Professional services firms may have more to gain from AI than almost any other kind of organization. Law firms, accounting practices, consultancies, engineering and architecture firms: their product is largely knowledge turned into documents, and that’s precisely what current AI tools are good at. The same firms also carry some of the strongest obligations about how client information is handled. That combination makes AI readiness in professional services a question of speed with care, rather than one or the other.
This post covers what’s different for professional services firms, the specific risks to address before AI touches client work, and where firms tend to find value first. As with any professional obligations question, your firm’s general counsel, ethics partner, or risk leader has the final word on what applies.
What’s different about professional services
- Client confidentiality is the product. Clients share information because they trust it stays within the engagement. A leak doesn’t just create legal exposure; it damages the reason clients hire you.
- Engagements are walled off from each other. Many firms maintain information barriers, often called ethical walls, between teams working for different clients or on conflicting matters.
- Clients set their own rules. Engagement letters, NDAs, and client guidelines may restrict how client information can be processed, and some clients now address AI use directly.
- Professional standards apply to the output. A professional signs off on the work, whatever tool helped produce it.
- The business model is often time-based. If AI makes work faster, hourly billing raises questions about pricing that other industries don’t face in the same way.
The risks to address first
Client information in the wrong tools
The most likely risk is a professional pasting client material into a public AI tool to summarize or draft from it. Client confidential information belongs in the “never in any unapproved tool” tier of your acceptable use policy, and people need an approved alternative at the same time. The shadow AI policy your IT team actually needs covers why the alternative matters.
Ethical walls and permissions
An AI assistant searches everything a user can access. If document permissions don’t reflect your information barriers, an assistant can surface material from a walled-off matter in seconds. Before connecting an assistant to firm content, confirm that permissions are set by matter or engagement, and that your barrier controls are enforced in the systems the assistant searches, not just in policy. The general cleanup approach is in fixing oversharing before Copilot.
Unverified output
AI tools can produce confident, plausible, and entirely wrong content, including invented sources. Courts have sanctioned lawyers who filed briefs containing case citations an AI tool made up; Mata v. Avianca in 2023 is the best-known example. The rule for every professional firm is simple: a professional verifies every fact, figure, and citation in AI-assisted work before it leaves the firm.
Client terms and disclosure
Review engagement letters and client guidelines for terms that affect AI use, and decide how the firm will disclose AI use to clients where it matters. For lawyers in the U.S., the American Bar Association’s Formal Opinion 512 addresses generative AI, including confidentiality, competence, client communication, and fees, and many state bars have issued their own guidance.
Where firms find value first
- Proposals and RFP responses, drafted from the firm’s past, non-confidential material.
- Knowledge search across firm templates, precedents, methodologies, and internal guidance, limited to content that isn’t client-specific.
- Internal meeting notes and action items.
- Research summaries, always verified against the primary sources.
- Answering staff questions about firm policies and procedures.
- The IT help desk.
Starting with firm knowledge rather than client material lets you learn how the tools behave before the higher-stakes uses. Picking your first AI use case covers how to choose and measure the first one.
The billing question
If a task that took four hours now takes one, what does the client pay for? This is a business decision rather than an IT one, but IT leaders should raise it early, because it affects adoption. Professionals who expect AI to reduce their billable hours may quietly avoid it. Firms are responding in different ways: moving some work to fixed fees, pricing on value rather than time, or reinvesting the saved time in work clients value more. Whatever the answer, it needs a decision from leadership, not a default.
Who owns AI decisions in a firm
Partnerships and professional firms make decisions differently from companies with a single chain of command, and AI governance has to fit that. In practice, it works best with a partner-level sponsor who can speak for the firm, the risk or ethics leader who owns professional obligations, IT, knowledge management if you have it, and one or two practice leaders who act as business owners for specific use cases. A small group like that, meeting briefly and often, can approve tools and uses far faster than a full partnership vote. The structure is covered in the 30-minute AI council.
How the six dimensions tend to look
Professional services firms often score well on security fundamentals, because client confidentiality has always demanded it, and on use cases, because the opportunities are obvious to everyone who writes for a living. They often score lower on data readiness, because document permissions have drifted over years of matters and engagements, and on governance, because nobody has been given the job of deciding what’s allowed. Skills vary widely: some professionals are already heavy users, others haven’t tried AI at all. That spread is itself a readiness issue, since the confident users are the ones most likely to paste client material into the wrong tool.
The asset: a client-safe AI checklist
- Engagement letters and client guidelines have been reviewed for terms affecting AI use.
- Our acceptable use policy names client confidential information explicitly.
- We have an approved AI tool whose contract prohibits training on our data.
- Document permissions are set by matter or engagement.
- Information barriers are enforced in every system an AI assistant can search.
- Our policy requires professionals to verify every fact, figure, and citation in AI-assisted work.
- We’ve decided how and when to disclose AI use to clients.
- Leadership has made a decision about billing for AI-assisted work.
- Staff have been trained with examples from our own practice.
- We keep an inventory of AI tools and features in use, including inside our practice management and document systems.
The first 90 days for a professional services firm
Days 1 to 30: publish the acceptable use policy, give professionals an approved tool, and review the permissions and barrier controls on your document systems.
Days 31 to 60: review client terms, decide the disclosure and verification rules, and build your AI inventory. Train staff with examples from your own practice.
Days 61 to 90: pilot one use case on firm knowledge, such as proposals or precedent search, with a baseline, and bring the billing question to leadership with real data from the pilot.
Where does your team actually stand?
The free AI Readiness Score uses 10 of the 24 assessment questions, spread across all six dimensions, and gives you a score in a few minutes.
Get your free AI Readiness Score →
Want to see what the full assessment covers first? Flip through a complete 38-page sample report.
Related guides
- Publish Your AI Acceptable-Use Policy This Month (3-Tier Template)
- The Shadow AI Policy Your IT Team Actually Needs (With Template)
- Fix SharePoint Oversharing Before You Turn On Copilot
- Picking Your First AI Use Case (and Proving It Worked)
- The 30-Minute AI Council: Lightweight Governance That Sticks
Frequently asked questions
What is the biggest AI risk for professional services firms?
Client confidential information going into the wrong tools, usually a professional pasting client material into a public AI tool. Close it with an approved tool, an acceptable use policy that names client information, and document permissions that respect engagement boundaries.
Do AI assistants respect ethical walls?
Only if your permissions do. An assistant searches everything a user can access, so information barriers must be enforced in the document systems it searches, not just written in policy. Check permissions by matter or engagement before connecting an assistant.
What guidance exists for lawyers using generative AI?
In the U.S., the American Bar Association's Formal Opinion 512 addresses generative AI, covering confidentiality, competence, client communication, and fees, and many state bars have issued their own guidance. Courts have sanctioned lawyers for filing AI-invented citations, as in Mata v. Avianca.
How does AI affect hourly billing?
If AI turns a four-hour task into one, the firm must decide what the client pays for. Options include fixed fees, value pricing, or reinvesting saved time. It's a leadership decision, and making it early helps adoption, because professionals who fear lost billable hours may avoid the tools.




