General information, not legal advice. Start with the exact clause text. "No AI tools" clauses vary enormously: some ban AI-GENERATED deliverables, some ban feeding client materials into third-party AI services (usually a confidentiality concern), and some ban any AI-assisted tooling outright. Which one you have changes both the breach analysis and the conversation. A confidentiality-driven clause, for example, turns on whether client code or data actually left your environment and what the tool's data settings were, which is something you may be able to answer well.
On the money: acceptance of conforming deliverables matters, and a total forfeiture for a process violation on accepted work is an aggressive position for them to take. This is one where the specific wording, your acceptance records, and the tool's data-handling settings really decide it, so get the documents in front of a lawyer before anyone sends angry emails. A calm technical writeup of what the tool did and didn't access is often the thing that de-escalates it.