Your CPA Firm Needs an AI Use Policy. Here's What to Put in It.
Your staff is already using AI for tax research, client memos, and data analysis. If your firm doesn't have a policy governing how, that's a gap your insurer will notice.
Your staff is already using AI. The question is whether you know about it.
Intuit has embedded AI across TurboTax and QuickBooks. Thomson Reuters is building AI into ONESOURCE. Drake added AI-assisted features this year. And beyond the tools your firm officially uses, individual staff members are copying client data into ChatGPT, Claude, or other consumer AI services to draft memos, research tax questions, or double-check calculations.
This isn’t a future problem. It’s a Tuesday-afternoon problem.
The regulatory context is forming
In May, we wrote about how the IRS requires a cybersecurity plan that most tax preparers don’t have. The Written Information Security Plan (WISP) required under IRS Publication 4557 covers how your firm protects client data. It was written before AI tools were on every desktop, but its requirements don’t have a carve-out for data that leaves your network through an AI prompt.
The AICPA has been developing guidance on AI-assisted tax preparation, focused on disclosure requirements, data handling, and the distinction between using AI for research versus using it for filing. The National Association of Tax Professionals partnered with a cybersecurity firm earlier this year to launch an AI governance curriculum specifically for tax professionals. The IRS Security Summit’s Summer 2026 campaign explicitly includes protecting client data from new technology risks.
Meanwhile, law firms are already further down this path. Five states require attorneys to certify whether AI was used in court filings. ABA Formal Opinion 512 established the ethical framework. We’ve been covering this trajectory all year. The accounting profession is roughly 12 months behind, and the gap is closing.
What an AI use policy needs to cover
If your firm doesn’t have an AI use policy, start with these six areas. None of them require technical expertise to define. They require someone in leadership to make decisions and write them down.
1. Which tools are approved, and which aren’t. Name the AI tools your firm sanctions for use with client data. Be specific: “Staff may use the AI features built into Thomson Reuters ONESOURCE. Staff may not paste client data into ChatGPT, Claude, Google Gemini, or any consumer AI service.” If the policy doesn’t name names, people will assume their favorite tool is fine.
2. What data can go into AI tools. Even approved tools have limits. Can staff paste a full tax return into an AI assistant? Client SSNs? Financial statements? Draw the line explicitly. A good default: no personally identifiable information (PII) enters any AI tool unless the tool’s enterprise agreement specifically prohibits the vendor from training on your data.
3. Who reviews AI-generated output. AI doesn’t get the final word. Every tax memo, client letter, research summary, or calculation that came from an AI tool needs human review before it goes to a client or into a filing. This sounds obvious, but without a stated policy, the pressure of busy season will erode it fast. Assign specific review responsibilities.
4. How you’ll disclose AI use to clients. This is where the profession is headed, even if formal rules haven’t landed yet. Some firms are adding a line to engagement letters: “Our firm may use AI-assisted tools for research, analysis, or document preparation. All AI-generated work is reviewed by a licensed professional before delivery.” Getting ahead of this costs nothing and builds trust.
5. How AI use connects to your existing WISP. Your Written Information Security Plan already covers how client data is stored, accessed, and protected. AI tools create new data flows that your WISP probably doesn’t address. Where does data go when staff uses an AI assistant? Is it stored on the vendor’s servers? Can it be used for model training? Your WISP should account for every path client data can take, and AI just added several new ones.
6. What happens when someone breaks the policy. Policies without consequences become suggestions. Define what happens when a staff member uses an unapproved tool, pastes client SSNs into a consumer AI service, or skips the review step. Clarity matters more than severity here.
Why this matters for your insurance renewal
Cyber insurance questionnaires are getting more specific about AI. We covered vendor risk after the EY breach earlier this week. The same trend applies here: underwriters are asking whether firms have policies governing new technology, including AI tools that handle client data.
If your renewal application asks “Do you have an AI use policy?” and the honest answer is no, that’s either a coverage gap or a premium increase. If a breach occurs because a staff member pasted client tax data into a consumer AI service, and you had no policy prohibiting it, your carrier will have questions about whether the claim is covered.
An AI use policy documented today, shared with staff, and referenced in your WISP strengthens your position with underwriters and gives you something concrete to point to if things go wrong.
You don’t need to be an AI expert
Writing an AI use policy doesn’t require understanding how large language models work. It requires the same kind of judgment you already apply to other firm policies: who can access what, what’s the review process, how do we handle mistakes.
The firms that will struggle are the ones that wait for formal regulations to force the issue. By the time the AICPA publishes its final AI standards or the IRS updates Publication 4557 to address AI explicitly, your staff will have been using these tools for years without guidance. The policy you write now doesn’t need to be comprehensive. It needs to exist, get shared with staff, and get revisited when the regulatory landscape catches up.
Artech Solutions helps CPA firms and law offices build AI use policies and update their security documentation to reflect how their staff actually works. If your firm needs help getting a policy in place before renewal season, let’s talk.

