Exhibitor login
AI Insider 09 September 2026

Client Files and AI: Who Determines Access to ChatGPT, Google, and Microsoft?

Client Files and AI: Who Determines Access to ChatGPT, Google, and Microsoft?

Accounting firms in the Netherlands are currently testing AI assistants capable of searching client files across the organization. This raises important questions about who has access to what information, especially as tools like Microsoft Copilot, OpenAI's ChatGPT Enterprise, and Google Gemini can easily be integrated with emails, documents, and CRM systems. The deployment of these technologies directly impacts the General Data Protection Regulation (GDPR) and the upcoming European AI regulation (AI Act).

The use of AI assistants presents organizations with the challenge of data minimization. These new workplace assistants require access to a variety of files to function effectively, increasing the temptation to grant them full access. However, this may lead to breaches of data protection, as employees might gain access to information that is not relevant to their specific tasks. It is therefore essential for organizations to determine in advance which sources the AI assistant may use and for what purpose, with accounting firms needing to exercise extra caution given their professional confidentiality.

Additionally, the roles of data controllers and processors must be clearly defined in a data processing agreement. This is crucial for determining who is responsible for which data processing activities. A DPIA (Data Protection Impact Assessment) is another important step in the implementation of AI, to map out risks and make agreements regarding incident reporting and audit rights. Furthermore, it is advisable to limit AI access to the minimum necessary by using role-based access and other techniques such as Retrieval-Augmented Generation (RAG) to ensure that no more personal data than necessary is processed.

The European AI Act imposes additional requirements on organizations deploying AI technology, such as risk management and human oversight. This is particularly relevant for functions where AI is involved in decision-making that may affect customers. Organizations should also provide transparency to customers regarding the use of AI, what data is processed, and what security measures are in place. Accountability for AI-generated outcomes must be clearly defined to ensure trust and minimize legal risks. It is advisable to start with small-scale implementations of AI and only scale up once the processes are functioning well.

Read the full article from AI Insider.