For many companies, artificial intelligence adoption has moved faster than the policies meant to govern it.
Employees are using ChatGPT, Claude, and other AI tools to summarize documents, draft emails, analyze spreadsheets, write code, and answer questions about internal operations. In many organizations, that behavior became normal before leadership decided what information may be shared, which accounts are approved, or which integrations are safe.
That creates a different kind of AI risk.
The immediate threat is not simply whether a model produces a wrong answer. It is whether sensitive company information is moving into systems, accounts, and connections the business has never formally reviewed.
For CPA firms, the issue is especially acute. They handle tax information, financial records, client communications and other material that carries confidentiality and professional obligations. Their clients are experimenting with the same technology, often with even less structure.
Oakspring Labs founder Val Kharkover believes many organizations are treating AI as a productivity decision when it has become a governance decision.
“Companies are asking whether AI can save an employee two hours, but they are not always asking what information that employee is putting into the model, what account they are using, what the retention settings are, or what third parties sit between the company and the model,” Kharkover said. “The productivity upside is real. So is the need to control how the technology touches company data.”
Myron Kharkover, co-founder and head of technology at Oakspring, sees the same problem from the infrastructure side.
“The model itself is only one part of the security picture,” he said. “You also have the connection, the user identity, the permissions, the connector, the API key, and the third-party application. If a company governs only the model name and ignores the path the data takes, it has not really governed the system.”
The Risk Is Not the Same for Every AI Account
One reason the governance problem is easy to misunderstand is that not every version of an AI product handles business data in the same way.
OpenAI says data from its business offerings and API is not used to train its models by default. Anthropic makes a similar commitment for its commercial products. Consumer products can operate under different privacy, retention, and model-improvement settings, and users may be able to allow conversations to help improve future models.
That distinction matters because employees do not always know which environment they are using.
A company may approve an enterprise workspace while an employee continues using a personal account. A developer may use an approved model through an unapproved routing service. A staff member may install a browser extension that passes information to another provider. A team may connect an AI assistant to cloud storage without understanding what it can read.
The governance failure is therefore not that every frontier AI lab simply absorbs every piece of business data submitted to it. The more practical risk is that companies lose control when employees use the wrong account, enable the wrong setting, or connect approved models through unapproved services.
For CPAs, Busy Season Makes Shadow AI More Likely
The problem becomes more difficult when firms are operating under deadline pressure.
During tax season, CPA teams may spend months working through incomplete source documents, late responses, extensions, complicated returns, and demanding client schedules. Partners are focused on review, delivery, and keeping work moving toward immovable deadlines.
In that environment, convenience tends to win.
An employee who believes an AI tool can summarize a long client email, organize a document, or accelerate research may use it without waiting for a formal technology review. The individual may be trying to serve the client faster, not create a security problem.
But sensitive information can still cross a boundary the firm never intended to cross.
That creates a dual governance problem. CPA firms must control how their own people use AI while many of their clients are asking the same questions about customer data, contracts, intellectual property, and internal systems.
Compliance Risk Is Only One Part of the Exposure
The most obvious concern is compliance and confidentiality.
A business may have obligations governing tax information, personal data, health information, financial information or customer records. Sending that information into an unapproved AI environment can create retention, disclosure, contractual, and audit questions even when no obvious breach occurs.
There is also a competitive risk.
Companies also possess information they would never intentionally publish: pricing strategy, client lists, acquisition plans, forecasts, product roadmaps, source code, and internal analysis. AI makes it easy to move that information outside the traditional perimeter because the act can look as harmless as pasting text into a chat box.
That does not mean a competitor can simply ask a model to reproduce another company’s confidential plan. The immediate issue is loss of control. Once proprietary information is sent through an unmanaged account or third-party service, the company may no longer have the retention, access, or audit assurances it assumed it had.
Security risk expands again when AI systems connect to email, cloud storage, CRM systems, financial platforms, code repositories, or internal databases.
The Connection to the Model Can Be as Important as the Model
Recent industry events have made that point more concrete.
Anthropic reported in September 2026 that some third-party model-routing services had retained user exchanges without users’ knowledge and that those transcripts later appeared in unauthorized model-distillation activity. The company said some exchanges contained sensitive business information and credentials.
The episode illustrates why vendor selection cannot stop at choosing a well-known model provider.
Companies also need to know how requests are routed, whether prompts are logged, where data is stored, who can access it, and what protections apply to every service in the chain.
For a CPA firm, those questions increasingly resemble the controls already expected around financial systems and client information. AI governance is becoming another layer of information governance.
The Client Problem Can Become an Advisory Opportunity
The same risk that creates work for security teams also creates an opportunity for trusted advisers.
Business owners are increasingly asking whether employees should be allowed to use AI, what tools should be approved, what information should never be entered, whether company data may be used for model improvement, and how AI systems should connect to internal software.
Those questions often reach CPAs because CPAs already understand the client’s business, data sensitivity, and operating environment.
But many regional firms do not have AI security specialists, engineers, or governance teams in-house. During busy season, they may have even less capacity to research products, review architecture, train employees and build policies.
Oakspring Labs has been expanding its work with CPA firms and their clients around that gap. The company says it can help organizations stand up approved AI environments, evaluate how models and integrations handle data, establish access and security controls, and create practical rules for employee use.
Education is a large part of that work. Staff need clear guidance about approved tools, what information can be shared, when data should be anonymized, how credentials should be handled, and when a workflow requires additional review.
For CPA firms, Oakspring’s model is designed to sit behind the existing client relationship. The CPA remains the trusted adviser while Oakspring provides technical and security capabilities that would otherwise require the firm to build a specialized team.
Governance Does Not Have to Mean Slowing AI Down
The temptation for a company worried about data risk is to ban AI outright.
That can create a different problem. If employees believe the tools make them materially more productive, a blanket prohibition can push usage into personal accounts and unapproved applications where the company has even less visibility.
A more durable approach is to define an approved path.
That can include business-grade AI accounts, role-based access, data classifications, retention settings, approved integrations, credential controls, logging, vendor review, and employee training.
The objective is not to eliminate experimentation. It is to make experimentation visible, deliberate, and proportionate to the sensitivity of the information involved.
The Strategic Question for CPA Firms
For regional CPA firms, AI governance is now both an internal obligation and a client-service question.
The firms already face pressure from national competitors investing in automation while clients adopt AI whether or not their advisers are prepared to guide them.
A CPA firm can allow AI, cybersecurity and data-governance conversations to move entirely to outside technology providers, or it can remain close to those decisions by bringing in specialist capability behind the relationship.
The latter can make the firm more differentiated and more difficult to replace while creating new advisory opportunities around problems clients are already trying to solve.
The larger lesson is that AI adoption is no longer only about what the model can do.
It is about what data the model receives, how that data gets there, who controls the connection, and whether the company can explain those choices after the fact.
For CPAs and their clients, the organizations that benefit most from AI may not be the ones that move fastest without controls. They may be the ones that capture the opportunity while building governance strong enough to keep the technology from outrunning the business.
Disclaimer: This article is for informational purposes only and does not constitute legal, cybersecurity, accounting, or professional advice. The information discussed reflects general considerations regarding artificial intelligence governance, data security, and technology management and may not apply to every organization’s specific circumstances. Businesses should consult qualified legal, accounting, cybersecurity, and technology professionals before implementing AI tools, policies, or governance frameworks. Any opinions or statements attributed to individuals or organizations represent their own views and experiences and should not be interpreted as a guarantee of specific outcomes.


