Picture a partner's MacBook on a Friday afternoon. The firm has an AI policy, adopted last year after two long meetings: no client names in prompts, no confidential figures pasted into chatbots, approved tools only. Everyone signed it. And on 20 August, an update to a popular assistant dated the whole document in a single release note: on Apple silicon Macs, the assistant's desktop app can now read and search the entire Messages archive, iMessage, SMS and RCS included, and draft or send replies from it.
Nothing in that release note breaks any rule the firm wrote. The policy governs what people put into the tool. The new capability is about what the tool can reach on its own. If the partner ever discussed a client matter over text, a third-party model can now be granted standing access to that conversation history with a couple of clicks, and no decision recorded anywhere in the firm.
The same fortnight produced movement on the second neglected front: what vendors keep. One frontier lab announced, in preview, a safety architecture designed to detect abuse across conversations while retaining none of the customer's content, promising that when something trips a wire, the lab receives only "a narrowly defined signal" about the type of activity involved. The details arrive in a technical paper promised for September. The direction is what matters: retention has become a competitive axis, which means it is now a property you can select for.
This article maps the two gaps and gives you the four questions that close them.
Key takeaways
The policy most firms actually have
The typical accountancy AI policy is a well-intentioned artefact of 2024. It lists approved tools, bans client identifiers in prompts, requires human review of AI-assisted output and reminds staff that professional standards apply. As far as it goes, it is right.
Its frame, though, is the copy-and-paste era: a person, a text box, a decision about what to type. Every rule in the document assumes the data enters the tool because a human moved it there.
The frame breaks in two places
The first break is reach. Modern assistants request standing access to surfaces: browsers with logged-in sessions, email accounts, calendars, and now a message archive. Access is granted once, in a permissions dialog the policy never mentions, by an individual who may not think of a texting history as client data. From that point the tool does not need anyone to paste anything.
The second break is retention. The policy says nothing about what happens to content after the tool processes it. How long is it stored, who at the vendor can see it, which sub-processors touch it, does it train anything. Those answers differ sharply between vendors and between plans of the same vendor, and they are the first things a client, or an AML supervisor, would ask about.
A policy that governs typing governs yesterday's risk. Reach and retention are where the current questions live.
What changed in August 2026
Two announcements in the same fortnight make the abstract concrete.
The assistant that reads your texts
The release note of 20 August is admirably plain about scope: on Apple silicon Macs, the Apple Messages plugin "can read and search iMessage, SMS, and RCS conversations and prepare or send messages through Messages", with the user asked to approve messages and recipients before sending. It shipped as a general feature, no beta label.
For a firm, the operative fact is where this runs: on the partner's own machine, under the partner's own account, entirely outside any IT-administered boundary. The question "has anyone in the firm granted a model read access to years of client-adjacent conversation" now has no default answer. Someone has to go and find out.
The pattern extends beyond one vendor and one archive. Over the summer, frontier assistants have been offered standing access to browser sessions carrying logged-in accounts, and now to a message history. Each arrival looks incremental in its own release note. Read together, they describe a direction: the assistant is moving from a destination people visit to a layer that sits across whatever the user can already open. Policies written for the destination era need a clause for the layer era.
⚠️ Watch: the feature behaves as designed. The risk lives in where the access decision happens: a personal permissions dialog, on a personal device profile, recorded nowhere the firm looks.
The lab that promises to forget
The 19 August announcement runs the other direction. Zero-data-retention API processing already meant prompts and responses are not retained after a request completes. The new preview extends the promise to safety systems: cross-conversation abuse detection built so that flagged activity produces a category signal rather than a human reading the content. A technical paper is promised for September, and one narrow carve-out remains for illegal-imagery review.
Treat the specifics as a preview, because that is what the vendor calls it. Treat the trend as real: retention policies have entered the sales conversation, which means firms can now demand answers that vendors are competing to give.
The four questions
Put these to any AI supplier that touches client data, and keep the answers with the engagement records.
1. What is retained, and for how long?
The spread runs from zero-retention API processing to indefinite storage with human review. Ask for the answer per product and per plan, in writing. The consumer tier of a tool and its enterprise tier frequently keep different promises.
2. Who can read it?
Under what circumstances do the vendor's employees access customer content: support tickets, safety review, engineering debugging. A vendor that has engineered those paths narrow can describe them precisely. Vagueness is itself an answer.
3. Which sub-processors touch the data?
Model hosts, logging providers, evaluation services. Your AML supervisor's processor question does not stop at the first company in the chain, and neither should yours.
4. What leaves the boundary when something is flagged?
Every serious vendor runs abuse detection. The differentiating question is what crosses the wall when a flag fires: the content itself, or a narrow signal about activity type. August's announcements show the second design is possible, so it is fair to ask who has it.
In practice: file the four answers alongside your engagement letters, revisit them at renewal, and reopen the file whenever a vendor ships a feature that changes reach, the way the Messages plugin did. A policy review triggered by release notes beats one triggered by an incident.
A short audit you can run
The gap between policy and reality closes fastest with three small pieces of work, none of which needs a consultant.
The device sweep
Ask every fee-earner one written question: which AI tools on your machines hold standing access to mail, messages, files, calendar or browser sessions. Collect the answers in a spreadsheet with three columns: tool, surface, business justification. Most firms discover the register in under a week, and the surprises cluster on personal devices used for work. The sweep also surfaces the quiet duplicates, three transcription tools where the firm approved one, each holding its own copy of meeting audio.
The access register
Turn the sweep into a standing register, owned by whoever owns software approvals. New grants of standing access join the register through the same approval route as new software. The register does for reach what the approved-tools list did for inputs: it converts an invisible personal decision into a visible firm decision. Renewal dates go in the register too, because access granted for a project has a habit of outliving the project.
The retention file
Send the four questions from this article to every vendor on the register, and file the written answers with the firm's AML processor records. Two follow-ups keep the file honest: re-ask at each contract renewal, and re-ask whenever a release note changes what a tool can reach. A vendor that answered in specifics last year and answers in generalities this year has told you something worth knowing.
Key habit: subscribe someone to the release notes of every tool on the register. August proved the point: both of the developments this article covers arrived as routine vendor announcements, days apart, and neither used the word "policy" anywhere.
Where this lands for a UK practice
Confidentiality is not a preference in this profession. PCRT and the professional bodies' codes bind members to protect client information, engagement letters promise it contractually, and AML supervision adds a regulator who asks the processor question directly. An AI tool inserted into research or drafting sits inside all three frameworks, whether or not the policy mentions it.
That is the standard we hold our own product to. GAIN Tax answers tax research questions from primary sources, and the way we handle the data that reaches us is documented plainly on our security and data handling page, with the boundaries of the tool itself stated on limitations and responsible use. We publish an accuracy benchmark for the same reason this article recommends written retention answers: claims you can check beat claims you have to trust. For the wider selection framework, our pillar guide to choosing AI tax research software treats security and accuracy as two halves of the same evaluation.
The firms that navigate this well share one habit: they treat AI tax research tools as processors of client data first and productivity tools second. The order matters, because the first framing generates the questions the second one forgets.
Conclusion
August 2026 moved the AI risk conversation past the prompt box. Assistants now ask for reach into the places client information actually lives, and vendors have begun competing on how little they remember. Both developments reward the firm that asks precise questions and keeps the answers on file. The four above take an afternoon to put to your suppliers. The afternoon is cheap; discovering the answers mid-incident is not.
If your next supplier conversation is about tax research specifically, create a GAIN Tax account and put our answers to the same four questions side by side with anyone else's.
Frequently asked questions
Does the Apple Messages feature send texts without permission? As shipped, no. The release note states the assistant asks the user to approve the message and recipients before sending. Reading and searching the archive is the feature's core function once access is granted.
Is zero-retention AI processing available now? Zero-data-retention API processing exists today for eligible customers of some vendors. The safety-layer extension announced on 19 August 2026 is a preview, with a technical paper promised for September. Ask vendors what applies to your plan in writing.
Do these risks apply if we only use enterprise AI plans? Enterprise plans typically carry stronger retention terms, and the reach problem is unchanged: a desktop assistant granted access to a message archive or inbox operates under the device owner's permissions, whatever the plan. Policy needs to cover the permissions dialog, and that is a training question as much as a procurement one.
What should our AI policy add first? A rule that standing data access grants to AI tools (mail, messages, files, browser) require the same approval as installing software, plus a register of which tools hold which access. That single addition moves the decision out of personal permissions dialogs. Pair it with a short briefing for fee-earners on what a reach-granting dialog looks like, because the rule only works when people recognise the moment it applies to.
Who inside the firm should own vendor retention answers? Whoever owns AML processor records is the natural home, because the supervisor's question and the AI question are the same question. The answers should sit where engagement records live, not in a chat thread.
Does GAIN Tax train models on client questions? Our data handling practices are documented on the security and data handling page, which is kept current as the product evolves. We built the page so the answer to this question is checkable rather than anecdotal.

