Every CPA uses AI now, or will soon. Even something as routine as pasting text into ChatGPT or uploading a document to a cloud-based analytics platform counts. And every one of those interactions falls under professional standards that predate AI by decades.
The rules aren’t new. The way they apply is.
The AICPA Rule That Covers Everything
Section 1.700.001 of the AICPA Code of Professional Conduct (the Confidential Client Information Rule) prohibits members in public practice from disclosing confidential client information without specific consent. It’s been in the code for years. What changed is the definition of “disclosure” in practice (AICPA Code of Professional Conduct).
When a CPA enters client data into an AI tool, that data typically leaves the CPA’s environment. Depending on the tool’s terms of service, the provider may store it, use it for model training, or make it accessible to its employees. That constitutes a disclosure under Section 1.700.001, whether the CPA intended it as one or not.
The practical question: does the client’s consent to the engagement cover AI tool usage? In most cases, standard engagement letters don’t address it.
Federal Law Adds Criminal Stakes
IRC Section 7216 makes it a criminal offense for tax return preparers to disclose taxpayer information to third parties without consent. The statute doesn’t distinguish between disclosing data to a person and disclosing it to a software platform.
Separately, the FTC Safeguards Rule (16 C.F.R. Part 314), issued under the Gramm-Leach-Bliley Act, classifies tax preparers as financial institutions. Every firm that prepares returns for compensation is required to maintain a Written Information Security Plan, commonly known as a WISP. Solo practitioners included (IRS Publication 4557).
The WISP requirement isn’t new either. But a WISP written in 2020 almost certainly doesn’t address AI tool usage. And that gap is exactly what regulators would look at in an investigation.
The Standards at a Glance
| Standard | What It Governs | AI Relevance |
| AICPA Section 1.700.001 | Confidential client information disclosure | Entering client data into AI tools constitutes disclosure to a third party |
| IRC Section 7216 | Unauthorized disclosure of taxpayer information | Criminal penalties if preparer shares return data with AI providers without consent |
| FTC Safeguards Rule | Information security for financial institutions | WISP is expected to address AI tool usage and data handling |
| IRS Pub 4557 | Safeguarding taxpayer data | Practical guidance on security plans; firms evaluated on documented processes |
| COSO GenAI Framework (2026) | Internal controls over generative AI | AI outputs treated as assertions requiring validation, not reliable facts |
What “Reasonable Precautions” Means in 2026
The phrase shows up throughout data security guidance, but it’s rarely defined with the specificity CPAs want. In the AI context, reasonable precautions generally translates to three practices.
Know what happens to the data. Does the AI provider store inputs? For how long? Can provider employees access it? Is it used for model training? These answers vary across platforms and change with each terms-of-service update.
Classify before entering. Client names, Social Security numbers, EINs, and financial account numbers are generally not appropriate inputs for general-purpose AI tools. Anonymized or synthetic data can often achieve the same analytical result without the compliance exposure.
Document the approach. IRS Publication 4557 emphasizes that firms facing a data breach will be evaluated on whether documented processes existed, whether they were current, and whether staff knew about them. An undocumented AI policy is, for compliance purposes, the same as no policy.
Cloud vs. Local: Different Risk Profiles
Cloud-based AI tools (most popular chatbots and document analysis platforms) transmit data to external servers. Once that happens, the firm’s security perimeter no longer applies. The provider’s practices become the relevant standard.
Locally hosted models process everything within the firm’s own infrastructure. No client data leaves. The tradeoff is cost and technical complexity, but the compliance math is considerably simpler. For CPAs weighing the options, the question isn’t which approach is better in the abstract. It’s which risk profile fits the firm’s data sensitivity, client base, and technical resources.
The Bottom Line
In February 2026, COSO published guidance specifically addressing generative AI internal controls. One principle stands out: AI-generated outputs are probabilistic, not deterministic. Organizations are expected to treat them as assertions that require validation, not as reliable facts. For CPAs, that means any AI-drafted memo, calculation, or research summary goes through the same review process as work produced by a first-year staff member. Possibly more.
The professional standards governing client data haven’t changed. Confidentiality, data security, and reasonable precautions are the same obligations CPAs have always had. AI just introduced a new way to trigger them without realizing it. Knowing what the rules actually say, and where the WISP hasn’t caught up, is the baseline for any CPA using these tools in any capacity.

