Doing bookkeeping faster is not the opportunity. Selling what it frees up is.
Every vendor sells accounting firms the same thing: the same work, cheaper. That protects a shrinking fee. The firms pulling ahead use automation to fund a service line they can sell at three to five times the price of bookkeeping, to the clients they already have.
AI for an accounting firm has two jobs. First, cut the cost of delivering compliance work so fee compression stops eating the practice. Second, turn the freed capacity into an advisory service line the firm sells to existing clients at a materially higher price.
Bring one messy workflow. We will show whether an agent, automation, SaaS product, or no build is the right next move.
The two jobs, and why one alone is a losing game
Cutting cost to serve is necessary and it is not a strategy. If you automate a $650 monthly engagement and keep charging $650, you have improved margin on a fee that competitors and software will keep pushing down. Automation is the funding mechanism. Repricing is the payoff.
- Defend: cut the cost of compliance work you already do
- Grow: sell the freed capacity back as advisory, at a higher price
- Do only the first and you win a race to the bottom more slowly
Use a product when the workflow is standard and the data path is simple.
Fast startLess controlBuild when integration, compliance, or differentiation decide the outcome.
Your stackYour codeWhat this does to the economics of a single client
Take one $650 a month bookkeeping client. Automating delivery lifts gross margin by roughly 23 points. Repackaging that same client into an AI-enabled service at $1,150 lifts revenue 77 percent and adds another 5 points of margin on top. The second move is worth more than the first.
Model C, cost to serve one client per month
| Line | Before | After agents | Repackaged |
|---|---|---|---|
| Monthly fee | $650 | $650 | $1,150 |
| Delivery hours | 7.5 | 3.1 | 4.4 |
| Labor cost at $42 loaded | $315 | $130 | $185 |
| Agent and tooling cost | $0 | $38 | $52 |
| Total cost | $315 | $168 | $237 |
| Gross margin | 51.5% | 74.2% | 79.4% |
Assumes a $42 fully loaded delivery hour and agents absorbing categorization, document chasing, and close prep. Illustrative model based on the assumptions shown. Not a guarantee of results. Individual firm results vary.
What you can sell, and what it should cost
Most firms price advisory by guesswork because there is no public benchmark. This is the ladder we see work. The goal is not to invent a new product. It is to move existing clients up one rung, which is a conversation you can have without winning a single new logo.
Model D, the service tier ladder
| Tier | What the client gets | Monthly price | Target margin |
|---|---|---|---|
| 1. Compliance | Tax and annual close | $450 to $900 | 55 to 65% |
| 2. AI-enabled bookkeeping | Automated categorization and reconciliation, monthly package | $900 to $1,600 | 70 to 78% |
| 3. AI controller | Tier 2 plus AP/AR agents, KPI dashboard, monthly review call | $2,000 to $3,800 | 72 to 80% |
| 4. Fractional CFO | Tier 3 plus scenario modeling, cash flow agents, board pack | $4,500 to $8,500 | 65 to 75% |
A realistic twelve month migration target is 25 percent of Tier 1 clients to Tier 2, and 15 percent of Tier 2 to Tier 3. Illustrative model based on the assumptions shown. Not a guarantee of results. Individual firm results vary.
The hours have to go somewhere, and you only get to spend them once
This is where most AI business cases quietly cheat. A nine person firm might free around 857 hours in year one. Those hours can become billable advisory work, or they can avoid a seasonal hire. They cannot do both. Any vendor who adds the two together and calls it total ROI is selling you a number, not a plan.
Model B, capacity reclaim for a nine person firm
| Line | Value |
|---|---|
| Firm-wide hours per year on categorization, chasing, cleanup, 1099s, close prep | 4,100 |
| Agent-eligible share | 38%, or 1,558 hours |
| Realistic year-one capture | 55%, or 857 hours |
| Path 1: redeploy to billable advisory | 857 hrs x 70% conversion x $165 realized = $98,983 |
| Path 2: avoid a seasonal hire | One staff accountant, fully loaded = $72,000 |
Path 1 and Path 2 are alternatives. Adding them together is the most common credibility failure in AI ROI marketing, and it is why most of these numbers should be read skeptically, including ours. Illustrative model based on the assumptions shown. Not a guarantee of results. Individual firm results vary.
What actually gets built
Not a chatbot bolted onto QuickBooks. Supervised agents that run inside your existing stack, take real actions in the ledger, and stop and ask a human when the situation is unclear. Every action is logged, because you will be asked to explain it during a review.
- Runs in your cloud, against your data, under your access controls
- Human approval gates on anything that touches a filing or a payment
- Full audit trail of every action, retrievable during review
- You own the code and can operate it without us
The uncomfortable part of the twenty-four month picture
Firms that do this properly end up with fewer clients, not more. Capacity moves to the engagements that carry margin, and the bottom of the client list gets released or repriced. If a plan promises more revenue, higher margin, and a growing client count all at once, it has not been thought through.
Model E, firm-level trajectory for a $2.1M practice
| Measure | Baseline | Month 12 | Month 24 |
|---|---|---|---|
| Revenue | $2.10M | $2.51M | $2.98M |
| Gross margin | 54% | 61% | 67% |
| Revenue per FTE | $150K | $179K | $199K |
| Advisory share of revenue | 12% | 27% | 41% |
| Client count | 240 | 236 | 228 |
The falling client count is deliberate, not an error. Illustrative model based on the assumptions shown. Not a guarantee of results. Individual firm results vary.
The four things being sold as an "AI accounting assistant"
This page is scoped to tools that touch the ledger, the bank feed and the workpaper. Research tools like Checkpoint Edge are deliberately out of scope here.
Inside that scope, four different products share one label. A bank feed classifier that suggests a category. A document extractor that reads a W-2 into a field. A drafting tool that writes the client email. And an agent that executes a step in your close.
Ask which one you are looking at before the demo starts. The first two touch the ledger and the workpaper. The third touches the client's inbox. Only the fourth does work without a person pressing a key.
The categories fail differently, so they need different gates. A bad category suggestion is caught in review. A bad email is caught by the sender. A bad agent action posts.
Firms buy across all four without noticing. That is how a practice ends up with three overlapping subscriptions and no measured saving.
How do you tell a rules engine from an agent during the demo?
Bring a de-identified export from one of your messiest clients. Ask the rep to run it live, in front of you. A sandbox tuned by the vendor tells you nothing.
A rules engine matches a string and returns a category. An agent reads context, picks a treatment, and shows its reasoning. Then ask what happens on the second occurrence.
Rules repeat identically forever. A model that scores confidence behaves differently once a pattern builds in the client's own history.
Intuit describes its top confidence tier as exactly that kind of history match. It says QuickBooks has strong data behind the suggestion, with a clear pattern in your history.
That is pattern matching, honestly labeled. It also explains why a client onboarded in November gets weak suggestions on their first bank feed. There is no history to match against yet.
Does the tool tell you when it is guessing?
Some do, and it is the single most useful feature in the category. QuickBooks grades its own suggestions. The lowest grade tells the user plainly that QuickBooks has limited data behind the suggestion.
Put this on your evaluation sheet. A tool that returns one answer with no confidence signal gives the reviewer nothing to triage by. Every line then gets the same attention, which is the same as no automation.
Confidence should sit at field level, not document level. A K-1 can be read correctly in eleven places and wrong in one.
Ask to see the low confidence queue during the demo, not the happy path. A vendor that cannot show you its own failure queue has not built one.
Where do bank rules actually run out?
At 2,000 rules per file, and five conditions per rule. Intuit publishes the ceiling directly, stating you can create up to 2,000 bank rules.
The second limit bites first. A single rule is capped, because you can set a single rule with up to 5 conditions.
Five conditions run out faster than you expect. This vendor, above a dollar threshold, only on the operating account, only when the description carries a second string. You are already at the ceiling.
Then there is the maintenance problem. Rules live inside one company file. They do not travel between clients except by copying them. A 40 client book means 40 rule sets to build and keep current.
Use the numbers in your own diagnosis. Count rules on your three messiest clients before you price any tool.
How much of a 1040 document set can software finish on its own?
Sixty five percent of standard documents, by the incumbent's own published figure. Thomson Reuters states that 1040SCAN eliminates the need to verify OCR data for 65% of standard documents by combining patented text-layer matching and AI.
Read the other half of that sentence. Roughly a third of standard documents still go to a person. Non standard documents are not in the denominator at all.
That remainder has a shape. SurePrep's review step color codes fields. It marks a field where OCR is uncertain about that field and requires verification.
Use 65% as your baseline when a newer vendor quotes you a number. Ask what their denominator is. Ask whether it includes the documents that arrive sideways in March.
What has to be settled with the vendor before any client file moves?
Start with what the vendor is. Under the 7216 regulations it is very likely a tax return preparer itself. The definition reaches a person who develops software that is used to prepare or file a tax return. Vendor selection is not an IT purchase. It admits a second preparer into the client's return data.
Then ask where the software actually runs. If anyone receiving the return information sits abroad, the rule is explicit. It requires the taxpayer's consent under § 301.7216-3 prior to any disclosure. Remote viewing counts as disclosure. "The data never leaves our tenant" does not answer the question.
Then read the contract. The Safeguards Rule reaches accounting firms directly, and diligence alone does not satisfy it. The rule obliges you to go further, requiring your service providers by contract to implement and maintain such safeguards. Encryption in transit and at rest belongs in the same clause. So does multi factor authentication.
So three questions cover the demo. Where does inference run, where does support sit, and what does the contract commit the vendor to. Answers given verbally do not count. For the full treatment of 7216 consent, client disclosure and reviewer duties, see our AI agents for accounting firms page.
The questions to put to a vendor in writing
There is a published list, and it came from the profession rather than a marketing page.
Send those six to the vendor before the second call. Add the three from the section above, plus one more. What does the published document scope exclude?
Some vendors already answer the training question on the record. Karbon states that it does not use your firm's data to train AI models, and no data is shared with third parties or used to inform any other Karbon customer's experience.
Ask for firm level controls too. Karbon notes that account administrators can disable AI functionality through firm settings. That is the switch a partner needs when a client objects.
What a 97% accuracy claim does not tell you
It does not tell you the denominator. Xero's marketing page says Xero reconciles your transactions at 97% accuracy, so there's less manual matching and more time for your business. No methodology is published on the page.
Treat every accuracy figure in this category as a vendor claim until a method appears. Nobody publishes the document mix, the sample size, or what counted as an error.
If that 97% held on your files, a client with 900 monthly transactions would still leave about 27 lines for someone to find. Xero publishes no test set. Treat that as arithmetic on a marketing number, not a workload estimate. The real figure could be better, or much worse.
Ask three questions instead of comparing percentages. What was the test set, who labeled the correct answer, and does the figure include the documents the tool refuses.
Does automation cut review time, or just move it?
It moves it, and the evidence comes from standard setters rather than vendors. One note on scope first. The PCAOB material below governs audits of issuers. A firm doing private company work sits under AICPA standards instead. The pattern still transfers.
It is about what happens after a tool flags something. The PCAOB observed that because technology-assisted analysis may enable the auditor to examine all items in a population, it is possible that the analysis may return dozens or even hundreds of items within the population that meet one or more criteria established by the auditor.
The IAASB reaches the same place from the other direction. In its worked example, the procedures performed using ATT do not provide sufficiently persuasive audit evidence for Group A, rather it further informs the auditor's risk assessment.
So budget reviewer hours, not just preparer savings. A firm that cuts prep by a third and adds an exception queue nobody owns has traded cheap time for expensive time.
The obligation does not shrink either. The IAASB puts it in one line. Regardless of the tools and techniques used, the auditor is required to comply with the ISAs.
What a pilot should look like before busy season
Pick one workflow, one client segment, and a closed prior period. Run the tool over books you already closed. Then you have the right answer to compare against.
Choose work where a mistake is visible immediately. Document sorting, extraction and duplicate detection flag things. Coding and accepting bank feed matches post to the ledger, so those need a person on the gate. Reconciliation belongs with the review side.
Baseline three numbers before anything is switched on. Prep hours per return type, reviewer hours per file, and the count of follow up loops back to the client's inbox.
Name one owner who knows the chart of accounts, usually a manager rather than a partner. Start after the spring deadline and finish testing by late summer. Decide in September, then leave Q4 for training the people who will use it.
How you will know the pilot failed
Reviewer hours went up and nobody noticed. That is the most common failure. It is invisible unless you baselined the reviewer, not just the preparer.
Watch for a growing queue of files the tool will not take. Vendors publish scope limits, including orientation requirements and excluded account types. Those exclusions arrive as a pile at the worst moment.
Watch for silent coding to a catch all account. A close that looks clean because unknown merchants were swept into one line is worse than an obvious exception list.
And watch the measurement itself. In a survey of 1,073 firms, 40% said they had not yet figured out how to track efficiencies due to technological advancements. Most pilots end in opinion rather than evidence.
Buy the tool or build the agent: the questions that decide it
Buy where a product already fits the standard path. Indexed 1040 binders, extraction from recognized forms and tax software integration are solved. Rebuilding them wastes money.
Build where the work is yours and the data must stay inside your boundary. Odd business returns, firm specific leadsheets, client chase loops, and anything where offshore hosting would trigger a consent requirement.
Most practices have no internal build capacity today. The 2024 CPA.com and AICPA PCPS CAS Benchmark Survey drew 206 self-selected respondents. Only 13% build automation with an internal team, while more than 67% are partnering with software vendors to provide these kinds of tools.
The report concedes self-selection bias, so read it as directional. The stack you are automating is messier than the demo assumes. In the same survey, only 46% of respondents report using a specific set of software applications that are fully integrated.
Implementation is also unpriced at most firms. Only 55% charge separately for client technology setup, and only 42% have a team that does it, per the same benchmark.
Where firms like yours have actually put AI so far
At the edges of the work, not the middle. A 2026 survey of 486 bookkeeping and accounting professionals published a task table. The figures below sit on an AI-active base rather than the full sample.
Those two bases are not the same, which matters on a page about denominators. The reported rows run like this:
- Drafting client emails and communication, 75% - Summarizing documents or meetings, 71% - Research and answering technical questions, 69% - Transaction categorization or coding, 42% - Financial reporting and commentary, 40% - Bank reconciliation, 24% - Tax return preparation, 9%
Read the bottom of that list before the top. Bank reconciliation at 24% and return preparation at 9% tell you where the technology has not earned trust yet.
Trust is the limit, not availability. In the same survey, only 19% trust AI enough to use it with limited review.
Almost nobody wants the tool acting alone. In a separate Intuit commissioned survey of 725 US accounting professionals, only 6% want AI to execute autonomously. That survey is vendor funded, and its sampling method is published on the page.
The shape firms do want is draft plus review. Asked what role AI should play in client work, 40% want AI as a support tool and 34% want AI to draft, with a human reviewing and signing off.
Who signs when the assistant prepared the workpaper
A person does, and the standard leaves no room. The AICPA's tax standards state that tools should be used to enhance or improve the member's understanding of a tax issue, not to supplant the member's professional judgment. The attestation under penalties of perjury cannot be handed to software.
AI is named inside that standard, not sitting outside it. Tools are defined to include tax preparation software, tax research publications (paper or electronic), tax-related calculation aid, tax planning software, state and local tax aids, online data search engines, data analytics, statistical models, artificial intelligence, and relevant professional publications and resources.
Reliance is allowed, and the limit is stated in the same breath. A member may reasonably rely on tools used in providing tax services to a taxpayer. Use of a tool does not absolve the member of professional obligations under AICPA or other applicable ethical standards.
When the output is wrong, the claim lands on the firm. An Aon risk consultant puts it directly. Generative AI can be confidently wrong. That can be a professional liability problem if you rely on its output without proper review.
The same column names who pays for it. If the tool provides incorrect information that goes unchecked, a client will come after the firm, not the AI tool.
What to leave in the client file
Three things, and none of them are hard. The same Aon column recommends that employees document the prompts used, how the outputs were verified, and who performed the review.
Store the named human approver, never a service account. If the log shows software approving software, the firm has automated away its own evidence.
Insurers are already asking to see the policy behind it.
Aon's risk control lead says carriers are going to ask a firm about their AI policy and procedures. They want to see firms are approaching the use of AI with the same basic risk management protocols that they would have in place for engagement letters or client acceptance and continuation or documentation.
Claims data does not exist yet, and that is worth saying plainly. The same source notes there really hasn't been a lot of claims or large dollar amounts paid on claims. Nobody can price this risk from experience.
The real blocker is time, not resistance from staff
Partners expect a fight from the team and get a calendar problem instead. In a survey of 1,073 firms, the biggest barrier to implementing emerging technologies was lack of time to explore or implement (41%). Staff resistance or fear of change registered at only 6%.
The tax side reports the same two constraints. In a separate survey of 639 tax and accounting professionals, almost half (47%) of respondents said the biggest reason they can't (or don't) pursue more automation is lack of time and resources, followed closely by the cost of implementation (45%).
Most firms are also less automated than the marketing suggests. In that same survey, about half (49%) of the respondents to this year's survey estimate that one-quarter of their tax workflows are automated, while 21% said that up to half are automated. And 18% said they use no automation at all.
So the practical answer is to scope small and staff it properly. A named owner with real hours beats a firm wide rollout nobody has time to run.
What do we actually have to change in our WISP before we switch an agent on?
Nothing in the Safeguards Rule names AI, so what forces the update is the material change language, not an AI rule. 16 CFR 314.3(a) is what makes the program written in the first place, and 314.4(g) requires you to evaluate and adjust it in light of "any material changes to your operations or business arrangements". An agent deployment also lands on 314.4(c)(2), identify and manage the data, personnel, devices, systems and facilities that enable your business purposes, on 314.4(c)(7), adopt procedures for change management, and on 314.4(d)(2)(ii), which pulls a vulnerability assessment forward whenever there are material changes to your operations.
The concrete gap sits in the template most firms started from. Publication 5708 is a Security Summit sample, not a rule, and it says so: it is "not intended to replace your own research, to create reliance or serve as a substitute for developing your own plan". The Rev. 8-2024 edition does not mention artificial intelligence anywhere. Its sample disclosure paragraph lists state and federal tax authorities, the tax software vendor, a bookkeeping service, a payroll service, a CPA firm, an Enrolled Agent, legal counsel and business advisors. No model provider appears on that list. Sample Attachment E is a hardware inventory, its guidance covering computers, phones, storage devices, cloud storage and paper records, with no row for an inference endpoint. A firm that adopted the sample verbatim has a plan that does not describe the disclosure it is about to start making.
We have fewer than 5,000 individual clients. Does that get us out of the Safeguards Rule?
No. It removes four requirements and leaves the rest. 16 CFR 314.6 reads in full: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." That is the written risk assessment, the penetration testing and vulnerability assessment cadence, the written incident response plan, and the annual report to your board or a senior officer.
Read the first one closely, because it is narrower than it looks. The exception names 314.4(b)(1), the paragraph that makes the risk assessment written and sets out what it has to contain. Paragraph (b) itself, base your information security program on a risk assessment, is not excepted. The assessment is still required, just not in the form the rule otherwise prescribes.
Encryption at 314.4(c)(3), multi factor authentication at (c)(5), service provider oversight at (f) and FTC notification at (j) are not on the list, so they apply at any size.
Count carefully before leaning on the exception. 314.2(b)(1) covers an individual who "obtains or has obtained" a financial product or service, so retained prior year files count, and 314.1(b) applies the rule to "all customer information in your possession," including "the customers of other financial institutions that have provided such information to you." Where an entity engagement hands you individual records, the count is genuinely unsettled: 314.1(b) pulls that information into scope, while 314.2(b)(2)(v) says an individual who is a consumer of another financial institution is not your consumer solely because you provide processing or other services to that institution. Get a written read from counsel rather than assuming the low number. Either way this is a headcount question, not a firm size question.
Is a model API a service provider under the Safeguards Rule if it retains nothing?
On the text of the rule, yes. 16 CFR 314.2(r) defines a service provider as any person or entity that "receives, maintains, processes, or otherwise is permitted access to customer information" through its provision of services directly to a financial institution subject to the part. Processes is listed separately from maintains, so an inference endpoint that receives a prompt containing customer information is inside the definition on its face, with or without retention.
Section 314.4(f) then sets three duties: take reasonable steps to select and retain providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider "based on the risk they present and the continued adequacy of their safeguards." The third one recurs, so an agreement signed at onboarding does not discharge it. The Commission made the same point in the preamble to the 2021 amendments, discussing a provider that stores and processes customer information: the firm must require that provider to encrypt it and "periodically determine whether it continues to do so."
Neither the rule text nor the 2021 rulemaking record mentions AI or model providers, so which parties in a given stack qualify is a facts question you have to work through with counsel, not one with a published answer. Running the agent in your own cloud changes who the vendors are, not whether the duty exists.
Do the agent's prompt logs and output logs have to be encrypted?
The stored ones, to the extent they contain customer information, yes. 16 CFR 314.4(c)(3) requires you to "protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest". Where you determine that is infeasible, the rule lets you substitute "effective alternative compensating controls reviewed and approved by your Qualified Individual".
A call from your systems to a hosted model is an external transmission. Footnote 164 of the 2021 amendments says the Commission believes transmissions "to remote users or to cloud service providers should be treated as external transmissions, as those transmissions are sent out of the financial institution's systems." That is preamble reasoning rather than rule text, but it is the Commission reading its own rule.
The same document says the Commission "declines to extend the encryption requirement to data in use", on the view that the technology had not been adopted widely enough to mandate. So the context window itself sits outside the requirement, while everything the agent leaves behind, prompt logs, traces, retrieval indexes and derived summaries, sits inside it.
Encryption at rest is also the off ramp from breach reporting. Under 314.2(m) a notification event is acquisition of unencrypted customer information, and the 2023 amendments state that the final rule does not require notification "if the customer information acquired is encrypted, so long as the encryption key was not accessed by an unauthorized person."
Does an agent running on a service account need multi factor authentication?
Probably not under the MFA provision itself, because that provision is written around people. 16 CFR 314.4(c)(5) requires multi factor authentication "for any individual accessing any information system, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls." Section 314.2(a) defines an authorized user as "any employee, contractor, agent, customer, or other person that is authorized to access any of your information systems or data", all of them persons.
The provisions you would actually govern a service account under are 314.4(c)(1), access controls that authenticate and permit access only to authorized users and limit each to what they need, and 314.4(c)(8), monitor and log activity and detect unauthorized access, use or tampering. Both of those are also written around authorized users, so on a strict reading the rule does not squarely address a non human identity anywhere. Treat that as a gap in the text, not as a permission.
The IRS restates the requirement more broadly than the rule does. Publication 1345, Rev. 12-2025, tells Providers to "implement multi-factor authentication for anyone accessing taxpayer information" and attributes that to the Safeguards Rule. Anyone is not the word the rule uses. If you are an Authorized IRS e-file Provider, expect the broader wording to be the one you get asked about.
Neither the rule text nor the 2021 rulemaking record mentions service accounts or non human identities, so the allocation above is a reading, not a settled answer. What the text does settle is the deliverable: a written Qualified Individual determination. Note the conflict if that individual works for the vendor that built the system. Section 314.4(a) permits a service provider in the role, but then you must retain responsibility for compliance and designate a senior member of your own personnel to direct and oversee them.
An agent exposed client data. Who do we have to notify, and how fast?
Two clocks, and the IRS one is the next business day. Publication 1345, Rev. 12-2025, sets a reporting of security incidents standard: Authorized IRS e-file Providers of individual income tax returns "must report security incidents to the IRS as soon as possible but not later than the next business day after confirmation of the incident." There is no volume threshold. Providers with multiple roles follow the instructions for reporting security incidents, and those that are EROs only contact their local stakeholder liaison.
Be clear about what that obligation is. Publication 1345 is not a rule in the CFR. It is the participation handbook for IRS e-file, and it says violating a provision of it "may subject the Authorized IRS e-file Provider (Provider) to sanctions", which run up to suspension or expulsion from e-file. That is the enforcement hook, and it only reaches you if you are a Provider.
The FTC clock is 30 days from discovery, and only where the notification event involves the information of at least 500 consumers, under 16 CFR 314.4(j). Paragraph (j)(2) imputes discovery widely: a notification event is treated as discovered when it is known to "any person, other than the person committing the breach, who is your employee, officer, or other agent." So the IRS report can fall due while you are still counting consumers for the FTC.
Clients are not on the federal list. The Commission declined to require consumer notification in the 2023 amendments, reasoning that "because all States have some form of consumer notification requirement," a direct requirement in the Safeguards Rule "would be largely duplicative of those State laws." Client notice is a state law question, and the Commission's own basis for skipping it was that your state already has one. The same document says the Commission "intends to enter notification event reports into a publicly available database."
Is every agent mistake a reportable breach?
No, and the rule gives you two different terms so you can tell which is which. A security event under 16 CFR 314.2(q) is any event resulting in "unauthorized access to, or disruption or misuse of, an information system, information stored on such information system, or customer information held in physical form." That is broad enough to reach an agent acting outside its intended scope even when nothing leaves the firm. A notification event under 314.2(m) is narrower: acquisition of unencrypted customer information without the authorization of the individual to which the information pertains. Only the second one triggers the FTC filing.
Two qualifiers matter. The written incident response plan at 314.4(h) covers security events "materially affecting the confidentiality, integrity, or availability of customer information in your control", so materiality is the limiter rather than whether data left the building. And 314.2(m) presumes unauthorized access is unauthorized acquisition "unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information." Without logs good enough to rebut it, you own that presumption.
The IRS standard is worded more broadly. Publication 1345 says that for its reporting standard, "an event that can result in an unauthorized disclosure, misuse, modification, or destruction of taxpayer information (e.g., breach) must be considered a reportable security incident." Can result, not did. No volume threshold, and no encryption carve out like the FTC's.
Neither the rule text nor the 2021 and 2023 rulemaking records mention AI, so whether an out of scope agent action counts as misuse of an information system has no published answer. Decide where your own line sits, in the incident response plan and in writing, rather than during an incident.
Has any state board of accountancy written a rule about using AI?
None that we could find, and the model language the boards work from does not use the term. The Uniform Accountancy Act, Ninth Edition, July 2025 and the UAA Model Rules, January 2024 contain no mention of artificial intelligence.
What the model rules do enforce is standards compliance. Model Rule 10-3 says a licensee "shall comply with all applicable standards," then lists them: AICPA standards for tax services, attestation, accounting and review services, and management consulting, GASB for governmental statements, and PCAOB and SEC rules only for "services subject to the authority of the SEC or PCAOB," which for a firm with no public clients means not at all. Model Rule 10-1 adds gross negligence as its own ground for discipline, including "making misleading, deceptive or untrue representations in the performance of services."
The supervision language sits in the AICPA Code of Professional Conduct, which binds members. The General Standards Rule, ET 1.300.001, requires professional competence, due professional care, adequate planning and supervision, and "sufficient relevant data to afford a reasonable basis for conclusions or recommendations." ET 1.300.010 defines competence to include that the member "supervises and evaluates the quality of work performed."
Every mention of AI in the Code is a pointer to material the Code itself labels nonauthoritative: Ethics Questions and Answers section 400.02, Using the Output of Technology, and a staff article, AI through an ethics lens. The AICPA's own journal treats the existing rules as the governing ones, noting that the General Standards Rule "hasn't changed." Boards write their own rules, so read yours, but expect to be judged on standards and supervision, not on your tooling.
Does AI training count for CPE, and does any state require it?
It counts, and no jurisdiction we could find requires it. NASBA's Fields of Study document, January 2024 lists Artificial Intelligence as a subject inside Information Technology, which is a technical field of study.
Two classification rules matter more than that headline. Courses in "the general use of software," the how-to kind run around a product, sit in Computer Software and Applications, which is non-technical, and the document names bookkeeping software such as QuickBooks as an example. And when a course "focuses on the application of information technology in an accounting, auditing or tax practice," it "should be categorized into the field of study of the respective practice: auditing, accounting, or taxes," so agent training built around return preparation counts as Taxes rather than as IT.
That matters because UAA Model Rule 6-4(b) asks for at least fifty percent of credits in technical fields, which its own chart puts at 60 of 120 on a triennial cycle, alongside 6 ethics credits. Nothing in the model rules requires a technology credit. The 2026 Statement on Standards for CPE Programs, effective August 1, 2026 and phased in through November 2028, does not mention artificial intelligence at all.
If the agent does the work our first-years learn on, can they still get licensed?
Yes, because the experience requirement counts hours and breadth, not who touched the keyboard. Under UAA Model Rule 6-2, experience "may consist of providing any type of services or advice using accounting, attest, compilation, management advisory, financial advisory, tax or consulting skills," one year is employment over at least a year that "includes no fewer than 2,000 hours" of those services, a licensee has to verify it, and the Board "shall look at such factors as the complexity and diversity of the work."
Nothing in that rule says a person must perform a task in order to have learned it. We found no board rule or guidance that addresses agent-assisted work in an experience affidavit either way, so the question is open rather than settled in your favor.
The arithmetic deserves attention anyway. The Uniform Accountancy Act, Ninth Edition added a route that trades 30 semester credit hours for a second year of work, "A baccalaureate degree with an accounting concentration and two years of experience," and its drafters describe the revisions as removing barriers to licensure. For a candidate on that route, twice as much of the licensure requirement now sits in the seat, and the repetitive work an agent absorbs is the work that used to fill it. Complexity and diversity has to be assigned on purpose from here, not picked up by accident.
A client asks for everything the agent produced on their file. What do we owe them?
Less than most partners assume, and the line lands in an unexpected place. Under the Records Requests interpretation at ET 1.400.200 in the AICPA Code, you must make client-provided records and your work products available, plus member-prepared records without which the client's financial information would be incomplete, and absent extenuating circumstances "no later than 45 days after the request is made."
Working papers are treated differently: "Working papers are the member's property, and the member is not required to make such information available," subject to state and federal statutes and regulations and to your own contracts. The same interpretation says a member "is not required to make formulas available" unless the member was engaged to deliver them as part of a completed work product, or the formulas produced member-prepared records the client's information would be incomplete without.
Our reading, and it is a reading rather than a rule, is that prompts, configuration, agent logs and intermediate output look more like working papers and formulas than like a deliverable, so they are usually yours to keep. Two things narrow that. Paragraph .05 of the same interpretation says a state board may refuse to let you withhold records the Code would let you withhold, and the board rule wins. And Circular 230 section 10.28 runs a separate track, requiring prompt return of records the client needs to meet federal tax obligations, a term that by its own text reaches documents your firm prepared and presented to the client if the client needs them for current compliance.
Settle which of these the client gets before the first engagement letter goes out, not during the first argument about it.
The agent got something wrong and the returns already went out. What is the order of operations?
Tell the client first, then find out how many returns carry the same error.
Circular 230 section 10.21 requires a practitioner who knows a client has made "an error in or omission from any return, document, affidavit, or other paper" submitted under the revenue laws to "advise the client promptly of the fact of such noncompliance, error, or omission," and to advise the client "of the consequences as provided under the Code and regulations."
Scope comes second because it changes your penalty position. The reasonable cause and good faith exception to the section 6694(a) preparer penalty, at Treas. Reg. 1.6694-2(e), does not apply where there is "a pattern of errors on a return or claim for refund" or "a repetition of the same or similar errors on numerous returns or claims for refund." That is exactly how a misconfigured agent fails, the same way, on every file it touched. Paragraph (e)(1) also withholds the exception from "an error that would have been apparent from a general review of the return or claim for refund by the tax return preparer."
What the same regulation credits is process you can show. Paragraph (e)(4) asks whether the preparer's "normal office practice" amounts to "a system for promoting accuracy and consistency," and names checklists, methods for obtaining necessary information from the taxpayer, a review of the prior year's return, and review procedures. A review step that runs inside the workflow and leaves a record is easier to produce later than one that lived in a partner's habits.
Who at the firm has to own the agent's procedures?
One named person, under a rule that took effect in 2014. Circular 230 section 10.36 puts the duty on any individual who has, or individuals who have or share, "principal authority and responsibility for overseeing a firm's practice governed by this part," who "must take reasonable steps to ensure that the firm has adequate procedures in effect for all members, associates, and employees" for complying with subparts A, B and C of Circular 230. If the firm identifies nobody, the IRS "may identify one or more individuals" for the role, which is a worse way to learn who it was.
Two limits are worth knowing before over-reading that. Discipline under 10.36(b) requires willfulness, recklessness or gross incompetence by that person, plus firm people who "are, or have, engaged in a pattern or practice" of failing to comply. One bad output is not an Office of Professional Responsibility case.
And the text reaches members, associates and employees. It does not name contractors or vendors, so it does not by itself make an outside vendor's staff answerable for your procedures. If you want the vendor held to a procedure, the contract has to do that work.
Concrete places agents earn their keep.
Policy matched. Refund ready for approval.
Bank reconciliation
Match across feeds and the ledger, surface only the exceptions a person needs to judge.
Month-end close prep
Assemble the close package, chase the missing documents, flag what does not tie.
account score
Client cleanup and onboarding
The wedge offer. Work through a messy back file fast enough to quote it as a fixed fee.
AP and AR chasing
The follow-up nobody has time for, run on schedule with a human on approvals.
Cash flow forecasting
The sellable advisory product: rolling 30, 60 and 90 day projections per client.
1099 and filing prep
Seasonal volume absorbed without seasonal hiring.
Common questions.
How much revenue can an accounting firm add with AI advisory services?+
What should a ten person firm automate first?+
Is it safe to give an AI system access to client financial data?+
Will AI replace accountants and bookkeepers?+
AI or offshore staffing, which is cheaper for a small firm?+
How long before a firm sees anything?+
Want agents like these in your stack?
Book a free assessment, we'll map where an AI agent creates real leverage in your workflows and scope the first one to ship.