AI Agents and Client Data: What a Small Business Must Get Right

If your business holds anything sensitive — financial records, client details, anything covered by an agreement — connecting an AI system to it deserves more thought than it usually gets. Here is the short version of what matters.

By John-Michael Tamburro · July 1, 2026

If your business holds anything sensitive — financial records, client details, anything covered by an agreement — connecting an AI system to it deserves more thought than it usually gets. Here is the short version of what matters.

Know where the data goes

The first question for any tool: does information sent to it leave your control, and is it retained or used for training?

Business and enterprise tiers of the major providers generally commit to not training on customer data and to limited retention. Consumer tiers frequently do not. The gap between those two is where most small-business exposure sits, because people trial something on a personal account and it quietly becomes part of the workflow.

If you cannot answer where a tool sends your data, do not connect it to anything confidential.

Restrict what each system can reach

The single most effective control is also the simplest: give each system access to the minimum it needs.

Our scheduling system cannot see financial data. Our bookkeeping system cannot send email. Not because we distrust them — because a system that cannot reach something cannot leak it, misuse it, or be manipulated into exposing it.

This is worth more than any policy document.

Understand who is accountable

Using a vendor does not transfer your obligations. If you hold client data under an agreement or a regulation, you remain responsible for it regardless of which supplier processes it.

Practically that means reading what the vendor commits to, keeping a record of which systems touch which data, and being able to answer the question if a client asks. In advisory work, they eventually will.

The confidentiality problem specific to deal work

If you handle transactions, some of your information is confidential in a way that goes beyond good practice — it is contractual, and often material and non-public.

Our position is straightforward: our systems operate in the back office. They do not touch live transaction information, and our published analysis and client advice are produced by people. Deciding that boundary in advance is far easier than deciding it under deadline pressure, and it is the question clients actually ask.

Practical controls that are worth the effort

Use business-tier accounts. The commitments differ meaningfully from consumer tiers.

Keep an inventory. Which systems exist, what each can access, who owns it. Three lines each. Most small businesses cannot produce this, which is itself the finding.

Review access when things change. Permissions granted for one purpose persist long after that purpose ends.

Do not paste sensitive material into general-purpose tools. This is the most common real-world exposure and it has nothing to do with agents.

Have a human check anything that leaves the building. For confidentiality as much as accuracy.

The proportionate view

None of this requires a security programme or a consultant. It requires knowing where your data goes, limiting what each system can reach, and deciding in advance what you will not automate.

A business that can answer those three has done more than most.

Related: How to Tell If an AI Vendor Knows What They're Doing.