Skip to content
Services All services Company Who we serve How it works Case study About Pricing Resources

Based in Miami · We work in English & Spanish

Security

Is AI safe for client tax data? IRS Pub 4557, WISPs, and zero-retention AI

Using AI with taxpayer data can be done responsibly, but only with the right contracts, settings, and controls. Here's what tax professionals should check before adopting any AI tool.

DBy · ·8 min read

"Can we put client data into AI?" is the most common question we hear from firm owners, and the right one to ask first. The short answer: yes, if you choose the right services, configure them correctly, and document the setup in your security plan. Pasting a client's return into a free consumer chatbot is a very different thing from a properly configured business integration.

Note: this article is general information, not legal advice. Confirm your specific obligations with your own counsel or compliance advisor.

The rules that already apply to you

Tax and accounting firms that handle taxpayer data are covered by the FTC Safeguards Rule under the Gramm-Leach-Bliley Act. The IRS lays out practical expectations in Publication 4557, Safeguarding Taxpayer Data, and offers a template in Publication 5708 for creating a Written Information Security Plan (WISP).

None of these rules prohibit AI. They require you to understand where taxpayer data goes, who can access it, how it's protected, and how you oversee the vendors that handle it. An AI service is simply another vendor and another data flow, and it should be treated that way.

Consumer AI vs. business AI

The single most important distinction is between consumer AI apps and business or API offerings:

  • Consumer apps (free or personal chat accounts) may, depending on the provider and settings, use conversations to improve their models and keep them for extended periods. They're generally not appropriate for client data.
  • Business and API offerings from major providers typically commit contractually not to train on your data, offer shorter retention, and in some cases offer zero-data-retention arrangements where inputs aren't stored after processing.

Read the actual terms, not the marketing page. You're looking for commitments on training, retention, sub-processors, data location, and breach notification.

Questions to ask any AI vendor

  1. Is our data used to train or improve models? (The answer should be no, in writing.)
  2. How long are inputs and outputs retained, and can retention be set to zero?
  3. Where is data processed and stored?
  4. Is data encrypted in transit and at rest?
  5. Which sub-processors have access?
  6. Will you sign a data processing agreement?
  7. How will you notify us of a security incident?

Controls that matter inside your firm

Good vendor terms are necessary but not sufficient. The controls inside your firm matter just as much:

  • Least-privilege access. Automations and staff should only reach the client data they need.
  • Multi-factor authentication on every system involved. The Safeguards Rule specifically calls for it.
  • Data minimization. Send the AI only what the task requires. Extracting fields from a W-2 doesn't need the client's entire file.
  • Audit logs of automated actions and data access.
  • Human review before anything reaches a filed return or a client.
  • Redacted or synthetic data for development and testing.

When to go private

Some firms, particularly those with high-net-worth clients, government-adjacent work, or strict client contracts, prefer that data never leaves their own environment. For them, AI can be deployed inside their own cloud tenant, or run with open-weight models on infrastructure they control. It costs more to set up and maintain, but it removes a category of third-party risk.

Update your WISP

Whatever you choose, document it. Your WISP should list each AI service as a vendor, describe what data it receives, and record the safeguards in place. If a regulator, insurer, or client ever asks how you use AI, you'll have a clear and accurate answer.

Every automation we build comes with documentation of its data flows and safeguards for your WISP. Read more on our security page.
Share

Want this applied to your firm?

Book a free automation audit and we'll map these ideas onto your actual workflows.

Book a free audit