Guy Pavlov
Client data and AI tools: seven checks before you sign up
I am not a lawyer. These are the checks I make before a tool touches client work:
- An approved-tools list, using business tiers where training on your data is off by contract.
- Retention and deletion settings, and where the data is stored.
- Access: the tool sees only what that person should see, and a person approves anything sent, paid, or deleted.
- Disclosure when people are talking to AI, where the EU transparency rule applies. That rule has applied since 2 August 2026.
- A one-page acceptable-use policy and short training, which also covers the AI-literacy duty.
- Inputs for a data protection impact assessment where health, legal, or other sensitive data is involved.
- A list of questions for your lawyer.
Where PIPEDA or Quebec Law 25 applies, I run the same checks against those rules, including Law 25 on automated decisions.
The Digital Omnibus on AI, Regulation (EU) 2026/1744, came into force on 27 July 2026. High-risk obligations are delayed to 2 December 2027 for stand-alone systems and 2 August 2028 for systems built into products. For a small firm, the transparency rule and the AI-literacy duty are the parts that matter now.