The IRS Just Published AI Guidelines for Tax Practitioners. Here Is What CPA Firms Need to Do Now
The IRS has issued guidelines for CPA firms on responsible AI use in tax practice, emphasizing compliance, due diligence, and secure data handling.
4 min read
Jordan Hetrick
:
Published
The IRS Office of Professional Responsibility (OPR) issued Alert 2026-19 on June 24, 2026. Titled "Introductory Guidelines for Responsible AI Use in Federal Tax Practice," it sets out how Circular 230 applies to generative AI. Tax firms that assumed AI sat outside professional-responsibility rules now have a document to answer to.
In 2026, the IRS Office of Professional Responsibility (OPR) made it clear that tax preparers who use AI need written rules for its use.
The guidance applies Circular 230, the IRS's conduct rules for tax professionals, and asks firms to document four things:
Client information should go only into secure, enterprise-approved AI tools, meaning business accounts your firm controls, and never into a public chatbot. Sharing it the wrong way can bring a civil penalty under IRC section 6713 and, in some cases, criminal charges under section 7216. The preparer who signs a return answers for everything in it, including anything AI wrote, so "the AI made it up" is not a defense under the competence rule in section 10.35.
The fix is simple and concrete: a short written policy that names the approved AI tools, says what staff may not do with them, and identifies who reviews AI-assisted work.
Not in those words. Circular 230 never mentions AI, and the alert introduces no new rule. It maps six existing provisions onto AI use, and the Journal of Accountancy's summary describes it the same way.
The obligation comes from section 10.36 of Circular 230. Anyone with principal authority over a firm's tax practice must take reasonable steps to ensure the firm has adequate procedures to comply with the rules. OPR now says those procedures have to cover AI, and that the firm needs documentation showing it followed them. Discipline under 10.36 requires willfulness, recklessness, or gross incompetence, plus a pattern of noncompliance in the firm. A single stray prompt will not trigger it. A firm with no policy and no records has a hard time showing it took reasonable steps, though.
The alert names four areas: staff training on AI capabilities and risks; protocols for secure data handling and accuracy monitoring; vetting of external AI providers; and records of all of it. Its closing checklist includes a few practical items, such as logging AI use and verification steps, setting access controls, and writing procedures for breaches or errors.
Section 10.35 sits underneath all of this. The alert reads competence to include understanding the technology, meaning how it generates content, where bias or error can enter, and whether an output is fit for an IRS matter. That is Circular 230 competence for AI in practice. A firm cannot train staff on something the partners have not learned themselves.
AI vendor vetting at a tax firm comes down to a few questions in the contract and the admin console. Does the vendor use your prompts to train its models? Where is the data processed and retained? Who at the firm can see what? Microsoft's documentation offers a useful reference point. Microsoft Copilot Chat (formerly Microsoft 365 Copilot Chat) under enterprise data protection does not use prompts and responses to train foundation models when staff sign in with a work account. Microsoft's separate privacy documentation for licensed Microsoft Copilot warns that it surfaces any organizational data a user can already view, so sloppy folder permissions become a client-data problem. Vetting the vendor covers half the job. Your own permissions cover the rest.
Fees belong in the file, too. Section 10.27 bars unconscionable fees, and the alert says that billing for time not actually spent, or double billing AI-assisted tasks, may violate it, depending on the facts. Write down how the firm bills AI-assisted work, knowing the AICPA is still pressing the IRS on value pricing.
The alert says no. Practitioners must handle client data using only secure, enterprise-approved AI, and the alert warns that uploads to unsecured or public systems carry the risk of unauthorized disclosure. It also flags a quieter danger: a generative tool can carry one client's information into an answer about another.
Section 7216 is a misdemeanor that applies to preparers who knowingly or recklessly disclose or misuse tax return information, and the statute sets the maximum penalty at 1 year in prison, a $1,000 fine, or both. Section 6713 adds a civil penalty of $250 per disclosure, capped at $10,000 a year, and unlike 7216 it does not require a knowing or reckless disclosure. The definition of tax return information is broad. It covers a client's name, address or identifying number when furnished in connection with preparing a return. Section 10.51(a)(15) of Circular 230 separately treats willful unauthorized disclosure as disciplinary conduct.
Whether a particular chatbot upload counts as a "disclosure" under 7216 depends on the facts and the vendor terms, so bring counsel into that call. The policy itself should not wait on the answer. Ban consumer chatbot accounts for anything containing client information, and name the approved tools by product and license tier.
No, and the guidance leaves little room to argue otherwise. Section 10.22 requires due diligence in preparing and filing returns and in the accuracy of what you tell clients. OPR reads that to mean verifying every fact, citation and calculation AI produces before it reaches a client or the IRS. Section 10.37 applies the same logic to written advice, where opaque AI reasoning can make reliance unreasonable.
Courts have already sanctioned lawyers over fabricated citations, with penalties running from several thousand dollars to public censure and removal from cases, according to the alert. It also points to Deloitte Australia, which reportedly refunded part of a government fee after a report contained invented quotes and nonexistent sources. Under section 10.50 of Circular 230, discipline ranges from censure (a public reprimand) to disbarment from practice before the IRS. A signature on the return makes the output yours.
This is a simple list for your firm to follow:
As a managed IT service provider, PK Tech brings nearly 17 years of experience serving CPA firms. PK Tech holds AICPA SOC 2 Type II attestation, verified through an independent third-party audit of its security and privacy controls.
Questions about AI-use policy and Circular 230 requirements? Schedule a chat with one of our pros.
The IRS has issued guidelines for CPA firms on responsible AI use in tax practice, emphasizing compliance, due diligence, and secure data handling.
This blog looks at how Copilot works to automatically draft email follow-ups, why it matters, and what Phoenix businesses should know before...
According to the AICPA survey 2025, 90% of tax software is still on-premise versus cloud-based. This blog will discuss what this means for CPAs.