In nearly every professional services firm I walk into, two things are true at the same time.

Everyone is already using AI. And almost no one can tell me what they’re allowed to do with it.

That gap, between what people are doing and what anyone has decided about it, is the whole story. It isn’t a technology gap. It’s a decision gap. And it’s where the leverage and the liability both come from.

I run an IT firm. I’m in client environments every week, across law, accounting, insurance, financial services, and healthcare. So this isn’t a “what is AI” explainer, and it isn’t a debate about whether AI takes your job. Neither of those helps you on Monday morning. This is what I’m actually seeing: what’s working, and what’s hurting firms that look a lot like yours.

Here’s the frame that matters. Every professional reading this is in the trust business. You get paid because clients believe you know things they don’t, and that you’ll be careful with what they tell you. AI is the most powerful tool to land in professional services in twenty years, and the fastest way to break that trust I have ever seen.

The rest of this is about how to use one without doing the other.

Where we actually are

Three numbers to ground the conversation.

Adoption already happened. The 2025-26 Oh, Behave! report from the National Cybersecurity Alliance and CybSafe found 65% of respondents now using AI tools, and 43% of workers admitting they’ve shared sensitive work information with AI tools without their employer’s knowledge. That’s up from 38% the year before. Meanwhile, 52% say they’ve never received any training on the security or privacy risks of these tools. We are well past the question of whether AI is in your workplace.

The performance gap is real and widening. Clio’s 2025 Legal Trends Report (and the pattern holds well outside law) found that growing firms use time-saving automations twice as much as stable firms and nearly three times as much as shrinking firms. Growing firms use AI at roughly double the rate of everyone else. So on the “will AI take my job” question: no. But the person using it well might.

The regulators arrived. ABA Formal Opinion 512 is out. State insurance commissioners are publishing AI bulletins. FINRA has guidance for advisors. The SEC and IRS are paying attention. The “we’ll figure it out later” era is over.

Two halves follow. First, where AI is genuinely earning its keep. Then, where it’s actively hurting professionals who got careless.

Part One: Leverage

1. First drafts of structured work

This is the least exciting use case and the highest return, so I’ll start here.

My technicians are excellent at fixing problems and terrible at documenting them. Getting a tech to write up a process after the fact is like pulling teeth, and even when they do it, you get bullet points that only make sense to the person who wrote them. Institutional knowledge walks out the door every time someone changes jobs.

I built a custom AI tool for exactly this. A tech finishes a job and drops in whatever they have: rough notes, a screenshot, a half-sentence description. The tool formats it into a clean knowledge base article, suggests a title, and categorizes it. Because I gave it web search, it can fill in steps the tech didn’t write down. Documented eight of twelve steps? It finds the other four.

What used to take hours (and honestly, usually just didn’t happen at all) now takes minutes. We get an article that’s 90 to 95% complete. The tech confirms it’s accurate, polishes it, publishes it.

One tool. Built in an afternoon. It solved a problem that had existed in my company for years.

The principle underneath it is the one I’d ask you to hold onto for the rest of this article:

AI is excellent as a first draft. Dangerous as a final answer.

2. Turning long things into short things

Second use case I’d bet on: summarization.

An accountant I know used to spend the first two weeks of every new engagement reading: prior-year returns, financial statements, the previous CPA’s working papers. Now she runs those documents through AI with a structured prompt: flag anything unusual, list the open questions, summarize in 300 words.

Two weeks of reading became a half-day of structured review. She still reads everything. But she reads it knowing where to focus.

The same pattern applies anywhere you have to read a lot to know a little: litigation discovery, deposition transcripts, deal due diligence, claims files, coverage analyses, investment committee memos, insurance policies and contracts.

If you read for a living, AI just handed you back a meaningful chunk of your week. The interesting question is what you do with it.

3. Pressure-testing your thinking

This is the most underrated use of AI, and almost nobody does it: using it not to produce work, but to challenge your own judgment.

Before a difficult client conversation, a hire, or a strategic decision, describe the situation and instruct the AI to argue against you. Not to validate the plan. To stress-test it. Have it play the opposing party. The skeptical board member. The client who’s about to say no.

I built a version of this for myself: four simulated advisors I run real decisions through before I commit. A conservative, numbers-first CFO who flags financial risk. A growth-minded marketer who challenges my assumptions. A practical operations lead whose job is to ask whether we can actually execute this. And a customer advocate who represents what the paying client will actually experience.

Nine times out of ten, the answer doesn’t change. The tenth time, it does, and that one pays for all the others.

Use AI to think harder. Not just to type faster.

4. Meeting capture into composite deliverables

The last one on the leverage side is the thing I use every single day.

I run an AI notetaker on every meeting, video calls and in-person alike. It transcribes the conversation, and before I’ve closed my laptop I have a clean summary, the decisions made, and the action items assigned. I’m not scribbling notes while trying to be present. Nothing quietly falls through the cracks two days later.

That part is table stakes. Here’s the part worth taking with you.

When I build a deliverable for a client (a proposal, a project plan, a strategic recommendation, an assessment), I don’t start from a blank page or a stale template. I feed in every transcript from every conversation we’ve had, plus the contract, the fact-finding documents, and the background research. Then I have it draft the deliverable from all of it at once.

The output is better than what I would have produced on my own. Not because the writing is better. Because the AI doesn’t forget the thing someone mentioned offhand six weeks ago in a meeting that was ostensibly about something else.

The client reads it and thinks: he was really listening. The honest answer is that I was. But AI is what made sure none of it got lost.

The work nobody bills for but everybody does (meeting capture, follow-through, deliverable assembly) is where AI gives you back days. And it makes you look sharper doing it.

Part Two: Liability

That’s the upside. Real, available, and mostly inexpensive.

Now the part that keeps me up at night.

Risk 1: Confidently wrong content

“Hallucination” is a charming euphemism for the AI made it up and sounded great doing it. Fake citations. Invented quotations. Statistics that were never published, attributed to institutions that never published them.

The case worth studying happened in April 2026. Sullivan & Cromwell, one of the most prestigious law firms in the world, filed an emergency motion in a bankruptcy proceeding in the Southern District of New York. The filing contained fabricated case citations, misquoted authorities, and non-existent legal sources. Nine days later, the co-head of the firm’s restructuring practice wrote to Chief Judge Martin Glenn to apologize, attaching a three-page, single-spaced list of corrections.

Two details make this the case I keep coming back to.

First: the errors weren’t caught by Sullivan & Cromwell. They were caught by opposing counsel.

Second, and this is the part every firm leader should sit with, Sullivan & Cromwell had a policy. They had comprehensive AI policies, mandatory training modules, and an office manual instructing lawyers to independently verify every AI-generated citation before anything goes to a court, regulator, or client. Their own training uses the phrase “trust nothing and verify everything.” The policy existed. It simply wasn’t followed, and the backstop review didn’t catch it either.

This is not a rare event. Damien Charlotin, a research fellow at HEC Paris, maintains a public database of court decisions worldwide where hallucinated material showed up in filings. In mid-2025 it held roughly 200 cases. As of late August 2026, it’s just under 2,000, with more than a thousand in U.S. courts alone. The pace hasn’t slowed; it’s steepened. And by definition, the database only counts the ones a judge caught and wrote up.

Before the non-attorneys tune out: this is not a lawyer problem. It’s a using AI without verifying it problem, and I see the same shape in every industry.

An accountant’s AI-drafted tax memo cites a revenue ruling that doesn’t exist. The client files on it. The error surfaces on audit, and the E&O carrier gets a call.

A financial advisor’s AI-drafted portfolio rationale cites performance data from a fund with a similar name and a completely different strategy. The client signs off because it looked right. Compliance catches it three weeks later.

Same pattern every time. Tool used. Output looked confident. Verification step skipped.

The duty to verify what goes out under your name has not changed. The technology has just made it dramatically easier to fail at it.

Risk 2: The leak nobody talks about

This is the one I see most often, and it almost never makes the news, because most of the time, the firm doesn’t know it happened.

When someone pastes client information into a free consumer-grade AI tool, that information has been sent to a third party. Depending on the tool and the tier, that party may store it, may use it to train future models, and may in some circumstances surface fragments of it elsewhere.

The canonical example is Samsung, April 2023. Three separate engineers over twenty days pasted proprietary source code and internal meeting transcripts into ChatGPT, to debug faster and to summarize meetings. Helpful. Well-intentioned. Entirely rational from where they sat. The data left Samsung’s perimeter. Samsung banned the tool. The data was not coming back.

Now translate that into your firm:

  • A paralegal pastes a discovery production in to summarize it.
  • A tax associate pastes a K-1 to check the math.
  • An underwriter pastes a client’s medical history to draft a coverage letter.
  • A wealth advisor pastes a client’s full net worth statement to draft a financial plan.

Every one of those, depending on the tool, is a potential breach of confidentiality. Of professional conduct rules. Of HIPAA. Of GLBA. Of state privacy law. Of your E&O policy. And of your client’s trust, which is the one you can’t buy back.

Here’s the uncomfortable part. In most firms right now, nobody (not the partners, not IT, not compliance) can answer a simple question: what AI tools are our people using, and on what data?

You cannot supervise what you cannot see.

Risk 3: Someone using AI against you

The last risk is the one I’d put at the top of every professional’s list right now, because it’s the one where the loss is immediate and denominated in dollars: AI-generated deepfakes. Voice cloning and video impersonation, aimed at your firm.

The source material is already public. Your LinkedIn intro video. Your podcast appearance. Last quarter’s webinar. It doesn’t take much clean audio to produce a voice clone convincing enough to work over a phone line.

Gartner’s 2025 survey of 302 cybersecurity leaders found 43% had experienced at least one deepfake incident on an audio call and 37% on a video call. Their 2026 follow-up puts it at 41% and 35%. This is not a spike that’s receding. IRONSCALES surveyed 500 IT professionals and found that 55% of organizations reported financial losses from deepfake or AI-voice fraud in a twelve-month window, averaging more than $280,000 per incident, with nearly a fifth losing $500,000 or more.

The case the industry keeps returning to is Arup, the engineering firm behind the structural work on the Sydney Opera House. In early 2024, a finance employee in their Hong Kong office received an email from the company’s UK-based CFO about a confidential acquisition, followed by a video call. The CFO was on the call. So were other executives the employee recognized.

Afterward, the employee executed fifteen wire transfers totaling $25.6 million.

Every person on that call except the employee was an AI-generated deepfake. Faces, voices, and mannerisms, all fabricated.

Put that inside your firm. A partner’s voice instructing a paralegal to wire trust funds to a new escrow account. A CFO’s voice pushing a vendor payment through before close of business. An advisor calling a custodian to authorize a transfer out of a client account. A banker approving a wire.

If your firm moves money, I’d wager the verification process in practice comes down to the partner called and told me to do it. That process was thin before AI. It is now catastrophically inadequate.

Notice what this means: a defense built on recognizing the fake is racing a curve it can’t win. The quality is climbing while the cost of production collapses. A face you recognize and a voice you trust are no longer evidence of who you’re talking to. The only control that holds is a process that doesn’t care whether the face and voice are real, because it verifies through a channel the attacker doesn’t control.

If your organization moves money, holds client funds, or executes instructions over the phone, your verification protocol is the most important document you own.

Three moves for this quarter

None of these require buying anything. All of them can be in place before quarter end.

1. Policy

Write a one-page AI use policy. Not ten pages. One. It answers four questions:

  • Which tools are approved?
  • What data never goes into any tool, regardless of approval?
  • What verification step is required before AI output goes to a client or a regulator?
  • Who does someone ask when they’re unsure?

If you can’t say it in one page, it’s too complicated to be followed. And as Sullivan & Cromwell demonstrated, a policy nobody follows is indistinguishable from no policy at all, so the one-page version isn’t a compromise. It’s the point.

2. Stack

Pick an approved-tools list and get your people off the free tier for client work.

The enterprise tiers of ChatGPT, Claude, Copilot, and Gemini come with contractual data protection. The free tiers do not. In most firms, the difference between safe AI and dangerous AI is which login your people happen to be using. That’s genuinely most of it.

And understand what you’re really buying: not just a data-protection clause, but visibility. You cannot supervise what you cannot see, and the free tier is invisible by design.

3. Cadence

Add “how are we using AI” to your leadership meeting. Fifteen minutes, monthly or quarterly. What’s working. What’s worrying anyone. Who needs help. What changed at the regulator level.

This field moves too fast for a one-time policy document. The firms that treat AI governance as a standing agenda item rather than a project will be fine. The ones that write a policy in March and never look at it again are the ones I’ll be reading about.

Policy. Stack. Cadence. The firms that do this will look back in a few years and wonder why it ever felt complicated.

The thing to take with you

AI is leverage when you set it up on purpose. Liability when you don’t.

The difference is almost never the tool. Sullivan & Cromwell and the solo practitioner down the street are using the same models. The difference is the decisions you make about how work gets done: what’s approved, what’s forbidden, what gets verified, and who’s watching.

Those decisions are not technical. They’re yours.