Answer
Can a firm use client work to improve its own AI tools?
Check the engagement terms before the technology. Most professional contracts already answer this, and usually not in the firm's favour.
Only if the engagement terms permit it, and most do not. Confidentiality clauses restrict use as well as disclosure, ownership clauses often assign the deliverable, and a model built on the work is a use of it.
Start with the clause, not the technique. Professional engagement terms typically say three separate things that bear on this: that the firm will keep the client's information confidential, that it will use that information only for the purposes of the engagement, and that some or all of the deliverable belongs to the client. The second is the one that catches internal tool building, and it is the one people skip — a purpose limitation is breached by using the material for a different purpose whether or not anybody outside the firm ever sees it.
Ownership is the second constraint and it varies more than firms remember. Where the deliverable is assigned to the client, the firm holds a licence to what it produced rather than the thing itself, and that licence is usually narrow. Where the firm retains ownership and grants the client a licence, the position is much better. Firms with a mixed history of engagement terms — most firms — cannot answer the question in general and have to answer it per client, which is itself a useful finding.
The distinction that firms reach for is between the client's information and the firm's own know-how, and it is a real distinction that does not do as much work as they hope. Nobody seriously argues that a lawyer forgets how to structure an argument between matters. What is contested is the artefact: a repository of past deliverables, an index over client documents, a model tuned on them. Those embed particulars rather than technique, and a search over them returns the particulars. The test worth applying is whether the tool can produce something a person could identify as coming from a specific client's matter.
Which suggests where the safe ground actually is, and it is substantial. Templates and precedents with the particulars removed by a person. A style guide derived from the firm's own writing. Checklists, process documents, and structured knowledge about how the firm works. A retrieval system over the firm's own published material and its internal guidance. All of these are the firm's own product and none of them requires reading anybody's engagement letter.
There is a separate question about the vendor, and it is often the one that decides the matter. Building an internal tool usually means sending material to somebody — a hosting provider, a model provider, an embedding service — which is a disclosure to a third party even when the tool is described as internal. That disclosure is governed by the same confidentiality clause and often by an explicit subprocessor provision. A firm can be entirely right that the tool is internal and entirely wrong that no disclosure occurred.
The route that works, where the value justifies it, is consent obtained properly rather than a clever reading. Asking clients — particularly institutional ones, who deal with this constantly and have positions on it — is a conversation firms consistently expect to go worse than it does. Some say no, which is information. Some say yes with conditions that are easy to meet. And a firm that asked has a durable answer, where a firm that reasoned its way to a permissive interpretation has an argument it will have to make at the worst possible moment.
A confidentiality clause that restricts use rather than only disclosure is breached by a tool that never shows anybody anything.
Siddharth Sharma, Context Theory
Related questions
Does anonymising the material solve it?
It helps with confidentiality and does less for the purpose limitation, which is about use rather than about identification. It also has to be real: removing names from a deliverable that concerns a distinctive transaction, a known dispute or a small market leaves the client identifiable to anyone in the field. The honest test is whether a knowledgeable outsider reading the output could say whose matter it came from.
What if we only use the work to evaluate a tool rather than to build one?
Evaluation is a use, and it involves the same disclosure to whatever the material passes through — so the analysis does not change, though the volume and the retention usually do. A defensible evaluation uses material the firm owns outright, synthetic examples, or a client's material with that client's agreement. The last is easier to obtain for evaluation than for training, because it is bounded and finite.
METHOD
Every figure below carries its source and the date it was verified. Nothing on this page is asserted.
The numbers on this page.
| What | Value | Specific to |
|---|---|---|
| US SMB full-service retainer | $3,500–$8,000 | Category-wide |
| Share of the buying journey completed before contacting a vendor | 60% | Category-wide |
2026 agency pricing survey · per month · verified
2026 B2B buyer surveys · verified
What is specific to this page.
| Kind | Claim | Check it against |
|---|---|---|
| Constraint | Engagement terms commonly impose a purpose limitation alongside a confidentiality obligation, and a purpose limitation is breached by internal reuse for a different purpose even where nothing is disclosed outside the firm. | The confidentiality and permitted-use clauses of the firm's own standard engagement letter and of its largest clients' amended versions. |
| Procurement | Where a deliverable is assigned to the client the firm holds only a licence to what it produced, and firms with a mixed history of engagement terms cannot answer the reuse question in general and must answer it per client. | Sampling closed engagements across several years and recording which assigned the deliverable and which retained it. |
| Workflow | The line between transferable know-how and the client's information is drawn by whether the artefact embeds particulars, so the operative test is whether the tool can produce something identifiable as coming from a specific matter. | Querying the proposed tool and checking whether returned material can be traced to a named engagement by a knowledgeable reader. |
| Software | Building an internal tool normally involves sending material to a hosting, model or embedding provider, which is a disclosure to a third party governed by the same confidentiality clause however internal the resulting tool is described as being. | Listing every external service the proposed build sends client material to, and checking each against the subprocessor clause in the engagement terms. |
Each row would be wrong on another industry's page. Where a sourced figure exists it is in the table above instead; these are the constraints that shape the work and do not happen to be numbers.
Start with the measurement.
Reading about a benchmark is not the same as knowing your own number. The audit produces yours, measured rather than estimated.
$497 · delivered in 5 business days · credited against month one