Using AI Safely in Your Tax Practice
Less theory. More things you can do this week.
Tom Gorczynski and I already covered the rules. We wrote about the Section 7216 disclosure and use framework, and we covered OPR’s guidance on AI in federal tax practice over on Tom Talks Taxes. If you have not read those, start there. I am not going to repeat them.
This article is the other half of the conversation. You know the rules apply. Now what do you actually do? Here is what I do, with examples you can use or adapt as needed.
1. Sanitize Before You Type
The single highest-value habit. Before anything goes into an AI tool, strip it of identifying information. Not just the name and Social Security number. Anything that could reasonably identify the client when combined.
Here is what that looks like in practice. Say you are researching a potential filing requirement.
Do not type this:
“My client Kirby Rockefeller, who lives in La Jolla, California, SSN ending 4821, received an inheritance of $700,000 from his uncle in Portgual. His uncle was not a US citizen, Kirby is. Does he have filing requirments? He also has $450,000 of real estate investment income.”
Type this instead:
“Client received an inheritance from a foreign relative. Are there any filing requirments?”
Same useful output. Zero client data disclosed. Notice what got removed: name, SSN, exact dollar amount, city, and occupation. For example, A dental hygienist in Dallas married to a TI employee who sold RSUs in 2023 is not anonymous. It is a person with a name that takes one LinkedIn search to find.
My rule: if the prompt could survive being read aloud at a conference without anyone identifying the client, it is clean. If you hesitate, it is not.
2. Build a Verification Step You Cannot Skip
Every citation gets verified before it leaves your office. Not spot-checked. Verified. Here is my actual workflow for anything AI-assisted that contains authority:
Pull the cited case, code section, or revenue procedure from the actual source. Tax Notes, the Tax Court’s DAWSON system, uscode.house.gov, or eCFR. Confirm it exists. Confirm it says what the output claims it says. Confirm it supports the argument I am making, not just the topic I am discussing.
That third check is the one practitioners skip. A real case cited for the wrong proposition is as bad as a fake case.
Make this physical if you have to. I know practitioners who print AI-assisted drafts and initial next to each citation as they verify it. That sounds tedious. It takes ten minutes.
You could also use an AI tool that gives you that information. Not to self-promote, but AskTomG.AI does exactly. You get the citations, the links to the citations, and you can build your research memo. You make the judgment call. It also now has a research library if you’re looking for a specific code cite, or just want a more traditional search.
3. Interrogate Your Vendors Like They Work for You
Because they do. Before any AI tool touches practice work, I want written answers to five questions:
Is my input used to train the model, and can I turn that off? Where is the data stored and for how long? Who at the vendor can see my prompts? Is there a business tier with a data processing agreement?
Here is the example that makes this concrete. The consumer version of most AI chatbots uses your conversations for model training by default or buries the opt-out in settings. The business and enterprise tiers typically exclude your data from training contractually. Same model. Same interface. Completely different risk profile. The price difference is usually the cost of one client lunch per month.
If you cannot get answers, that is an answer. Under the FTC Safeguards Rule (16 C.F.R. Part 314), you are required to assess your service providers, and an AI vendor holding your prompts is a service provider. Document what you asked, what they answered, and when. Put it in your files. A reasonableness standard rewards people who can show their work.
4. Write the AI Section of Your WISP
I know, you are probably sick of the word WISP. But, your Written Information Security Plan should answer four questions about AI: which tools are approved, who may use them, what data may be entered, and what happens when someone breaks the rule. Here is sample language you can adapt:
“The firm has approved the following AI tools for practice use: [tool, tier, and account type]. All other AI tools are prohibited for any work involving client information. No client-identifying information may be entered into any AI tool without a documented exception approved by [name]. Identifying information includes names, taxpayer identification numbers, addresses, exact dollar amounts, employer names, and any combination of details that could reasonably identify a client. All AI-assisted work product containing citations or calculations must be independently verified before delivery to a client or submission to any taxing authority. Violations must be reported to [name] within 24 hours and will be treated as a potential security incident.”
Five sentences. That is genuinely most of it. The firms that get hurt will not be the ones with imperfect policies. They will be the ones with no policy, because no policy means no training, no accountability, and no evidence of reasonable safeguards when someone asks.
5. Train Your People With Scenarios, Not Slides
A policy nobody understands is decoration. Skip the hour of slides and run fifteen minutes of scenarios at a staff meeting. Here are three I would use:
A staff member wants to paste a client’s bookkeeping export into a chatbot to categorize transactions. Allowed? (No. Bank data is loaded with identifying detail: payee names, locations, amounts. Sanitizing a full export is impractical, so this needs an approved tool with a data agreement, or it does not happen.)
A staff member uses AI to draft a penalty abatement letter with no client details, then adds the specifics in Word afterward. Allowed? (Yes. This is the pattern you want. Generic in, specific out, on your own machine.)
A staff member asks AI to summarize a Tax Court case and includes the summary in a client memo without reading the case. Allowed? (No. The drafting was fine. Skipping verification was not.)
If your team can sort those three correctly, your training worked. Get a signed acknowledgment and calendar it annually.
6. Keep the Data You Feed AI Behind the Same Locks
An overlooked one. AI tools are accounts, and accounts get compromised. If your chatbot history contains months of practice prompts, that history is now sensitive data sitting behind a password. Treat the account accordingly: a unique password from your password manager, multi-factor authentication turned on, and a passkey if the vendor supports it. Review the connected devices and active sessions occasionally, the same way you should with email. And periodically delete conversation history you no longer need. Data you do not retain is data nobody can steal.
7. Let AI Inform. You Decide.
The habit that holds the rest together. AI is excellent at surfacing authority, organizing facts, drafting language, and pressure-testing an argument. It does not exercise professional judgment, and nothing about your obligations lets it. This is exactly how we built AskTomG.AI: the tool informs, and the practitioner retains every decision under Circular 230.
The practical example: when AI gives me an answer on a representation question, I do not ask “is this right?” I ask “where would this break?” Then I go verify the load-bearing authority myself. The tool sharpens my thinking. It does not replace it. The day you catch yourself forwarding an AI answer to a client without that step is the day to reread everything above.
Pick the two that close your biggest gaps. If I had to choose for you: sanitize your prompts starting with the very next one, and send your primary AI vendor the five questions from item three. Both cost nothing. Both are documentable. Both move you from “I use AI” to “I use AI responsibly,” and that distinction is the whole game.
The tools are worth it. I would not run my practice without them at this point. But the trust your clients place in you predates the technology, and it will outlast whatever tool you are using this year. Protect it accordingly.
Have questions? I know tech questions can sometimes be sensitive and you may not want to publicly post them, so send me a message.




