Plain Answers · Accounting
Can CPAs use ChatGPT with client data?
Not by default. Here's the diligence.
Not by default — and no AI product earns a blanket "yes." Whether client tax or financial data can go into a tool depends on the deployment: the contract behind the plan you're on, what the vendor keeps and does with it, and what your clients have agreed to. For research questions with no client facts in them, use whatever helps. The line is the client's data.
Rules that may apply to you
Depending on what you do and who you serve, you may be subject to rules such as the ones below. We link the official sources and leave the interpretation to your counsel or your professional liability carrier's risk advisors. This is a starting point, not a complete list, and nothing on this page says what these rules require of you.
- IRS Publication 4557, Safeguarding Taxpayer Data(opens in new tab)
- IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice(opens in new tab)
- FTC Safeguards Rule: What Your Business Needs to Know(opens in new tab)
- 16 CFR Part 314, Standards for Safeguarding Customer Information(opens in new tab)
- IRS — Section 7216 information center(opens in new tab)
- California Business and Professions Code section 5063.3(opens in new tab)
The frame: an AI tool is one more service provider
You already have a framework for this, because you already have outside vendors. Tax and accounting practices may be subject to the FTC Safeguards Rule, and the IRS publishes security guidance for tax professionals, including a template for a written information security plan. All of it is linked above. If your firm has such a plan, it almost certainly says something about how you choose and oversee service providers.
So the practical question isn't "is this chatbot allowed?" It's "have we done for this vendor what our own written plan says we do for every vendor?" A personal chatbot account that a staff member opened on their own has, by definition, been through none of it.
Two more things to raise with your counsel
Client permission. California CPAs may be subject to Business and Professions Code section 5063.3, which concerns confidential client information (linked above). Whether sending data to a given AI vendor is a disclosure that needs a client's permission is a legal question for your counsel. "Where is our data processed, and in which countries?" is the factual one, and you can ask any vendor today.
Tax return information. Tax return preparers may also be subject to federal rules on disclosing and using tax return information; the IRS keeps a Section 7216 information center, linked above. If a tool would receive return information, ask your counsel how those rules apply to it before the season starts, not during.
What to ask an AI vendor
- Which contract governs the plan we'd use — and does it make security commitments, or only describe features?
- Is our data used to train or improve models? Which document says so?
- How long are prompts, uploads, and logs retained, including after deletion?
- Where is data processed and stored? Which countries, which subprocessors?
- Can your personnel view our content? When, and is it logged?
- What independent security assessments can you share?
- How will you notify us of an incident?
Apply the same list to us. We'll tell you up front that we don't currently hold a SOC 2 certification, which is one reason we prefer designs where your client data never reaches our infrastructure at all.
What we check when we deploy for a firm
- It goes in your plan. If your written security plan inventories the hardware that holds client data, an in-house AI server is one more line on that list, and we hand you the details to fill it in.
- No outbound path. The server is firewalled from the internet, and we test it with the uplink unplugged.
- Client-level access. Staff see the engagements they're assigned to. The AI answers from the same set, and no wider.
- Season-proof capacity. We size for your February, not your July. The number that matters is how many people are generating at the same moment at peak.
- Version pinning. The model doesn't change mid-season unless you decide it does. A workflow that depends on specific AI behavior shouldn't be surprised by an update in March.
- Retention that matches your policy, for documents, extracted data, and logs alike.
What in-house AI changes, and what it doesn't
When the model runs on hardware in your office, client data isn't disclosed to an outside AI vendor, so the vendor questions above mostly answer themselves. The cost is a one-time purchase — $1,500 to $7,500 for a single-GPU server — instead of a per-seat fee that peaks with your headcount. Document extraction and a private research knowledge base are two natural starting points.
It doesn't write your security plan, train your staff, or decide what your engagement letter should say about AI. For the general version of this question, see Is ChatGPT safe for business documents?