Tax & Compliance

The IRS Just Issued a Warning About AI and Your Tax Data. Here Is What It Means for Your Business.

The rules that govern tax professionals apply fully to AI-assisted work. There is no AI exception, no grace period, and no “the computer did it” defense.

If your accountant or tax attorney is using artificial intelligence to prepare your returns, the IRS has something to say about it. And as a business owner, you should be paying attention, because the data at risk is yours.

On June 24, 2026, the IRS Office of Professional Responsibility (OPR) issued Alert 2026-19, “Introductory Guidelines for Responsible AI Use in Federal Tax Practice.” Its message is direct: the rules that govern tax professionals, Treasury Circular 230 (31 C.F.R. Part 10), apply fully to AI-assisted work. In the OPR’s words, technology is a powerful tool, not a substitute for professional judgment.

Here is what the warning actually says, and what it means for you.

The IRS’s Core Warning: AI Can Fabricate Data, and Your Data Can Leak

The bulletin identifies two risks every business owner should understand.

First, AI makes things up. Generative AI can produce fabricated outputs (hallucinations), bias, and opaque reasoning. Courts have sanctioned lawyers for filings containing fake citations, with penalties including financial sanctions of several thousand dollars, public censure, mandatory ethics courses, default judgments, removal from cases, and referrals to state bar authorities. And it is not just lawyers. The OPR cites a report Deloitte Australia prepared for the Australian government in 2025 that contained invented quotes attributed to a judge, references to non-existent reports, and books ascribed to the wrong author, all apparently produced by generative AI. Deloitte reportedly refunded part of its fee. If your tax professional files something built on fabricated AI output, the professional gets disciplined, but your return is the one that is wrong.

Second, and more important for you: AI tools can expose your confidential tax data. The OPR describes a risk most business owners have never considered: data a firm feeds into an AI system for one client can be repurposed by the program when answering questions about a different client. Your financials could literally bleed into someone else’s file. On top of that, uploading data to public or unsecured AI platforms risks unauthorized disclosure of tax return information, which carries civil and criminal penalties under IRC Sections 6713 and 7216(a), and separately violates Circular 230 Section 10.51(a)(15). “Tax return information” is defined broadly and includes your name, address, and identifying numbers (Treas. Reg. Section 301.7216-1(b)(3)). The IRS’s instruction to practitioners: handle all client data using only secure, enterprise-approved AI.

If your tax preparer pastes your financial statements into a free public chatbot, they may be violating federal law with your data.

Public AI vs. Private AI: What Is the Difference?

The bulletin tells practitioners to use only “secure, enterprise-approved AI” and to never upload sensitive data to public or unsecured systems. Here is what that actually means.

Public AI is the free, consumer version of a chatbot, used with no contract governing your data. Think free ChatGPT, free Google Gemini on a personal account, Meta AI inside WhatsApp or Instagram, or any chatbot someone signed up for with a personal email. On these platforms there is no agreement protecting confidentiality, inputs may be used to train the model, and the firm has no control over where the data goes or who can access it. When client financials are pasted into one of these tools, the information has left the firm’s control. Period.

Private (enterprise) AI is a tool deployed under a commercial agreement with real data protections: the provider commits in writing that your inputs are not used to train models, data is encrypted, access is controlled by the firm, and usage can be audited. Examples include Claude for Work, ChatGPT Enterprise, Microsoft 365 Copilot running inside a firm’s own Microsoft environment, Azure OpenAI deployments, and the AI built into professional research platforms like Westlaw Edge, Bloomberg Tax, and Lexis-Nexis, which the IRS bulletin itself mentions. Some firms go further and run AI models entirely on their own computers, so sensitive data never leaves the office at all.

The Three-Question Test
  1. Is there a signed commercial agreement covering confidentiality and data use?
  2. Does the provider commit in writing that inputs are not used to train its models?
  3. Can the firm control access, monitor usage, and delete data?

Yes to all three means enterprise-approved. No to any means the tool should be treated as public, and your data should stay out of it.

Watch for the trap in the middle: a paid individual subscription to a consumer chatbot is still not enterprise-approved, because the firm has no agreement, no administrative control, and no audit trail. The account belongs to the employee, not the firm.

A simple analogy: public AI is like discussing your finances in a crowded café, where you cannot control who is listening. Private AI is a conference room in your advisor’s office with the door closed and confidentiality agreements signed by everyone inside.

What the IRS Now Requires of Your Tax Professional

The bulletin walks through five Circular 230 provisions that directly affect the service you receive:

1. Due diligence (Section 10.22). Your practitioner must thoroughly review every AI-created document before it reaches you or the IRS, verifying the accuracy of facts, citations, and calculations. Sole reliance on AI is not permitted; human scrutiny and editing are essential.

2. Fees (Section 10.27(a)). This one goes straight to your bottom line. Billing clients for time not actually spent because AI did the work faster, or double billing for AI-assisted tasks, may constitute an “unconscionable fee.” The OPR says cost savings should be passed on openly, that practitioners should disclose the AI activities performed, and that they should fairly credit cost reductions to the client’s account.

3. Competence (Section 10.35). Practitioners must understand both the tax law and the AI systems they use, including how those systems generate content, their limitations, and where bias or errors can arise. Lack of technological competence, the OPR warns, could lead to improper advice or flawed filings.

4. Firm procedures (Section 10.36). Firm leaders must implement internal policies covering comprehensive staff training on AI risks, protocols for secure data handling and accuracy monitoring, and vetting of third-party AI tools, all documented. Leaders who fail to do so through willfulness, recklessness, or gross incompetence face discipline themselves.

5. Written advice (Section 10.37). Any written tax advice must rest on reasonable factual and legal assumptions. Practitioners cannot rely on AI projections or representations without verification: citations must be checked, cases read, and financial forecasts and formulas confirmed. If the AI system’s logic is opaque, relying on it may itself be unreasonable.

How This Affects Your Business

Your data security now depends on your practitioner’s AI practices. Your tax file contains everything: revenue, payroll, ownership structure, bank accounts, identification numbers. The cross-client contamination risk the OPR describes means sloppy AI practices could expose your information to strangers. You have a direct financial and legal interest in asking where your data goes.

Your bills should reflect AI efficiency. If AI cuts a five-hour research task to one hour, the IRS says you should not be billed for five. Business owners now have regulatory backing to ask how AI use affects fees. In the practice of law, many firms have historically charged a research fee for LexisNexis and Westlaw. An AI fee could be a charge we see in future invoices from attorneys and accounting firms, and the same transparency rules will apply to it.

Errors on your return are still your problem. Penalties, interest, and audit exposure land on the taxpayer first. The practitioner faces professional discipline, but you face the IRS. That is why the verification requirements matter to you, not just to them. A good practice here is to ask whether the service provider carries insurance that would respond if they make a mistake (such as AI coverage, cyber, directors and officers, litigation, or professional liability), and to evaluate whether audit insurance makes sense for your own business.

A licensed human must still sign off. No matter how much AI helped, final decisions must rest with qualified professionals who understand tax law and ethical standards. You are paying for judgment, and the IRS just confirmed you are entitled to it.

State law may add another layer. The bulletin notes that states including California, Colorado, Illinois, and Utah have enacted AI governance legislation focused on transparency, bias reduction, and consumer protection, and points to professional guidance such as ABA Formal Opinion 512 (July 29, 2024) on generative AI in legal practice. Responsible firms are tracking both federal and state obligations.

Five Questions to Ask Your Tax Professional Now

  1. Do you use AI in preparing my returns or advice, and for what tasks?
  2. Who personally reviews and verifies AI output before anything is filed or sent to me?
  3. Where does my data go? Are your AI tools enterprise-approved under a commercial agreement, or are they public consumer tools?
  4. If AI makes your work faster, how is that reflected in my bill?
  5. Does your firm have a written AI policy covering training, data security, and vetting of third-party tools?

These questions track the OPR’s own best practices list, which tells firms to establish secure data handling protocols, document AI usage and verification, train staff, vet third-party AI offerings before purchasing, never upload sensitive data to unsecured sites, and treat AI-generated text as a draft subject to thorough review. A practitioner who answers confidently is running a compliant, modern practice. A practitioner who gets defensive is telling you something.

The Bottom Line

The IRS is not banning AI in tax practice. The bulletin itself acknowledges that generative AI offers cost savings, rapid data analysis, and better research, and that virtually all professional tax firms already use some form of AI, whether they know it or not. What the IRS is saying is that the professional duties of diligence, competence, confidentiality, and fair billing do not bend for new technology. The accountability always lands on a human.

For business owners, this guidance is leverage. You now have an IRS-backed checklist for evaluating whether your tax professional is using AI responsibly, protecting your data, and passing efficiency savings on to you. Use it.

Sources: IRS Office of Professional Responsibility, Alert Issue Number 2026-19, “Introductory Guidelines for Responsible AI Use in Federal Tax Practice” (June 24, 2026); Treasury Circular 230, Regulations Governing Practice Before the Internal Revenue Service, 31 C.F.R. Part 10, Sections 10.22, 10.27(a), 10.35, 10.36, 10.37, and 10.51(a)(15); IRC Sections 6713 and 7216(a); Treas. Reg. Section 301.7216-1(b)(3); ABA Formal Opinion 512 (July 29, 2024).

This article is for informational purposes only and does not constitute legal or tax advice. Consult a qualified professional regarding your specific situation.