Insight
Understanding your obligations — what tax professionals need to know before using AI and large language models with client data, and a practical checklist for staying compliant.

I am reluctant to add to the volume of commentary out there about AI; however, the general level of misunderstanding that exists surrounding the proliferation of these tools means it is inevitable. I am not here to talk about the general security concerns, risks, and considerations that we need to be aware of, but rather the specific obligations we have as tax professionals.
The use of AI, and specifically Large Language Models (LLMs) in the accounting industry, is ubiquitous; however, the level of appropriate knowledge is still lagging behind. In two recent seminars I attended, there was an overwhelming belief that Microsoft Co-Pilot and desktop versions of Claude (Anthropic) and ChatGPT (OpenAI) were local models and therefore completely safe to use with sensitive information. To confirm, local in this instance means the entire model (often an open-weight variant) is installed on a device that you control, and none of the prompts or answers leave your device/network. Microsoft Co-Pilot, Claude, ChatGPT, and all frontier models process your prompts on their servers, which you do not control. There are options you can select (dependent on your model and subscription), such as to not have your data train the models; however, this is not the same as a local model and does not mean that you can use it with reckless abandon when dealing with sensitive or personal identifiable information.
A second element to consider is a study undertaken in February 2026 where it was tested just how well “anonymised” text protected someone’s identity. Given minimal text data, the agent autonomously searched, cross-referenced and attempted to re-identify the person behind the redacted text. It was successful in 9 out of 33 scientists that tested this. Simply removing personal identifiable information may not be sufficient to adequately protect client information moving forward. This may not technically be a notifiable data breach, under the terms at the moment, as it was not a breach in the sense as defined by the OAIC, which typically governs tax agents (as a result of The TFN Rule [2015] and its connection with the Taxation Administration Act [1953] and The Privacy Act [1988]). Strictly speaking:
A data breach happens when personal information is accessed or disclosed without authorisation or is lost. If the Privacy Act 1988 covers your organisation or agency, you must notify affected individuals and us when a data breach involving personal information is likely to result in serious harm.
Under the current provisions, the information has not been disclosed, but rather inferred, solved, or calculated, and therefore not a breach under the definition guidance of a notifiable data breach.
Further to this, we need to be aware of our obligation to advise clients of all AI/LLM tools that we will be using with or for their data. This can be done informally through mediums such as your website or newsletter, or more formally through your terms of engagement — it may be prudent to review your obligations under APES 305 (Terms of Engagement) to ensure you are complying with this at a wider level.
To help guide tax agents further, in addition to the recent webinar that was hosted by the Tax Practitioners Board (TPB), they also released guidance statement TPB(GS) 55/2026: The use of Artificial Intelligence and the Code of Professional Conduct. This guidance is a beneficial read to ensure compliance with the Tax Agent Services Act 2009 (TASA), but more importantly, it provides some useful assistance and considerations before and during the deployment of AI during your engagements and ensuring adherence to the core competencies, confidentiality, and independence as it relates to the act and tax agent services.
To help guide practitioners, there is a useful checklist that can be informally followed to help ensure overall compliance, and to ensure an appropriate level of professional scepticism exists when using AI:
I do not propose that as a collective we need to become luddites in the face of using this technology; however, it is an area that tax agents are clearly being monitored and guided on. Having an understanding of the technology at a fundamental level, and more importantly our obligations and requirements, can ensure that this technology can be deployed in a safe and professional manner that will add value to your services, maintain compliance, and minimise risks to all parties.
Reference: Lermen, S., Paleka, D., Swanson, J., Aerni, M., Carlini, N., & Tramér, F. (2026). Large-scale online deanonymization with LLMs. arXiv. https://arxiv.org/pdf/2602.16800