이 페이지에서4분 읽기
개요
In the US it includes a written information security plan (WISP) required under the FTC Safeguards Rule, and it now has to cover AI tools and AI-driven phishing. It matters because tax offices hold Social Security numbers, bank details and income records that criminals use for identity theft and fraudulent refunds, and generative AI makes the scams aimed at them more convincing.
심층 분석
The Gramm-Leach-Bliley Act treats paid tax preparers as financial institutions. Under it, the Federal Trade Commission's Safeguards Rule requires them to keep a written information security program. The FTC's amended rule, which took full effect in June 2023, spells out the elements. Firms must designate a qualified individual to oversee the program, conduct a written risk assessment, control access, encrypt customer data in transit and at rest, use multifactor authentication, train staff, oversee service providers, keep an incident response plan and have the qualified individual report on the program. A later amendment requires firms to notify the FTC of certain breaches involving unencrypted information of at least 500 consumers. The IRS supports this through Publication 4557, Safeguarding Taxpayer Data, and Publication 5708, a WISP template developed with the Security Summit partnership. Preparers are also reminded of the requirement when they obtain or renew a PTIN. AI brings two kinds of issue. The first is threats. Language models help criminals write fluent, personalized phishing emails, including the long-running new-client scam and fake IRS or software-vendor messages. Voice cloning makes impersonation calls more believable. The old tell of poor grammar is no longer reliable. The second is the firm's own use of AI. Pasting client returns into a consumer chatbot can put taxpayer data under terms the firm has not reviewed. Separately, Internal Revenue Code Section 7216 restricts the use and disclosure of tax return information without taxpayer consent. A WISP should list approved AI tools, what data each may process and how vendors are vetted. A common misconception is that small firms are too small to be targeted. Criminals seek out small practices because their defenses are often weaker and their data is just as valuable.
전략적 영향
위험과 안전
치명적인 AI 피해와 일상적인 AI 피해는 누가 위험을 이해하고 누가 조치를 취할 수 있는지에 따라 달라집니다.
더 명확한 결정들
공공 및 전문 지식은 강력한 안전 정책이 정치적으로 가능한지 여부를 결정합니다.
과장된 과장을 뚫고 나가기
명확한 설명은 과대광고, 연구실 홍보, 모호한 윤리 연극에 의한 포착을 줄입니다.
The Future of Tax Preparer Data Security and AI
AI-assisted fraud is likely to keep getting more convincing, so defenses that do not rely on spotting mistakes will matter most: MFA, verification over a separate channel and least-privilege access. Regulators have been tightening expectations over time, and professional bodies keep updating guidance. As more preparers adopt AI for intake and review, vendor contracts and data-handling terms will become a routine part of a WISP rather than an afterthought. The core duty does not change: know where client data goes, limit who can reach it, and be ready to respond when something goes wrong.
실제 구현
A two-person tax office uses the Security Summit's WISP template to write its plan. The plan names a qualified individual, lists every system that stores client data and adds a rule against pasting client information into unapproved AI chatbots.
During filing season a preparer receives a polished email from a supposed new client with a link to their tax documents. The link leads to a credential-harvesting page. Because the office requires multifactor authentication, the stolen password alone cannot open the tax software.
A firm evaluating an AI document-intake tool asks the vendor how it encrypts data, whether client data is used to train models, how long data is kept and where it is stored, and records the answers in its vendor file.
A staff member receives a phone call in a voice that sounds like the firm owner, asking her to change a client's direct-deposit account. Office policy requires confirming any such request through a second, known channel, so she hangs up and calls the owner back.
위험 및 가드레일
실존적 위험을 공상과학처럼 다루면서 능력을 합성합니다.
높은 자율성 하에서 정렬과 표면 제품 안전성을 혼동합니다.
영어가 아니거나 전문가가 아닌 청중에게는 품질이 낮은 소스만 남겨 둡니다.
구현 로드맵
제품 손상, 오용, 통제력 상실/잘못 정렬 위험을 분리합니다.
일정과 심각도에 대한 귀하의 견해를 바꿀 수 있는 증거가 무엇인지 물어보십시오.
마케팅 주장보다 기본 소스와 구체적인 평가를 선호하세요.
인식뿐만 아니라 경력, 정책, 자금 조달 또는 기술 등 하나의 행동 경로를 식별하십시오.
계속 탐색하세요
Free newsletter
Get the daily AI briefing
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Take the Tax Preparer Data Security and AI quiz
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
자주 묻는 질문
What is Tax Preparer Data Security and AI?
Tax preparer data security is the set of legal duties and practical safeguards that protect client tax information. In the US it includes a written information security plan (WISP) required under the FTC Safeguards Rule, and it now has to cover AI tools and AI-driven phishing. It matters because tax offices hold Social Security numbers, bank details and income records that criminals use for identity theft and fraudulent refunds, and generative AI makes the scams aimed at them more convincing.
Why does the FTC Safeguards Rule apply to paid tax preparers?
The GLBA classifies tax preparers as financial institutions, which brings them under the FTC's Safeguards Rule.
Which IRS publication is the WISP template developed with the Security Summit?
Publication 5708 is the WISP template. Publication 4557 covers safeguarding taxpayer data more broadly.
Why does the guide say poor grammar is no longer a reliable phishing warning sign?
Generative AI removes the clumsy writing that once gave phishing away.
A caller who sounds like the firm owner asks to change a client's direct-deposit account. Which control does the guide recommend?
Out-of-band verification defeats cloned voices and spoofed messages, because the attacker does not control the second channel.
Which Internal Revenue Code section limits using or disclosing tax return information without taxpayer consent?
Section 7216 restricts preparers' use and disclosure of return information, which bears on pasting client data into outside AI tools.
계속 학습하세요
관련 가이드
이 주제에 대해 선택된 추가 가이드