Can You Send Client Tax Data to an AI Tool? Section 7216 Says Yes, With Consent
26 CFR 301.7216-3 permits consent-based disclosure, so 7216 is no absolute bar. What consent requires, what is unsettled, and the Safeguards Rule overlap.
Yes, with consent. The regulation under Section 7216 permits disclosure where the taxpayer has given a valid written consent, so the common claim that 7216 is an absolute bar is simply wrong. The harder questions sit elsewhere: whether a model API disclosure is the kind the regulation contemplates, and what the Safeguards Rule separately requires of you.
Does Section 7216 ban disclosure to a third party outright?
No. 26 CFR 301.7216-3(a)(1) permits a preparer to disclose tax return information as the taxpayer directs, provided the preparer first obtains the taxpayer's written consent. The regulation is a prohibition with a route through it, not a prohibition with no route at all.
In its own words, a preparer "may disclose or use tax return information as the taxpayer directs as long as the preparer obtains a written consent from the taxpayer as provided in this section". The section is titled "Disclosure or use permitted only with the taxpayer's consent".
The same paragraph sets the quality of the consent. It "must be knowing and voluntary", and except in the narrow case at (a)(2), "conditioning the provision of any services on the taxpayer's furnishing consent will make the consent involuntary". So the one shape that reliably fails is the consent buried in an engagement letter as a condition of being taken on as a client.
The penalties under 7216 are real, and advisers who lead with them describe a wall where the regulation describes a gate. The cost of that is not caution, it is paralysis in the wrong place: a firm that believes disclosure is categorically barred never builds a consent process, so when a partner starts using a tool anyway, and partners do, there is nothing to route it through.
What does a valid consent have to look like?
Written, specific, and obtained first. 301.7216-3(a)(3)(i) requires every consent to include the name of the tax return preparer and the name of the taxpayer, and, for a disclosure, to "identify the intended purpose of the disclosure" and to "identify the specific recipient (or recipients) of the tax return information".
Read the recipient requirement against an AI deployment, because it is the one that bites. A consent gesturing at "technology providers" does not identify a specific recipient. Naming the vendor means knowing which vendor, and that is a question many firms cannot answer about tools already in use.
Two timing rules matter as much as the form. 301.7216-3(b)(1), headed "No retroactive consent", provides that "A taxpayer must provide written consent before a tax return preparer discloses or uses the taxpayer's tax return information." There is no cure after the fact, which is the uncomfortable part for a firm where a tool is already in use. And under 301.7216-3(b)(5), a consent that does not state its own duration runs for one year from the date the taxpayer signed it.
Have counsel or your tax practice build the document from the current text rather than from a template in circulation, because a consent that fails on form is worth nothing at all.
Does the data leave the United States?
If it does, and social security numbers are in it, there is a specific rule and it is strict. 301.7216-3(b)(4) provides that a preparer inside the United States generally "may not obtain consent to disclose the taxpayer's social security number (SSN)" to a preparer outside the United States for a return in the Form 1040 series.
The exception at 301.7216-3(b)(4)(ii) permits it "only if" the disclosure is made "through the use of an adequate data protection safeguard as defined by the Secretary in guidance published in the Internal Revenue Bulletin", and the preparer verifies the maintenance of those safeguards in the consent request itself.
Whether that rule reaches a model API is unsettled, because it is written in terms of disclosure to a tax return preparer outside the United States and a model vendor is not obviously one. What is not unsettled is that you need to know where the processing happens, and many hosted endpoints do not promise a region by default.
Does a disclosure to a model API even count as a disclosure?
Nobody has answered that, and it is the genuinely unsettled question in this area. Treat it as a disclosure and obtain consent anyway, because the cost of being wrong runs one way only.
We are not aware of IRS guidance, a Revenue Ruling or a court decision addressing whether routing tax return information through a model API, particularly one that retains nothing, is a disclosure within the meaning of 7216, or how the analysis changes when the processing happens inside infrastructure the firm itself controls.
Anyone who tells you confidently either way is reasoning by analogy, not citing authority. What follows is a posture, not an answer. If the question is later resolved in the permissive direction you have lost the cost of a consent form. If it is resolved the other way, a firm that guessed has made an unconsented disclosure of tax return information across its client base, at scale and in writing.
Consent under 7216 does nothing for the Safeguards Rule
These are two separate regimes with two separate agencies behind them, and satisfying one earns you nothing under the other. A perfect 7216 consent file does not make you compliant with 16 CFR part 314, and a mature Safeguards program does not authorize a disclosure that needed consent.
Three pieces carry most of the weight. 314.4(c)(3) requires you to "Protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest". 314.4(g) requires you to adjust the program for, among other things, "any material changes to your operations or business arrangements". And 314.2 defines a service provider as "any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution that is subject to this part."
On that text a model API looks like a service provider, because "processes" is listed separately from "maintains", so a vendor that keeps no copy is still inside the definition. Treat it as a reading rather than a ruling. No FTC action or court decision we are aware of has applied 314.2 to a model vendor.
Your WISP almost certainly does not describe this disclosure
Search your written information security plan for "AI" before you do anything else. If it came from IRS Publication 5708, the sample WISP, Rev. 8-2024, the search returns nothing: across its 29 pages the document contains no occurrences of "artificial intelligence" and no standalone "AI".
That is not a flaw in the publication, which says itself that it is "not intended to replace your own research, to create reliance or serve as a substitute for developing your own plan". It does mean a firm that adopted the sample verbatim holds a plan that does not describe the disclosure it is about to start making, and 314.4(g) is what makes updating it an obligation rather than good practice. We set out what to add to the WISP separately.
Is a 7216 consent a privilege shield?
No, and conflating the two is a live risk for firms doing work alongside counsel. A consent makes a disclosure lawful under the tax rules. It does not make the material privileged, and it does not prevent a waiver argument.
A recent memorandum from the Southern District of New York makes the waiver point directly. In United States v. Heppner, No. 25 Cr. 503 (JSR), a footnote records that "even if certain information that Heppner input into Claude was privileged, he waived the privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party." The court treated the platform as an ordinary third party. Our full reading of that ruling is worth your time if you work alongside litigators.
That is one district court memorandum and it binds no other court, so do not file it as settled law. Do file the framing: third party disclosure, analyzed the way third party disclosure always is. Lawful under 7216 and protected from discovery are different properties, and a consent form delivers only the first.
Does the under 5,000 consumer exception help here?
Not with 7216. 16 CFR 314.6 provides that "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers", and that is an exception inside the Safeguards Rule only.
It has no effect on the tax disclosure rules at all. It also leaves 314.4(g) and the change management requirement at 314.4(c)(7) in place at any size, so a small firm adding an AI tool still owes the program update and still owes a procedure for approving the tool before it touches client data.
What to put in front of counsel
Five questions, so you get answers not a memo.
- Does our data flow constitute a disclosure under 7216, and if that is uncertain, confirm we proceed as though it does.
- Draft or review the consent against the current text of 301.7216-3, not against our existing template, and confirm it names the specific recipient.
- Does the flow leave the United States at any point, and does 301.7216-3(b)(4) change what we need.
- Are we treating the vendor as a service provider under 314.2, and what diligence does that require of us.
- What goes into the WISP, and who owns that section.
Where Gaper fits
Gaper builds and deploys custom AI agents for accounting firms inside your own cloud, which keeps tax return information within infrastructure already covered by your security program instead of introducing a new processor to document and consent around. We are an implementation partner rather than a software vendor, so the agents and their configuration are yours and the data path is one you can describe precisely. General enquiries go to hello@gaper.io.
What this means for your firm
Stop repeating that 7216 cannot be consented away, because 301.7216-3(a)(1) permits disclosure as the taxpayer directs on a written consent, and the claim will not survive contact with a client's counsel. Treat a model API disclosure as a disclosure and get the consent before the tool is used, because (b)(1) rules out consenting after the fact. Then do the Safeguards work separately, starting with the WISP update that 314.4(g) already requires.
Thirty minutes, no commitment. We map one workflow, make the build or buy call, and scope the smallest thing worth shipping.
Frequently asked questions
Does Section 7216 ban disclosure to a third party outright?
What does a valid consent have to look like?
Does the data leave the United States?
Does a disclosure to a model API even count as a disclosure?
Is a 7216 consent a privilege shield?
Does the under 5,000 consumer exception help here?

Consolidate Client Ledgers Across QuickBooks, Xero and Sage
IndustryAutomate Tax Workpaper Preparation: What Automates, What Assists, and What Stays With the Preparer
A step by step look at tax workpaper preparation for CPA firms: which steps automate today, which only draft, and which stay with the licensed preparer.
Sep 21, 2026
NLP vs LLM (2026): Pick the Right AI Tool
Ready to turn AI into execution?
Book a free assessment of one workflow. We map it, make an honest build versus buy call before any code, and if an off the shelf product covers the job we will tell you so.