The AI Acceptable Use Policy
Your staff are already using AI. An acceptable use policy is the document that decides which tool, holding what, under whose terms, and it is the document an examiner, an insurer, or a client asks to see. This is what one has to cover for a firm that holds tax return information.
// 01 / Licence_First
The rule that matters most is a licensing rule
Most policies open with a list of prohibited behaviours. That is the wrong first page. The first page is which product people are actually signed in to, because two things called Copilot carry entirely different contractual terms.
Microsoft 365 Copilot on a commercial licence, assigned to a named user through your tenant, is covered by the Microsoft Data Protection Addendum and the Product Terms, which carry the Enterprise Data Protection commitments: prompts and responses stored at rest in your tenant’s geography, not retained by the model provider, and not used to train the public models. Where the model runs is a separate question with a different answer. The model runs in Microsoft’s cloud, not inside your tenant, and Microsoft does not yet commit to running it inside the United States for U.S. tenants.
Microsoft Copilot on a personal account is a consumer product, free or paid through Microsoft 365 Personal, Family, Premium or Pro; Microsoft no longer sells Copilot Pro. Someone who signed up individually, on a personal card, is not under those commitments no matter how similar the product looks on screen. The interface gives almost no signal about which one a person is in.
So the policy has to state the licence, not the brand, and somebody has to check. A rule that says "use Copilot" is not a rule. The licensing brief covers where each plan sits.
// 02 / Why_Written
Why a tax firm needs this written down
Requires a written information security program with documented controls over how customer information is handled and who may handle it. An AI tool that touches client files sits inside that scope, so the program has to say what is permitted.
Paid preparers are required to hold a written data security plan, and Form W-12 asks you to confirm it exists. A plan that does not mention the AI tools your staff opened last year no longer describes the firm.
Sending tax return information outside the firm is a disclosure, and the regulation sets out when consent is required and what form it takes. Consent is available. It is a specific signed document, per client and per disclosure, not a line in an engagement letter.
Cyber and professional liability applications now ask directly whether the firm governs AI use. The realistic first cost of having no policy is a stalled renewal, or a question you cannot answer accurately, well before anything becomes an enforcement matter.
// 03 / Section_7216
What Section 7216 actually asks of you
This section is deliberately narrow, because Section 7216 is where AI policies for tax firms most often overstate.
Putting client tax return information into a tool your firm does not run is a disclosure, Microsoft 365 Copilot included, because the model runs in Microsoft’s cloud. That holds regardless of what the vendor promises about training, because the promise is a contractual term between you and the vendor rather than a change to what the regulation treats as a disclosure. A vendor undertaking not to train on your data is worth having, and it is a different question.
It does not follow that a general-purpose tool is off limits. Consent exists precisely so that disclosures can be made lawfully. What the regulation asks is that you know a disclosure is happening and have handled it deliberately, rather than finding out later that it happened by default.
Claremont's position on the tools it deploys is stated as architectural intent, not as legal certainty:
26 CFR 301.7216-2(d)(1) lets a preparer share return information without the client's consent only with another tax return preparer located in the United States, to prepare or help prepare the return, and only if the service is not a substantive determination. A provider of auxiliary services, and its employees who assist, count as tax return preparers. Location means where the people who receive or view the information are, not where the provider is headquartered.
We set the tenant's data residency to the United States, and we set which model providers the tenant is permitted to use. Microsoft commits to store Microsoft 365 Copilot prompts and responses at rest in the United States for U.S. tenants. Its data protection terms let it process data in the United States or any other country where Microsoft or its subprocessors operate, and U.S.-only processing for Copilot is expected by the end of 2026, not committed.
Until Microsoft commits to U.S.-only processing and the firm can show who reaches the data, Claremont's position is that client tax return information goes into Microsoft 365 Copilot only with each client's consent under 26 CFR 301.7216-3. For Form 1040 clients the consent follows Rev. Proc. 2013-14, and the Social Security number stays out even with consent (26 CFR 301.7216-3(b)(4)). We restrict AI actions to mechanical discrepancy analysis rather than substantive tax determinations, and implement contractual barriers against foundational model training to maintain the strict confidentiality of Tax Return Information.
Nothing on this page is legal advice, and nothing on it is a determination about your firm. Section 7216 questions belong with your counsel.
What that means for the Return Reviewer. The deployed agent crosswalks a draft return against the source documents before it is filed, flagging where a figure does not tie to its document, tiering variances with the box and the document named, comparing year over year, and drafting an open-items letter. It does not analyze filed returns, does not conclude whether a position is correct, and does not answer what a variance means. Its instruction set enforces this: every output is a working paper for preparer review, nothing it produces is filed or sent without human sign-off, and conclusions about tax treatment stay with the CPA.
// 04 / First_Step
The step before any external tool
Some work will always go to a tool your firm does not run, and a policy that pretends otherwise gets ignored by the third week. The workable rule is that identifiers come out first.
The Clean Room is the step. It tokenizes names, Social Security numbers, EINs, and account numbers before you paste, then restores them in the answer that comes back. It runs entirely in your browser, nothing is transmitted, and it takes about thirty seconds. It is free and it needs no licence.
Naming a specific tool matters more than naming a principle. "Remove client identifiers first" is a sentence people agree with and skip. "Open the Clean Room, paste, copy the tokenized text" is a step people can follow.
// 05 / Policy_Contents
What the policy has to contain
- Which tools, by licence. Named products and the licence tier each person holds, with someone responsible for checking that what is installed matches what is approved.
- What may go in, by data class. Client identifiers, return data, and engagement material handled separately from general research, with the Clean Room named as the route for anything going into a tool your firm does not run.
- Human review before anything is relied on. Every output is a draft. A person reviews it and a person signs it. This is the clause that matters most in a filing-season week.
- Where the record lives. Which system holds evidence of AI use, so the firm can answer a question about it later instead of reconstructing from memory.
- Who signs, and how often. Staff acknowledgement on a stated cadence, and a named owner who updates the policy when a tool changes. An unreviewed policy dates faster than the software it governs.
// 06 / Boundaries
What we do not do
- We do not determine your Section 7216 position. We document what your firm does and how the tooling is configured. Whether a particular disclosure requires consent, and what that consent says, is your counsel's call.
- We do not publish a consent template. Consent language is drafted for a firm and its providers, and a downloaded form is the wrong instrument for it.
- We do not monitor AI use around the clock. The platform logs continuously; review runs on a defined business-hours cadence.
- We do not audit, certify, or attest. Claremont performs assessments and produces documentation you can hand to whoever asks.
// 07 / Next_Step
If your firm has no policy yet
The AI acceptable use policy is one of four documents in the Safeguards Pack, built from a single intake call. Or take the readiness check first and see where you stand.
Version 2026.2 · Revised 23 September 2026 · Supersedes version 2026.1 of 6 September 2026, which superseded the PDF brief of 1 September 2026
