Guy Pavlov

Client data and AI tools: seven checks before you sign up

I am not a lawyer. These are the checks I make before a tool touches client work:

  1. An approved-tools list, using business tiers where training on your data is off by contract.
  2. Retention and deletion settings, and where the data is stored.
  3. Access: the tool sees only what that person should see, and a person approves anything sent, paid, or deleted.
  4. Disclosure when people are talking to AI, where the EU transparency rule applies. That rule has applied since 2 August 2026.
  5. A one-page acceptable-use policy and short training, which also covers the AI-literacy duty.
  6. Inputs for a data protection impact assessment where health, legal, or other sensitive data is involved.
  7. A list of questions for your lawyer.

Where PIPEDA or Quebec Law 25 applies, I run the same checks against those rules, including Law 25 on automated decisions.

The Digital Omnibus on AI, Regulation (EU) 2026/1744, came into force on 27 July 2026. High-risk obligations are delayed to 2 December 2027 for stand-alone systems and 2 August 2028 for systems built into products. For a small firm, the transparency rule and the AI-literacy duty are the parts that matter now.