The Hidden Risks of Using AI With Taxpayer Data

AI and taxpayer data privacy risks for CPA firms and clients, featuring a confidential tax return, security lock, and AI technology.

Artificial intelligence is rapidly changing how CPA firms prepare tax returns, review financial information, draft client communications and perform research.

Used correctly, AI may help accounting professionals work more efficiently and identify issues more quickly.

But efficiency does not eliminate responsibility.

When a CPA firm enters a client’s tax information, financial records or personally identifiable information into an artificial intelligence platform, the firm may be disclosing that information to a third-party service provider.

That disclosure can trigger several separate legal and professional obligations.

For CPA firms, the issue is not merely whether the software promises that it will not train its models using customer data.

For clients, the issue is not merely whether they trust their CPA.

The more important questions are:

  • What information is being shared?
  • Which company receives it?
  • Why is the information being shared?
  • How long will it be retained?
  • Who may access it?
  • What other companies process it?
  • What happens if the provider changes its technology, policies or subprocessors?
  • Has the CPA firm independently evaluated and documented those risks?

A responsible discussion about AI in accounting should begin with these questions—not treat them as an afterthought.

A Client’s Tax Information Is More Than a Social Security Number

When people think about taxpayer-data security, they often focus on Social Security numbers, bank account numbers and identity theft.

Those risks are important, but tax return information can be much broader.

It may include:

  • A client’s name and address
  • Social Security numbers and employer identification numbers
  • Income and expenses
  • Bank and investment information
  • Business revenue and profit margins
  • Payroll records
  • Ownership percentages
  • Medical or dependent information
  • Retirement accounts
  • Estate-planning information
  • Property transactions
  • Pending tax disputes
  • Financial projections
  • Notes provided to the tax professional

Section 7216 of the Internal Revenue Code generally restricts a tax return preparer’s use or disclosure of tax return information without taxpayer consent unless a regulatory exception applies. The IRS maintains specific rules governing when consent is required and how certain consents must be presented.

This means that removing a Social Security number does not necessarily remove the firm’s §7216 obligations.

A client’s revenue, expenses, business structure or tax circumstances may still constitute protected tax return information.

What Does §7216 Require?

Section 7216 addresses whether a tax return preparer may use or disclose tax return information.

In some situations, disclosure to a service provider may fall within a regulatory exception. In other situations, the CPA firm may need the client’s prior written consent.

A proper analysis depends on:

  • The type of return involved
  • The information being disclosed
  • The recipient
  • Whether the recipient is located inside or outside the United States
  • The work the recipient will perform
  • Whether the recipient is making substantive tax determinations
  • How the information will be used

For individual Form 1040 clients, the IRS imposes particularly detailed consent requirements. A consent may need to identify the intended recipient, the information being disclosed, the purpose of the disclosure and the duration of the authorization.

The consent generally must be obtained before the disclosure occurs.

A broad statement buried in an engagement letter may not satisfy every applicable requirement.

Consent Is Not the Same as Due Diligence

This is one of the most important distinctions for both CPA firms and their clients.

A valid §7216 consent may authorize a CPA firm to disclose certain tax return information.

It does not establish that:

  • The vendor is secure
  • The vendor’s contract adequately protects the client
  • The firm evaluated the vendor’s subprocessors
  • The information will be promptly deleted
  • The vendor will never experience a security incident
  • The firm configured the software correctly
  • The disclosure is consistent with all other professional obligations
  • The client understood the practical consequences of the disclosure

Consent answers one question:

May the firm make this disclosure?

Vendor due diligence answers a different question:

Is this service provider capable of protecting the information, and has the firm taken reasonable steps to manage the risk?

A CPA firm may need to satisfy both.

The FTC Safeguards Rule Applies to CPA and Tax Firms

The FTC Safeguards Rule requires covered financial institutions to develop, implement and maintain administrative, technical and physical safeguards for customer information.

The IRS expressly directs professional tax preparers to maintain security plans and comply with applicable FTC requirements.

Among other requirements, a covered firm must oversee its service providers by:

  1. Taking reasonable steps to select and retain providers capable of maintaining appropriate safeguards;
  2. Requiring those safeguards by contract; and
  3. Periodically assessing providers based on the risks they present and the continued adequacy of their safeguards.

This requirement can apply whether the third party is:

  • An AI platform
  • A cloud storage provider
  • A tax software company
  • A bookkeeping contractor
  • An offshore preparation team
  • A domestic independent contractor
  • A customer relationship management platform
  • A document-processing service
  • An administrative support company

Calling a product “enterprise-grade” does not eliminate the CPA firm’s responsibility.

Neither does hiring someone as a 1099 contractor rather than an employee.

IRS Security Summit Resource

What Should a CPA Firm Review Before Using AI?

A CPA firm does not necessarily need to personally inspect an AI provider’s servers or source code.

However, the firm should obtain enough reliable evidence to make and document a reasonable risk-based decision.

A CPA firm should independently investigate a provider’s data-security practices rather than relying entirely on marketing claims.

That evaluation may include:

The correct legal entity

The firm should identify the entity with which it is contracting and the entity that will receive or process the information.

Brand names are not always the same as legal entities.

The applicable product

Consumer, professional, business, enterprise and API products may have different:

  • Data-use terms
  • Retention periods
  • Security controls
  • Administrative features
  • Contractual protections
  • Model-training policies

A firm should not assume that protections advertised for an enterprise product also apply to a personal or consumer account.

The contract and data-processing agreement

The firm should review:

  • Confidentiality obligations
  • Permitted uses of client data
  • Security requirements
  • Breach-notification terms
  • Data deletion provisions
  • Subprocessor rights
  • Audit rights
  • Indemnification provisions
  • Limitations of liability
  • Termination procedures

OpenAI, for example, offers enterprise privacy commitments and a data-processing addendum for qualifying business services. Its current materials state that business data is not used to train its models by default and that retention controls are available for certain products and organizations.

Anthropic similarly states that inputs and outputs from its commercial products are not used for model training by default.

Those commitments are relevant, but they are only part of the firm’s analysis.

Independent security reports

The CPA firm may request and evaluate:

  • SOC 2 reports
  • ISO certifications
  • Penetration-testing summaries
  • Vulnerability-management information
  • Incident-response procedures
  • Encryption documentation
  • Access-control policies

The firm should confirm that the report actually covers the product being used and review any exceptions, limitations and customer responsibilities.

Retention and deletion

The firm should determine:

  • Whether conversations are stored
  • How long data remains available
  • Whether deletion is automatic or manual
  • Whether backup copies remain temporarily
  • Whether zero-data-retention options are available
  • Whether retention settings differ among features

“Not used for training” does not necessarily mean “never stored.”

Authorized access

An AI provider must technically process submitted information to provide the service.

Depending on the applicable product, contract and circumstances, limited personnel access may also occur for reasons such as:

  • Security investigation
  • Abuse prevention
  • Technical support
  • Incident response
  • Legal compliance
  • Service administration

OpenAI’s data-processing terms describe safeguards involving personnel, access controls, monitoring, logging and breach response.

Anthropic has similarly stated that designated personnel may access certain conversation data on a need-to-know basis in specified safety and policy-enforcement circumstances.

The issue is therefore not that the provider can necessarily “do whatever it wants.”

The issue is that the data has left the CPA firm’s direct environment and is being processed within another company’s infrastructure under contractual, technical and legal controls that the client did not personally select.

Subprocessors

Large software providers frequently use additional companies for:

  • Cloud hosting
  • Data storage
  • Security monitoring
  • Customer support
  • Analytics
  • Authentication
  • Infrastructure services

The CPA firm should understand which subprocessors may receive or support the processing of client information and how changes to those subprocessors are communicated.

Why Data Aggregation Creates Risks Beyond Identity Theft

Identity theft is only one potential consequence of disclosing sensitive information.

Large collections of data may reveal patterns about:

  • Business profitability
  • Cash-flow pressure
  • Debt
  • Investment behavior
  • Health conditions
  • Family relationships
  • Estate-planning decisions
  • Pending transactions
  • Tax positions
  • Financial vulnerability

Individually, one piece of information may appear harmless.

Combined with other information, it may become much more revealing.

This is why data minimization matters.

A firm should not upload an entire tax return when a redacted summary, hypothetical example or isolated question would accomplish the same purpose.

Even where a vendor contract restricts the use of information, CPA firms should evaluate the consequences of:

  • Unauthorized access
  • Credential compromise
  • Accidental sharing
  • Incorrect workspace permissions
  • Insecure integrations
  • Vendor breaches
  • Governmental or legal demands
  • Changes in ownership
  • Changes in contractual terms
  • Misconfigured retention settings
  • Employees using personal AI accounts

The relevant question is not simply:

Will this provider train its model using the data?

The better question is:

What happens to this information from the moment it is entered until every retained copy is deleted?

How Circular 230 Fits Into the Discussion

Circular 230 governs practice before the IRS and imposes duties involving competence and due diligence.

Section 10.22 requires practitioners to exercise due diligence in preparing or assisting with returns and other documents, determining the correctness of representations made to the Treasury Department, and determining the correctness of representations made to clients regarding matters administered by the IRS.

Circular 230 is not the primary federal data-security law for CPA firms.

The FTC Safeguards Rule and §7216 provide more direct authority concerning data security and disclosure.

However, careless AI use can still affect a practitioner’s ability to satisfy Circular 230 duties.

For example, a CPA should not blindly rely on an AI-generated tax conclusion without:

  • Confirming the governing law
  • Checking whether authorities are current
  • Reviewing cited sources
  • Evaluating the facts independently
  • Correcting hallucinated or inaccurate information
  • Exercising professional judgment

AI may assist the CPA.

It does not replace the CPA’s responsibility for the final work product.

A practitioner cannot blindly rely on an AI output or another person’s work without exercising reasonable care.

Do All Contractors Require a §7216 Consent?

Not necessarily.

Some disclosures to domestic contractors performing permitted tax preparation, processing or auxiliary services may fall within regulatory exceptions.

Other arrangements may require prior taxpayer consent.

The answer depends on what the contractor receives, where the contractor is located and what the contractor does with the information.

A firm should never assume that someone may access taxpayer information merely because the person:

  • Signed a contractor agreement
  • Received a Form 1099
  • Works under the firm’s direction
  • Has accounting experience
  • Uses firm-provided software
  • Agreed verbally to confidentiality

The firm should separately evaluate:

  1. Whether §7216 permits the disclosure;
  2. Whether client consent is required;
  3. Whether offshore-disclosure requirements apply;
  4. Whether professional confidentiality rules require notice or consent;
  5. Whether the service provider has adequate safeguards;
  6. Whether the arrangement is documented in the WISP.

What Should Be Included in the Firm’s WISP?

A written information security plan should identify how the firm protects client information and manages reasonably foreseeable risks.

For AI and outsourcing, the WISP should address:

  • Approved AI platforms
  • Prohibited consumer accounts
  • Permitted and prohibited data
  • Redaction requirements
  • Vendor-approval procedures
  • User-access controls
  • MFA requirements
  • Workspace administration
  • Data-retention settings
  • Logging and monitoring
  • Contractor access
  • Offshore access
  • Incident response
  • Client-consent procedures
  • Annual or risk-based reassessment
  • Procedures when a vendor changes its terms

A WISP should not merely name the software.

It should document why the firm approved the software, the safeguards reviewed, the limitations imposed and who is responsible for ongoing oversight.

Questions Clients Should Ask Their CPA Firm

Clients have a legitimate interest in understanding where their information goes.

Before authorizing disclosure, a client may ask:

  1. Will any of my information be uploaded to an AI platform?
  2. Which company and product will receive it?
  3. Will you use a consumer, business or enterprise account?
  4. What information will be disclosed?
  5. Why is the disclosure necessary?
  6. Can the work be completed without sharing personally identifiable information?
  7. Will the provider retain the information?
  8. Is the data used for model training?
  9. Could provider personnel access the information?
  10. Which subprocessors may receive it?
  11. Is the information processed outside the United States?
  12. How did the CPA firm evaluate the provider?
  13. Does the firm maintain a WISP?
  14. What happens if I refuse consent?
  15. How long will my consent remain effective?

A client should not be pressured to sign a vague or unlimited consent without understanding the practical consequences.

If the client refuses consent, the firm may need to perform the work internally, use a different process or decline the engagement.

Questions CPA Firms Should Ask Before Uploading Client Data

Before entering client information into an AI tool, the firm should ask:

  • Is this information necessary?
  • Can it be redacted?
  • Is it tax return information under §7216?
  • Does an exception apply?
  • Is written consent required?
  • Is the account approved by the firm?
  • Does the contract prohibit model training?
  • What is the retention period?
  • Is zero-data retention available?
  • Have subprocessors been reviewed?
  • Has this vendor been added to the WISP?
  • Has due diligence been documented?
  • Has the vendor been reassessed recently?
  • Could the same task be completed using hypothetical facts?

If the firm cannot answer these questions, it probably should not upload the information yet.

A Practical Framework for Lower-Risk AI Use

CPA firms can use AI responsibly, but only after establishing controls.

A practical framework includes:

1. Inventory every AI use

Identify every platform being used by owners, employees and contractors.

Unauthorized “shadow AI” may create more risk than approved firmwide tools.

2. Classify the information

Separate:

  • Public information
  • Internal firm information
  • Confidential client information
  • Tax return information
  • Personally identifiable information
  • Highly sensitive financial information

3. Minimize the data

Use hypothetical or redacted information whenever possible.

Avoid uploading full source documents merely for convenience.

4. Conduct the legal analysis

Determine whether §7216 consent, professional notice or another authorization is required.

5. Vet the provider

Review the contract, security documentation, retention terms, subprocessors and access controls.

6. Configure the platform

Enable appropriate:

  • MFA
  • SSO
  • Administrator controls
  • Retention settings
  • Sharing restrictions
  • Audit logs
  • Connector restrictions

7. Update the WISP

Document the risk assessment, approval and required controls.

8. Train personnel

Employees and contractors should know what information may and may not be submitted.

9. Reassess the provider

Review material changes to:

  • Terms
  • Ownership
  • Security reports
  • Subprocessors
  • Features
  • Retention
  • Data-use policies

10. Preserve human review

Every tax conclusion, communication and work product should be reviewed by a competent professional.

The Bottom Line

Artificial intelligence can be useful to CPA firms.

But the discussion should not begin with prompts, automation or efficiency.

It should begin with:

  • §7216
  • The FTC Safeguards Rule
  • Professional confidentiality
  • Circular 230 diligence and competence
  • Vendor due diligence
  • Data minimization
  • Client understanding and consent
  • Documented ongoing oversight

A client’s signature does not eliminate the firm’s responsibility.

A vendor’s promise not to train on customer data does not mean the information was never transmitted, processed, retained or potentially accessed under limited circumstances.

And an “enterprise” label is not a compliance safe harbor.

The safest firms will not avoid AI entirely.

They will use it deliberately, document why each provider was approved, limit the information disclosed and remain accountable for protecting the clients who trusted them.

Concerned About How Your CPA Firm Handles Sensitive Financial Data?

Choosing a CPA firm is not only about tax knowledge. It is also about trusting the people, systems, contractors, and technology that may access your information.

At Corridor Consulting, we take a deliberate approach to taxpayer confidentiality, data security, vendor oversight, and the responsible use of technology. We help business owners and families navigate complex accounting, tax, and financial issues without treating privacy or professional judgment as an afterthought.

Start with our brief Discovery Chat Questionnaire so we can understand your situation and determine whether our firm may be a good fit.

Signup to receive notices of new insights

"Share the Wealth"

If you found this article valuable, why not share the wealth of knowledge? We’d be thrilled if you could pass it on to friends, colleagues, and your social network. Every share helps us reach and empower more people like you. Click the icons below to share and make a difference today!

Your sharing makes a huge impact in people’s lives – Thank you!

LinkedIn
Twitter
Facebook
Pinterest

This post is for educational and informational purposes only. It is not tax, legal, or investment advice and should not be relied on as such. Every individual’s personal and business situation is unique, and the ideas discussed here may not fit your specific facts and circumstances. Tax and legal rules change over time and may apply differently in your state or to your situation. Corridor Consulting is not a law firm and does not provide legal advice or legal representation. Before acting on any information in this post, you should consult with a qualified tax professional and a licensed attorney who can review your situation and provide advice tailored to you.

Skip to content