Skip to main content
Back to Insights
AI Advisory•Sep 26, 2026•8 min read•By Justin Kane

AI for CPA Firms: What Section 7216 and Client Confidentiality Actually Allow

For tax preparers, pasting client data into a public AI tool is not just a privacy question. It is a Section 7216 question. Here is what the rules actually allow and the controls that make AI defensible.

AI for CPA Firms: What Section 7216 and Client Confidentiality Actually Allow illustration

"Can accountants use ChatGPT?" is the question CPA firm partners actually type into search engines, and it is the wrong question. The right question is what data goes into which tool under what terms. For most professionals that is a confidentiality question. For tax return preparers, there is also a federal statute standing in the middle of it.

The statute most AI policies never mention

IRC Section 7216 restricts how tax return preparers may use and disclose tax return information, and it is a criminal provision: knowing or reckless disclosure or use outside what the regulations allow carries penalties, with a civil companion in Section 6713 that does not require intent. The IRS maintains a Section 7216 information center for practitioners, and the regulations under it define "tax return information" broadly. As a working rule, treat essentially anything a client furnishes in connection with preparing a return as covered.

Now put a public AI chatbot next to that. A staff accountant pastes K-1 detail into a consumer tool to draft a client email. Information furnished for return preparation has just been handed to a third party, under consumer terms the firm never reviewed and that may allow the provider to retain it. Whether any particular act crosses the line is a facts-and-circumstances question that deserves real legal advice. The point is that it is a 7216 question at all. Most firm AI policies, where they exist, never mention the statute.

What the consent framework means for AI tools

The 7216 regulations permit certain uses and disclosures without client consent, including some disclosures to contractors assisting with preparation under defined conditions, and they require specific written consent for most everything else, with detailed rules about form and timing. The framework was written for tax software, outsourcing, and cross-marketing. Nobody drafted it with chatbots in mind, which is exactly why firms need to reason carefully instead of assuming.

Four practical implications follow. First, consumer AI tools are close to indefensible for anything touching tax return information, because you have no agreement that even attempts to make the provider your service provider. Second, business-tier agreements matter enormously: they define the provider's role, and the major business tiers, including Anthropic's commercial terms, do not permit training on customer content by default. Third, the firm needs to decide in writing which tools, if any, may ever touch tax return information, and treat that category as its most restricted tier. Fourth, where a workflow depends on sending tax return information to a third-party tool, get specific advice on whether it fits an exception or requires consent, and if consent is needed, build it into the engagement process deliberately. This is not an area to improvise.

Tax is one concern. Audit and attest are another.

On the audit side the confidentiality duty is still there. The AICPA Code of Professional Conduct's Confidential Client Information Rule requires client consent before disclosing confidential client information, with limited exceptions, and it applies across the practice, not just to tax. But audit adds a second problem: evidence.

A workpaper has to show what was done, by whom, and who reviewed it. If AI drafted a memo, produced an analysis, or summarized support, and the file does not reflect how that output was verified, the firm has a workpaper integrity problem before anyone asks a privacy question. Peer reviewers will ask how the work was performed. For public company audit work, PCAOB inspections put weight on documentation and supervision, and "the tool wrote it and a reviewer skimmed it" is not a posture any firm wants to defend.

The defensible position is the same in both practices: AI is a drafting and processing aid whose output is reviewed and owned by the professional of record, and the file shows it, the way it would for work done by a first-year staff member.

Where AI genuinely helps a CPA firm

Document intake and organization. Client data arrives as a chaotic pile: scans, statements, prior-year files, photographed receipts. Sorting, naming, classifying, and filing that pile to firm conventions is repetitive, low-judgment work AI does well, and it is the same pattern we build in AI document automation: verify before acting, keep an audit trail, and a human ratifies the result.

Engagement letters and standard communications. First drafts from firm templates, tailored to the engagement, with a partner reviewing before anything goes out. Low risk, real hours saved, especially in the weeks when every engagement letter needs to go out at once.

Research and technical drafting, with review. A first draft of a technical memo is a legitimate use. A citation you did not verify is not. AI is at its most confident exactly when it is wrong, so the working rule is that every authority gets checked against the primary source before the memo carries the firm's name.

Busy-season triage. Summarizing long email threads, extracting open items, drafting status updates, turning a partner's dictated notes into a review checklist. Nothing client-facing without review, and nothing sensitive outside approved tools, but this is where hours quietly come back.

Notice the pattern. The wins are where risk is low and repetition is high. The judgment your clients pay for stays with the person whose name is on the return or the report.

The control set that makes it defensible

An approved-tools list on business terms. Named tools, business-tier agreements, no-training defaults, retention configured. Everything else is out, including consumer accounts, by policy and where possible by technical control.

A data classification keyed to obligation. Not by document type but by the duty attached: tax return information in the most restricted tier, other confidential client information next, internal and public material below. The classification tells staff which tool may touch which tier without requiring legal analysis at the keyboard.

Human review as a stated rule. The professional of record owns the output, and for audit work the file reflects the review. This is what keeps AI a tool rather than an unsupervised preparer.

Training and certification staff actually complete. A short, role-specific training and a recorded certification. It changes behavior, and it is the evidence you produce when a client, a peer reviewer, or an insurer asks how the firm controls AI.

Governance that matches reality. A policy that bans what your infrastructure quietly permits is aspirational. Pair the policy with configuration so the rules are enforced, not just written. That pairing is the core of AI governance as we build it, and an AI readiness assessment is the fastest way to see how far your current setup is from it.

Key takeaways

  • For tax preparers, client data in a public AI tool is a Section 7216 use and disclosure question, not just a privacy concern.
  • The consent framework was not written for AI, so decide in writing which tools may touch tax return information and get specific advice where consent may be required.
  • Audit adds workpaper integrity: the file must show how AI-assisted work was performed and reviewed.
  • The real wins are intake, engagement letters, drafting with review, and triage. Judgment stays with the professional of record.
  • Defensibility comes from approved tools on business terms, classification keyed to obligation, human review, and certified training.

Talk it through

Working out what your firm can safely do with AI before next busy season? Start with a 45-minute call.

Frequently asked questions

Related reading

More from the DoubleChecked library.

AI Readiness Checklist

The questions every regulated firm should answer before adopting AI

Free Guide
Free Executive Resource

The Regulated Firm's AI Readiness Checklist

Six questions that decide whether your firm can adopt AI without putting client data, a renewal, or an examination at risk. Walk them before your next audit, not after.

  • Where client data is leaving your environment through personal AI accounts
  • Whether your AI controls would survive a SOC 2 audit or an examination
  • Where a human, not the model, needs to ratify the output

We respect your inbox. Unsubscribe at any time.