Start with the part that will actually help you: you are not missing something.
You went looking for the rule about AI and client tax information. What you found was a criminal statute from 1971, a regulation whose relevant paragraph was written in 2008, a revenue procedure from 2013, and a great many careful people declining to finish a sentence. That is not you failing to find the answer.
That is the answer.
We went looking too, and came back empty. The IRS Section 7216 Information Center, the Section 7216 FAQ, the alerts out of the Office of Professional Responsibility, Circular 230, and the whole Federal Register rulemaking record behind the regulation, sixteen documents running from 1996 to 2018. We found no IRS ruling, revenue procedure, FAQ, Internal Revenue Manual provision, written determination or case applying Section 7216 to an AI assistant. Our search was wide and it was not exhaustive of IRS written determinations, which have no reliable full-text search. Take it as a floor, not a proof: as of August 2026, if there is an answer out there, it is well hidden.
Before anything else, so it colours the rest. We are an IT company. We are not lawyers, we cannot tell you what Section 7216 permits your firm to do, and nothing here is legal advice. What we can do is read the primary sources carefully, quote them exactly, and tell you what we see. We are in this room with CPA firms most weeks, and this question comes up in all of them now.
Everyone who could answer had a reason not to
Watch what each party actually did. Not what they said. What they did.
The IRS wrote about AI in June and answered nothing. On 24 June 2026 the Office of Professional Responsibility issued Alert 2026-19, “Introductory Guidelines for Responsible AI Use in Federal Tax Practice.” Item 6 names the exact provisions in play:
“IRC sections 6713 and 7216(a): Civil and criminal preparer penalties apply for unauthorized use or disclosure of tax return information. Section 10.51(a)(15) of Circular 230 also prohibits the willful disclosure or use of tax return information in an unauthorized manner, including in violation of the IRC.
GAI platforms may present risks regarding the unauthorized disclosure of sensitive taxpayer information, especially when data is uploaded to unsecured or public systems. Practitioners must strictly handle all client data using only secure, enterprise-approved AI. AI systems should be utilized with robust confidentiality safeguards firmly in place. Willful mishandling of taxpayer information through AI may lead to disciplinary actions under Circular 230.“
Read that again with an eye for what is absent. It sets a security standard. It does not say whether connecting an assistant is an authorized disclosure, it does not mention the contractor exception, and it does not mention client consent. The whole question turns on the word “unauthorized,” and the alert uses it without defining it. If anyone at the IRS believed this was already settled, that was the page to say so on. Four days later the Section 7216 FAQ page was refreshed, and it still contains no reference to AI.
Treasury already declined the argument your vendor is going to make. In the 2008 rulemaking, a commenter proposed letting preparers disclose to service providers under a Gramm-Leach-Bliley-style regime: a written contract limiting the provider’s use, careful vendor selection, contractual security requirements. Treasury:
“This recommendation was not adopted … the sensitivity of tax return information justifies affording tax return information stronger protections than other information subject to the GLBA.”
A separate proposal, to rely on the AICPA ethics rules instead, was turned down over the concern that information “would not be adequately protected if a tax return preparer could disclose tax return information to any third-party service provider without taxpayer consent to that disclosure.”
Look at the shape of what got refused: written contract, vendor diligence, contractual safeguards. That is a modern vendor data processing agreement, described in 2008 and declined. It is also, almost exactly, the security page every AI vendor will point you at. In fairness those passages answer a proposal for a broad new exception; they do not interpret the specific paragraph everybody argues about. They tell you the direction Treasury was facing. Treasury has not faced it again since.
The last formal word on any of this is from 2013. Revenue Procedure 2013-14 still governs the form of consents. Nothing since.
And the whole profession has been running on an untested theory for years. Cloud tax software holds live client returns. Hosted document systems, cloud backup, e-signature platforms, all of it, and nobody collects a per-client consent for any of them. We could not locate a single IRS statement placing hosted software inside the exception everyone assumes covers it. That practice rests on custom and on the absence of enforcement. It describes what firms do, which is a different thing from what the rule permits.
So here is the honest shape of it. The regulator that could answer wrote about AI and pointedly did not. The department that wrote the rule refused this structure once and has not revisited it. The last guidance predates every tool you are asking about. And the entire profession is standing on a floor nobody has ever inspected, which is a fine place to stand right up until someone looks down.
Nobody in that chain has an incentive to go first. Being wrong in public is expensive here in both directions: say no, and you have just told a few hundred thousand preparers that their existing software arrangements need consents. Say yes, and you have blessed something nobody fully understands yet. Silence costs whoever is silent nothing at all.
It costs you, though. You are the one with the decision on your desk.
What the words do settle
Four things are not in dispute, and they are the ones people get wrong.
Read-only does not get you out of it. The regulation defines disclosure as “the act of making tax return information known to any person in any manner whatever.” Restricting what a system may do with information is a different question from whether the information was made known to it. Same problem with pasting into a chat window, which is the version already going on in a lot of firms, quietly, without anyone deciding it.
A client’s name is tax return information. Expressly: “any information, including, but not limited to, a taxpayer’s name, address, or identifying number, which is furnished in any form or manner for, or in connection with, the preparation of a tax return.” The line people draw in their heads, never a Social, just the question, does less work than it feels like it does.
This is not a strict-liability statute, and that matters more than it sounds. Section 7216(a) reaches a preparer who acts “knowingly or recklessly.” Section 6713 adds a civil penalty of $250 for each disclosure, capped at $10,000 a year; Section 7216 makes it a misdemeanour. We are not going to tell you what clears the recklessness bar. We will point out that “recklessly” is a word about how you decided, which is why the file you keep about this decision is not busywork.
Your Safeguards Rule work does not answer this one. The regulation says so directly: GLBA requirements “do not supersede, alter, or affect the requirements of section 7216.” Two separate tracks. Everything in your WISP still applies, and none of it settles this. (The FTC Safeguards Rule for accounting firms, translated covers that track.)
One more, and it explains why this is landing on you now. IRS Publication 4557 is the Service’s own twenty-one-page guide to safeguarding taxpayer data, and the string “7216” does not appear in it anywhere. A plan built faithfully out of Pub 4557 never raised a consent question, because the publication never raises one. (Publication 4557, in six lines.)
The paragraph everybody is arguing about
There is one exception people reach for, and this is the whole of it:
“Disclosures to contractors. A tax return preparer may disclose tax return information to a person under contract with the tax return preparer in connection with the programming, maintenance, repair, testing, or procurement of equipment or software used for purposes of tax return preparation only to the extent necessary for the person to provide the contracted services, and only if the tax return preparer ensures that all individuals who are to receive disclosures of tax return information receive a written notice that informs them of the applicability of sections 6713 and 7216 to them and describes the requirements and penalties of sections 6713 and 7216. Contractors receiving tax return information pursuant to this section are tax return preparers under section 7216 because they are performing auxiliary services in connection with tax return preparation.”
Both readings are real, which is exactly why this has not resolved.
The five listed activities are programming, maintenance, repair, testing and procurement: all things done to software, by someone who builds it, fixes it, exercises it or supplies it. An assistant reading a mailbox all day is doing none of those. Against that, the regulation’s own stated reason for treating contractors as preparers is functional, “because they are performing auxiliary services,” and the rules already put software developers inside the preparer perimeter. And there is the practical argument that the narrow reading would put every cloud tax package in the profession offside.
Two conditions ride along regardless of which way it goes, and both get skipped.
The written notice is one of them. Not a courtesy: the regulation’s Example 2 describes a software provider’s employee viewing real client data for quality assurance and calls the disclosure impermissible “because Firm failed to ensure that C received a written notice” about Sections 7216 and 6713. Worth asking the practical version too, which nobody seems to: at a large AI company, who exactly receives that notice, and will they acknowledge it?
The second is what invoking the exception says out loud. Contractors covered by it are tax return preparers under section 7216, carrying the same penalties. Lean on this exception and you are asserting that your AI vendor is a tax return preparer. Ask whether your vendor would agree.
What we would actually do Monday
None of the above is a decision. This part is, and most of it is not legal at all.
Find out what has already gone in. A firm asking whether it may connect an assistant is usually already using one. Pasting sits outside every control anyone can configure, and it is a present-tense question, not a future one. Ask your people plainly and without heat.
Find out what the account can really reach. This gets described badly everywhere, including by us in an earlier draft of this page. An assistant’s actual reach is the overlap of three things: what the signed-in account has permission to open, what the connector was granted when somebody clicked approve, and which of those resources it actually indexes. At a small firm that overlap is usually wider than anyone pictures, because of things nobody remembers: an old shared mailbox, a site inherited through a group, a Teams channel with a scanned organizer in it. Writing it down is IT work and it belongs before the legal conversation, not after, or you will get advice about a setup you do not have.
Run it somewhere with nothing in it. An assistant pointed at an account holding no client tax information gives you a working tool this week and keeps this question out of it. Two honest caveats: that boundary is only as good as what people put in that account next month, and whether it changes your Section 7216 position is a question for your adviser, not for us. It is a containment pattern, and containment needs maintaining.
Ask the specific question, not the general one. “Can we use AI” gets you a shrug. This gets you an answer: does routing tax return information to a general-purpose AI vendor fall inside Treas. Reg. §301.7216-2(d)(2), and if not, what does a compliant consent look like for our client mix?
Write down what you decided and why. Because of that word “recklessly.”
If consent turns out to be the route
More structured than people expect, and more survivable. Treas. Reg. §301.7216-3 governs consent, Rev. Proc. 2013-14 governs its form. Consent comes before the disclosure, the regulation stating “No retroactive consent.” Knowing and voluntary, signed and dated, naming the specific recipient and the specific information, copy to the taxpayer at execution, one year by default where no duration is given.
Two that catch people out. Opt-out consents are not permitted, so a paragraph telling clients they may decline is not the instrument. And for Form 1040 clients the consent has to be its own separate signed document.
The revenue procedure specifies mandatory wording. We have not reproduced it here and we would not draft it for you.
Where to get a real answer
If your firm carries professional liability coverage, you are probably already paying for an advisory line.
CAMICO policyholders get consultation with, in CAMICO’s own words, no limit on frequency or duration, covering ethics and cyber, plus a technical tax specialist for federal tax issues. Firms insured through the AICPA program with CNA have a no-additional-charge line; read CNA’s own disclaimer alongside it, that advice through it “should not be viewed as a substitute for the guidance and recommendations of a retained professional.”
One thing to know before you spend the call: we could not verify that any of these produces a written answer. Every one is described as telephone or informal. On an unresolved question under a criminal statute, a call ending in “we would be cautious” may well be the answer, and it is still not a document you can put in a file. If you want something you can file, that is counsel, and an hour of the right lawyer’s time is cheaper than the version where you find out later.
Two that cannot help, so you do not waste the call: the IRS Practitioner Priority Service is described by the IRS as a channel for account-related issues, not tax law or ethics. And nobody should promise you a private letter ruling here; we could not verify one is available.
The part I would say across a table
Everybody in this story is being careful, and being careful is free for all of them. It is not free for you, because you are the one with a client’s return open and a tool sitting right there that would genuinely help.
So do the unglamorous things, which are the ones actually in your control. Know what has already gone in. Know what the account can reach. Keep the tool somewhere harmless until you have an answer you can point at. Ask the sharp version of the question to somebody you are already paying. Write down what you decided.
Then go back to work. This will get answered eventually, by somebody who finally has more to gain from saying it than from staying quiet. Until then, the firms that come out of this well will be the ones who can show what they did and why, which has been the answer to most of these questions for about thirty years.
If you want a hand with the technical half, bring the list of systems your firm’s email account can reach and we will go through it with you. Book a call.
Sources
- 26 U.S.C. §7216
- 26 U.S.C. §6713
- Treas. Reg. §301.7216-1 (definitions)
- Treas. Reg. §301.7216-2 (permissible disclosures, incl. the contractor exception)
- Treas. Reg. §301.7216-3 (consent)
- TD 9375, 73 Fed. Reg. 1058 (Jan. 7, 2008) — the rulemaking preamble
- Rev. Proc. 2013-14 — consent form and content
- IRS Section 7216 Frequently Asked Questions
- IRS Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024)
- IRS Office of Professional Responsibility, Alert 2026-19 (June 24, 2026) — IRS bulletin distribution; no irs.gov PDF published as of Aug. 5, 2026