The Firms That Ban AI Will Lose Their Best People
A ban does not stop your team from using AI. It pushes your sharpest people onto risky public tools in secret, or out the door to a firm that gave them a safe one.
Key Takeaways
- ✓ A ban does not remove AI from your firm. It moves it into the shadows on unapproved public tools. KPMG and the University of Melbourne found 57 percent of employees hide their AI use from their employer.
- ✓ Secret use of public ChatGPT or Claude subscriptions is a real data and compliance liability. Client details get pasted into tools you do not control and cannot audit.
- ✓ Owners underestimate how much their own team already uses AI. McKinsey found leaders see heavy use at roughly a third of its real level.
- ✓ The fix is not a ban and not a public free-for-all. It is a private, firm-controlled setup with a clear rule set, so your best people work in the open and your data stays inside the firm.
Partners describe a version of this constantly: the firm has a simple AI policy, which is that no one is allowed to use it. It gets said like it settles the matter. It does not. The associates are already using it on their personal phones. They have just stopped saying so, and they are pasting client details into a free public tool nobody at the firm can see.
I build AI systems for professional-services firms on Chicago's North Shore. The firms that ban AI are not keeping it out. They are pushing their best people onto unapproved public tools, in secret, while teaching them to wonder whether the firm down the road is a better place to build a career.
The ban feels safe. It is the opposite. It creates a hidden data liability and a slow leak in your talent at the same time, and you will not see either one on a report until your sharpest twenty-eight-year-old gives notice.
A Ban Does Not Stop AI. It Hides It on Risky Tools.
Here is the thing owners get wrong. A policy does not control behavior you cannot see. Your team carries a phone. The phone has a chatbot on it. When you say no, you do not remove the tool. You remove your ability to know how it is being used, and on which tool.
The numbers back this up. In the 2025 KPMG and University of Melbourne global study of more than 48,000 people across 47 countries, 58 percent of workers said they intentionally use AI for their job, and 57 percent said they have hidden that use from their employer. A separate survey by the security firm Anagram, reported by Newsweek, found nearly half of employees (45 percent) use AI tools their company has banned. A ban does not produce zero usage. It produces secret usage on whatever free public tool an employee happened to find, with no oversight, which is the worst outcome for a firm that handles client money, client cases, or client health information.
This is the part that should worry a partner more than the talent risk. When an associate pastes a client's financial statement, a draft settlement, or a medical history into a generic public chatbot, that information has left your control. You cannot prove what was retained, where it was processed, or who could see it. For a firm bound by confidentiality, that is not a productivity question. It is a data and compliance exposure that a ban actively makes worse by driving the behavior underground.
Ban AI at your firm and your sharpest twenty-eight-year-old leaves for the firm that did not. The ban does not protect you. It just pushes the work onto a public tool you cannot see and thins your bench.
Why This Matters for North Shore Firms
A national firm can lose a few good associates and backfill them by Friday. A 14-person law firm in Lake Forest or a boutique RIA in Winnetka cannot. On the North Shore, your edge is your people, and the bench is thin. Losing one strong associate or producer is not a line item. It is a year of lost momentum and a client relationship at risk.
The people most likely to walk are the ones you least want to lose. They are early in their careers, they are fast, and they think about the next ten years. They watch which firms are building skills that will matter and which are pretending the last two years did not happen. PwC's 2026 Global AI Jobs Barometer found that workers with AI skills command a 62 percent wage premium, which tells you the market already treats these skills as valuable. A young associate sees that too. A firm that forbids the tool is, in their eyes, a firm that is letting their skills go stale on purpose.
There is a second cost that is easy to miss. When the partner bans the tool but the associates use it anyway, you train your whole team to hide things from leadership and to route client data through tools the firm never vetted. That habit does not stay contained to AI. The firms that handle this well do the opposite. They give people a private, firm-controlled way to use AI out loud, at their desk, with help. That combination of openness and control is worth more than any single workflow, and it is exactly what a public subscription cannot give you.
Replace the Ban With a Private Setup and Clear Rules
People do not need a wall, and they should not be left on a public tool. They need a private lane the firm owns and a one-page set of rules.
The reason owners reach for a ban is usually a real fear: someone pastes a client's financial statement or a sealed matter into a public tool. That fear is correct. The mistake is the response. A ban does not close that risk, it hides it. The real fix is to remove the reason anyone reaches for a public tool in the first place, by giving the team a private setup the firm controls, paired with a short rule set that says what is fine, what needs the private tool, and what never goes into AI at all.
This is the core of how I build for North Shore firms. For most confidential work, that means custom internal workflows running on an approved business account where your data is never used for training. For the most sensitive firms, it means a private local AI setup that keeps every document inside the building, on hardware you own. A generic public subscription cannot offer either one. It cannot be audited, it cannot be locked to your rules, and it was never designed for a firm that signs confidentiality into every engagement. The private lane is the version of "yes" that a professional-services firm can actually defend.
SAMPLE CLAUDE PROMPT
"Write a one-page AI use policy for a small professional-services firm that handles confidential client information and uses a private, firm-controlled AI setup. Keep it plain enough that a busy person will actually read it. Cover three things: tasks where the firm's approved AI tool is fine to use, information that must only go through the private setup, and information that must never be entered into any AI tool, public or private. Avoid legal jargon and keep it to one page."
Give Your People Real Training, Not a Memo
The interest is already there. What is missing is a safe tool and a half-day of hands-on help with real work.
The gap is not desire. It is training and tooling. In the same McKinsey work, employees said they expect AI to reshape a large share of their job far sooner than their leaders do, yet most report little or no formal training. The KPMG and University of Melbourne study found a similar split: most workers use AI, far fewer have ever been trained on it. Your people are figuring this out alone, at home, on the weekend, on whatever public tool they found, because the firm gave them nothing official to use.
That is a retention problem and a security problem wearing the same coat. A young associate who teaches themselves on a public tool the firm refused to support starts to feel they are carrying the firm into the future on their own time, and your client data is riding along on a consumer account.
Flip both at once. Run short, hands-on sessions on the real work your team does, inside the firm's own setup, and you turn a private frustration into a reason to stay. That is the whole idea behind how I run team AI training. One North Shore family office I worked with reached full team adoption within four weeks by training on the work people already did, inside a setup the firm controlled, rather than on a public tool in the abstract.
SAMPLE CLAUDE PROMPT
"Design a 90-minute hands-on AI training session for the staff at my firm, using our own approved internal AI setup rather than a public app. The team does [describe two or three recurring tasks]. Build it around those real tasks from start to finish, not a tour of features. Include what I show first, the exact steps each person practices on their own work, and one simple check they run to confirm the output is right before they use it."
Make AI a Reason to Stay, Not a Reason to Leave
The firm that gives people a safe, current way to work becomes the firm ambitious people want to build a career at.
Turn the whole thing around. Right now a ban is a reason your best people quietly look elsewhere and quietly route work through tools you cannot see. The same energy, pointed the other way, becomes a reason they stay. A small firm that openly invests in a private AI setup and in its people's skills is offering something a bigger, slower competitor often will not: the chance to stay current and valuable while doing real client work, without the firm taking on hidden data risk to get there.
This is where small firms have an edge they rarely use. You can move faster than a national firm with a committee and a legal department. You can sit down with one associate, pick one workflow, and have it running inside a controlled setup next week. That speed is a recruiting and retention story, and it is one a generic software vendor or a national consultancy is structurally unable to tell. It is a story worth building on purpose, usually starting with a short AI consulting engagement to decide what is worth doing first, what to run privately, and what to leave alone.
SAMPLE CLAUDE PROMPT
"Act as an advisor on talent and AI for a small professional-services firm. We want to use a private, firm-controlled AI setup and our support for AI skills as a way to keep and attract good young people, without overpromising. Give me three concrete, low-cost things we could offer our team in the next 90 days, and a short, honest way to describe each one to a recruit without sounding like hype."
How to Get Started
You do not need to reverse course in public or admit the old policy was a mistake. You need to quietly replace a blanket no with a private setup the firm controls. Here is the order I use.
Find out what your team already uses
Ask, without blame, which public tools people already reach for and for which tasks. You will likely find more usage, and more client data on consumer accounts, than you expected. This is your real starting point, not a clean slate.
Stand up a private setup and one page of rules
Replace the ban with a firm-controlled tool and a short rule set: what is fine, what stays inside the private setup, what never goes near AI. Give people a safe lane so no one has a reason to use a public app again.
Train on real work and say it out loud
Run one hands-on session on a real task inside the private setup, and tell the team the firm supports this. The point is to move usage out of the shadows and signal that staying here keeps their skills sharp and their work safe.
What This Does Not Replace
Opening a safe door to AI is not the same as removing judgment. Every output that carries real downside, a filing, a coverage decision, a client letter, still ends at a human gate. A private setup and a rule set widen the safe lane. They do not remove the requirement that a person reviews and signs the work that goes out under your firm's name.
It also does not mean a generic vendor or a national consultancy can do this for you. A software vendor sells the same boxed product to a thousand firms and has no idea how your partners actually handle a high-touch client relationship, so their tool sits unused or, worse, gets fed client data it was never built to protect. A national consulting firm understands the strategy but moves at the speed of a committee, bills like one, and hands a boutique practice a slide deck instead of a working setup. Neither one sits down at your desk on the North Shore. This is close, hands-on work that fits how your firm already runs, and it is the kind of work an agile local builder is actually positioned to do.
That risk to your talent and your client data is live right now, on a phone in your office, whether or not you have looked at it. The next twelve months will widen the gap between firms that gave their people a safe lane and firms that did not, because the people doing the hiding are the same people the market is now paying a premium to poach. The AI readiness quiz takes about five minutes and gives you a quick read on where your firm stands. And if you suspect your current policy is quietly costing you good people and exposing client data on public tools, the free 30-minute AI audit is a direct way to see exactly where that exposure is and turn a hard no into a safe, private yes. In person on the North Shore or by video, no obligation, and no pitch deck.
Frequently Asked Questions
Is banning AI at my firm actually a problem if it protects client data? +
The intent is right, but a ban delivers the opposite. Surveys find most employees use AI anyway and many hide it, so a ban produces secret use on public consumer tools, which is far worse for confidentiality than a private setup with clear rules. You protect client data by removing the reason anyone reaches for a public app: give the team a firm-controlled tool, a one-page rule set, and for sensitive work a private local setup. A blanket no just moves your client data somewhere you cannot see it.
Why would banning AI cause me to lose good people? +
Your most ambitious people, often your youngest, expect to work with these tools and see AI skills as part of their future value. The market backs them up: PwC's 2026 Global AI Jobs Barometer found a 62 percent wage premium for workers with AI skills. A firm that forbids the tool reads, to them, as a firm letting their skills go stale. They keep using AI in private, on whatever public app they found, and start considering firms that support it safely and openly. The loss shows up as turnover, not as a policy violation.
Why not just buy a public ChatGPT or Claude subscription for the team? +
Because a generic public subscription is built for everyone and accountable to no one. It cannot be locked to your firm's rules, it cannot be audited the way a confidentiality obligation requires, and a consumer account gives you little control over how client data is handled. The professional answer is a private, firm-controlled setup: custom internal workflows on an approved business account, or a private local AI machine for the most sensitive work, both built around how your firm actually operates.
Can a national consulting firm or a software vendor handle this for me? +
Rarely well, for a boutique practice. A software vendor ships the same product to a thousand firms and does not understand how your partners manage a high-touch client relationship, so the tool goes unused or gets fed data it was never built to protect. A national consultancy moves at the speed of a committee and hands you a strategy deck, not a working setup. A small North Shore firm is better served by an agile local builder who sits down at your desk, builds the private workflow, trains your team, and leaves it in your control.
My team says they do not use AI. Should I take that at face value? +
Be careful. Leaders see heavy AI use at roughly a third of its real level, and more than half of workers say they hide it. A flat denial often means people do not feel safe saying yes, and that the use is happening on public tools you cannot see. Ask without blame, frame it as wanting to give them a safe tool, and you will usually learn the real picture is more use, on riskier tools, than you assumed.
Related Articles

What I Told Lake Forest College Students About AI — And Why It Matters for Your Firm
The same AI shift reshaping hiring is coming for professional services. Here's what I told Lake Forest College students — and why it matters for your firm.

How to Build and Effectively Use Claude Skills for Your Team
Someone writes a sharp prompt, and by Friday nobody remembers the wording. A Claude Skill turns your team's best prompt into a standing instruction Claude follows every time. Here is how to build and share one, no code and no developer.

Small PE Firms Don't Need More Associates
A two-person deal team can now run the sourcing, diligence, and monitoring work that used to take a full associate class. Here is what that shift actually changes for small PE and growth equity firms.
About the author
Written by
Michael Pavlovskyi
Founder, Bace Agency
Michael builds custom Claude and GPT workflows for insurance agencies, law firms, and PE firms on Chicago's North Shore. Speaker at Northwestern and Lake Forest College on practical AI adoption for professional services.
Connect on LinkedInWant to see how AI fits in your firm?
Book a free 30-minute AI audit. No obligation, no pitch deck.
Book a Free AI Audit →