FTC Safeguards Rule and AI for tax preparers

No rule is written for AI at a tax firm. Here is how the Safeguards Rule, IRS Pubs 4557 and 5708, and section 7216 apply to it, with a WISP addendum.

King & Company, updated

In short

No federal rule is written specifically for AI at a tax or accounting firm, and IRS Publications 4557 and 5708 do not mention it. The FTC Safeguards Rule already treats an AI vendor as a service provider and an AI workspace as an information system, so the firm's existing duties on vendor contracts, access, MFA, encryption, logging, disposal, and training cover it. Section 7216 is a separate question about disclosure and use of return information, and whether consent is needed for an AI vendor is not settled, so take it to counsel.

The FTC Safeguards Rule has no provision written for AI, and tax preparers who want to use AI on client work are governed by the same rules that already cover their tax software, their portal, and their IT provider. Under those rules an AI vendor is one more service provider and an AI workspace is one more information system, and section 7216 adds a separate question about disclosure and consent that the firm's counsel has to answer.

This article reads the primary sources and maps each requirement to the AI decision it governs. It describes what the documents say. It is not legal advice, and the person who signs your written information security plan should confirm each point with the firm's counsel.

Which rules apply to a firm that prepares returns?

Three sets of rules do most of the work.

The first is the FTC Safeguards Rule, issued under the Gramm-Leach-Bliley Act. The FTC's guidance lists tax preparation firms among its examples of covered financial institutions, alongside "credit counselors and other financial advisors," which is why advisory firms should check their own coverage too.

The second is the IRS guidance that points preparers to that rule. Publication 4557 says that under the Safeguards Rule tax return preparers must create and enact security plans to protect client data, and Publication 5708 gives the outline and a sample template for the written information security plan, the WISP.

The third is Internal Revenue Code section 7216 and its civil counterpart, section 6713, which restrict how a preparer may disclose or use tax return information. This one is about confidentiality and consent, and a firm can have sound security and still have a section 7216 question to resolve.

What do Publication 4557 and Publication 5708 say about AI?

They say nothing about it. We downloaded Publication 4557 (Rev. 6-2024) and Publication 5708 (Rev. 8-2024) from irs.gov on October 2, 2026 and searched the text of both. Neither contains the term "artificial intelligence" or the abbreviation "AI." If you are reading this later, check whether either publication has been revised.

That absence is worth keeping in mind when a vendor describes an AI product or plan as meeting IRS requirements. Neither publication approves, rates, or names any AI product, and a search of both for ChatGPT, Claude, and Copilot also came back empty. What they do contain are duties that fall on the firm. Publication 4557 tells preparers to select service providers that can maintain appropriate safeguards, make sure the contract requires those safeguards, and oversee their handling of customer information. It also says multi-factor authentication "is required for all companies regardless of size." Publication 5708's sample plan has the firm list where client information is stored, including web-based and cloud applications, and says third-party access will be "the minimum required to conduct business."

Your AI vendor is a service provider: what does the Safeguards Rule require of you?

The rule defines a service provider as any person or entity that "receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution." An AI vendor that processes a client's W-2s, K-1s, or prior-year return on the firm's behalf fits those words. We did not find an FTC statement that addresses AI vendors by name, so treat this as a reading of the definition and confirm it with counsel.

If the vendor is a service provider, section 314.4(f) asks three things of the firm:

  1. Take reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue.
  2. Require those safeguards by contract.
  3. Periodically assess the provider based on the risk it presents and the continued adequacy of its safeguards.

In practice this means the firm needs a contract with the AI vendor in the firm's own name, with terms the firm has read. A staff member's personal account on a consumer plan gives the firm no contract to point to. Vendor terms differ by plan, and we cover how to read them in what happens to data you send to an AI model.

How do access, MFA, encryption, logging, and disposal apply to an AI workspace?

The rule's definition of an information system covers electronic resources that contain customer information or are connected to a system that does. An AI workspace that staff upload client documents into, or that is connected to the firm's document management system, falls inside that description. The safeguards in section 314.4 then apply to it the way they apply to everything else.

What the rule requiresThe AI decision it governs
Limit access to authorized users, and to the customer information they need for their duties, 314.4(c)(1)Who has a seat in the workspace, which projects or folders each person can open, and which connectors each person can use
Multi-factor authentication for any individual accessing any information system, unless the Qualified Individual approves an equivalent control in writing, 314.4(c)(5)How each person signs in to the AI workspace, whether MFA is enforced on every seat, and whether any shared logins exist
Encryption of customer information in transit over external networks and at rest, 314.4(c)(3)Confirm in the vendor's documentation and contract how data is encrypted, and record it in the vendor file
Monitor and log the activity of authorized users, 314.4(c)(8)Whether the plan gives the firm audit logs, who reviews them, and how often
Secure disposal no later than two years after last use, subject to the rule's exceptions, and periodic review of retention, 314.4(c)(6)The retention setting for chats, uploaded files, and project knowledge, set deliberately and matched to the firm's record retention policy
A risk assessment as the basis of the security program, 314.4(b), in writing unless the small-firm exception below appliesThe AI tool, the plan, and the data it touches appear in the assessment
Security awareness training updated to reflect identified risks, 314.4(e)Staff training covers what may go into the tool and what may not

Two further points from the rule are worth knowing before an incident. The firm must notify the FTC within 30 days of discovering a notification event that involves the unencrypted information of at least 500 consumers, and the rule's definition of customer information includes records handled or maintained on the firm's behalf. State breach laws and the firm's insurance policy have their own notice terms, which counsel and the carrier should walk through.

The other point concerns small firms. Section 314.6 excuses firms that maintain customer information on fewer than five thousand consumers from four provisions: the written risk assessment in 314.4(b)(1), the continuous monitoring or penetration testing in (d)(2), the written incident response plan in (h), and the annual written report in (i). The service provider, access, encryption, MFA, disposal, logging, and training requirements are not on that list. Publication 5708 also states that tax and accounting professionals are considered financial institutions "regardless of size."

Section 7216: disclosure, use, and the consent question

Section 7216 is a criminal provision that, in the IRS's words, prohibits preparers from "knowingly or recklessly disclosing or using tax return information." A convicted preparer may be fined up to $1,000, imprisoned up to one year, or both, for each violation. Section 6713 adds a civil penalty of $250 for each disclosure or use, capped at $10,000 per calendar year outside the identity theft cases, and the IRS FAQ notes that the civil penalty "does not require that the disclosure be knowing or reckless."

The definition is broad. The same FAQ describes tax return information as all the information a preparer obtains "in any form or manner that is used to prepare tax returns or is obtained in connection with the preparation of returns." A client's source documents, the organizer, and the workpapers are all inside it.

When a firm sends that information to an AI vendor, the question is whether the transfer falls within a disclosure the regulations permit without consent. Treasury Regulation 301.7216-2 has two provisions that practitioners point to:

  • Paragraph (d)(1) permits disclosure to another preparer located in the United States for preparing a return or providing auxiliary services, "so long as the services provided are not substantive determinations or advice affecting the tax liability reported by taxpayers." It defines a substantive determination as "an analysis, interpretation, or application of the law."
  • Paragraph (d)(2) permits disclosure to a contractor "in connection with the programming, maintenance, repair, testing, or procurement of equipment or software used for purposes of tax return preparation," only to the extent necessary, and only if the people receiving the information get written notice that sections 6713 and 7216 apply to them.

The IRS FAQ also states that if the other preparer is located outside the United States, the taxpayer must sign a consent, and that a valid consent must be signed and dated by the taxpayer and include specific required language.

What is settled and what is still argued?

The settled part is short. Return information is protected, the civil penalty does not require that a disclosure be knowing or reckless, consent has a prescribed form, and a disclosure to a preparer located outside the United States needs the taxpayer's consent.

The argued part is how an AI vendor fits. Writing in the AICPA's Tax Adviser, Edward R. Jenkins, CPA takes the view in a February 2024 column that both firm-owned and hosted generative AI systems "will likely fall within the definition of 'auxiliary services'" and so would not require consents for disclosure. In the same column he asks how these systems will steer clear of use and disclosure violations, and tells readers to consider where the system is located, because consents differ between domestic and non-U.S. disclosures.

A more cautious reading starts from the regulation's own limits. If the tool is asked to analyze or apply the law to a client's facts, that looks closer to a substantive determination than to data entry. If the vendor processes data outside the United States, the offshore consent rule comes into view. If the vendor's terms let it use customer content for its own purposes, that raises the use side of the statute. The IRS FAQ, marked as last reviewed or updated on June 28, 2026, does not mention AI, so neither reading has been confirmed by the IRS. This is the question to put to counsel in writing, including whether a consent in the engagement letter is the simpler course for your firm.

What should you add to your WISP?

Publication 5708's outline has sections for risk assessment, inventory, safety measures, and attachments. An AI addendum can sit as one more attachment. The outline below is our suggestion for what it should hold, written to be adapted, and it is not an IRS or FTC form.

  1. Tools and plans in use. The AI product, the plan name, the contracting entity, the contract date, and who administers it.
  2. Data in scope. Which categories of client information may be entered, which may not, and which client groups are excluded.
  3. Service provider file. The contract and data terms relied on, the vendor's security documentation, the date of the last reassessment, and the date of the next.
  4. Access. Who has a seat, how seats are approved and removed, and the sign-on method with MFA.
  5. Connected systems. Each connector or integration, what it can read and write, and who approved it.
  6. Retention and disposal. The retention setting in the workspace and how it lines up with the firm's record retention policy.
  7. Logging and review. What activity is logged, who reviews it, and how often.
  8. Human review. Who reviews AI-assisted output before it reaches a return or a client, and how that review is recorded.
  9. Section 7216 position. Counsel's conclusion on consent, the consent language if one is used, and the written notice given to contractors.
  10. Training and incidents. When staff were trained on this addendum, and how an AI-related event feeds into the firm's incident response plan.

The staff-facing version of items 2 and 8 belongs in the firm's AI acceptable use policy, so that people have one page to follow.

A setup that keeps the answers simple

Most of the questions above get harder as the number of tools, accounts, and parties grows. A firm can keep them manageable with five choices:

  • One business workspace under the firm's own contract, so there is one vendor file to maintain.
  • Sign-on through the firm's identity provider with MFA, so access follows the same joiner and leaver process as everything else.
  • Retention set on purpose and written into the addendum.
  • Connectors limited to what a specific workflow needs, added one at a time.
  • A named reviewer on every return-related output, which is also what a well-designed review step looks like in any workflow.

King & Company works inside the client firm's own AI workspace, so the workflows, skills, and client documents stay in the firm's environment. An outside engineer who can see return information is still a person with access, so we expect a firm to list us in its service provider file, and to ask counsel how section 7216 applies to us as well. The broader setup is described in how to set up secure AI workflows for confidential client data.

Questions to take to your counsel and your IT provider

For counsel:

  • Does our use of this AI vendor fall within a permitted disclosure under Regulation 301.7216-2, and on what reasoning?
  • Should our engagement letter include a section 7216 consent that names the AI vendor, and what language is required?
  • Does any task we plan to give the tool amount to a substantive determination?
  • What written notice do we owe contractors who can see return information?
  • Which state privacy and breach laws apply in addition to the federal rules?

For the IT provider or Qualified Individual:

  • Which plan are we on, and what do its terms say about data use, retention, and where data is processed?
  • Is MFA enforced for every seat, and are there any shared or personal accounts in use?
  • What does the workspace log, and who looks at it?
  • Which connectors are turned on, and what can each one reach?
  • When did we last reassess this vendor, and is it in the risk assessment and the WISP?

If you would like a second set of eyes on the setup before busy season, get in touch.

Common questions

Can a tax preparer use AI on client returns?

Nothing in the FTC Safeguards Rule, IRS Publication 4557, or IRS Publication 5708 prohibits it, and none of them names AI. The firm has to bring the tool inside its written security program as a service provider and an information system, and it has to decide with counsel how section 7216 applies to sending return information to that vendor.

Does IRS Publication 4557 say anything about AI?

No. A text search of Publication 4557 (Rev. 6-2024) and Publication 5708 (Rev. 8-2024), downloaded from irs.gov on October 2, 2026, found no mention of artificial intelligence. Both describe duties that apply to any system or vendor that touches taxpayer data.

Is an AI vendor a service provider under the FTC Safeguards Rule?

The rule defines a service provider as any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered financial institution. An AI vendor that processes client documents for the firm fits those words, though no FTC statement we found addresses AI vendors by name, so confirm the reading with your counsel.

Do I need a section 7216 consent before using AI on a client's return information?

It is not settled. The regulations permit some disclosures to contractors and to other preparers providing auxiliary services without consent, and require consent in other cases, including disclosures outside the United States. The IRS section 7216 FAQ does not mention AI, so get your own counsel's view before return information goes to an AI vendor.

Does the Safeguards Rule apply to a firm with fewer than 5,000 clients?

Yes. Firms that maintain customer information on fewer than five thousand consumers are excused from four provisions: the written risk assessment, the continuous monitoring or penetration testing requirement, the written incident response plan, and the annual written report. The service provider, access control, encryption, MFA, disposal, logging, and training requirements still apply.

Tell us where the time is going

King & Company embeds with your team and builds the AI workflows, skills, and integrations around the work you already do. Describe the work your team would rather not be doing, and we will come back with how we would approach it.