Learn · External AI Collaboration

Can clients use their own AI with your data?

Short answer. They can, safely, if you share a defined portion of the information through an access layer that decides what their AI may retrieve. Sending files or opening your workspace to a client’s AI gives up that control; sharing a governed projection keeps it.

Last reviewed 24 September 2026

The situation

Your clients increasingly use AI themselves. A finance director might ask Claude to summarise the accounts you prepared. A business owner might ask ChatGPT which records they still owe you. They would like their AI to work with the information you hold for them, rather than copying and pasting from emails and PDFs.

That is a reasonable request. The question is how to allow it without handing over more than you intend.

Three ways it happens today

  1. Files by email or download. The client uploads your PDFs into their AI. Simple, but once sent you have no control over what happens next, and files go stale.
  2. Access to your systems. The client is given a login to a shared folder, portal or practice system, and connects their AI to it. The AI may then see whatever that login can see, which is often more than intended.
  3. A governed share. You define exactly what the client may see and do, and their AI connects to that share. Everything else stays out of reach.

The third approach is the one that scales, especially for professional firms that hold information about many clients side by side.

What a governed share needs

  • A defined portion of the record. Approved accounts, client documents, outstanding requests and deadlines, but not internal notes, risk assessments or profitability.
  • An identity for the guest. The client, and their AI, should be identifiable principals, not an anonymous link.
  • Defined actions. Perhaps the client’s AI may upload documents or respond to a request, but may not change anything else.
  • Expiry and revocation. Access should end when the engagement ends, or sooner if needed.
  • A record. You should be able to see what was retrieved and when.

What you cannot control

Once information reaches the client’s AI, it is subject to the client’s AI provider and the client’s own settings. You cannot recall information that has already been retrieved. That is why the portion you share should contain only what the client needs, and why confidential or third-party information should be kept out of it entirely.

Questions to settle first

  • Does your engagement letter or terms of business say anything about how clients may process the information you provide?
  • Is anything in the shared portion about someone other than the client?
  • Who at your firm decides what goes into the client’s view, and who approves changes?
  • How will you respond if a client asks their AI for something outside the share?

How Kroy approaches it

In Kroy a client is a guest: a first-class principal with its own identity, permissions, expiry and audit trail. You share a projection of the client’s record, not your workspace. The client can use Kroy directly or connect their own Claude, ChatGPT or another supported AI. Their AI receives only what the projection allows, and a request for your internal notes is refused and recorded. Share with a person, an organisation or the AI they already use.