CPA firms
AI for Small CPA Firms: Safe Uses Before Next Tax Season
By Kevin Sims, Founder, Lumon Studios5 min read
AI for small CPA firms is most useful in the work around the return, not the return itself: client intake, chasing missing documents, first drafts of engagement letters, meeting notes, research you then verify, and email triage. Before any of it touches client data, three sets of rules decide which tools you can use: the FTC Safeguards Rule, the IRS security guidance in Publication 4557, and Internal Revenue Code section 7216 on disclosing tax return information. Here is how to get the benefit without creating a problem.
How firms like yours are using AI now
The JPMorgan Chase Institute, looking at payments from small business bank accounts, found that the share of professional services firms paying for AI tools rose from roughly 4 to 5 percent in 2019 to about 30.3 percent by 2025. That counts paid tools only, so free use is not captured.
The IRS has noticed. In June 2026 its Office of Professional Responsibility published introductory guidelines for responsible AI use in federal tax practice. Its core message: treat AI output as a draft, verify facts, citations and calculations, and keep client data only in secure AI tools your firm has approved at the enterprise level.
On the question owners ask most, will AI replace accountants: a Census Bureau working paper based on a survey of US businesses found that most AI users rely on it to augment tasks, and that AI related employment decreases occurred in only 2% of firms during its late 2025 to early 2026 reference period. That is survey data across all industries, not a forecast for accounting, but it matches the IRS view that judgment stays with the professional.
Six safe uses of AI for small CPA firms
1. Client intake and document chasing
A big seasonal time sink is waiting on clients. Practice platforms already handle the secure part: TaxDome lists tax organizers and client management among its features, and Karbon offers a client portal and tax organizers alongside its AI features. Use AI to write friendlier, clearer reminder wording and checklists. Let the portal, not a chatbot, hold the documents.
2. Engagement letter first drafts
Give AI your own approved template and the scope in plain words, and ask it to draft the letter. A partner then reviews every clause. Never let AI invent terms, fees or limitation language on its own; your professional liability carrier's guidance should drive that.
3. Meeting notes
Transcription and summary tools can save real time after planning meetings. California Penal Code section 632 bars recording a confidential conversation without the consent of all parties, so ask permission at the start of every recorded call, and use only a tool that meets your security plan.
4. Research, with every citation checked
AI is useful for a first pass on an unfamiliar issue, but it can fabricate authority. The OPR guidance says due diligence "requires verifying the accuracy of facts, citations, and calculations produced by AI." Open every Code section, regulation and ruling yourself before relying on it.
5. Email triage
Karbon says its AI can summarize long email threads, suggest editable quick replies and draft emails from tasks. If your firm runs on Microsoft 365, Microsoft says prompts and responses in Microsoft Copilot and Copilot Chat are not used to train foundation models. For general writing with no client data, OpenAI says it does not train on ChatGPT Business data by default.
6. Drafting your written security plan
The IRS publishes a sample template in Publication 5708, Creating a Written Information Security Plan. AI can help you adapt the template to your office, which is a good first project because it involves no client data.
The rules: Safeguards Rule, Publication 4557 and Section 7216
FTC Safeguards Rule. The FTC lists tax preparation firms among its examples of financial institutions covered by the rule. Covered firms need a written information security program, a designated Qualified Individual, and multifactor authentication for anyone accessing customer information. On vendors, the FTC says your contracts must spell out your security expectations and build in ways to monitor the provider. The regulation itself, 16 CFR part 314, requires you to oversee service providers. The FTC also explains that, since May 13, 2024, firms must notify it no later than 30 days after discovering a breach involving at least 500 consumers' unencrypted information. Firms holding information on fewer than 5,000 consumers are exempt from a few provisions, such as the written incident response plan, but not from the rest. An AI vendor that sees client data is a service provider.
IRS Publication 4557. Safeguarding Taxpayer Data puts it simply: "Protecting taxpayer data is the law." It says tax return preparers must create and enact security plans under the Safeguards Rule, and it tells firms to select service providers that can maintain appropriate safeguards and to oversee their handling of customer information.
Section 7216. The Treasury regulations describe section 7216 as a criminal penalty for preparers who knowingly or recklessly disclose or use tax return information for a purpose other than preparing a return, with up to one year of imprisonment. "Disclosure" is defined broadly as "the act of making tax return information known to any person in any manner whatever." The regulations also list exceptions, including some disclosures to other preparers in the United States, and generally require the client's consent before disclosure to a preparer outside the United States. Whether a particular AI tool fits an exception or needs written client consent is a question for your own advisor. Until you have that answer, keep tax return information out of AI tools that are not covered by your security plan and vendor contracts.
Confirm with your attorney, your CPA society or your professional liability carrier how these rules apply to your firm.
A one week setup for your firm
- List every AI tool already in use, including personal accounts staff use for work.
- Sort tasks into two buckets: no client data (templates, marketing, internal procedures) and client data.
- For the client data bucket, allow only tools inside your existing platforms or vendors with written security terms you have reviewed.
- Add AI to your written security plan: approved tools, who approves new ones, and what never goes into a chatbot.
- Turn on multifactor authentication on every AI tool and platform that touches client files.
- Train staff for 30 minutes on the policy and on checking citations.
- Document the review step so you can show that a professional checked AI drafts before they left the office.
What to watch out for
- Fabricated citations. The OPR guidance points to court sanctions against lawyers for fake citations as a warning for tax practitioners.
- Billing. OPR says billing for time not actually spent, or double billing for AI assisted tasks, may violate Circular 230's fee rule depending on the facts.
- Free consumer accounts. Pasting a client's return into a personal chatbot is exactly the kind of disclosure section 7216 and the OPR guidance warn about.
- Offshore processing. Ask every vendor where data is processed and stored.
Where to start
Draft your AI policy into your written security plan this week, then pick one no client data project, such as reminder templates. If you want a second set of eyes, start with our AI assessment or see our AI consulting services. Related reading: AI for independent insurance agents, how to hire an AI consultant in Marin County, and the health care version of these privacy questions in Is ChatGPT HIPAA compliant?
Frequently asked questions
Will AI replace accountants?
Not on current evidence. A Census Bureau working paper found most firms using AI rely on it to augment tasks, and AI related employment decreases occurred in only 2% of firms. The IRS Office of Professional Responsibility says AI output must be treated as a draft and verified by a qualified professional, so judgment and signature stay with the CPA.
How can AI help accountants?
The safest wins are around the return: clearer client reminders and checklists, engagement letter first drafts from your template, meeting summaries, first pass research you then verify, email summaries, and adapting the IRS sample written information security plan. Keep client data inside platforms covered by your security plan and vendor contracts.
What is the best AI for CPA firms?
Usually the AI built into tools you already use, because it keeps client data in one secure place. Practice platforms such as Karbon offer AI email summaries and drafting, and Microsoft 365 firms can use Copilot. A general chatbot is fine for work with no client data. Check every tool against your written security plan first.
Can I paste a client's tax return into ChatGPT?
Not into a personal or unapproved account. Section 7216 regulations define disclosure as making tax return information known to any person in any manner, and the IRS Office of Professional Responsibility says client data belongs only in secure AI approved at the enterprise level. Whether a specific tool fits an exception or needs client consent is a question for your advisor.
Sources
- JPMorgan Chase Institute: Understanding AI use by small businesses (April 2026)
- IRS Office of Professional Responsibility: Introductory Guidelines for Responsible AI Use in Federal Tax Practice (June 24, 2026)
- US Census Bureau: The Microstructure of AI Diffusion, working paper CES 26 25
- TaxDome: practice management for accounting firms
- Karbon: AI features for accounting firms
- California Penal Code section 632 (California Legislative Information)
- Microsoft Learn: Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat
- OpenAI: Enterprise privacy at OpenAI
- IRS Publication 5708: Creating a Written Information Security Plan for your Tax and Accounting Practice
- FTC: FTC Safeguards Rule, What Your Business Needs to Know
- eCFR: 16 CFR part 314, Standards for Safeguarding Customer Information
- IRS Publication 4557: Safeguarding Taxpayer Data
- eCFR: 26 CFR 301.7216 regulations, penalty for disclosure or use of tax return information
- eCFR: 26 CFR 301.7216 regulations, permissible disclosures or uses without consent