Is It Safe to Use AI With Client Data? An Honest Answer for Accountants

Is it safe to use AI with client data? Sometimes, under conditions you control. It is not safe by default, and the difference has surprisingly little to do with the technology. What decides the question is a set of rules that existed long before ChatGPT: the moment you put a client’s financials into someone else’s software, you have disclosed confidential information to a third party, and your professional obligations travel with the data. Whether that disclosure is defensible depends on which tool you used, under which terms, with which controls around it. This guide covers all three, with the actual rules attached, because much of what currently ranks for this question is written by companies selling the tools.

The rules were written before AI. They still decide the question.

Start with the AICPA’s Confidential Client Information Rule, section 1.700.001 of the Code of Professional Conduct. A member in public practice shall not disclose confidential client information without the client’s specific consent. There is no AI exception in it.

The Code’s interpretation on third-party service providers (1.700.040) is the closest thing members have to a map for AI vendors, and as the Journal of Accountancy has laid out, it offers two ways to stay compliant. Either put a contract in place that binds the provider to confidentiality and gives reasonable assurance it can prevent unauthorized release of the information, or obtain the client’s consent before anything is disclosed. In our reading, a cloud AI tool that processes client books sits squarely inside that interpretation, so one of those two paths needs to be true before the data moves.

Tax practitioners carry a second, sharper obligation. Under IRC section 7216, a preparer who knowingly or recklessly discloses tax return information, or uses it for anything other than preparing the return, commits a federal misdemeanor punishable by up to a year in prison and a fine of up to $1,000, rising to $100,000 for certain disclosures. The word doing the work in that sentence is “recklessly”: nobody has to prove you meant it. The IRS regulations do exempt some US-based auxiliary service providers from the consent requirement, but the same Journal of Accountancy analysis warns that a disclosure permitted under 7216 can still violate the AICPA rule. The tests are separate, and you have to pass both.

There is a third layer many firms discover late. As the IRS states plainly, Federal Trade Commission regulations require professional tax preparers to create and enact security plans to protect client data, and the IRS and its Security Summit partners remind preparers that a written information security plan, the WISP, is a requirement rather than a suggestion. An AI tool that touches client data belongs in that plan, in writing, with someone’s name next to it.

If you practice in the UK, Canada, or Australia, the statutes differ, but your professional body’s confidentiality rules run on the same logic: the client’s information is not yours to share. And if your work or your clients touch the EU, the AI Act’s own compliance clock now runs alongside those rules.

The riskiest habit is also the most common one

The scenario that should worry you is not the enterprise deployment with a signed data processing agreement. It is a staff accountant pasting a client’s general ledger export into a free chatbot at 9 p.m. to get a variance summary.

The AICPA’s member insurance program puts the problem in one sentence: when data is entered into a generative AI tool, you are sharing that data with the tool’s owners. Its advice is to treat anything typed into one with the care you would give something posted on a public site.

The training question makes this concrete. As of August 2026, OpenAI’s own help pages say consumer ChatGPT improves by training on the conversations people have with it unless the user opts out, while its business tiers and API do not train on inputs or outputs by default. That one default, sitting in a help article most users never read, is the gap between a client’s payroll figures staying in a session and becoming training material.

Our working rule is blunt: client-identifiable data never goes into a personal or free chatbot account. The issue is not that the models are malicious. A free account simply gives your firm no confidentiality contract at all, which makes the AICPA’s two-path test nearly impossible to pass. If your firm wants a general-purpose assistant, put it on a business tier under a firm agreement, confirm the no-training default in the terms, and keep a copy of those terms in your files. The Journal of Accountancy’s July 2026 guide to drafting a firm AI policy adds the operational piece: restrict entry of confidential information into tools that cannot keep it private, show staff what proper redaction looks like, and document in the client file which prompts were used, how the output was verified, and who reviewed it.

What a good answer from a vendor sounds like

Every vendor conversation should start with the same question: is our client’s data used to train your models, and can we opt out?

Good answers exist, and they are specific. Xero says financial data shared through its Claude connector is used solely for the user’s session and is never used to train the models. Intuit says its platform applies customer data with the customer’s permission. Those are the companies’ own statements, not findings we audited, but they have the right shape: specific, on the record, and quotable back to the vendor if anything changes. Get the answer in writing and keep it in the engagement file. We walked through what the Xero and Intuit moves mean for firms, control by control, in our edition on AI moving into client books.

The training question is also no longer hypothetical at the firm level: this summer we covered a $2 billion firm training its own AI model on decades of accumulated client work, an arrangement whose public announcement said nothing about consent. When your own firm, not just your vendor, becomes the one doing the training, every question in this guide points inward too.

A vendor that cannot produce that sentence about training has answered the question anyway.

Four controls that make it defensible

Consent before the demo. Build AI disclosure into the engagement letter, so clients agree in writing before their data touches a third-party tool. The Journal of Accountancy was walking practitioners through the disclosure question back in early 2025; at this point it is simply what a well-run firm does. Tax practitioners have the added duty under the Statements on Standards for Tax Services to make reasonable efforts to protect taxpayer information shared with others.

A human between the tool and the client. Use AI to suggest and to draft, and keep a person reviewing anything that posts to the ledger or leaves the building. This is the Due Care principle doing its ordinary work: you remain responsible for the work product no matter what produced the first draft. For what skipping that step looks like at scale, see the KPMG report we covered in which AI fabricated 40 of the 45 sources cited in a published document.

An audit trail you can stand behind. If a tool can act on the books but cannot show how a number was derived, “the AI produced it” will not satisfy a lender, an examiner, or your own quality review. Make traceability a selection requirement, not a feature you hope is there.

An exit plan from day one. In December 2024, the bookkeeping company Bench shut down two days after Christmas and told customers to pull their data within days; the company that bought the remains later put the number of stranded active customers near 12,000. Keep your own copy of the source data and know the export path before you sign. If you are adopting one of the new AI-native ledgers, read the exit terms twice, because that is a platform decision more than a purchase.

Six questions to put to every AI vendor, in writing

Does our data train your models, and can we opt out? Where is the data stored, and what security and compliance standards do you hold? Can we export everything, in a usable format, and how quickly? How is accuracy measured, and against what baseline? What controls keep a human in the loop before anything hits the ledger? Who is liable when the tool is wrong?

Written answers to those six questions are the cheapest due diligence available, and we apply the same lens, tool by tool, in our independent guide to AI accounting tools. A vendor that answers cleanly is telling you something. So is one that changes the subject.

What it means for you

If you are a solo practitioner or a small firm: the free-chatbot habit is the exposure to close first, because it is the one a claims adjuster will ask about. A business-tier account with training off and the terms on file costs little and turns an indefensible practice into a documented one. Update the engagement letter template the same week.

If you run a firm: write the AI policy before an incident writes it for you. Inventory which tools touch client data, fold them into the WISP, and put the six questions to every vendor on the list. The templates and walkthroughs now exist, so the excuse that this is all too new has expired.

And when a client asks whether you use AI with their books, the right answer is already sitting in your engagement letter, agreed to in advance. If it is not, that is the gap to fix this month.

The bottom line

Is it safe to use AI with client data? It can be made defensible, and defensible is the standard that matters in a regulated profession. The model was never the main risk. The real risks are disclosure without consent, terms nobody read, output nobody reviewed, and an exit nobody planned. Close those four and AI becomes what it should have been from the start: capable software working under professional supervision. What cannot be delegated is the duty itself. AI can do the work. It cannot sign the work, and it cannot carry the confidentiality obligation that comes with the signature. That obligation stays with the person named in the engagement letter, which is exactly why clients will keep choosing the firms that treat their data as something to protect rather than something to feed the software.

Footnote

Footnote is an independent publication, with no affiliate links and no vendor paying for placement, and we hold no consulting relationships with any company named here. This guide is informational and reflects our reading of public rules and vendor statements as of August 2026. It is not professional accounting, tax, or legal advice, professional rules vary by jurisdiction, and you should consult your own counsel or state board about your situation. Vendor data practices are drawn from company statements and public documentation, are attributed, and were not independently audited by us.