AI Tools and Professional Standards: What the Rules Actually Say

Every CPA uses AI now, or will soon. Even something as routine as pasting text into ChatGPT or uploading a document to a cloud-based analytics platform counts. And every one of those interactions falls under professional standards that predate AI by decades.

The rules aren’t new. The way they apply is.

The AICPA Rule That Covers Everything

Section 1.700.001 of the AICPA Code of Professional Conduct (the Confidential Client Information Rule) prohibits members in public practice from disclosing confidential client information without specific consent. It’s been in the code for years. What changed is the definition of “disclosure” in practice (AICPA Code of Professional Conduct).

When a CPA enters client data into an AI tool, that data typically leaves the CPA’s environment. Depending on the tool’s terms of service, the provider may store it, use it for model training, or make it accessible to its employees. That constitutes a disclosure under Section 1.700.001, whether the CPA intended it as one or not.

The practical question: does the client’s consent to the engagement cover AI tool usage? In most cases, standard engagement letters don’t address it.

Federal Law Adds Criminal Stakes

IRC Section 7216 makes it a criminal offense for tax return preparers to disclose taxpayer information to third parties without consent. The statute doesn’t distinguish between disclosing data to a person and disclosing it to a software platform.

Separately, the FTC Safeguards Rule (16 C.F.R. Part 314), issued under the Gramm-Leach-Bliley Act, classifies tax preparers as financial institutions. Every firm that prepares returns for compensation is required to maintain a Written Information Security Plan, commonly known as a WISP. Solo practitioners included (IRS Publication 4557).

The WISP requirement isn’t new either. But a WISP written in 2020 almost certainly doesn’t address AI tool usage. And that gap is exactly what regulators would look at in an investigation.

The Standards at a Glance

StandardWhat It GovernsAI Relevance
AICPA Section 1.700.001Confidential client information disclosureEntering client data into AI tools constitutes disclosure to a third party
IRC Section 7216Unauthorized disclosure of taxpayer informationCriminal penalties if preparer shares return data with AI providers without consent
FTC Safeguards RuleInformation security for financial institutionsWISP is expected to address AI tool usage and data handling
IRS Pub 4557Safeguarding taxpayer dataPractical guidance on security plans; firms evaluated on documented processes
COSO GenAI Framework (2026)Internal controls over generative AIAI outputs treated as assertions requiring validation, not reliable facts

What “Reasonable Precautions” Means in 2026

The phrase shows up throughout data security guidance, but it’s rarely defined with the specificity CPAs want. In the AI context, reasonable precautions generally translates to three practices.

Know what happens to the data. Does the AI provider store inputs? For how long? Can provider employees access it? Is it used for model training? These answers vary across platforms and change with each terms-of-service update.

Classify before entering. Client names, Social Security numbers, EINs, and financial account numbers are generally not appropriate inputs for general-purpose AI tools. Anonymized or synthetic data can often achieve the same analytical result without the compliance exposure.

Document the approach. IRS Publication 4557 emphasizes that firms facing a data breach will be evaluated on whether documented processes existed, whether they were current, and whether staff knew about them. An undocumented AI policy is, for compliance purposes, the same as no policy.

Cloud vs. Local: Different Risk Profiles

Cloud-based AI tools (most popular chatbots and document analysis platforms) transmit data to external servers. Once that happens, the firm’s security perimeter no longer applies. The provider’s practices become the relevant standard.

Locally hosted models process everything within the firm’s own infrastructure. No client data leaves. The tradeoff is cost and technical complexity, but the compliance math is considerably simpler. For CPAs weighing the options, the question isn’t which approach is better in the abstract. It’s which risk profile fits the firm’s data sensitivity, client base, and technical resources.

The Bottom Line

In February 2026, COSO published guidance specifically addressing generative AI internal controls. One principle stands out: AI-generated outputs are probabilistic, not deterministic. Organizations are expected to treat them as assertions that require validation, not as reliable facts. For CPAs, that means any AI-drafted memo, calculation, or research summary goes through the same review process as work produced by a first-year staff member. Possibly more.

The professional standards governing client data haven’t changed. Confidentiality, data security, and reasonable precautions are the same obligations CPAs have always had. AI just introduced a new way to trigger them without realizing it. Knowing what the rules actually say, and where the WISP hasn’t caught up, is the baseline for any CPA using these tools in any capacity.

Posted in CPE