이 페이지에서4분 읽기
개요
For tax work, the rules of Internal Revenue Code section 7216 on disclosing or using tax return information also apply. In practice that means knowing where the data goes, getting client consent or contractual protections when required, and vetting the vendor before any client information enters the tool. This matters because pasting a client file into the wrong chatbot can be an unauthorized disclosure with professional, civil and even criminal consequences.
심층 분석
Three sets of rules shape how a CPA can use AI with client information. The first is the AICPA Code of Professional Conduct. Its Confidential Client Information Rule (1.700.001) bars members in public practice from disclosing confidential client information without the client's specific consent, with limited exceptions such as responding to a valid subpoena or a peer review. The Code also has interpretations on third-party service providers, which cover most AI vendors. Broadly, the member should tell the client before sharing confidential information with such a provider. The member should also either have a contract requiring the provider to keep the information confidential, with reasonable assurance that it has procedures to do so, or get the client's specific consent. The second applies to tax preparers. Section 7216 makes it a crime for a return preparer to knowingly or recklessly disclose or use tax return information outside permitted purposes. Section 6713 adds a civil penalty. The Treasury regulations under section 7216 list some disclosures that need no consent. Many others need written consent obtained before the disclosure, signed and dated by the taxpayer, and in the format the IRS prescribes; Revenue Procedure 2013-14 gives the format guidance. Tax return information disclosed to anyone outside the United States gets stricter treatment. Whether a particular AI vendor falls under a no-consent exception is a legal question the firm should resolve with counsel, not assume. The third is data security law. Tax and accounting firms are generally covered by the FTC Safeguards Rule, which requires a written information security program. IRS Publication 4557 gives practical safeguarding guidance. Two misconceptions are common: stripping names does not make data anonymous. A combination of location, income, business type and dates can identify a client; and an enterprise AI plan does not remove the firm's obligations. It only makes them easier to meet.
전략적 영향
위험과 안전
치명적인 AI 피해와 일상적인 AI 피해는 누가 위험을 이해하고 누가 조치를 취할 수 있는지에 따라 달라집니다.
더 명확한 결정들
공공 및 전문 지식은 강력한 안전 정책이 정치적으로 가능한지 여부를 결정합니다.
과장된 과장을 뚫고 나가기
명확한 설명은 과대광고, 연구실 홍보, 모호한 윤리 연극에 의한 포착을 줄입니다.
The Future of CPA Ethics and Client Data When Using AI
Professional bodies, state boards and the IRS are paying more attention to AI in tax and accounting practice. Firms should expect more specific guidance, updated engagement letter language and AI-specific vendor contract terms. How confidentiality and section 7216 apply to particular AI setups may be clarified over time, so firms should watch AICPA and IRS publications rather than rely on today's assumptions. Technology is also moving toward private deployments and stronger contractual data controls, which make compliant use easier. Consent, documentation and professional judgment will still be required.
실제 구현
A tax preparer wants help drafting a reply to a client's IRS notice. Instead of pasting the notice into a free consumer chatbot, they use the firm's approved enterprise tool under a contract that bars training on inputs, and first remove the name, SSN and address.
A firm evaluating an AI bookkeeping assistant asks the vendor for its SOC 2 Type II report, data retention periods, subprocessor list and data processing location. It also checks whether a written contract bars the vendor from using client data to train its models.
A firm updates its engagement letters to tell clients that third-party service providers, including AI tools, may process their information. It also reviews whether any planned use of tax return information needs separate section 7216 consent.
A staff accountant pastes a client's full trial balance and payroll register into a personal chatbot account. The firm treats this as a possible unauthorized disclosure: it reviews the tool's data terms, asks for deletion where possible, documents the incident and retrains staff.
위험 및 가드레일
실존적 위험을 공상과학처럼 다루면서 능력을 합성합니다.
높은 자율성 하에서 정렬과 표면 제품 안전성을 혼동합니다.
영어가 아니거나 전문가가 아닌 청중에게는 품질이 낮은 소스만 남겨 둡니다.
구현 로드맵
제품 손상, 오용, 통제력 상실/잘못 정렬 위험을 분리합니다.
일정과 심각도에 대한 귀하의 견해를 바꿀 수 있는 증거가 무엇인지 물어보십시오.
마케팅 주장보다 기본 소스와 구체적인 평가를 선호하세요.
인식뿐만 아니라 경력, 정책, 자금 조달 또는 기술 등 하나의 행동 경로를 식별하십시오.
계속 탐색하세요
Free newsletter
Get the daily AI briefing
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Take the CPA Ethics and Client Data When Using AI quiz
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
자주 묻는 질문
What is CPA Ethics and Client Data When Using AI?
CPAs can use AI tools with client data only in ways that respect their confidentiality duties. For tax work, the rules of Internal Revenue Code section 7216 on disclosing or using tax return information also apply. In practice that means knowing where the data goes, getting client consent or contractual protections when required, and vetting the vendor before any client information enters the tool. This matters because pasting a client file into the wrong chatbot can be an unauthorized disclosure with professional, civil and even criminal consequences.
Under the AICPA Confidential Client Information Rule, what is generally required before a member in public practice discloses confidential client information, outside the listed exceptions?
The rule bars disclosure without the client's specific consent, with limited exceptions such as responding to a valid subpoena or a peer review.
What does Internal Revenue Code section 7216 primarily target?
Section 7216 is a criminal provision aimed at return preparers who improperly disclose or use tax return information.
Which Internal Revenue Code section adds a civil penalty for improper disclosure or use of tax return information by preparers?
Section 6713 provides the civil penalty that sits alongside the criminal provision in section 7216.
When section 7216 consent is required, which description matches the regulations as summarized in the guide?
The regulations require written consent before the disclosure, signed and dated by the taxpayer, and in the format the IRS prescribes. Rev. Proc. 2013-14 gives the format guidance.
Under the AICPA's third-party service provider interpretations, what is broadly expected before sharing confidential client information with an AI vendor?
The member should tell the client and either rely on a contract that makes the provider keep the information confidential, with reasonable assurance of its procedures, or get specific consent.
계속 학습하세요
관련 가이드
이 주제에 대해 선택된 추가 가이드