Direct answer for 2026
Yes—but only within the limits imposed by tax-preparer ethics, professional standards, contractual duties, and applicable privacy law. A tax preparer may collect documents needed to prepare returns, use software or cloud services to organize that information, and sometimes use AI to extract figures, identify inconsistencies, explain rules, or improve internal quality control. That permission does not automatically authorize unrestricted AI training, sale of client information, indefinite retention, or disclosure to vendors that cannot protect the data. As of September 29, 2026, there is no single universal US federal rule that answers every AI and tax-data question, so clients must consider both the preparer’s professional obligations and privacy laws in the relevant jurisdiction.
Also worth reading: What Are the Biggest AI Financial Privacy Risks, and How Can You Protect Your Data? · How Can Financial Advisors Use Secure AI Automation Without Risking Client Data? · How Can an AI Financial Advisor Improve Small-Business Cash Flow Management in 2026?
For a US tax professional, IRS Circular 230 remains important, but it does not function as a comprehensive consumer privacy statute. Confidentiality duties can arise from a written engagement agreement, professional standards, state law, contractual restrictions, and the limits on representation or misconduct. Tax information may also be protected by federal or state tax-confidentiality statutes, although those protections do not always cover every private communication or every type of business record. A client should not assume that the word “tax” makes every document absolutely confidential or that paying the preparer creates consent for any form of automation.
What preparers can generally do
Tax preparation normally requires sensitive information, including Social Security numbers, dates of birth, employer information, bank and brokerage records, real-estate details, dependents’ information, and sometimes account balances or transaction histories. Preparers use this data for legitimate purposes such as calculating taxable income, reconciling reported documents, responding to notices, maintaining working papers, and—when properly authorized—examining potential credits or deductions. If a preparer uses a service provider to scan receipts, categorize transactions, or answer questions about tax forms, the factual inputs still concern the client even if an AI company performs part of the processing.
AI can reduce repetitive work, but it does not remove professional accountability. A 2026 Thomson Reuters examination of AI in tax and accounting emphasizes both efficiency opportunities and the need for review, while professional commentary has noted that formal IRS guidance on when a preparer must disclose AI assistance remains limited. A human preparer should therefore verify calculations, trace unusual results to source documents, avoid entering unsupported facts, and correct errors before filing. Consent to processing is not consent to waive the duty of care, and a platform’s claim that it is merely an “assistant” does not eliminate the possibility that sensitive data is transmitted, retained, or used to improve a model.
The strongest practice is purpose-limited use. Data supplied to a tax system for a 2025 return should not automatically be used to market unrelated services, build a general consumer profile, train a model shared across unrelated customers, or support decisions about lending or employment. Vendors should be assessed according to actual data flows rather than marketing descriptions. Tax professionals may face obligations under Circular 230 and applicable state rules, but the client’s documentation, consent, and instructions also matter when deciding whether a particular deployment is acceptable.
The main privacy rules clients should expect
There is no national privacy statute called the “tax preparer data privacy rules” in the United States. Instead, several layers operate together. IRS rules for authorized representatives govern access to taxpayer accounts and the use of power-of-attorney authority; they are not a general authorization for a preparer to expose documents to any third party. Circular 230 governs aspects of practitioner conduct, including confidentiality, diligence, and advice, but questions involving AI disclosure may depend on the facts and the specific professional standard. Some preparers are also subject to state board rules and accountant confidentiality laws.
Separate privacy or cybersecurity statutes may apply depending on location and conduct. The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over covered personal information, including the right to know, delete, correct, and opt out of certain forms of “sharing” or “selling.” Access, deletion, and opt-out rights have exceptions, and many exemptions apply to information processed or maintained solely in completing or providing a product or service. Other states have adopted or proposed privacy laws with different thresholds, definitions, and enforcement dates, so a rule in one state cannot safely be generalized nationwide. The EU GDPR can also apply when personal data is processed in relation to people in the European Union, subject to its jurisdictional and material-scope conditions.
International developments make cross-border handling harder. Indonesia issued additional personal-data protection rules, while European debates have focused on privacy in tax administration and government access to banking information. Those examples illustrate why banks, software providers, and tax advisers must evaluate jurisdiction and onward transfers. A US client’s use of a hosted tax tool does not remove privacy obligations merely because the server, support team, or subprocessor is located elsewhere. The practical question is not simply whether a law exists, but whether the client, provider, data subject, and processing activity fall within that law’s reach.
Consent, third parties, and AI vendors
Consent should be informed, specific, and proportionate. General language buried in a tax-preparation agreement may be relevant as contractual evidence, but it is not automatically sufficient to satisfy every privacy-law standard. The client should be able to learn whether documents are uploaded to a cloud platform, whether the vendor retains copies, whether the information is used for product improvement or AI training, which subprocessors receive access, where data is stored, and how long it remains available. A material change from local scanning to generative AI processing should trigger a renewed explanation rather than passive acceptance.
Vendor review should distinguish an ordinary service from a system that makes consequential predictions about a person. A tool that identifies “$4,200” from a 1099 is one use case; an engine that labels a taxpayer as likely to commit fraud, denies a refund strategy, or creates a persistent risk score is another. The latter can expose data to bias, function creep, and decisions the client never expected. Vendors may state that customer data is not used for training, but contractual promises, technical controls, incident history, and deletion procedures still need examination. Encryption in transit protects data during transfer, while encryption at rest, access logging, multifactor authentication, and tested deletion processes address different risks.
| Feature | Conventional tax-preparation software | Generative AI or “agentic” tax assistant | Human tax professional using controlled AI |
|---|---|---|---|
| Data entered | Forms, statements, documents, limited transaction details | Free-form financial, identity, or document information | Minimum necessary data entered under a reviewed workflow |
| Main benefit | Predictable calculations and standardized compliance workflows | Drafting, document extraction, explanations, and question answering | Faster review, broader scenario analysis, with professional judgment retained |
| Main privacy risk | Cloud storage, excessive document collection, vendor access | Broad context windows, retention, training, prompt leakage, and hidden sub-processors | Client misunderstands controls or fails to verify a plausible but incorrect answer |
| Expected vendor pricing | Often roughly $0–$100 for simple DIY filing; higher with premium filing, state, or professional features | Commonly $20–$200 per month for individual plans, with enterprise and API pricing varying | Often several hundred dollars for routine returns; hundreds to thousands for complex advice or representation |
| Appropriate protection | Account controls, provider terms, document minimization | Explicit no-training terms, short retention, encryption, and AI-specific consent | Written confidentiality terms, vendor review, human sign-off, audit logs, and deletion schedule |
Begin with a direct conversation before sending documents through a new AI feature. The client can ask whether the preparer or software uses AI, what functions are automated, whether tax documents train any model, whether customer data is retained after a return is filed, and whether a human reviews the output. A clear answer should identify actual data flows. Terms such as “secure,” “encrypted,” or “compliant” are not substitutes for details about retention, training, subprocessors, incident notification, and deletion. A client who receives an ambiguous response can reasonably postpone transmitting especially sensitive records until the vendor supplies adequate information.
Next, minimize the information supplied. A preparer may need a tax return for a particular year, but not necessarily five years of bank statements, passwords, complete medical records, or identity-document images. Redact account numbers where the full value is not needed, upload only relevant pages, and use separate folders for each engagement. Do not paste a complete tax return, Social Security number, or account credentials into a consumer chatbot merely because the chatbot promises confidentiality. If a platform does not contractually prohibit model training or sensitive-data retention, assume that the risk has not been eliminated.
Maintain evidence of instructions and consent. Save the engagement agreement, vendor privacy terms, AI disclosures, and any written instruction limiting a provider’s use of the data. Review outputs against the original forms and ask why a number changed. Filing responsibility remains with the taxpayer unless a professional has expressly assumed additional duties, and reliance on an AI-generated answer does not transfer responsibility to the model vendor. For a business return, governance may require a data-processing agreement, security review, approved-tool list, employee training, and records showing who reviewed the final work.
Common mistakes and unrealistic assumptions
One common mistake is treating “the IRS is using AI” as evidence that private tax software may do anything it wants. Government analytics, criminal-investigation tools, and taxpayer-service systems serve different purposes and operate under different controls. A reported example involving the Department of Government Efficiency and student information illustrates the public-policy concern around using sensitive databases, not a grant of permission for tax professionals to reuse taxpayer records. Similarly, disputes over tax authorities’ access to banking data concern public administration and privacy protections; they do not settle the private preparer-client relationship.
Another mistake is confusing tax confidentiality with a promise of total secrecy. Confidentiality does not prevent every legally permissible disclosure, such as obtaining consent, correcting a filing error, responding to a lawful process, or using a subcontractor where professional and contractual duties permit it. It also does not mean information is never subject to retention, security, or breach duties. Clients should examine the specific legal basis, purpose, recipients, and safeguards rather than demand either “no exceptions ever” or “anything goes.”
A third mistake is assuming that a small tax office has no cybersecurity obligations. Threats can arrive through email compromise, fake tax-document links, malicious attachments, compromised credentials, or an unapproved AI tool. One reported vendor-breach case involving tax data and an extended disclosure period also demonstrates why incident detection and prompt notice matter, although the reported timeline should be confirmed directly with authoritative sources before relying on it operationally. Firms should require multifactor authentication, separate tax-account credentials, tested backups, vendor inventory, staff training, and an incident plan that can support notification duties.
Finally, many clients overprice the benefit of AI. A $150 annual tool may help someone reconcile straightforward forms, but it cannot determine the legal treatment of a complicated trust, cross-border income, equity compensation, or state tax issue without accurate facts and professional interpretation. A cheaper human-reviewed workflow may be more reliable than an expensive autonomous agent. Price should be considered alongside error risk, data sensitivity, time saved, and whether the output is merely advisory or will lead to filing.
When to act and what it may cost
Act before the next upload if the platform cannot explain its AI use, will not commit to deleting or not training on tax documents, requests passwords it does not need, uses a free consumer chatbot for sensitive data, or cannot identify where information is stored. A business should act before an employee adopts a tool on their own, because one unapproved integration can expose records belonging to the company, customers, or applicants. Individuals should also act when a return includes self-employment income, investment sales, medical-related entries, dependents’ information, or other data that could create significant harm if exposed.
There is no universally reliable “privacy tax.” DIY products commonly range from free to about $100 for simple federal filing, with state returns, premium support, or add-ons increasing the price. Individual AI assistants often advertise subscriptions from roughly $20 to $200 per month, but those prices do not measure privacy, accuracy, or tax competence. Professional preparation commonly starts at several hundred dollars, while complex returns, audits, representation, or business advice can run into the thousands. Secure enterprise products may cost substantially more because of identity controls, audit logging, contractual protections, and integration work.
The prudent spending order begins with free, low-risk measures: enable multifactor authentication, remove unnecessary fields, compare the provider’s terms, and ask for plain-language answers. The next step is a controlled product with data minimization, short retention, encryption, and a clear no-training commitment. A human-reviewed professional service is usually the better choice for a consequential filing, but even then the client should confirm exactly which parts were automated. Paying for a premium tier does not guarantee that the preparer followed instructions or that an AI answer is correct.
The defensible 2026 standard
A tax preparer can defensibly use AI when the purpose is legitimate, the client receives meaningful disclosure, the vendor is bound to appropriate controls, only necessary data is processed, and a qualified human reviews the result. The client should also be able to obtain documents, correct information, and request deletion where no legal retention or recordkeeping exception applies. A firm should document the service, maintain an approved-vendor register, train staff, and revisit the arrangement when the model, vendor, data flow, or tax engagement materially changes.
The key phrase for a client question is not “Can AI do taxes?” but “Can this specific system process these specific documents under terms I understand and can enforce?” The answer changes with the document type, jurisdiction, vendor, professional role, and intended decision. As of September 29, 2026, privacy compliance is best understood as an accountability process, not a checkbox added to tax software. That approach does not make every AI use impractical; it makes the useful, lower-risk uses clearer and the unacceptable uses easier to reject.
For a current decision, ask the preparer for the provider name, retention schedule, training policy, list of AI functions, subprocessor information, security controls, and deletion process. Then compare those answers with the actual privacy policy and engagement agreement. If the explanations conflict, request written clarification before uploading more data. A client who does that is not paying for fear or technology avoidance; the client is preserving accuracy, confidentiality, and the practical ability to correct a consequential error.