← Blog

AI Data Protection for Accounting Firms Starts Before the Prompt Leaves

Parminder Singh
Parminder Singh··5 min read
Summarize with AI

Tax preparation firms face specific duties when taxpayer information enters an AI request. The FTC Safeguards Rule requires access controls, encryption, monitoring, retention controls and service-provider oversight, while federal tax rules restrict disclosure and use. The practical control point sits before an authenticated request reaches a model provider.

Industry Verticalsai-governanceai-compliancedata-loss-preventionpolicy-enforcementaudit
AI Data Protection for Accounting Firms Starts Before the Prompt Leaves

A tax manager copies a draft return into an approved assistant and asks for a client letter. That single HTTP request can contain a Social Security number, filing status, dependents, business income and facts derived during preparation. AI data protection accounting firms need begins at the request boundary, before the model provider receives any of it.

Two federal regimes shape that decision. The FTC Safeguards Rule expressly includes tax preparation firms within its coverage, while the tax-return-information rules restrict disclosure and use by tax return preparers. Vendor approval alone leaves the firm to prove that this information could reach this destination for the stated purpose.

TL;DR

  • The FTC Safeguards Rule requires covered tax preparation firms to control, encrypt, monitor and limit access to customer information.
  • Tax return information includes material supplied for preparation and information generated or derived from it.
  • An approved model vendor still needs a permitted purpose, a controlled destination and the required service-provider treatment.
  • Inspect the authenticated HTTP request before transmission, then record the identity, data class, destination and decision.

Taxpayer information reaches beyond the finished return

The tax-return-information definitions in 26 CFR 301.7216-1 cover information furnished in connection with preparing a return and information generated or derived in that process. The same section defines disclosure broadly as making return information known to any person in any manner.

That scope matters because accounting teams rarely paste a complete return into a model. They submit a partnership allocation, a payroll reconciliation, an acquisition note or a paragraph about why a position changed. Derived material can still carry tax return information even after obvious identifiers have been removed.

Picture a monitor late in the evening during filing week. A yellow sticky note covers the client's name, but the prompt still contains the entity address, ownership percentages and a distinctive sale amount. Removing one field has not settled what the remaining combination reveals.

A useful classification policy therefore looks beyond pattern matching for taxpayer identification numbers. It also asks which application supplied the text, which engagement it belongs to and whether the destination is approved for that information class. AI DLP and traditional DLP explains why prompt context needs its own treatment.

The Safeguards Rule creates a control program around the request

The FTC Safeguards Rule in 16 CFR Part 314 requires covered financial institutions to maintain a written information-security program with administrative, technical and physical safeguards appropriate to their operations and the sensitivity of customer information. Tax preparation firms are named in the rule's scope.

Its required elements have direct AI counterparts. Access controls should limit who may send customer information to a model. Encryption protects information in transit and at rest. Monitoring has to cover activity by authorized users as well. Retention controls remove customer information when a legitimate business need ends. Service-provider oversight requires selection, contractual safeguards and periodic assessment.

A small firm handling information for fewer than 5,000 consumers receives exceptions from specified provisions. It still carries the remaining duties. Treating that threshold as a complete exemption would leave the access and protection questions unresolved.

The IRS Safeguarding Taxpayer Data guide reinforces the operational work with guidance on need-to-know access, multifactor authentication, encryption and audit trails. The regulation supplies the duty; the IRS guide helps a preparer turn it into daily practice.

Disclosure authority has to exist before transmission

The contractor exception in 26 CFR 301.7216-2 permits certain disclosures for programming, maintenance, repair, testing or procurement services only to the extent necessary for the contracted service and after the recipient receives written notice of the applicable requirements and penalties.

A general-purpose model call should never inherit that exception by assumption. The firm needs to identify the purpose, recipient, information involved and authority for the disclosure. Where an exception fails to apply, 26 CFR 301.7216-3 sets conditions for written, knowing and voluntary taxpayer consent.

My view is blunt: a vendor security review is a poor substitute for deciding whether the disclosure itself is authorized. A provider can offer strong security and still sit outside the permitted purpose for a particular return.

Put the declared use case into the authorization decision. A research assistant approved for public tax guidance should reject an engagement document. A drafting service approved under reviewed terms may receive a narrowly classified excerpt. AI governance for accounting firms covers the ownership needed to approve those use cases.

Request records make the control testable

A policy document describes intended behavior. Testing needs a population of actual events. For each managed model request, record the authenticated employee or agent, engagement or purpose reference, detected data class, resolved provider and model, policy version, action and timestamp. A redaction should identify the class removed without copying the sensitive value into a general log.

Those fields let a reviewer sample October 2026 traffic and ask concrete questions. Start with the requests that carried taxpayer information. Identify their destinations, then review blocked disclosures and the exception behind each permitted request. The result can be compared with the approved-use inventory and provider assessment.

Retention needs two separate decisions. The firm may preserve decision metadata for testing while keeping full prompts inside a more restricted evidence store, or avoid payload retention entirely and keep a hash plus controlled reference. The Safeguards Rule's disposal requirement argues against copying complete returns into every observability system. Signed audit logs for AI requests describes integrity controls for the decision record.

This data-protection design differs from an engagement workpaper trail. The first prevents and records disclosure at the request boundary. The second documents the professional procedure and review. AI audit trail requirements by regulation explains the fields that support reconstruction without turning a gateway record into substantive accounting evidence.

Coverage must name the unmanaged paths

An HTTP enforcement point can inspect a request only when an authenticated user or agent sends it through the managed route and the payload is available for inspection. That includes configured browser access, internal applications and agents calling approved LLM endpoints through the gateway.

Direct use of a public AI website on a personal device sits outside that route. So do local models, desktop inference, email, file synchronization and vendor-native AI inside accounting software when its calls never traverse the firm's gateway. Opaque payloads also prevent content inspection. Those populations need endpoint restrictions, application controls, provider evidence or a separate prohibition.

The same boundary applies after transmission. A gateway can choose a destination and block content before it leaves. Provider retention, training, human review, backups and onward disclosure remain matters for contract, configuration and provider oversight. It also cannot create taxpayer consent, determine that a contractor exception applies or perform the firm's annual risk assessment.

DeepInspect

DeepInspect is a stateless proxy for authenticated HTTP traffic between firm users or agents and LLM endpoints. It evaluates application-supplied identity, request classification, approved destination and policy before forwarding. Each permit, redaction, reroute or block creates a signed per-decision record outside the calling application's write path.

For accounting firms, that puts a control in front of taxpayer and client information before transmission and supplies a testable population of decisions. DeepInspect excludes local inference, personal devices, vendor-native processing outside the route, consent, legal-purpose determinations, provider-side retention and professional review. Book a demo today.

Frequently asked questions

Does every accounting firm fall under the FTC Safeguards Rule?

The rule expressly identifies tax preparation firms, but an accounting firm's status depends on the services it performs and the applicable jurisdiction. A firm should document which entities and activities are covered rather than apply one conclusion to every audit, advisory and bookkeeping engagement. The request control can then attach the correct information class and policy to the relevant service line.

Does encryption make a model disclosure permissible?

Encryption protects information during transmission and storage. Authorization for the disclosure remains a separate issue under the tax-return-information rules and the firm's contractual duties. TLS can secure an impermissible transfer just as effectively as a permitted one. The request decision therefore needs both transport protection and an approved recipient, purpose and data class.

Should a firm retain full prompts for monitoring?

The Safeguards Rule calls for monitoring and retention controls, but that does not require placing every payload in a broad security log. Store the minimum record needed to test the control, then keep any required full content in a restricted evidence system with its own retention schedule. Client obligations and the engagement context should determine the final design.

Can a gateway establish valid taxpayer consent?

A gateway can check for a consent reference supplied by the application and enforce a policy based on it. It cannot obtain knowing and voluntary consent, verify that the disclosure text met every legal condition or decide that consent was unnecessary. The preparer and counsel own those determinations, with the consent record maintained in the proper client system.