A preparer pasting a client's return into a chatbot is not a policy problem. It is potentially a disclosure of tax return information, and §7216 is a criminal statute.
Criminal misdemeanor exposure
Civil penalty, no intent required
A record of what actually left
Most firms know the statute exists. Fewer have re-read it since generative AI arrived in their workflow.
IRC §7216 makes it a criminal misdemeanor for a tax return preparer to knowingly or recklessly disclose or use tax return information other than in connection with preparing that return. The implementing rules live in Treasury Regulations §301.7216-1 through §301.7216-3.
§6713 sits alongside it as a civil penalty with no knowledge requirement. A preparer who did not intend anything improper can still be liable.
"Tax return information" is defined broadly. It is not limited to the return itself. It covers information furnished in any form or manner for, or in connection with, preparing a return, including what the client told you and what you derived from it.
"Disclosure" is the act of making that information known to another person. There is no exception for making it known briefly, or for a good reason, or to a machine.
None of these are hypothetical. All of them are ordinary attempts to do the job faster.
A preparer asks an assistant to explain an unusual K-1 treatment and pastes the schedule in, names and identifiers included.
A W-2, 1099, or organizer PDF is uploaded to an AI tool for extraction or summarization, carrying SSNs and account numbers with it.
Staff paste a client's facts into an AI writing tool to draft an explanation letter, which is a disclosure and arguably also a use.
A notetaker silently joins a client call and sends the transcript to a third-party service nobody at the firm evaluated.
The firm has an approved tool with a signed agreement. Staff use their own free accounts because they are already logged in.
The regulations treat disclosures to preparers outside the United States more restrictively. Most staff have no idea where a given tool processes data.
Treasury Regulation §301.7216-2 permits certain disclosures without taxpayer consent, including to other tax return preparers providing auxiliary services in connection with preparing a return, with tighter conditions when the recipient is located outside the United States. §301.7216-3 covers the disclosures that do require consent, and Revenue Procedure 2013-14 sets out what a valid consent has to say and how it has to be obtained.
Whether a general purpose AI service qualifies as an auxiliary service provider under those rules is genuinely contested. Reasonable practitioners take different positions, and the answer turns on the vendor, the contract, where processing happens, whether the vendor may retain or train on the data, and how the tool is actually used in your workflow.
We are not going to resolve that question for you, and you should be sceptical of any vendor who offers to. What a firm can do is make sure the question only ever arises for tools it has actually evaluated, and that it never arises by accident because someone pasted a return into a free chatbot on a Tuesday afternoon.
That is a control problem, and it is solvable today.
If a disclosure is not covered by an exception, there is one other route: the taxpayer's prior written consent. It is more prescriptive than most firms expect.
Consent is governed by Treasury Regulation §301.7216-3, and for anyone filing in the Form 1040 series the form and content are set out in Revenue Procedure 2013-14. This is not a general permission slip. A consent authorises a specific disclosure, of specific information, to a specific recipient, for a specific purpose, and it has to be obtained before the disclosure happens.
The mandatory wording is prescribed, not paraphrasable. Revenue Procedure 2013-14 specifies the exact statements a 1040-series consent must contain, along with formatting requirements. A consent written in a firm's own words, however well intentioned, can fail on its face.
There are also rules you cannot draft your way around: a preparer may not ask again for a consent the taxpayer has already refused for that purpose, and disclosures to preparers located outside the United States are treated more restrictively.
A valid consent has to name the recipient. "AI tools" does not, and neither does a list a firm intends to keep adding to. If your consent names one vendor and a preparer uses a different assistant next season, the consent you hold does not cover it. If it names none, it is unlikely to satisfy the requirement at all.
Consent is also per taxpayer. A firm running a thousand returns through an AI-assisted workflow needs a thousand valid consents, refreshed as they expire, tracked against the specific vendor named in each. That is an operational burden most practices discover only after committing to the workflow.
Which is why the practical answer is usually narrower. Decide which tools the firm has actually evaluated, get a written position from counsel on whether an exception covers them or consent is required, then make sure taxpayer data cannot reach anything else. Consent is a real route, but it works best for a deliberate, named arrangement rather than as blanket cover for whatever a preparer opens in a browser tab.
The elements above are a summary, not a checklist to build a form from. Revenue Procedure 2013-14 and §301.7216-3 contain the operative requirements, including exact wording, formatting, electronic signature conditions, and separate rules for disclosures outside the United States. Have counsel draft or review any consent before you use it.
The same conduct usually implicates several regimes at once.
Tax preparers are treated as financial institutions under the GLBA Safeguards Rule, which requires a written information security program and controls over service providers.
IRS guidance for preparers, including Publication 4557, expects a documented written security plan. An undocumented AI workflow is a gap in it.
Practice standards for those who practise before the IRS, with their own diligence and competence expectations.
Professional standards on confidentiality apply independently of the tax code, and state boards enforce their own rules.
Policy tells people what not to do. DataFence decides what actually leaves.
A W-2 or organizer PDF headed for an AI tool is classified and stopped before it reaches the site, not logged afterwards.
The dominant AI risk for a tax practice is not uploading. It is pasting. Text input monitoring is available on Enterprise and Onyx plans.
SSNs, ITINs, account and routing numbers, names, addresses, and dates of birth are exactly the entities the engine is built to detect.
Allow the vendor you evaluated and signed an agreement with. Block the rest. The rule follows the data, not the person's memory of the policy.
AI activity reporting shows usage by service, by person, and by the type of sensitive data involved. Tools nobody approved show up as a list, not a surprise.
User, destination, classification, and the entities detected, logged for every allow, warn, and block. That is the evidence a WISP review or an examination asks for.
When a block is wrong, staff request an exemption with a business justification. A partner reviews it with the detection evidence attached, and the decision is recorded.
Push the extension through your MDM or RMM. Seasonal preparers and contractors are covered on day one, not after onboarding.
Two views answer the questions a §7216 conversation actually turns on: what was disclosed and to whom, and whether anyone is heading for trouble.
Where the boundary is. DataFence enforces in the browser. That covers how staff reach AI assistants, webmail, cloud storage, and portals, across every website rather than a list of approved ones. It is not an operating-system agent and does not inspect native desktop applications or command-line traffic. Your tax software running locally is outside its scope, and we would rather say so here than let you find out later.
IRC §7216 is a criminal provision that makes it a misdemeanor for a tax return preparer to knowingly or recklessly disclose or use tax return information other than in connection with preparing that return. It is paired with §6713, a civil penalty that applies without any knowledge requirement. The implementing rules are in Treasury Regulations §301.7216-1 through §301.7216-3.
It may. Tax return information is defined broadly and a disclosure is the act of making it known to any person outside the firm. Sending that information to a third-party AI vendor is at minimum a question a firm needs a documented answer to. Whether a given tool falls within a permitted exception depends on the vendor, the contract, where processing occurs, and how the tool is used, which is a determination for your counsel rather than a vendor.
Under §7216 a violation is a misdemeanor carrying a fine of up to $1,000, imprisonment of up to one year, or both, together with the costs of prosecution. Under §6713 the civil penalty is $250 for each prohibited disclosure or use, capped at $10,000 in a calendar year. The civil penalty does not require intent.
This is genuinely unsettled. Treasury Regulation §301.7216-2 permits certain disclosures to other tax return preparers providing auxiliary services in connection with preparing a return, with tighter conditions when the recipient is outside the United States. Whether a general purpose AI service fits that definition is a question practitioners disagree on, and it turns on specific facts. Firms should get a written position from counsel rather than assume either answer.
By controlling what actually leaves the firm rather than relying on policy alone. Enforcement at the browser inspects files and text before they are transmitted, so tax return information can be blocked from reaching tools the firm has not approved, while approved workflows continue. Every decision is logged, which gives the firm a record of what was disclosed and to whom.
Schedule a demo and see the AI services your staff are using, what taxpayer data is heading to them, and what it looks like when the answer is no.
This page is not legal or tax advice. It is a plain-language summary of publicly available authorities, provided for general information by a security vendor rather than a law firm. IRC §7216, IRC §6713, Treasury Regulations §301.7216-1 through §301.7216-3, and Revenue Procedure 2013-14 contain requirements, exceptions, and consent formalities that are not fully reproduced here, and authorities change. Whether any particular use of an AI tool constitutes a disclosure or use, and whether any exception or consent applies to your firm, depends on your specific facts. Consult qualified counsel and review the current authorities directly, including the IRS Section 7216 information center, before relying on any position.