Where Does Your Client Data Go When Your Team Uses AI?
Your team is already using AI tools. Some of them keep what gets typed in. In a free 30-minute AI Risk Review, you sit down with Brian Butterfield, CISSP, and find out exactly where your firm's information is going.
Did The Tool Keep It?
Your team is uploading documents to get work done faster. That is reasonable. The question is what happens to those documents afterward.
- A settlement demand with the client's numbers in it
- A closing file with names, addresses, and wire details
- A parenting plan with a family's personal circumstances
- A deposition summary they wanted cleaned up quickly
- A contract they asked AI to find the weak points in
- Discarded. Some plans process the input and delete it
- Stored. Held on a server under whatever terms apply to that account
- Used for training. The content may help train future versions of the model
- Which one applies depends on the tool, the plan, and the account someone signed into
- Most of that is knowable. It just has to be checked
Paying More Does Not Make It More Private
With the most widely used AI tool on the market, the individual plans share the same privacy terms regardless of price. Only the organizational plans change the data relationship.
And here is the detail that undoes the rest of it. If someone at your firm is signed into their own personal account, they sit outside your firm's agreements entirely. A firm can be paying for the organizational plan and still have client information moving under individual terms, depending on which account was used.
The Bar Named Three Things To Check.
Can Your Firm Answer Them?
In January 2024, the Florida Bar issued Ethics Opinion 24-1, making Florida one of the first states with formal guidance on generative AI. The headline is good news: lawyers may use these tools.
The opinion also gets specific. It says lawyers should protect client confidentiality by researching the AI program's policies on three things.
That is real work. It means reading terms of service across every tool in use at the firm, confirming which plan each person is signed into, and turning all of that into an answer you would be comfortable giving a client.
If your firm has already done it, the review confirms where you stand and gives you documentation. If it has not been assigned to anyone yet, this is a straightforward way to get it done.
Assumed protection is not the same as verified protection.
Five Answers In 30 Minutes
No software to install. No prep required. No sales pitch.
Where Your Data Goes
The AI tools your team actually uses, and where they send firm data.
Which Tools Retain Or Train
Which of those tools keep or learn from what gets typed in.
What AI Can Reach In Microsoft 365
The email, document, and account access AI currently has.
Gaps In Your Coverage
What your cyber liability policy expects you to have closed.
Your Next Three Steps
The clearest fixes first, prioritized and in writing.
You leave with a written summary and Brian's recommendations.
Not a quote. Not a proposal. A picture of where your firm stands today.
Start With A Call. End With Clarity.
Three steps, start to finish.
Step 1: Fill Out The Short Form
Name, firm, email, phone, firm size, and any AI tools you already know your team uses. About a minute.
Step 2: Pick Your Time
Brian's calendar is on the same page. You are booking directly with him, not with a scheduler.
Step 3: Get It In Writing
Brian walks through all five areas, then sends a written summary with prioritized recommendations. Yours to keep.
Brian Butterfield, CISSP
Co-Founder and Chief Security Officer at Microtech. A Certified Information Systems Security Professional with about thirty years in security, most of it with compliance-driven firms. He has delivered Florida Bar approved continuing legal education on this material.
Brian runs every AI Risk Review himself. That is the reason there are only ten a month. You are booking time with him, not with a sales team.
"Thirty minutes on a video call so I can walk you through what we found, face to face. It is free because I would rather you know."
What Florida Firms Say About Microtech
The Three Things We Hear Most
"We already have an IT provider."
Good, and this is not about replacing them. It is a second opinion. If your provider has this handled, the report says so and you have documentation you did not have before. If there are gaps, you hear it from someone independent. Nothing about this requires you to change anything.
"We barely use AI here."
Worth confirming rather than assuming. AI features are increasingly built into software firms already pay for, and people sign into personal accounts without thinking of it as adopting a new tool. The review either confirms what you believe or shows you something worth knowing.
"What happens if you find something?"
There is no version of this you fail. The report is yours and it is confidential. Hand it to your current IT provider, act on it internally, or keep it on file. Knowing where you stand is the point.
Verify It. Do Not Assume It.
Ten Florida firms a month, because Brian runs every review himself. If this month fills, get on next month's calendar. Sooner is better, because this is moving faster than the guidance is.
Book Your Free AI Risk ReviewWe are not looking to replace your IT provider. Every firm benefits from a second set of experienced eyes.