Can My Tax Preparer Use AI Without Telling Me?

The direct answer is: probably not without telling you if the tool receives your personal financial information, tax returns, documents, account identifiers, or client communications. A tax preparer may use AI to research a tax rule, summarize a document, draft routine workpapers, detect unusual figures, or improve software code without automatically disclosing every prompt, but the privacy and consent consequences change when identifiable tax data enters an external system. The U.S. tax code, Circular 230, IRS publications, and state privacy or professional-conduct rules do not appear to contain one universal rule saying “AI disclosure is always required.” Instead, the answer depends on what the software does, where the information is stored, whether the provider trains on it, whether the engagement agreement covers the technology, and what contractual, professional, or statutory duties apply.

Also worth reading: What Controls Should an AI Tax Preparer Have Before Filing Returns in 2026? · How Can an AI Financial Advisor Improve Responsible AI Finance Safety Without Giving Up Control? · How Should Investors Use AI Risk Controls Without Putting Too Much Trust in the Stock?

That does not mean silence is necessarily acceptable. Circular 230 imposes confidentiality duties on covered tax return preparers, while tax practitioners may also be bound by a written confidentiality agreement, state-board rules, employer policies, and duties owed to clients. If a provider retains prompts or scans for its own model training, transfers data across borders, or permits human review, a client could reasonably expect the preparer to explain that arrangement before sensitive information is submitted. As of September 28, 2026, the safest position for an individual is to ask for the tool name, data categories, retention period, training policy, human-access rules, and whether information can be masked before processing.

Why the Rules Are Not Completely Clear

AI is not itself a regulated category of tax software in the same way that a tax return preparation program can be regulated or examined. A tool might generate a draft tax memo, classify receipts, compare prior and current returns, identify missing forms, or suggest optimization strategies. The same activity can involve different privacy consequences depending on whether it runs inside the preparer's private system, uses a consumer chatbot, connects to cloud document storage, or sends data to a vendor that retains conversations for product improvement.

The IRS framework is centered on authority, standards, due diligence, records, and accuracy rather than a detailed checklist for disclosing an AI prompt. A practitioner can still satisfy ordinary professional obligations by obtaining information, verifying outputs, protecting confidential communications, maintaining appropriate records, and exercising reasonable care. The unresolved part is how those duties should be applied to generative systems whose providers may retain, inspect, or train on customer data under terms that clients never directly accepted. CNBC has reported that some experts view IRS guidance as unclear on whether a tax preparer must tell a client when AI is used, which reflects the absence of a bright-line mandate rather than permission to ignore informed consent.

A useful distinction is between low-risk internal assistance and high-risk external processing. Typing a generic question such as “Explain the difference between a Section 179 deduction and a bonus depreciation election” usually exposes little client-specific information. Uploading a complete Form 1040, Social Security number, dependent details, brokerage statements, or scanned W-2 creates a materially different privacy record. The preparer should apply a stricter disclosure standard when information is sensitive, extensive, difficult to replace, or likely to be used by a third party outside the firm's ordinary tax workflow.

What Counts as Personal Financial Information in AI Tools?

For privacy purposes, “personal information” is broader than a Social Security number alone. It can include names, addresses, dates of birth, filing status, spouse or dependent information, employer names, account numbers, transaction histories, estimated tax payments, charitable contributions, business revenue, and details that reveal a client's financial condition. Even apparently harmless metadata can identify a person when combined with a tax year, employer, filing status, and uncommon deduction.

The data categories entered into an AI system matter as much as the tool's advertised purpose. A prompt containing only a redacted tax question is different from one that includes an unredacted return and a request to identify deductions. Receipt images can expose merchants, locations, purchase dates, and sometimes payment information. Voice tools may record a conversation, cloud document tools may retain a searchable copy, and integrations that connect QuickBooks, bank, brokerage, or tax software can move data beyond the prompt itself. The client should therefore ask not only whether AI is used, but also what surrounding systems can access the information.

Consumers should also distinguish between a business plan and a free or personal plan. A paid workspace may promise contractual controls, restricted training, regional hosting, or administrative logging, while a free consumer account may reserve broader rights to retain or review content. A familiar brand name is not proof of a private arrangement: the exact product, plan, settings, and terms control. For example, asking a chatbot to remove a name from a paragraph does not guarantee that the name was never transmitted to the provider or entered temporary processing logs.

How to Compare Disclosure and Privacy Approaches

There is no single “AI tax review” method that suits every client. The relevant comparison is not whether one system is more advanced than another, but how each option handles confidential information, independent verification, cost, transparency, and accountability. A low-cost approach can still be responsible if the data is minimized and the outputs are checked. An expensive enterprise platform can still create risk if retention, training, or subprocessors are not understood.

FeatureManual or internal AI reviewConsumer AI toolFirm-managed AI platformFully managed privacy review
Data exposureLowest if performed inside controlled systemsPotentially highLower when contracts and masking are enforcedMinimized through approved workflow and redaction
DisclosureAsk how internal tools are usedAsk for product, plan, retention, and training termsReview firm policy and client agreementDocument the process, vendors, and review controls
Typical costMostly professional labor$0 to $20+ per user per month$20 to $200+ per user per monthUsually quote-based; may cost hundreds or thousands per review
Accuracy controlProfessional checks every conclusionProfessional must independently verify all outputsPlatform may assist, but practitioner remains accountableIndependent review plus documented sign-off
Best fitSensitive returns and complex questionsEducation and generic draftingEstablished firms seeking standardized toolsHigh-risk estates, businesses, or multi-jurisdiction planning
Prices are broad planning estimates rather than universal rates, and vendors frequently change features or packaging. A small firm may face a $30 monthly subscription for a premium individual account, while an enterprise license can be priced per seat, per firm, or through a custom agreement. The larger financial cost is often not the license; it is an incorrect return, missed document, inconsistent advice, or breach of client trust. A $20 monthly tool is inexpensive if it is used responsibly, but it can be expensive if it produces an unsupported position that requires substantial correction.

Questions to Ask Your Tax Professional

Ask whether the firm uses AI during preparation, review, planning, document collection, client communication, or quality control. It helps to separate those functions because “we use AI” is not an answer that reveals meaningful risk. The preparer should be able to identify the principal provider, explain whether the prompt is retained, describe training restrictions, state where processing occurs, identify any human reviewers, and confirm whether client data is combined with information from other customers. A practitioner may decline to disclose a vendor's confidential architecture, but disclosure generally should not require trade secrets; public terms and contractual practices are ordinarily explainable.

The client should also ask how the preparer verifies an AI-generated conclusion. Accurate tax advice can require reconciling a return to source documents, checking election deadlines, applying a taxpayer-specific limitation, and distinguishing federal treatment from state treatment. AI can make drafting faster without deciding whether the result is legally or factually correct. The tax professional should remain accountable for advice, and the engagement record should show that material outputs were reviewed against statutes, regulations, guidance, and client facts.

A practical request for written confirmation might be: “Please identify each AI tool used for my engagement, the data it receives, whether that data is retained or used for training, whether human review occurs, and who is responsible for verifying its output.” Clients should ask for this before sending documents, not after a return has already been uploaded. If the firm says that it uses an internal model and will not disclose details, the client can request at least a plain-language explanation of confidentiality safeguards, approved providers, and the process for handling a data-incident report.

Practical Steps to Protect Your Tax Data

Start with data minimization. Do not paste a complete tax return, bank statement, or identity document into a consumer chatbot when a redacted question would answer the issue. Replace names with neutral labels, remove account numbers, omit unnecessary dates of birth, and summarize the relevant tax facts. A prompt such as “A single filer in 2025 has $145,000 of qualified business-property purchases and asks whether Section 179 or bonus depreciation is available” can support research without exposing a client identifier.

Next, ask the provider to confirm its settings and contract. Look for information about retention, model training, administrator controls, encryption, regional storage, deletion, subprocessors, and access by personnel. The terms should be evaluated in conjunction with privacy notices; a marketing claim that a service is “secure” does not establish that prompts will never be retained. If the client cannot understand the terms, the individual should choose an approved alternative rather than assume the risk is zero.

Finally, preserve human review and a clear record. Keep copies of the engagement agreement, consent or disclosure communications, consent forms for electronic filing, and relevant source documents. Ask the preparer to explain material advice in ordinary language and to identify when a recommendation depends on facts that have not been verified. If the client is dissatisfied with an answer, the right response is to request a second professional review, not simply to ask the same AI system for another answer. Generative systems can produce confident variations without any of them being correct.

Common Mistakes and Red Flags

One common mistake is assuming that a familiar AI brand is a tax-service brand. A general chatbot, a tax-specific feature, and a firm's private integration may use different storage and training arrangements. Another mistake is assuming that redaction performed in the visible prompt also removes data already contained in an attached file. Before uploading, the client should open the document, inspect every page, and remove unnecessary headers, barcodes, account numbers, and identifying references.

A second mistake is treating a disclaimer as a substitute for disclosure. Statements such as “AI can make errors” or “consult a tax professional” do not explain whether a preparer used the tool or where the information went. A third mistake is asking only whether the output is accurate. Accuracy and privacy are separate questions: an accurate answer can still come from an unauthorized disclosure, and a private answer can still be wrong. Tax planning also has timing issues, so a plausible response without a verified effective-date and source check is not sufficient.

Red flags include a firm that refuses to identify any provider, says client information may improve the vendor's model without explaining the setting, uploads an entire return to a free consumer account, cannot say who reviewed a generated tax position, or promises that AI replaces professional judgment. The client should pause before proceeding and obtain written clarification. For a complex return, a business transaction, an estate, or a multi-state matter, a privacy-compliant process is more important than saving a few dollars by using an unregulated shortcut.

When You Should Act and What It May Cost

Act before the preparer receives your documents if the client has a strict privacy agreement, operates a business, handles confidential employee or investor data, lives in a jurisdiction with specific privacy expectations, or needs advice that could materially affect taxes. It is also reasonable to ask at the beginning of every engagement because the cost of changing tools is lower before data is uploaded. If a return has already been submitted to a tool, ask what was shared, when it was shared, whether it was retained, and how deletion or access control can be requested.

The cost of asking questions is usually minutes of professional time. The cost of a private review depends on the provider: individual AI subscriptions can range from free to more than $20 per month, business seats may fall around $20 to $200 or more per month, and custom firm or enterprise arrangements are quote-based. A separate privacy or tax-planning consultation may be priced hourly, flat fee, or as part of an ongoing engagement. There is no responsible universal price for an “AI tax review,” because a simple redacted question and a multi-entity return require different levels of work.

The best value comes from treating AI as an assistive research and drafting layer, not as the decision-maker. For ordinary clients, a short written policy plus verified use of an approved tool may be sufficient. Higher-risk clients should require a named vendor, contractual restrictions, access logging, redaction, deletion procedures, and an independent human sign-off. If the preparer cannot explain those controls in plain language, the client should consider a different professional or firm.

The Bottom Line for Clients and Firms

Tax preparers can use AI, and many will do so as software becomes embedded in research, document management, and review processes. But “Can they use it without telling me?” should be answered as a practical privacy question rather than a yes-or-no rule: low-risk internal use may not always trigger a specific disclosure mandate, while uploading identifiable tax information usually warrants an explanation and, where appropriate, consent. The absence of a universal IRS AI-disclosure rule is not a license to disregard confidentiality, contractual commitments, or informed expectations.

Clients should ask five concrete questions: What information enters the tool? Who can see it? How long is it retained? Is it used to train or improve the provider's systems? Who verifies the tax conclusion? A credible answer will identify the process in writing and connect the tool to a human professional who remains responsible for the advice. If the answer is vague, the client should delay uploading sensitive material and request a controlled alternative. For a trusted AI financial-advisor workflow, privacy is not an extra feature; it is part of the advice.