Your WISP was written before AI, and the IRS sample never mentioned it
IRS Publication 5708 has zero references to artificial intelligence. If your firm built its WISP from the sample, it no longer describes what you do.
If your firm built its written information security plan from the IRS sample, the plan does not describe the disclosure your firm is about to start making. Publication 5708 contains no reference to artificial intelligence anywhere in its 29 pages. That is not a criticism of the sample. It is a gap you now own.
Does the IRS sample WISP cover artificial intelligence?
No. IRS Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice, revision 8-2024, contains zero occurrences of the phrase "artificial intelligence" and no standalone use of "AI" across all 29 pages.
The sample is a good document. It covers devices, passwords, access, physical security and incident response. It was simply not written for a practice that sends client data to a third party model, because that was not what practices were doing.
A firm that adopted the sample verbatim has a plan that is silent on the single largest change to its data flows in years.
What the sample says about itself
It says it is a starting point, in terms firms often skip past. Publication 5708 states it is "not intended to replace your own research, to create reliance or serve as a substitute for developing your own plan based upon the specific needs and requirements of your business or firm."
That sentence is doing real work. Adopting a sample does not transfer responsibility to the IRS, and the document says so in its own words. If the plan does not match the practice, the plan is the problem.
Does section 7216 stop your firm using AI?
No, and the belief that it does is a common misreading. Section 7216 is a consent statute, not a prohibition. 26 CFR 301.7216-3(a)(1) provides that a preparer "may not disclose or use a taxpayer's tax return information prior to obtaining a written consent from the taxpayer", and then says directly: "A tax return preparer may disclose or use tax return information as the taxpayer directs as long as the preparer obtains a written consent from the taxpayer as provided in this section."
Anyone telling you that 7216 cannot be consented away is wrong on the text. The consent route exists. It has conditions, and the conditions are where firms fail.
The consent "must be knowing and voluntary", and conditioning your services on the taxpayer giving it generally makes it involuntary and therefore invalid, except in the narrow case at (a)(2) of disclosure to another preparer for assistance or auxiliary services.
When do you not need consent at all?
When the disclosure fits the preparer-to-preparer rule, and that rule has a hard edge that is easy to miss. 26 CFR 301.7216-2(d)(1) permits disclosure to another preparer in the United States for preparing a return or providing auxiliary services, "so long as the services provided are not substantive determinations or advice affecting the tax liability reported by taxpayers."
The regulation then defines the limit: "A substantive determination involves an analysis, interpretation, or application of the law."
Apply that to an agent. One that extracts figures, reconciles documents or routes data is doing processing. One that reads a fact pattern and tells your staff how a provision applies is analyzing, interpreting or applying the law. The first may sit inside (d)(1). The second does not, and no amount of describing it as a productivity tool changes the character of the work.
The written notice that is easy to miss
There is a specific, checkable obligation when you hand data to a technology contractor, and it is routinely skipped. 26 CFR 301.7216-2(d)(2) permits disclosure to a person under contract "in connection with the programming, maintenance, repair, testing, or procurement of equipment or software used for purposes of tax return preparation" only to the extent necessary, "and only if the tax return preparer ensures that all individuals who are to receive disclosures of tax return information receive a written notice that informs them of the applicability of sections 6713 and 7216 to them and describes the requirements and penalties of sections 6713 and 7216."
Ensures. Not mentions in a contract recital. If your implementation partner's engineers can see production return data, that notice is your obligation, and it has to reach the individuals.
The same paragraph settles who they become: "Contractors receiving tax return information pursuant to this section are tax return preparers under section 7216 because they are performing auxiliary services in connection with tax return preparation."
Does owning the deployment take the vendor out of it?
No. Ownership changes where the logs, credentials and hosting region sit. It does not remove a party from the analysis.
26 CFR 301.7216-1 defines a tax return preparer to include "Any person who is engaged in the business of providing auxiliary services in connection with the preparation of tax returns, including a person who develops software that is used to prepare or file a tax return and any Authorized IRS e-file Provider."
A firm that builds and maintains an agent touching return data is inside that definition on its own terms. So is the model provider, on the same reasoning. If a vendor tells you that a client owned deployment means there is no third party, treat that as a reason to look harder, not a reason to relax.
The one disclosure consent cannot authorize, and its exception
Social security numbers going offshore on a Form 1040 series return, unless a specific safeguard is used. 26 CFR 301.7216-3(b)(4)(i) bars a US preparer from obtaining consent to disclose a taxpayer's SSN to a preparer located outside the United States for those returns.
The exception at (b)(4)(ii) permits it "only if the tax return preparer within the United States discloses the SSN to a tax return preparer outside of the United States through the use of an adequate data protection safeguard as defined by the Secretary in guidance published in the Internal Revenue Bulletin", and verifies the maintenance of those safeguards in the consent request itself.
This is the paragraph to read before selecting a hosting region. If your agent runs outside the United States and sees Form 1040 data, this is directly in your path.
What a valid consent actually requires
More formality than a general engagement letter clause carries, and the details are disqualifying rather than cosmetic.
Consent must come before the disclosure or use, with no retroactive consent at (b)(1). A single document cannot authorize both uses and disclosures, at (c)(1), so they need separate documents, and each disclosure or use must be "specifically and separately" identified. A consent covering an entire return must tell the taxpayer they can request a more limited disclosure, at (c)(2). You must give the taxpayer a copy at the time of execution, at (c)(3). And if the consent does not state a duration, at (b)(5) it runs for one year from signature.
A broad "we may use technology vendors" clause in an engagement letter satisfies almost none of this.
What to add to your WISP
Name the systems, the data and the people. Which agents are in use, on which engagements, and what categories of tax return information they can reach. Where the processing happens, including the hosting region, because of the SSN rule above. Who the contractors are, and the date you sent the 6713 and 7216 written notice to their personnel. Which disclosures you treat as covered by 301.7216-2(d)(1) and why you concluded they are not substantive determinations. Where your consent forms live, and who checks them.
Then add the change trigger: what happens to this plan when a model, a prompt or a scope changes. Your plan also has to move under the FTC Safeguards Rule, which requires adjustment for any material changes to your operations or business arrangements.
Where this is unsettled
Two questions have no clean answer today, and firms should document their reasoning rather than pretend to certainty.
The first is whether a model provider's use of inputs for training is a "use" of tax return information within the meaning of 7216 when the provider is itself a preparer under the definitions above. The text reaches it. There is no published guidance applying 7216 to that fact pattern.
The second is where the line falls between processing and a substantive determination for an agent whose output a human reviews before it reaches the return. A reasonable firm can argue the human made the determination. The regulation does not say so, and a firm that cannot show the human actually did the work has a weak version of that argument.
Where Gaper fits
Gaper builds and deploys production AI agents inside the firm's own cloud, which means the hosting region, the retention and the access logs are things the firm can set and evidence, rather than facts it has to take from a vendor. It does not take Gaper or the model provider outside the 7216 definitions, and your consent and notice obligations are unchanged. The lead form is at gaper.io/appointment and general enquiries go to hello@gaper.io.
What this means for your firm
Open your WISP and search it for the word artificial, then for the name of every tool your staff currently paste client data into, because if the plan does not describe what the practice does, the plan is evidence against you rather than for you. Decide, in writing, which uses you treat as processing under 301.7216-2(d)(1) and which require consent, and build the consent forms to the separate document and specific identification rules rather than to an engagement letter clause. If an outside contractor can see return data, send the 6713 and 7216 written notice to their individuals this week and keep proof you did.
Free assessment. No commitment. General enquiries: hello@gaper.io
Frequently asked questions
Does the IRS sample WISP cover artificial intelligence?
Does section 7216 stop your firm using AI?
When do you not need consent at all?
Does owning the deployment take the vendor out of it?
AI Agent Data and Privacy: What Enterprises Need to Know Before Production
A practical guide to AI agent data privacy for enterprises: what agents touch, where data leaks, and the controls that get a pilot safely into production.
Jun 23, 2026
Natural Language Processing in Electronic Health Records: Custom LLM Approaches

Adaptive Project Portfolio Management (PPM) using AI
Ready to turn AI into execution?
Book a free assessment of one workflow. We map it, make an honest build versus buy call before any code, and if an off the shelf product covers the job we will tell you so.