IRC §7216 FOR CPAs AND TAX PREPARERS

Your Staff Are Using AI, But
IRC §7216 Did Not Change.

A preparer pasting a client's return into a chatbot is not a policy problem. It is potentially a disclosure of tax return information, and §7216 is a criminal statute.

§7216

Criminal misdemeanor exposure

§6713

Civil penalty, no intent required

Evidence

A record of what actually left

What §7216 actually prohibits

Most firms know the statute exists. Fewer have re-read it since generative AI arrived in their workflow.

The rule

IRC §7216 makes it a criminal misdemeanor for a tax return preparer to knowingly or recklessly disclose or use tax return information other than in connection with preparing that return. The implementing rules live in Treasury Regulations §301.7216-1 through §301.7216-3.

§6713 sits alongside it as a civil penalty with no knowledge requirement. A preparer who did not intend anything improper can still be liable.

The penalties

  • §7216: fine of up to $1,000, imprisonment of up to one year, or both, plus the costs of prosecution.
  • §6713: $250 for each prohibited disclosure or use, capped at $10,000 in a calendar year.
  • Beyond the statute: Circular 230 exposure, state board complaints, AICPA standards, professional liability, and the client conversation you would rather not have.

Two definitions do most of the work

"Tax return information" is defined broadly. It is not limited to the return itself. It covers information furnished in any form or manner for, or in connection with, preparing a return, including what the client told you and what you derived from it.

"Disclosure" is the act of making that information known to another person. There is no exception for making it known briefly, or for a good reason, or to a machine.

Where AI creates the exposure

None of these are hypothetical. All of them are ordinary attempts to do the job faster.

Pasting a return into a chatbot

A preparer asks an assistant to explain an unusual K-1 treatment and pastes the schedule in, names and identifiers included.

Uploading source documents

A W-2, 1099, or organizer PDF is uploaded to an AI tool for extraction or summarization, carrying SSNs and account numbers with it.

Drafting client correspondence

Staff paste a client's facts into an AI writing tool to draft an explanation letter, which is a disclosure and arguably also a use.

AI meeting notetakers

A notetaker silently joins a client call and sends the transcript to a third-party service nobody at the firm evaluated.

Personal accounts

The firm has an approved tool with a signed agreement. Staff use their own free accounts because they are already logged in.

Processing outside the US

The regulations treat disclosures to preparers outside the United States more restrictively. Most staff have no idea where a given tool processes data.

The question the profession has not settled

Treasury Regulation §301.7216-2 permits certain disclosures without taxpayer consent, including to other tax return preparers providing auxiliary services in connection with preparing a return, with tighter conditions when the recipient is located outside the United States. §301.7216-3 covers the disclosures that do require consent, and Revenue Procedure 2013-14 sets out what a valid consent has to say and how it has to be obtained.

Whether a general purpose AI service qualifies as an auxiliary service provider under those rules is genuinely contested. Reasonable practitioners take different positions, and the answer turns on the vendor, the contract, where processing happens, whether the vendor may retain or train on the data, and how the tool is actually used in your workflow.

We are not going to resolve that question for you, and you should be sceptical of any vendor who offers to. What a firm can do is make sure the question only ever arises for tools it has actually evaluated, and that it never arises by accident because someone pasted a return into a free chatbot on a Tuesday afternoon.

That is a control problem, and it is solvable today.

Getting consent, and what a valid one requires

If a disclosure is not covered by an exception, there is one other route: the taxpayer's prior written consent. It is more prescriptive than most firms expect.

Consent is governed by Treasury Regulation §301.7216-3, and for anyone filing in the Form 1040 series the form and content are set out in Revenue Procedure 2013-14. This is not a general permission slip. A consent authorises a specific disclosure, of specific information, to a specific recipient, for a specific purpose, and it has to be obtained before the disclosure happens.

What a valid consent has to do

  • Come first. Consent must be obtained before the disclosure or use, not documented afterwards.
  • Be in writing, signed and dated by the taxpayer, on paper or electronically, and knowing and voluntary.
  • Name the parties. The preparer and the taxpayer, and critically the specific recipient of the disclosure.
  • Identify the information and the purpose. Which tax return information is being disclosed or used, and what it will be used for.
  • Carry the mandatory statements required for 1040-series filers, including notice that federal law may not protect the information from further use or distribution once disclosed, that the taxpayer is not required to sign, and how to complain to the Treasury Inspector General for Tax Administration.
  • State a duration, or default to one year from the date of signature.
  • Stand as its own document, separate from the engagement letter, with a copy provided to the taxpayer.

The mandatory wording is prescribed, not paraphrasable. Revenue Procedure 2013-14 specifies the exact statements a 1040-series consent must contain, along with formatting requirements. A consent written in a firm's own words, however well intentioned, can fail on its face.

There are also rules you cannot draft your way around: a preparer may not ask again for a consent the taxpayer has already refused for that purpose, and disclosures to preparers located outside the United States are treated more restrictively.

Why AI makes the consent route awkward

A valid consent has to name the recipient. "AI tools" does not, and neither does a list a firm intends to keep adding to. If your consent names one vendor and a preparer uses a different assistant next season, the consent you hold does not cover it. If it names none, it is unlikely to satisfy the requirement at all.

Consent is also per taxpayer. A firm running a thousand returns through an AI-assisted workflow needs a thousand valid consents, refreshed as they expire, tracked against the specific vendor named in each. That is an operational burden most practices discover only after committing to the workflow.

Which is why the practical answer is usually narrower. Decide which tools the firm has actually evaluated, get a written position from counsel on whether an exception covers them or consent is required, then make sure taxpayer data cannot reach anything else. Consent is a real route, but it works best for a deliberate, named arrangement rather than as blanket cover for whatever a preparer opens in a browser tab.

The elements above are a summary, not a checklist to build a form from. Revenue Procedure 2013-14 and §301.7216-3 contain the operative requirements, including exact wording, formatting, electronic signature conditions, and separate rules for disclosures outside the United States. Have counsel draft or review any consent before you use it.

§7216 is not your only obligation here

The same conduct usually implicates several regimes at once.

FTC Safeguards Rule

Tax preparers are treated as financial institutions under the GLBA Safeguards Rule, which requires a written information security program and controls over service providers.

IRS WISP expectations

IRS guidance for preparers, including Publication 4557, expects a documented written security plan. An undocumented AI workflow is a gap in it.

Circular 230

Practice standards for those who practise before the IRS, with their own diligence and competence expectations.

AICPA and state boards

Professional standards on confidentiality apply independently of the tax code, and state boards enforce their own rules.

How DataFence controls the exposure

Policy tells people what not to do. DataFence decides what actually leaves.

Stop the disclosure before it happens

  • Uploads are inspected before transmission.

    A W-2 or organizer PDF headed for an AI tool is classified and stopped before it reaches the site, not logged afterwards.

  • Pasted and typed text is inspected too.

    The dominant AI risk for a tax practice is not uploading. It is pasting. Text input monitoring is available on Enterprise and Onyx plans.

  • Classification recognises taxpayer data.

    SSNs, ITINs, account and routing numbers, names, addresses, and dates of birth are exactly the entities the engine is built to detect.

  • Approved tools keep working.

    Allow the vendor you evaluated and signed an agreement with. Block the rest. The rule follows the data, not the person's memory of the policy.

Know what happened, and prove it

  • See which AI services your staff actually use.

    AI activity reporting shows usage by service, by person, and by the type of sensitive data involved. Tools nobody approved show up as a list, not a surprise.

  • A record of every decision.

    User, destination, classification, and the entities detected, logged for every allow, warn, and block. That is the evidence a WISP review or an examination asks for.

  • Exceptions that are documented, not whispered.

    When a block is wrong, staff request an exemption with a business justification. A partner reviews it with the detection evidence attached, and the decision is recorded.

  • Deployed across the firm.

    Push the extension through your MDM or RMM. Seasonal preparers and contractors are covered on day one, not after onboarding.

What the firm sees

Two views answer the questions a §7216 conversation actually turns on: what was disclosed and to whom, and whether anyone is heading for trouble.

DataFence AI Activity Reporting showing AI events against total enforcement events, how many were blocked before leaving the browser, the AI services in use, and the sensitive entity types detected in AI-bound content.
AI Activity Reporting. Which AI services received data, who sent it, how much was stopped, and which sensitive entity types were involved. This is the record to reach for when someone asks what the firm disclosed and where it went.
DataFence Insider Risk showing risk tiers from Critical to Low, people evaluated, events scored against a 90-day baseline, a risk by department chart, and a ranked list of users.
Insider Risk. Staff ranked against their own prior activity rather than raw volume, so a preparer whose behaviour changed during filing season stands out instead of whoever simply touches the most returns. Every score opens to the factors behind it.

Where the boundary is. DataFence enforces in the browser. That covers how staff reach AI assistants, webmail, cloud storage, and portals, across every website rather than a list of approved ones. It is not an operating-system agent and does not inspect native desktop applications or command-line traffic. Your tax software running locally is outside its scope, and we would rather say so here than let you find out later.

Frequently Asked Questions

What is IRC §7216?

IRC §7216 is a criminal provision that makes it a misdemeanor for a tax return preparer to knowingly or recklessly disclose or use tax return information other than in connection with preparing that return. It is paired with §6713, a civil penalty that applies without any knowledge requirement. The implementing rules are in Treasury Regulations §301.7216-1 through §301.7216-3.

Does pasting client data into an AI tool count as a disclosure?

It may. Tax return information is defined broadly and a disclosure is the act of making it known to any person outside the firm. Sending that information to a third-party AI vendor is at minimum a question a firm needs a documented answer to. Whether a given tool falls within a permitted exception depends on the vendor, the contract, where processing occurs, and how the tool is used, which is a determination for your counsel rather than a vendor.

What are the penalties under §7216 and §6713?

Under §7216 a violation is a misdemeanor carrying a fine of up to $1,000, imprisonment of up to one year, or both, together with the costs of prosecution. Under §6713 the civil penalty is $250 for each prohibited disclosure or use, capped at $10,000 in a calendar year. The civil penalty does not require intent.

Does the auxiliary services exception cover AI vendors?

This is genuinely unsettled. Treasury Regulation §301.7216-2 permits certain disclosures to other tax return preparers providing auxiliary services in connection with preparing a return, with tighter conditions when the recipient is outside the United States. Whether a general purpose AI service fits that definition is a question practitioners disagree on, and it turns on specific facts. Firms should get a written position from counsel rather than assume either answer.

How can a firm use AI without creating §7216 exposure?

By controlling what actually leaves the firm rather than relying on policy alone. Enforcement at the browser inspects files and text before they are transmitted, so tax return information can be blocked from reaching tools the firm has not approved, while approved workflows continue. Every decision is logged, which gives the firm a record of what was disclosed and to whom.

Find out what left your firm last season.

Schedule a demo and see the AI services your staff are using, what taxpayer data is heading to them, and what it looks like when the answer is no.

This page is not legal or tax advice. It is a plain-language summary of publicly available authorities, provided for general information by a security vendor rather than a law firm. IRC §7216, IRC §6713, Treasury Regulations §301.7216-1 through §301.7216-3, and Revenue Procedure 2013-14 contain requirements, exceptions, and consent formalities that are not fully reproduced here, and authorities change. Whether any particular use of an AI tool constitutes a disclosure or use, and whether any exception or consent applies to your firm, depends on your specific facts. Consult qualified counsel and review the current authorities directly, including the IRS Section 7216 information center, before relying on any position.