top of page

The IRS Published AI Guidance for Tax Pros. There Is Not One New Rule in It.

Writer: cAIberOps (SY-ber-ops) | MSSP
cAIberOps (SY-ber-ops) | MSSP
Aug 20
6 min read

The IRS Office of Professional Responsibility issued its guidance on artificial intelligence on June 24, 2026. If you prepare returns for a living, it is the most direct word your regulator has offered on AI. Read it closely and you will notice something: there is not one new rule in it.

Every duty it applies to AI already existed. Due diligence on what you submit. Competence with the tools you use. Firm procedures and supervision. Verified assumptions behind written advice. Fees that reflect the work. And confidentiality, which the guidance grounds in two provisions older than most people using the tools.

That is not a gap in the rules. It is the point. The obligations that govern client data in your firm were written to outlast technology, and AI did not arrive with an exemption.

The machinery is older than the tools

Start with the part many preparers still find surprising: under the Gramm-Leach-Bliley Act, tax and accounting professionals are considered financial institutions. That is the IRS's own phrasing, not ours. That classification carries the FTC Safeguards Rule with it, and the Safeguards Rule is why every paid preparer with a PTIN is required by federal law to maintain a Written Information Security Plan. Not encouraged. Required. The IRS publishes a 28-page template, Publication 5708, so nobody has to start from a blank page.

Since May 2024 there is a clock attached: a security event affecting the unencrypted information of 500 or more consumers must be reported to the FTC within 30 days of discovery.

Then there is the older provision. Section 7216 of the Internal Revenue Code makes it a federal misdemeanor for a preparer to knowingly or recklessly disclose tax return information, or to use it for any purpose beyond preparing the return it was furnished for. Up to $1,000 in fines and up to a year in prison per violation, with the fine rising to $100,000 where identity theft is involved, and civil penalties under section 6713 alongside. Consent has to be signed before the disclosure or use happens. Retroactive consent is never valid.

Whether any particular AI entry crosses that line is a facts-and-consent question for your counsel, and we are not going to pretend otherwise. What is not in question is where the June guidance points: it ties practitioner confidentiality duties directly to sections 6713 and 7216, and it tells firms to handle client data using only secure, enterprise-approved AI, warning that public or unsecured platforms can expose confidential information.

A statute from 1971 and a banking law from 1999 turn out to be the actual AI rules for your profession.

What is actually happening inside firms

Now set that machinery against the profession's own numbers.

In the Blue J and CPA.com survey of more than 1,000 US tax professionals published in June 2026, 60% of tax firms use AI for tax research at least weekly. A year earlier it was 33%. It nearly doubled in twelve months.

And governance is not keeping up. In Karbon's State of AI in Accounting 2026 report, a global survey of nearly 600 accounting professionals, only 21% of firms have an AI policy or strategy, and fewer than half invest in AI training.

Put those two facts side by side. A written security plan is mandatory for every preparer in the country. An AI policy exists at roughly one firm in five.

The account question decides more than the tool question

Most firm conversations about AI are about which tool to allow. The exposure usually lives one level down, in which account the tool is signed into.

A firm's business agreement covers the firm's accounts. It does not cover the personal account a staff member is logged into on the same machine, where consumer terms apply and conversations can be used for model training unless the individual finds the setting and turns it off. Verizon's 2026 Data Breach Investigations Report found that regular AI use on corporate devices rose from 15% to 45% of employees in a single year, and that 67% of those users were signed in through non-corporate accounts.

The tool is the same. The terms are not. And nothing on the screen tells the person which side of that line they are on. During filing season, when a prior-year return needs summarizing at 9pm, the account that is already signed in is the account that gets used.

What it costs when it goes wrong

One number from IBM's 2026 Cost of a Data Breach report, and it is cross-industry rather than accounting-specific, so we will label it that way: employee use of unapproved AI tools was involved in 43% of security incidents, up from 20% the year before. Breaches involving shadow AI averaged $5.39 million, and one in five of them ended in a regulatory fine.

For a tax practice the stakes concentrate further, because return information is identity theft in kit form. Names, Social Security numbers, income, dependents, bank accounts for direct deposit. A firm's files are exactly what refund fraud is built from, which is why the IRS runs a Security Summit and why the WISP requirement exists at all.

The honest part

No regulator has brought a public enforcement action against a tax or accounting firm for staff putting client data into a consumer AI tool. Not the FTC, not the IRS, as of August 2026. If a vendor tells you the fines are already landing, ask them for the case.

There are also real open questions the June guidance did not answer, and the profession has noticed. It does not say whether preparers must tell clients that AI touched their return, a gap AICPA staff have publicly flagged. Anyone claiming the rules are settled is ahead of the facts.

What exists today is machinery: a mandatory security plan, a consent regime with criminal teeth, a guidance document pointing both at AI, and an examination environment that assumes your firm can answer for where client data goes.

Where a firm starts

Not with the policy. With the inventory.

Your WISP is supposed to describe how client data is protected. It cannot describe flows nobody has seen. You cannot train staff on tools you do not know they use. You cannot collect a section 7216 consent for a use you never detected. And if a client asks whether their return touched an AI system, you cannot answer from memory.

So the order runs the same way it has run for every industry in this series. Find out what is actually in use: every AI application, browser extension, plugin, and agent across the firm's machines, and which account each one is signed into. Sort it into sanctioned tools on firm accounts and everything else. Then write rules that name tools instead of categories. Then keep looking, because an inventory taken once describes a single Tuesday, and busy season installs things.

Where we fit, and where we do not

We are a managed security provider. We are not your compliance counsel, we do not write your WISP, and we do not collect your consents. Be wary of a security vendor who offers to.

What we run is the layer those documents assume is already working. Our Managed AI Security service starts with a free AI Discovery: a light install, about a week of quiet observation, then a report of every AI tool, extension, and agent in use across your machines, including which are running on personal accounts, risk ranked in plain English. Nothing changes for your staff while it runs, and the report is yours whatever you do next.

From there we enforce what you decide, on the tools you approve, and keep watching as new ones appear. None of it guarantees compliance, and no honest vendor would say otherwise. It supports the safeguards your WISP already commits you to, and it produces the one answer the rest of your obligations quietly depend on.

More on how this looks for accounting practices specifically: cybersecurity for accounting and CPA firms.

The question worth asking before October

Not "do we have an AI policy." Ask instead: if a client asked tomorrow which AI tools have touched their return information, and on whose accounts, could this firm answer with a record rather than a guess?

Most firms cannot yet. That is a solvable problem, and it is free to start solving.

If you run a tax or accounting practice in Washington DC, Northern Virginia, or Maryland and want a plain-English read on where you stand, book a free 15-minute call.

Comments


bottom of page