HƯỚNG DẪN xã hội

Bảo mật dữ liệu của người khai thuế và AI

Bảo mật dữ liệu của người khai thuế là tập hợp các nghĩa vụ pháp lý và các biện pháp bảo vệ thực tế nhằm bảo vệ thông tin thuế của khách hàng.

  • đọc 4 phút
  • Cập nhật lần cuối
Trên trang nàyđọc 4 phút
  1. Tổng quan
  2. Lặn sâu
  3. Tác động chiến lược
  4. The Future of Tax Preparer Data Security and AI
  5. Triển khai trong thế giới thực
  6. Rủi ro & lan can
  7. Lộ trình thực hiện
  8. Tiếp tục khám phá
  9. Câu hỏi thường gặp

Tổng quan

In the US it includes a written information security plan (WISP) required under the FTC Safeguards Rule, and it now has to cover AI tools and AI-driven phishing. It matters because tax offices hold Social Security numbers, bank details and income records that criminals use for identity theft and fraudulent refunds, and generative AI makes the scams aimed at them more convincing.

Lặn sâu

The Gramm-Leach-Bliley Act treats paid tax preparers as financial institutions. Under it, the Federal Trade Commission's Safeguards Rule requires them to keep a written information security program. The FTC's amended rule, which took full effect in June 2023, spells out the elements. Firms must designate a qualified individual to oversee the program, conduct a written risk assessment, control access, encrypt customer data in transit and at rest, use multifactor authentication, train staff, oversee service providers, keep an incident response plan and have the qualified individual report on the program. A later amendment requires firms to notify the FTC of certain breaches involving unencrypted information of at least 500 consumers. The IRS supports this through Publication 4557, Safeguarding Taxpayer Data, and Publication 5708, a WISP template developed with the Security Summit partnership. Preparers are also reminded of the requirement when they obtain or renew a PTIN. AI brings two kinds of issue. The first is threats. Language models help criminals write fluent, personalized phishing emails, including the long-running new-client scam and fake IRS or software-vendor messages. Voice cloning makes impersonation calls more believable. The old tell of poor grammar is no longer reliable. The second is the firm's own use of AI. Pasting client returns into a consumer chatbot can put taxpayer data under terms the firm has not reviewed. Separately, Internal Revenue Code Section 7216 restricts the use and disclosure of tax return information without taxpayer consent. A WISP should list approved AI tools, what data each may process and how vendors are vetted. A common misconception is that small firms are too small to be targeted. Criminals seek out small practices because their defenses are often weaker and their data is just as valuable.

Tác động chiến lược

Rủi ro và an toàn

Những tác hại thảm khốc và thường ngày của AI đều phụ thuộc vào việc ai hiểu được rủi ro và ai có thể hành động.

Quyết định rõ ràng hơn

Kiến thức công cộng và chuyên môn định hình liệu chính sách an toàn mạnh mẽ có khả thi về mặt chính trị hay không.

Phá vỡ sự thổi phồng

Những lời giải thích rõ ràng làm giảm sự thu hút bởi sự cường điệu, PR trong phòng thí nghiệm và sân khấu đạo đức mơ hồ.

The Future of Tax Preparer Data Security and AI

AI-assisted fraud is likely to keep getting more convincing, so defenses that do not rely on spotting mistakes will matter most: MFA, verification over a separate channel and least-privilege access. Regulators have been tightening expectations over time, and professional bodies keep updating guidance. As more preparers adopt AI for intake and review, vendor contracts and data-handling terms will become a routine part of a WISP rather than an afterthought. The core duty does not change: know where client data goes, limit who can reach it, and be ready to respond when something goes wrong.

Triển khai trong thế giới thực

A two-person tax office uses the Security Summit's WISP template to write its plan. The plan names a qualified individual, lists every system that stores client data and adds a rule against pasting client information into unapproved AI chatbots.

During filing season a preparer receives a polished email from a supposed new client with a link to their tax documents. The link leads to a credential-harvesting page. Because the office requires multifactor authentication, the stolen password alone cannot open the tax software.

A firm evaluating an AI document-intake tool asks the vendor how it encrypts data, whether client data is used to train models, how long data is kept and where it is stored, and records the answers in its vendor file.

A staff member receives a phone call in a voice that sounds like the firm owner, asking her to change a client's direct-deposit account. Office policy requires confirming any such request through a second, known channel, so she hangs up and calls the owner back.

Rủi ro & lan can

  • Xử lý rủi ro hiện hữu như khoa học viễn tưởng trong khi khả năng lại phức tạp.

  • Nhầm lẫn giữa an toàn sản phẩm bề mặt với sự liên kết dưới quyền tự chủ cao.

  • Chỉ để lại những khán giả không phải người Anh và không có chuyên môn với những nguồn chất lượng thấp.

Lộ trình thực hiện

  1. Tách biệt các tác hại của sản phẩm, sử dụng sai và rủi ro mất kiểm soát/sai lệch.

  2. Hỏi bằng chứng nào sẽ thay đổi quan điểm của bạn về thời gian và mức độ nghiêm trọng.

  3. Ưu tiên các nguồn chính và đánh giá cụ thể hơn các tuyên bố tiếp thị.

  4. Xác định một lộ trình hành động: sự nghiệp, chính sách, nguồn tài trợ hoặc kỹ năng - không chỉ là nhận thức.

Tiếp tục khám phá

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Tax Preparer Data Security and AI quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Bắt đầu bài kiểm tra

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Câu hỏi thường gặp

What is Tax Preparer Data Security and AI?

Tax preparer data security is the set of legal duties and practical safeguards that protect client tax information. In the US it includes a written information security plan (WISP) required under the FTC Safeguards Rule, and it now has to cover AI tools and AI-driven phishing. It matters because tax offices hold Social Security numbers, bank details and income records that criminals use for identity theft and fraudulent refunds, and generative AI makes the scams aimed at them more convincing.

Tại sao Quy tắc Bảo vệ của FTC áp dụng cho người khai thuế được trả tiền?

GLBA phân loại người khai thuế là tổ chức tài chính, điều này khiến họ phải tuân theo Quy tắc bảo vệ của FTC.

Ấn bản IRS nào là mẫu WISP được phát triển cùng với Hội nghị thượng đỉnh về bảo mật?

Ấn phẩm 5708 là mẫu WISP. Ấn phẩm 4557 bao gồm việc bảo vệ dữ liệu của người nộp thuế một cách rộng rãi hơn.

Tại sao hướng dẫn lại nói rằng ngữ pháp kém không còn là dấu hiệu cảnh báo lừa đảo đáng tin cậy nữa?

AI sáng tạo loại bỏ lối viết vụng về từng gây ra lừa đảo.

Một người gọi có vẻ giống như chủ sở hữu công ty yêu cầu thay đổi tài khoản tiền gửi trực tiếp của khách hàng. Hướng dẫn khuyến nghị điều khiển nào?

Xác minh ngoài băng tần đánh bại các giọng nói nhân bản và tin nhắn giả mạo vì kẻ tấn công không kiểm soát kênh thứ hai.

Phần nào của Bộ luật Thuế vụ hạn chế sử dụng hoặc tiết lộ thông tin khai thuế mà không có sự đồng ý của người nộp thuế?

Mục 7216 hạn chế việc người khai thuế sử dụng và tiết lộ thông tin trả lại, liên quan đến việc dán dữ liệu khách hàng vào các công cụ AI bên ngoài.