The short answer
No new rules. The IRS wants your AI decisions written down.
The IRS office that can suspend or disbar tax practitioners has said how their existing duties apply to work AI helped with. It tells them to use only secure, enterprise-approved AI for client data, and never defines the term. Practitioners who oversee the firm must take reasonable steps to make sure it has adequate procedures. For AI, the alert asks for every step to be written down. So a partner should list which AI tools touch client information, who approved each one, and where that is written.
On June 24, 2026, the IRS Office of Professional Responsibility issued Alert 2026-19, Introductory Guidelines for Responsible AI Use in Federal Tax Practice. That office enforces Circular 230. This is the first time it has said, section by section, how a practitioner's existing duties apply to work AI helped produce.
Most of the coverage since has been about hallucinations, where AI makes things up. The stories are fake citations, sanctioned lawyers and a reminder to check your work. That part is real. It is also the part every firm already understood.
The part a partner should notice is quieter, and it sits in a different section. It uses a word the IRS has not used about AI before.
That word is documented.
The six existing rules it applies
The alert does not create a new rule. It shows how six existing rules apply to AI, and that difference matters. A firm that was compliant on June 23 did not become non-compliant on June 25. What changed is that a firm can no longer say it was unclear how the rules applied.
§ 10.22, due diligence. A practitioner has to check the facts, citations and calculations AI produced before the work reaches a client or the IRS. AI output is a draft.
§ 10.27(a), fees. Unconscionable fees are prohibited. The alert applies that to billing for time AI did not spend.
§ 10.35, competence. Competence now includes knowing how the AI tool produces its content and where it gets things wrong.
§ 10.36, procedures to ensure compliance. The duty about the firm's procedures as a whole. More on it below.
§ 10.37, written advice. Advice has to rest on assumptions the practitioner checked independently. The alert notes that if nobody can see how the tool reached its answer, relying on it may not be reasonable.
IRC §§ 6713 and 7216(a). The civil and criminal penalties for a preparer who discloses or uses return information without authorization. § 10.51(a)(15) ties them back into Circular 230. It makes willful unauthorized disclosure a basis for discipline in its own right.
That last pair is the one to think about. A disclosure to an AI tool the firm does not govern is not only a risk under the tax code. It is also a separate professional conduct matter, in front of the office that can suspend or disbar a practitioner from practice before the IRS.
Nobody defined enterprise-approved
On protecting client data, the alert is direct. It tells practitioners to handle client data using only secure, enterprise-approved AI, with confidentiality safeguards in place. It also tells them never to upload sensitive data to unsecured sites.
That phrase is the one that matters, and the alert does not define it. Neither does Circular 230. Neither does any regulation currently on the books.
So your firm is held to a standard it cannot look up. In practice, three readings are going around, and some are easier to defend than others.
The vendor reading: enterprise-approved means a paid tier. Most of the market is selling this reading, and it is the weakest of the three. A business subscription changes the contract. On its own, it does not change who can reach the data, where it is stored, or whether the firm can prove any of that later.
The tenancy reading: enterprise-approved means the data stays inside a boundary the firm controls. This is stronger, and closer to what the alert is worried about. Under this reading, the tool runs in an environment the firm administers, under an agreement the firm holds. The company that provides the AI model sits outside that boundary, not inside it.
The evidence reading: enterprise-approved means the firm approved it and wrote that down. Someone with authority looked at the tool and decided it was fit for client data. They wrote down why, and the firm can produce that decision when asked. Note that the word is approved. Approving is something a person does, not a feature a product has.
Read § 10.36 alongside the four things the alert says that section asks of a firm (below). The third reading then stops being one interpretation among three. It starts to look like the plain requirement.
The rule that reaches the partners
Section 10.36 is not aimed at the staff member who pasted a K-1 into a chatbot. It reaches the people who run the practice. In the regulation's terms, that is any individual subject to the provisions of Circular 230 who has, or shares, principal authority and responsibility for overseeing the firm's practice.
Any individual subject to the provisions of this part who has, or shares, principal authority and responsibility for overseeing a firm's practice governed by this part must take reasonable steps to ensure that the firm has adequate procedures in effect for all members, associates and employees, for purposes of complying with subparts A, B and C of this part, as applicable.
31 CFR Subtitle A, Part 10 § 10.36(a), condensedA single mistake does not bring discipline under § 10.36(b). Discipline attaches when the people in charge fail to put procedures in place, or fail to see that they are followed. The failure has to come from willfulness, recklessness or gross incompetence. And the result has to be a pattern or practice inside the firm.
Now think about how AI actually gets into a small practice. It matches that pattern-or-practice test uncomfortably closely. AI does not arrive as a purchase. It arrives as a habit. One person finds it useful in February and shows two colleagues in March. By the next filing season, the firm has a practice that nobody wrote down, nobody owns and nobody watches. Nobody ever decided on it. A pattern is exactly what an unmanaged tool produces.
The alert then lists four things it says § 10.36 asks of a firm using AI.
Training. Staff training on the risks and the requirements.
Internal protocols. Ways of handling client data securely and of monitoring AI output for accuracy.
Vetting. Checking any third-party AI tool before the firm signs a contract for it.
Documentation. In the alert's own words, all steps and processes documented to show adherence to the section.
That last item is the point of this whole brief. It is not enough to have good practices. You have to be able to show them.
A firm can keep every one of those procedures in someone's head and be genuinely careful. It can still have nothing to hand the person who asks. We found the same failure in our own firm when we filled out a cyber insurance application. Our safeguards were running the entire time, and no record proved it. An examiner cannot give credit for a safeguard they cannot see. Neither can an underwriter, or a client's counsel during due diligence.
The billing paragraph nobody quotes
The most surprising paragraph in the alert has nothing to do with security. The commentary has almost entirely skipped it.
Under § 10.27(a), a practitioner may not charge an unconscionable fee. The alert applies this to AI directly. Billing for manual labor or time that was not actually spent may cross that line, depending on the facts. So may double billing for a task AI assisted. The alert names two facts that bear on whether billing crosses that line: a noticeable pattern across clients, and the size of the billing differences. It says cost savings should be passed on openly: disclose what AI did, and credit the reductions to the client's account.
For a firm that bills by the hour, this is a real risk that grows quietly. Every hour AI saves is an hour that must not appear on an invoice as though someone worked it. Nobody plans to bill it. It happens because the timesheet habit is older than the tool.
There is a useful side too. Suppose your firm can show what AI did on an engagement, and what it credited back. That firm is in a much better position than one relying on the fact that nobody has asked yet. The same written record that answers § 10.36 answers the billing question too.
What your firm should be able to show
Six written records. None of them needs new software. A firm of ten to twenty-five people can put the set together in a few weeks.
An approved tools list, with the approver. Which AI tools may touch client information. The decision is made by someone whose role gives them that authority, not by whoever happened to set the tool up. Record the date of the decision and what it rested on. This is the record that turns enterprise-approved from a description into a fact.
A written AI acceptable use policy. What staff may enter into an AI tool, and what they may not. What has to be reviewed before it leaves the firm. What a staff member does when they are unsure. Short enough that people will read it.
A dated training record. Who was trained, on what, and when. The alert names training first of its four items. It is the cheapest of the six records to produce, and the one most commonly missing.
A vendor assessment for each approved tool. Where the data goes, whether it trains a public model, what the agreement says, and who at the firm accepted it. The alert asks for third-party tools to be vetted. This is what vetting looks like when it is written down.
A review standard for AI-assisted work. Who checks AI-assisted work before it carries the firm's name, and how that check is marked. §§ 10.22 and 10.37 both land here.
A § 7216 consent position, split by return type. This records whether the firm relies on a client's written consent or on an exception. For clients filing in the Form 1040 series, Rev. Proc. 2013-14 governs the format. The consent carries the mandatory language, and each separate disclosure or use gets its own written document. That document may be furnished as an attachment to an engagement letter, rather than as a clause inside one. For clients not filing in the 1040 series, the regulation is less prescriptive. A consent may be in any format, including in the text of an engagement letter, as long as it meets § 301.7216-3(a)(3)(i). Timing does not vary by return type: the consent is written, and it comes before the disclosure. If the firm is relying on an exception instead of a consent, the record is a written analysis of which exception and why.
Sources for the paragraph above, since who each rule covers is the point most often gotten wrong: Rev. Proc. 2013-14 § 1 for the Form 1040 series limit, § 2.01 for the separate-document rule, and 26 CFR § 301.7216-3(a)(3) for the treatment of taxpayers outside the 1040 series.
Notice what is not on the list. No product. No platform. No certification either. None exists for this, and anyone offering one is selling a document with no issuer behind it.
What to do in the next two weeks
Do this in the next two weeks, before the October deadline crowds it out.
A partner should ask three questions. The alert makes answering them a duty of the firm. Ask the practice itself, not the IT provider.
Which AI tools touch client information at this firm today?
Who approved them?
Where is that written?
In most firms of this size, the honest answer to the first question is longer than the partners expect. The honest answer to the second and third is: nothing yet.
That gap is not a security failure. It is a gap in the written record, and it is the cheaper kind to close. Closing it starts with writing down decisions the firm has mostly already made.
The alert is four pages long, free and written in plain language. It was addressed to you. Read it before someone quotes it back to you.
Related questions
Does OPR Alert 2026-19 create new rules for AI in tax practice?+
No. It shows how six obligations that already existed apply to AI-assisted work. Five are Circular 230 sections: 10.22 on due diligence, 10.27(a) on fees, 10.35 on competence, 10.36 on procedures to ensure compliance and 10.37 on written advice. The sixth is the preparer penalties at IRC 6713 and 7216(a), which section 10.51(a)(15) ties back into Circular 230. A firm that was compliant on June 23, 2026 did not become non-compliant on June 25. What changed is that a firm can no longer argue that nobody knew how the existing duties applied.
What does enterprise-approved mean?+
The alert uses the phrase and does not define it. Neither does Circular 230, and neither does any regulation currently on the books. Three readings are going around. One: it means a paid vendor tier. Two: it means the data stays inside a boundary the firm controls. Three: someone with authority approved the tool for client data and wrote down why. Read section 10.36 alongside the four things the alert says that section asks of a firm, and the third reading is the one that fits. Approving is something a person does, not a feature a product has.
Which section of Circular 230 reaches the partners?+
Section 10.36. It reaches any individual subject to the provisions of Circular 230 who has, or shares, principal authority and responsibility for overseeing the firm's practice. That person must take reasonable steps to ensure the firm has adequate procedures in effect for all members, associates and employees. A single mistake does not bring discipline under 10.36(b). Discipline applies when someone fails to put procedures in place, or fails to see they are followed, through willfulness, recklessness or gross incompetence. The result also has to be a pattern or practice inside the firm.
Does the alert say anything about billing?+
Yes, and it is the paragraph most often skipped. Under section 10.27(a), a practitioner may not charge an unconscionable fee. The alert applies that to billing for manual labor or time that was not actually spent, or double billing for a task AI assisted. The two facts it names are a noticeable pattern across clients and the size of the billing differences. It says cost savings should be passed on openly: disclose what AI did, and credit the reductions to the client's account.
What should a firm be able to produce?+
Six written records, none of which needs new software. An approved tools list naming the approver and the date of the decision. A written AI acceptable use policy. A dated training record. A vendor assessment for each approved tool, covering where the data goes and what the agreement says. A review standard saying who checks AI-assisted work before it carries the firm's name. And a section 7216 position split by return type, stating which written consent or which exception the firm is relying on, and why.
Is there a certification for enterprise-approved AI?+
No. No certification exists for this, because no regulation defines the phrase. What answers the question is the firm's own written approval decision: which tools may touch client information, who decided that, on what date, and what the decision rested on.
Claremont Security works with accounting and tax firms on the FTC Safeguards Rule, IRS Publication 4557, and governed deployment of Microsoft Copilot in the firm's own Microsoft 365, with the model providers the firm chose. Our AI Exposure Check runs the § 7216 question against your own tools, free and with no account: claremontsecurity.com/ai-exposure
claremontsecurity.com/insights/enterprise-approved-ai-circular-230
