AI & Client Data: the rules
§7216, the Safeguards Rule/WISP, and what's required before AI touches client data.
1. Your account tier decides what client data can go in
Every module in this playbook links back here. AI can save you real hours, but you're a licensed professional handling other people's money and confidential data, and the rules that govern you don't pause because a tool is new. As of June 2026 the IRS has said this directly: OPR Issue 2026-19 ("Introductory Guidelines for Responsible AI Use in Federal Tax Practice") applies Circular 230 to AI in tax practice, so the duties below now carry the IRS's explicit signature. These are the six rules that keep AI use safe, compliant, and defensible. Make the compliant path your default path and you never have to think about it again.
The first question before any client data touches an AI tool is what kind of account you're on, because the contract behind the account is what changes. (PII = names, SSNs, EINs, account numbers, addresses, and identifiable financial detail.)
- Personal / consumer plan (Free, Pro, Max): your inputs can be used to train the model unless you've opted out, and no data-protection agreement stands behind you. → Anonymize. Keep real client data out. "The client," "$X," "[STATE]," "Entity A", the AI's help is just as good on a scrubbed fact pattern. (Anthropic's consumer training and opt-out terms have shifted over time; verify the current terms rather than assume.)
- Firm-approved Team / Enterprise plan (commercial terms): your inputs are contractually excluded from model training, and a Data Processing Addendum (DPA) is included automatically, you don't have to negotiate it. → Real client data is permissible once you also have the §7216 basis and WISP coverage in Rule 2. If you'll routinely work with real client context, this is the right setup, not the free consumer app.
- ⚠️ Team/Enterprise is not a magic word. Sending tax return information to any third-party tool is still a disclosure under §7216, just a far more defensible one. The commercial tier makes it defensible, not automatic. (Zero Data Retention is a separate, hard-to-obtain control, it is not required and its absence is not a blocker.) See Regulatory Foundation for the full tool-tier analysis.
The floor, on either tier: keep Social Security numbers and EINs out, every time. They're the highest-risk identifiers and the easiest to strip.
2. Know the obligations that make Team/Enterprise use defensible
The commercial tier opens the door; these are what keep you on the right side of it. Two rules reach AI use directly:
- IRC §7216: As a tax return preparer you generally cannot disclose or use a client's tax return information without consent, and sending it to a third-party AI service can count as a disclosure. Two ways to stay clean:
- Anonymize so there's nothing to disclose, or
- keep it to low-level prep support (OCR, summarizing, extracting, classifying, formatting, workpaper cleanup) used only to prepare that client's return, which generally fits an exception, while substantive tax advice, offshore access, or anything the vendor trains on puts you back in get written consent or don't. See Regulatory Foundation for the consent mechanics.
- FTC Safeguards Rule (Gramm-Leach-Bliley): Your firm must have a Written Information Security Plan (WISP), and any AI tool you adopt should fit inside it: data-protection terms, access controls, no training on your data. A Team/Enterprise plan with its automatic DPA is built to fit; a consumer plan is not.
When in doubt: anonymize, or use your firm-approved tool with the §7216 basis in place. That one habit covers most of your exposure.
3. AI is not a source of law: verify every citation
General AI models (Claude, ChatGPT, Gemini) confidently invent Code sections, Treasury Reg cites, case names, rulings, and dollar thresholds that look perfect and don't exist.
- Use general AI to frame the question, structure the analysis, and draft the memo, not as the authority.
- For answers you'll rely on, use citation-grounded tax research tools (CCH AXcess Intelligence, Thomson Reuters CoCounsel, Blue J, TaxGPT, etc.) and confirm every cite against the primary source before it goes in a memo, return, or client answer.
- If you can't verify a citation, treat it as wrong until you can.
4. You are the reviewer of record
AI drafts, organizes, and speeds you up. You review, decide, and sign. Nothing AI produces goes to a client, a taxing authority, or a workpaper file without your competent review. This isn't just good practice. Circular 230 holds you to competence and due diligence, and your state board and the AICPA Code of Professional Conduct hold you to professional judgment that you cannot delegate to a model.
5. Stay inside your professional standards
- Circular 230: competence (§10.35, which includes understanding how your AI tool works and where it fails) and due diligence (§10.22) in practice before the IRS.
- Firm procedures (Circular 230 §10.36): if you run a firm, have a written AI policy (which tools are approved, for what, and what is off-limits), train your staff on the risks, vet AI vendors in writing, and document it. OPR Issue 2026-19 made this explicit for AI.
- AICPA Code of Professional Conduct & Statements on Standards for Tax Services (SSTS): integrity, objectivity, due care, confidentiality.
- SSARS / GAAS: if your work includes compilations, reviews, or audits, the standards (and independence requirements) still apply to AI-assisted work product.
- Your state board of accountancy: you're licensed at the state level; when a rule turns on jurisdiction, check your board.
6. Bill for the work, not the hours AI saved you
This one is new, and most firms have not thought about it. OPR Issue 2026-19 put fees on the table under Circular 230 §10.27(a) (unconscionable fees). If AI turns a three-hour task into ten minutes and you bill the three hours anyway, or you double-bill AI-assisted work, OPR says that can be an unconscionable fee, especially as a pattern across clients.
Do this instead: disclose your AI use to the client (general terms are fine) and credit the efficiency you gained back to their bill. Everyone has focused on confidentiality; this is the duty that catches people off guard.
The one-line version
Personal account: anonymize. Team/Enterprise: real client data is OK with your §7216 basis and WISP coverage. Keep SSNs and EINs out either way. Verify before you rely. And the license, and the signature, are yours, not the AI's.
If anything in a module ever seems to conflict with this page, this page wins.
Want the "why" behind these rules?
See Regulatory Foundation for the cited, fact-checked detail on each obligation, IRC §7216/§6713 consent mechanics, the FTC Safeguards Rule/WISP service-provider duties, the revised SSTS, OPR Issue 2026-19 (the IRS's first written AI guidance, including the new billing-transparency duty), and the proposed Circular 230 technological-competence amendment, plus a pre-flight checklist and an honest list of what's still an open question.