Answer yes if you have controls preventing client data being used in unauthorised AI tools, for example employees pasting it into personal ChatGPT or Claude accounts. Controls can be technical (blocking unauthorised AI domains/apps, DLP rules) or procedural (policy, training). Describe your safeguards in the notes section or upload evidence.