Ask an accountant how they keep client data safe with AI and you'll almost always hear the same line: "I've turned off training." It's a reasonable thing to believe. It's also, on its own, close to worthless as a compliance position. Turning off training stops one thing... the provider reusing your conversations to train future models. Everything else still happens. Your prompt still leaves your computer. It's still processed on a server, usually abroad. It's still retained for a while. It's still, in the language of the law, being handled by a third party on your behalf. If you process client data through AI, and virtually every firm does, you're the data controller and the AI provider is your processor. That's a defined legal relationship with eight separate obligations attached. The training toggle covers roughly one of them. This isn't hypothetical any more either. The PCRT bodies, including the ICAEW, published AI guidance in January. The IRS issued its first Circular 230 guidance on AI in June. The UK's Data (Use and Access) Act landed in February. None of it created new duties. All of it confirmed the existing ones apply, and that regulators are actually looking now. I put together a free guide walking through all eight things compliance actually requires, in plain English, with a simple framework for deciding what's safe to do with client data. Fifteen minutes to read. Attached below. The full course covers the other four chapters this guide doesn't (agentic AI, connecting AI to QuickBooks and Xero, prompt injection, and the 2026 rules by jurisdiction) ... that's inside Premium if you want to go deeper. Where does your firm genuinely stand on this right now... sorted, working on it, or hadn't thought about it until this post? 👇