A good managed IT provider will tell you they have an AI programme. They usually do, and it is usually real: an approved tool on a business tier, single sign-on, the consumer version blocked at the firewall, data loss prevention rules on what can be pasted where.
We are not your compliance adviser and none of this is advice. It is a description of published rules with the links attached, so you can hand it to the person who is.
All of that is worth having. None of it answers the question the profession actually asks of you.
The line, in one sentence
An IT provider governs which door opens. A practice governs what is allowed to walk through it.
Those sound like the same job from the outside. They are not, and the distinction is written into the rules the practice is held to, not the ones the IT provider is held to.
What an IT provider can decide
- Which application is installed and which is blocked
- Whether it runs on a business tier or a consumer account
- Who signs in, from which device, with what authentication
- Whether the traffic is logged and the session retained
- What patterns are stopped before they leave the machine
What only the practice can decide
- Whether this client's information may be disclosed at all
- Whether consent was needed, and whether it was obtained
- Whether the engagement letter covered it
- Whether the output is fit to sign your name to
- Whether the review actually happened, and how you would show it
Three published rules that put it on the practice
The AICPA Code. Interpretation ET §1.150.040, on the use of a third-party service provider, as described by the Journal of Accountancy, requires a member to either contract with the provider to maintain confidentiality in accordance with the Code, or inform the client — preferably in writing, or through a provision in the engagement letter — that a third party may be used, and obtain consent. And the article is direct about what does not transfer: working with a third party "does not eliminate risk for the CPA firm."
Section 7216. For tax return preparers, the disclosure or use of information furnished in connection with preparing a return is constrained by statute, and as The Tax Adviser sets out, consent — where required — has specific prescribed language. That is a duty attached to the preparer. There is nobody to hand it to.
The FTC Safeguards Rule. This is the one that surprises people. Under 16 CFR 314.2, the examples of a financial institution include, in the rule's own words: "An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution because tax preparation services is a financial activity listed in 12 CFR 225.28(b)(6)(vi)."
Which means 16 CFR 314.4(f) applies to you directly, and it is about exactly this: "taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards", "requiring your service providers by contract to implement and maintain such safeguards", and "periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards."
Selecting, contracting with and assessing a service provider is not a thing a service provider can do on your behalf. That is the whole shape of the problem.
On the securities side the same idea shows up in FINRA Regulatory Notice 24-09, which says the rules apply whether a firm develops the tool itself or is "leveraging the technology of a third party, including through embedded features in existing third-party products."
What this looks like when it goes wrong
Not dramatically. It looks like a firm that has done everything its IT provider asked, is genuinely well configured, and cannot answer a client's question about whether their information went into an AI system — because the person who could answer it was never asked to have an opinion.
The IT provider knows which tool was approved. Only the practice knows which engagement letter said what.
What we can and cannot do, said plainly
We build this kind of software, so it is worth being honest about where our own boundary sits.
We can tell you where a document went, keep it on hardware you control, make the output land in the file rather than in a window, and produce a record of what ran and when. That is a real and useful half.
We cannot tell you whether it should have gone. We cannot read your engagement letters, decide whether a consent was required, or sign anything. Any vendor telling a licensed practice that their product makes them compliant is selling the half they do not own.
What to do
Ask your IT provider one question in writing: which AI tools are reachable from our machines, and where does the text go when we use them. That is squarely their job and they should be able to answer it quickly.
Then take that answer to whoever owns your engagement letters. The second conversation is the one that has probably not happened, and it is shorter than it sounds — usually one meeting and one paragraph.
Both of those can be delegated and neither needs you in the room. The part that cannot be delegated is deciding that the two answers have to meet, because nobody below you is positioned to notice that they never have.
The cost of leaving them apart is not a penalty. It is a question you cannot answer. A client asks whether their information went anywhere near an AI system, and the person who could tell them was never asked to have an opinion — so the answer is "let me check", to somebody who trusted you not to have to.
We can answer the first question. We cannot answer the second, and a vendor telling a licensed practice otherwise is selling the half they do not own. If it is the first one that is stuck, that is a conversation worth having.