberately not an argument for moving everything. Firms that run a cloud assistant for general drafting and something local for client files are in a sensible position, and that is the pattern we see most often. Use each where it fits.
Frequently asked questions
Can I use ChatGPT for confidential documents?
For general, non-sensitive work, many organisations reasonably do, particularly under an enterprise agreement with no-training commitments. The harder cases are documents belonging to clients, candidates or employees, material covered by professional standards, and anything where you may be asked to state where processing occurred. Those are usually better handled in an environment you control, and the decision should be made per document type rather than once for the whole firm.
Which documents should not go to cloud AI?
In most professional firms: client identity and onboarding files, beneficial ownership records, audit working papers, payroll and HR records, board and strategy material, contracts under negotiation, internal methods and pricing logic, and recordings of client or staff meetings.
Is it against the rules to use AI on client work?
That depends on your jurisdiction, your regulator, your professional body and your engagement letters, and it is a question for your own compliance function rather than for a vendor. What is generally true is that being able to state where processing happened makes the question much easier to answer.
How do I write an AI policy that people will actually follow?
Make it decidable and give people a route. A list of document types with a clear call for each beats a principle that requires judgement in the moment, and every prohibition needs a sanctioned alternative or it will be quietly ignored.
Is a private cloud enough?
It depends which question you are answering. Dedicated capacity in a provider’s data centre is a genuine improvement on a shared consumer service and satisfies many contractual concerns. It does not change the physical fact that the document leaves your building. If your concern is contractual, private cloud usually answers it. If your concern is physical, it does not.
Start with one process
If you can name a single workflow that is expensive, repetitive and sits in the right-hand column, that is the one worth mapping first. We start with the workflow, not the software.
One email a month on private AI. For people who cannot put their work in the cloud. No spam, unsubscribe anytime.


