Is it safe to let AI read your clients' emails?
Every firm owner we talk to asks some version of this question, and they’re right to. Your inbox is full of things clients trusted you with: bank details, salaries, health information on an insurance claim, a candidate’s right-to-work documents.
The short answer: yes, it can be safe, if you set it up deliberately. The risks are real but manageable, and they’re mostly the same ones you already manage when you adopt any new system.
What could actually go wrong?
It helps to be specific. The realistic risks are:
- Your data is used to train someone else’s model. This depends on the plan and provider you use.
- The automation sees more than it needs to. An inbox assistant with access to every mailbox and every shared drive is a bigger risk than one that can read one shared inbox.
- A wrong answer reaches a client. The AI drafts a reply that sounds confident and is wrong: a deadline, a fee, a policy detail.
- Data ends up somewhere new. Client emails copied into a spreadsheet, a chat tool or a third-party app nobody reviewed.
- It breaks quietly. Something changes upstream, and the automation stops working or starts doing something odd, and nobody notices for a week.
Each of these has a straightforward control.
How do you use AI on client email safely?
These are the rules we build to, and what you should ask of anyone who builds for you.
Use business-grade AI accounts, never personal ones
Use the business or enterprise tiers of Claude, ChatGPT or your chosen provider, or their APIs. Read the current data terms and confirm that, on your plan, your data isn’t used to train models. No client data in free personal accounts, ever. This one rule removes the most common way client data leaks into AI tools: staff pasting emails into whatever they have open.
Give each automation the minimum access it needs
An inbox triage workflow needs to read one shared inbox and create drafts. It doesn’t need to delete mail, read the partners’ personal inboxes, or see payroll. Scope access tightly, and use a dedicated account or app registration for each automation, so you can see what it did and switch it off without affecting anything else.
Keep data in the tools you already use
The safest place for client data is where it already lives: your Microsoft 365 or Google Workspace tenancy, your practice management or agency management system, your ATS. Build automations that read from and write back to those systems, rather than copying data into new places.
Keep a person on anything client-facing, financial or regulatory
This is the most important rule. The AI drafts and people send. Replies sit in the drafts folder until someone has read them. Some things never get automated at all:
- Accounting firms: tax positions, advice, and KYC/AML decisions stay with a qualified person.
- Recruiting agencies: decisions about candidates stay with a recruiter. AI can summarise a CV, but it shouldn’t screen people out on its own.
- Insurance brokers: cover advice and anything about a claim stay with a broker.
Once a narrow, low-risk category is reliably right, such as “thanks, we’ve received your documents”, you can let that category send automatically. Earn the trust first.
Log everything
Every email read, every draft written, every message sent and every approval should be recorded somewhere you can check. If a client asks “why did I get this?”, you should be able to answer.
Test on past cases before going live
Run the automation on last month’s emails first and compare its drafts with what your team actually sent. You’ll find the gaps before a client does.
Make someone responsible for it after launch
Automations break quietly. Someone should own each one, check it weekly, and know how to switch it off.
What about data protection rules?
Your existing obligations still apply: GDPR or the data protection law where you operate, your professional body’s guidance, and the terms of your engagement letters. Adding an AI provider usually means adding a data processor, which may need to appear in your privacy notice and records. If you’re unsure, take advice before client data goes anywhere new. This is a one-off piece of work, not a reason to avoid the whole thing.
What does a safe first project look like?
Start with something where a mistake is cheap and a person sees every output. Two good options:
- Drafted replies in a shared inbox. The AI sorts incoming email and drafts replies to routine questions. A person reviews and sends every one. Nothing leaves without a human pressing send.
- Document chasing. The automation works out what’s missing and drafts the request. It doesn’t need to read the documents themselves, only whether they’ve arrived. We walk through it in How accounting firms can automate document chasing with AI.
Either one gives your team a few weeks to see how the AI behaves on real work before you widen its scope.
The bottom line
The question isn’t really “is AI safe?” It’s “is this particular setup safe?”, and that has a concrete answer: which plan, which access, where the data goes, who approves what, and who’s watching it. If you can answer those five questions for an automation, you’re in good shape.
Safety is part of every spec we write at Spur. If you’d like a second pair of eyes on how your firm could use AI with client data, book a 30-minute call. For ten automations with the human checkpoints already marked, get the free Capacity Playbook.
FAQ
Does ChatGPT or Claude train on our emails?
It depends on the plan. Business, team, enterprise and API offerings from the major providers generally don't use your data for training by default, while some personal plans may. Read the current data terms for the exact plan you're on before any client data goes in.
Do we need our clients' permission?
Check your engagement letter, your privacy notice and the data protection rules where you operate. Using a new processor for client data may need to be disclosed. If you're unsure, take advice before you start.
Can the AI send emails on its own?
Only if you choose to let it, and only for narrow, low-risk messages such as "thanks, documents received". Everything else should sit as a draft until a person sends it.
What's the biggest risk in practice?
Usually not a data breach, but a confident wrong answer going to a client. That's why drafts, human approval and clear rules about what the AI may and may not answer matter more than anything else.