All answers
Security & compliance

With ChatGPT Enterprise (data residency in the US, no training on data) versus Teams, is it acceptable to put client PII into the enterprise version?

39:18From the May 13 call · Launching the Group: PII, Custom Models, and Scripting vs LLMs

There's no single correct answer here—it comes down to your firm's risk profile. One member noted their firm invested in ChatGPT Enterprise plus paid for US data residency, and a security consultant they worked with concluded PII was acceptable under that enterprise setup (with the models not training on the data), whereas it was a hard no under the Teams tier. Others agreed that enterprise/paid tiers are a 'much safer bet' than consumer tools, similar to using tools like Blue J for tax research—some firms will use these tools for sensitive data, some won't, and it depends on how much risk you're willing to accept. One participant noted accountants tend to be conservative by nature, which isn't a bad thing even if it means extra work, since nobody wants to be 'the case that every accountant learns about after the fact.' As an added layer of protection, one firm's policy requires any taxpayer data going into an external LLM to first pass through deterministic software that extracts/strips out PII (e.g., via OCR read and scraping out name, SSN, etc.) before it's fed to the LLM—though this was acknowledged as possibly overkill. That firm is also adding new engagement letter language disclosing that they use AI tools for administrative tasks and having clients consent to this as an additional layer of protection.

The full answer is members-only

Membership gets you this answer, the recording, and the rest of the library.

See membership

Already a member? Sign in