AI Help for Accountants › Guides › Ethics & confidentiality

AI, confidentiality, and the accountant's rules: what to clear before client data goes in

Before you put a client's ledger, return, or personal information into an AI tool, four rules apply: IRC section 7216, Circular 230, the GLBA Safeguards Rule with your firm's WISP, and the AICPA confidentiality rule. This page explains each in plain words and gives you the questions to ask a vendor. It is educational only, not tax, accounting, or legal advice, and your state board and firm compliance lead have the final say.

The short version:

What rules apply when you use AI on client data?

Four, and they overlap. Section 7216 governs consent for tax-return information. Circular 230 governs your competence and due diligence as a practitioner. The GLBA Safeguards Rule and the IRS-required WISP govern how you secure client financial data. The AICPA confidentiality rule governs disclosure of any confidential client information. None of them were suspended for AI, and none of them care that a tool is fast. The rest of this page takes them one at a time.

What is IRC section 7216, and does AI trigger it?

IRC section 7216 is a federal law with criminal and civil penalties. In plain words: if you prepare tax returns, you must get the client's consent before you use or disclose their tax-return information for anything beyond preparing the return. "Tax-return information" is broad -- it covers almost anything the client gives you to do the return. Putting that data into a third-party AI tool is a use or disclosure to the vendor, so it can require consent first. The safe move is to have the client sign the section 7216 consent language before any return data goes into a tool, and to keep tools that process return data inside terms you have reviewed.

What does Circular 230 require of AI-assisted work?

Circular 230 is the set of Treasury Department rules that govern people who practice before the IRS -- CPAs, enrolled agents, and attorneys. It requires due diligence and competence. Translated for AI: you may use a tool, but you stay responsible for what you sign, and you must understand the tool well enough to catch its mistakes. An AI answer is a draft, not an authority. If it invents a citation or miscodes an entry and you file it, that is on you, not the software. Build a review step into every AI-assisted task so the responsibility is met on purpose, not by luck.

What are the GLBA Safeguards Rule and the WISP?

The GLBA Safeguards Rule is a Federal Trade Commission (FTC) rule under the Gramm-Leach-Bliley Act. It requires financial institutions -- which the FTC reads to include tax and accounting firms -- to keep a written plan to protect customer financial information. The WISP, or Written Information Security Plan, is that plan. The IRS requires every tax preparer to have one. It says who can access client data, how it is stored, and what happens in a breach. When you add an AI tool, you have to fit it inside the WISP: note where the data goes, how the vendor secures it, and who can see it. If a tool does not fit your plan, the tool changes, not the plan.

What does AICPA rule 1.700 say about confidentiality?

Rule 1.700 is the confidentiality rule in the AICPA Code of Professional Conduct. A member cannot disclose confidential client information without the client's consent. Sending client data to an outside AI vendor is a disclosure to that vendor, so the vendor's data handling is your concern, not just theirs. The AICPA's tax-practice standards (the SSTS, or Statements on Standards for Tax Services) sit alongside it and set how you handle tax work. The takeaway is the same across all of them: know where the data goes, and get consent when the rule calls for it.

What to ask an AI vendor before client data goes in

Before any client ledger, return, or personal information reaches a tool, get written answers to these. Keep them with your WISP.

Ask the vendorWhy it matters
Do you train your AI models on our data? Can we turn that off in the contract?Training on your data is a disclosure risk under rule 1.700 and section 7216
How long is our data kept, and can we force deletion?Your WISP has to account for where data lives and how it ends
Who at your company can access our content, and under what controls?Access controls are core to the GLBA Safeguards Rule
Where is our data processed, and is it isolated from other customers?Separation reduces breach and cross-client exposure
Do you carry a security attestation such as SOC 2 Type II?An independent audit of the vendor's security controls is real evidence, not a promise

A vendor that answers cleanly is telling you something; so is one that will not. This review is the first step in our getting-started plan, and it comes before you run AI on bookkeeping or the tax workflow.

Common questions

Does IRC section 7216 apply when I use AI on tax returns?

Yes, it can. Section 7216 is a federal law that requires a tax preparer to get the client's consent before using or disclosing tax-return information. Putting return data into a third-party AI tool is a use or disclosure, so get written consent before you upload.

What is a WISP, and do I need one to use AI?

A WISP is a Written Information Security Plan -- a document that sets out how your firm protects client data. The IRS requires every tax preparer to have one. Any AI tool you add has to fit inside it, so update the WISP to cover the tool.

What does Circular 230 require when I use AI?

Circular 230 is the Treasury Department's rules for people who practice before the IRS. It requires due diligence and competence. In practice you can use AI, but you stay responsible for what you sign, and you must understand the tool well enough to catch its mistakes.

Can I put client data into an AI tool?

Only after you check the vendor's terms. Confirm in writing that the vendor does not train its models on your data, that you can delete your data, and that access is controlled. AICPA rule 1.700 treats sharing confidential client information without consent as a breach.

Is client consent always required?

Not always, but for tax-return information under section 7216 it often is, and some situations call for it under the AICPA rules too. When in doubt, get consent and document it. Your state board and your firm's compliance lead have the final say. A local pro can help you build the consent and vendor-review routine -- see the find a local pro tool below.

Last reviewed: 2026-07-24. This site is educational only -- it is not tax, accounting, or legal advice, and we refer local pros, we do not vet or endorse them. The rules named here are authorities to confirm with each vendor and your own firm's compliance lead.

Want help choosing and setting up?

Tell us your area and we'll point you to a local AI consultant who can run the vendor review, fit the tool into your WISP, and set the section 7216 consent language up before any client data goes in.

Find a local AI pro →
Find a local pro

Get these tools set up for you

Free to use. We take no cut of what you pay a consultant, and we refer rather than endorse.