AI is only a productivity win if it doesn't create a confidentiality breach. Here's how to get the speed without handing client data to the wrong place.
Everything else in the Academy makes you faster. This one keeps you out of trouble. Accountants hold some of the most sensitive data anyone has — Social Security numbers, income, bank details, whole financial lives. The moment AI enters the workflow, a new question appears that didn't exist before: where does the text I paste actually go?
The honest answer is: it depends on the tool, the plan, and the settings — and most people never check. That uncertainty is exactly why you need a habit that's safe by default.
When you paste text into a consumer AI tool, it travels to that company's servers to be processed. Depending on the product and your account tier, it may also be retained, reviewed by staff for quality, or — on some free consumer tiers — used to help train future models. Business and enterprise tiers typically promise not to train on your data and offer stronger retention controls, but the details vary by vendor and change over time.
You don't need to become a data-privacy lawyer. You need one working assumption:
Treat the following as never-in-raw unless you're on a vetted, contractually covered tool and you have the right client consent:
The good news: you rarely need the identifiers for the AI to help. The model doesn't care whether the taxpayer is "John Smith, SSN 123-45-6789" or "the taxpayer." It can investigate a reconciliation, draft a client email, or explain a notice just as well with the sensitive specifics stripped out.
Two professional obligations sit underneath all of this. You don't need to memorize the statutes, but you should know they exist.
Your professional standards and, for many, state law and the AICPA Code of Professional Conduct, require you to keep client information confidential. Feeding it to a third-party service the client never agreed to can put that duty at risk — the same way emailing it to an unvetted vendor would.
For tax preparers specifically, Internal Revenue Code §7216 makes it a criminal provision to knowingly or recklessly disclose or use a client's tax-return information without the client's consent. "Disclosure" can include routing that information through an outside service. The IRS's Publication 4557 (Safeguarding Taxpayer Data) is the companion practical guidance on protecting that data. The practical upshot: sending raw taxpayer information to an AI tool without appropriate consent and safeguards is a real compliance risk, not a hypothetical one.
Here's the workflow that lets you keep the productivity and drop the risk:
The AI Prompt Sanitizer runs entirely in your browser — nothing is uploaded — and flags SSNs, EINs, card and account numbers so you can redact them in one click before pasting into any AI tool.
Open the AI Prompt Sanitizer → See the PII-safe prompt playbooks →Free weekly read on AI for accountants — and a heads-up when new Academy lessons go live.