Yes for most of the work, and no for anything carrying a client's tax return information, unless an exception covers it or the client has already given written consent. The binding rule is not a vendor privacy policy. It is section 7216, it is criminal, and consent is its default. The useful half of the answer is that most of what a firm does all day carries no return information at all.

None of this is legal advice. It is a plain reading of the published regulations, and your own counsel has the last word on your firm.

The rule with teeth is criminal, not contractual

Almost everything written about accountants and AI argues about vendor privacy policies. The rule that governs a preparer predates all of it. 26 CFR 301.7216-1(a), read on the eCFR on 5 August 2026, puts it plainly: "Section 7216(a) prescribes a criminal penalty for tax return preparers who knowingly or recklessly disclose or use tax return information for a purpose other than preparing a tax return. A violation of section 7216 is a misdemeanor, with a maximum penalty of up to one year imprisonment or a fine of not more than $1,000, or both, together with the costs of prosecution."

A civil penalty sits on top. The same section describes section 6713(a) as "$250 for each prohibited disclosure or use, not to exceed a total of $10,000 for a calendar year." Per disclosure, which is an unhappy way to count a busy week of pasting.

Pasting a return into a general cloud tool hands the information to a third party, so it is a disclosure. The text allows nothing for small amounts, or for asking a tool to check arithmetic rather than do the return.

Everyone who touches the file counts

The regulation widens who is bound, and its own Example 1 says so plainly: "Under these circumstances, only R is a tax return preparer for purposes of section 7701(a)(36), but all four employees are tax return preparers for purposes of section 7216". The receptionist scanning 1099s is inside the rule alongside the person who signs the return.

The person most likely to try ChatGPT on a messy client document is rarely the signing preparer, so a policy written for the CPAs alone misses most of the keyboards.

Consent comes first, and it has a shape

Absent an exception, the order is fixed. 26 CFR 301.7216-3(a)(1) says a preparer "may not disclose or use a taxpayer's tax return information prior to obtaining a written consent from the taxpayer, as described in this section." Written, and beforehand.

The regulation then closes the obvious shortcut. Consent "must be knowing and voluntary," and "conditioning the provision of any services on the taxpayer's furnishing consent will make the consent involuntary." An engagement letter that makes AI processing a term of being a client is what the rule names.

Exhibit 1

Written consent is the default, and it happens before the paste.

Does the payload contain tax return information? If no, treat it like any everyday task. Does a §301.7216-2 exception cover a cloud AI processor? Unsettled. Ask your counsel. The (d)(1) route needs a preparer recipient, no advice, and US processing. Otherwise, written consent comes first Knowing and voluntary. Consent cannot be a condition of doing the work. Consent does not finish the job The Safeguards Rule still asks for a written program, contract terms and a periodic reassessment.
Note: this path is our reading of the regulations as published on the eCFR, retrieved 5 August 2026, and it is not legal advice. Step two is genuinely unresolved for cloud AI processing, so nobody can hand you a yes or a no on it, including us.

The exception nobody can settle for you

There are exceptions in 26 CFR 301.7216-2, and the nearest candidate is (d)(1). It permits disclosure to another preparer "for the purpose of ... obtaining or providing auxiliary services in connection with the preparation of any tax return, so long as the services provided are not substantive determinations or advice affecting the tax liability reported by taxpayers." It even contemplates an "electronic, mechanical, or other form of tax return processing service," which reads like it was written with machines in mind.

Two conditions make it awkward. The recipient has to be a tax return preparer itself, and the exception excludes substantive advice, which is exactly what people reach for a language model to get. A third is easy to miss: (d)(1) is framed around disclosure within the United States, so where your vendor processes the data bears on the analysis in a way it does not under HIPAA.

We are not going to tell you the exception applies, and we are not going to tell you it does not. As far as we can find, no authority has settled it for cloud AI. That is a question for your counsel, and a firm that leans on the exception without asking is betting on an untested argument.

A second rule, asking a different question

Section 7216 is not the only thing pointed at a tax firm. The FTC's own compliance guide for the Safeguards Rule, retrieved 5 August 2026, lists who counts as a financial institution and names the vertical outright: "credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, and investment advisors that aren't required to register with the SEC."

There is no signed-paperwork equivalent of a HIPAA business associate agreement here. 16 CFR 314.4(f) sets a standing duty instead: "Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards," "Requiring your service providers by contract to implement and maintain such safeguards," and "Periodically assessing your service providers." Select, contract, reassess.

SEC-registered advisers sit under Regulation S-P instead, at 17 CFR 248.30, which requires written safeguards policies and a response program whose notification duty expressly reaches an incident "that occurred at the covered institution or one of its service providers." Different regulator, same conclusion about your vendor.

Exhibit 2

One paste, two rules, and they are not asking the same thing.

One paste of client return data into a cloud AI tool 26 U.S.C. §7216 FTC Safeguards Rule WHAT IT ASKS Did you disclose or use the information? WHAT IT ASKS Do you have a written security program? WHAT KIND OF RULE Criminal misdemeanor, plus a $250 civil penalty each time WHAT KIND OF RULE Administrative, enforced by the Federal Trade Commission WHAT SATISFIES IT An exception in the regulation, or prior written consent WHAT SATISFIES IT Selection, contract terms and periodic reassessment WHO IT REACHES Everyone who handles the data, not only the signer WHO IT REACHES Tax preparation firms, named in the FTC's own guide
Note: a summary of two rules, not the rules themselves, drawn from 26 CFR 301.7216 and 16 CFR 314 on the eCFR plus the FTC's own compliance guide, all retrieved 5 August 2026. SEC-registered advisers sit under Regulation S-P rather than the Safeguards Rule.

The tier you buy decides what you can promise

Vendor terms do not answer the section 7216 question, but they decide whether you can satisfy the second column. Read on 2026-08-13: OpenAI does not train on business and API content by default, keeps API inputs up to 30 days for abuse monitoring, and gates zero data retention behind approval on specific endpoints. Anthropic's Commercial Terms say "Anthropic may not train models on Customer Content from Services" and, more useful in a contract file, "Customer Content is Customer's Confidential Information."

Google's terms for its unpaid services put it in bold: "Do not submit sensitive, confidential, or personal information to the Unpaid Services." That is a vendor telling you what its product is not for. These terms move, so re-read them before you rely on any of it.

None of that is client consent. A no-training clause governs the vendor's use of your data; section 7216 is about your act of handing it over. If the sorting is the part you are stuck on, we wrote about sorting which of your tasks actually contain client data, and about what running AI on a machine in your own office really costs for the narrow slice that cannot leave at all.

What a small firm can do this month

List the ten things people in the office would most like AI help with, then mark which ones carry return information. The unmarked ones can move to a business account today. Move everything else off personal accounts, which is where uncontrolled pasting happens.

Then write the policy down. One page: the approved tools, the data that never leaves the office, and the person to ask when it is unclear. Give it to every employee, not the credentialed staff alone, because that is who section 7216 covers. Put your AI vendors on the same service-provider list as your shredding company, with contract terms and a reassessment date. If you want a hand deciding this and writing it down with you, that is work we do.

Common questions

Can accountants use ChatGPT?

Yes, for most of it. Marketing copy, a job ad, an internal process note with no client in it: none of that is tax return information and none of it engages section 7216. What you type into the box draws the line, not the job you are doing, which is why the sorting happens task by task rather than tool by tool.

Is ChatGPT safe for client data?

Safe is the wrong axis, because two rules ask different things. Section 7216 asks whether you disclosed the information at all, and a business tier with strong terms is still a disclosure to a third party. The Safeguards Rule asks whether the vendor is selected, contractually bound and reassessed, where a business tier helps and a personal account cannot.

What should a CPA firm's AI policy cover?

Four things, at minimum. Which tools are approved and on which accounts. What data may never be entered, in terms your staff will recognize. Who reviews output before it reaches a client or a filing. And how you record consent when return information really is in play.

Start a conversation

All notes Start a conversation