Tax return information

IRC Section 7216 and AI: questions tax firms should ask.

An AI workflow can raise questions about both the use and disclosure of tax return information. Data location matters, but location alone is not the legal test.

Published by PrivateStride · Last updated August 11, 2026

The core distinction

Security and permission answer different questions.

A system can be well secured and still require a separate use or disclosure analysis.

Section 7216 and its regulations address certain knowing or reckless disclosures and uses of tax return information by tax return preparers. Related provisions and guidance include exceptions, consent rules, definitions, and civil penalties. Your advisers need the actual people, data, purpose, systems, and contracts to analyze a proposed workflow.

An on-premises system may reduce external data flows. That can make the architecture easier to explain and control. It does not establish that every use inside the firm is permitted, and it does not remove every possible disclosure.

See how PrivateStride documents data flows

The review record

Give counsel a workflow, not a product description.

Write the answers before the pilot. Revisit them when the model, vendor, purpose, or data path changes.

01

Who is the tax return preparer?

Identify the firm and people involved, then determine which rules apply to the preparer and the proposed activity. Do not assume every accounting workflow has the same analysis.

02

What is the tax return information?

List the fields, documents, facts, prompts, derived text, and outputs involved. Masking a name may not remove the sensitivity or legal character of the remaining information.

03

Is this a use, a disclosure, or both?

Describe what the firm will do with the information and every person or system outside the relevant boundary that may receive it. A workflow label such as “summarization” is not enough detail.

04

What purpose does the workflow serve?

Tie the activity to a specific preparation, assistance, administrative, legal, security, product-improvement, or other purpose. The purpose can affect the analysis.

05

Does an exception or consent rule apply?

Have qualified advisers analyze current statutes, regulations, revenue procedures, guidance, and facts. If consent is considered, confirm its required form, timing, content, and delivery.

06

What do the contracts and controls show?

Document where data goes, who can access it, retention, deletion, subprocessors, model training, support, audit evidence, and the firm’s instructions. Controls support the analysis; they do not replace it.

Example issue map

Trace one document through the full workflow.

This is an illustration of the questions to document. It is not a conclusion about whether a workflow is permitted.

StepRecordQuestionEvidence
InputTax organizer and source documentsWhat information enters, and for what exact purpose?Data inventory and approved use case
ProcessingPrompt, retrieval context, and model operationWho or what can receive or access the information?Architecture and access diagram
OutputDraft summary or client question listHow will the output be used and professionally reviewed?Workflow procedure and reviewer record
After useLogs, backups, exports, and support recordsWhat persists, where, for how long, and under whose control?Retention settings and contract terms

A controlled launch

Do the legal review before real taxpayer data enters.

Start technical validation with synthetic or approved test data. Use the pilot to verify roles, logging, output review, deletion, and failure handling. Move to production information only after the responsible business, legal, privacy, tax, and security owners have approved the written workflow.

Put the approval path into policy

Production gate

  1. The intended purpose and data are written down.
  2. Use and disclosure questions have been reviewed.
  3. Required consents or exceptions are documented, if applicable.
  4. Data flows, access, retention, and support are verified.
  5. Professional review and records treatment are assigned.
  6. Material changes trigger a new approval.
See how workflows move from baseline to adoption

Start with IRS material

Use current authority and advice for the actual facts.

Do not rely on a vendor summary, an old consent form, or a general statement about where a server sits.

Primary sources: The IRS maintains the Section 7216 Information Center with regulations, revenue procedures, revenue rulings, and related material. The FTC’s Safeguards Rule guide addresses information-security program questions that may sit next to the Section 7216 analysis. PrivateStride’s evidence and claim definitions appear in our methodology.

Keep reading

Turn the policy into a working system.

These guides cover the decisions that sit next to this one.

ChatGPT and client data

Review the exact product, data, purpose, and workflow before approval.

Read the guide

Safeguards Rule and AI

Bring AI systems into the written risk and control program.

Read the guide

Compare AI architectures

Understand what local processing changes and what it does not.

Read the guide

Capacity & AI risk assessment

Map the risk before you choose the tool.

In 30 minutes, we identify your highest-value workflows, likely shadow-AI exposure, and the controls a private AI program would need. The findings are yours to keep.

Book your audit 30 min · No preparation · Confidential