When does a tax agent need client permission to use AI?
The answer depends on what the AI tool actually does with the client's information.
Using AI is not, by itself, the legal trigger. The important issue for a registered tax practitioner is whether confidential client information is being disclosed to a third party and how the firm's other professional and privacy obligations apply to that use.
The Tax Practitioners Board's Guidance Statement TPB(GS) 55/2026 says practitioners must obtain client permission before divulging client information to a third party. The guidance specifically notes that this can include entering client information into AI chatbots or copilots, depending on how the tool is configured and used.
That last qualification matters. Two products can both be described as AI while having very different data arrangements.
Published 23 August 2026. Last reviewed 23 August 2026. Technically reviewed by the Taxpartna tax team.
Start with the data flow
Before deciding what permission is needed, answer four questions:
- 1What client information will be entered?
- 2Who receives it?
- 3Where is it processed and stored?
- 4What can the recipient do with it?
If the firm cannot answer those questions, it is too early to decide that a general privacy clause covers the use.
Scenario 1: staff paste client information into a public AI chatbot
This is the clearest risk case.
If an employee pastes identifiable client tax information into a third-party AI service, the information is being transmitted outside the firm to the service provider.
The firm needs to consider:
- Code item 6 confidentiality obligations
- whether client permission has been obtained
- the Privacy Act where it applies
- TFN rules where TFN information is involved
- where the data is processed and stored
- vendor retention and training terms
- the firm's own approved software policy
A free or consumer AI account should not be treated as harmless simply because the employee is using it for work.
Scenario 2: the firm uses a commercial product built on a third-party model API
This arrangement can be less obvious to staff.
The accounting firm may contract with Vendor A, but Vendor A may send prompts or extracted client data to Model Provider B.
The practitioner should understand the complete disclosure chain.
Client permission should not be assessed only by reference to the brand name visible on the screen. The firm needs to know which third parties actually receive the information.
The vendor's data processing agreement and subprocessor list are useful sources for this review. Our AI vendor due diligence checklist for tax agents sets out the questions to ask.
Scenario 3: the firm uses a private or self-hosted AI environment
A private deployment can materially change the confidentiality analysis, but the label "private" is not enough by itself.
The firm should establish whether:
- the model runs within the firm's or vendor's controlled environment
- client information is sent to another model provider
- external support personnel can access the content
- cloud infrastructure providers have access beyond normal hosting functions
- information is processed overseas
If there is no disclosure of client information to a third party through the AI use itself, the TPB's third-party permission requirement may not be triggered merely because the system uses AI. Other confidentiality, privacy, engagement and governance considerations can still apply.
This is a point where firms should assess the actual architecture rather than use broad statements about AI generally.
Scenario 4: the firm uses AI with de-identified information
Removing names from a prompt does not always mean the information is genuinely de-identified.
A detailed set of facts about a client, business transaction, location and ownership structure may still allow the client to be identified.
Before relying on de-identification, consider whether the remaining information could reasonably be linked back to the client, particularly when combined with other information.
Firms should have a defined process rather than leaving each staff member to decide what counts as anonymous.
Scenario 5: AI is built into software the firm already uses
AI functionality is increasingly being added to accounting, document, email and practice management software.
The fact that the firm already uses the software does not mean every new AI feature has automatically been assessed.
A product update can change:
- what information is sent externally
- who the subprocessors are
- where data is processed
- how long content is retained
- whether data can be used for product improvement
Material new AI functionality should go through the firm's vendor approval process before staff use it with client information.
What form can client permission take?
The TPB guidance says client permission may be obtained through a signed engagement letter, signed consent or other communication such as a relevant fact find and consent. It also notes that a general authority to disclose information to third parties may be acceptable.
The firm should make sure the permission actually covers the proposed disclosure.
A well-drafted engagement process may explain:
- that approved technology providers may be used in providing the service
- the type of information that may be disclosed
- the purpose of the disclosure
- whether information may be processed or stored outside Australia
- whether AI-enabled systems may be used
- where the client can obtain further information
The wording should reflect the firm's real systems. A broad clause should not be used to hide a disclosure that would surprise a reasonable client.
Permission does not solve every issue
Obtaining client permission does not make an unsuitable tool suitable.
The practitioner still needs to consider whether:
- the tool is secure enough for the information
- the disclosure is permitted under applicable privacy law
- TFN information is handled appropriately
- the output can be reviewed competently
- the use sits within the firm's quality management system
- staff are properly supervised
Permission is one control, not a waiver of the practitioner's obligations.
A practical approval process for firms
A sensible process is:
Step 1: classify the tool
Record whether it is:
- public consumer AI
- enterprise AI
- AI inside an existing software product
- third-party API product
- private hosted model
- self-hosted model
Step 2: classify the data
Decide whether the proposed use includes:
- no client information
- de-identified client information
- ordinary confidential client information
- TFNs or identity information
- complete tax files
Step 3: identify recipients
Map every third party that receives or can access the information.
Step 4: check existing authority
Review the engagement letter and any separate privacy or technology consent.
Step 5: obtain additional permission where required
Do this before client information is disclosed.
Step 6: retain evidence
Keep a record of the authority relied on and the approved use case.
Where Taxpartna fits
Taxpartna is designed to process client tax information within a private, self-hosted model environment and not send client documents to a public AI chatbot or third-party model provider for general model training.
That architecture is relevant to a firm's confidentiality analysis, but each firm should still assess its own engagement terms, privacy obligations and vendor arrangements. See TPB AI guidance for tax practitioners for the broader framework.
Taxpartna does not decide whether a particular firm's client permission is legally sufficient.
Authoritative sources
Client permission and confidentiality obligations depend on current TPB and privacy guidance. The following primary sources should be checked when this page is technically reviewed or materially updated.
- TPB - The use of Artificial Intelligence and the Code of Professional Conduct
- TPB - Factsheets and guidance
- OAIC - Australian Privacy Principles
Frequently asked questions
No single rule says that the mere use of AI always requires consent. The TPB focus is on disclosure of client information to a third party and the practitioner's wider confidentiality and professional obligations. The tool's configuration and data flow matter.
Important information. This page provides general information only and is not legal or privacy advice. Firms should review TPB(GS) 55/2026, their engagement terms, vendor arrangements and applicable privacy obligations before using AI with client information. Taxpartna is a quality assurance assistance platform for registered tax practitioners.
