Generative AI has quietly moved from novelty to production tool inside tax practices — drafting memos, summarizing regulations, comparing entity structures, and even proposing citations to the Internal Revenue Code. Until recently, practitioners navigating that shift had only their professional judgment and the general framework of Circular 230 to lean on. That changed with the IRS Office of Professional Responsibility (OPR) issuing its first introductory guidelines on the use of AI in tax practice, as reported by Thomson Reuters Tax & Accounting.
The message from OPR is not that AI is off-limits — it's that the tool doesn't change who is responsible when something goes wrong. If you are a CPA, enrolled agent, or tax attorney practicing before the IRS, Circular 230 still governs your work, whether the first draft came from your associate, a research platform, or a large language model.
What OPR Actually Said
OPR's guidance is intentionally introductory rather than prescriptive. Instead of banning specific tools or mandating disclosures, it reminds practitioners that the long-standing duties baked into Circular 230 — competence, diligence as to accuracy, confidentiality of client information, and supervisory responsibility over the work product — apply in full force when generative AI enters the workflow. In other words, OPR is not writing a new rulebook; it is telling practitioners that the existing rulebook already covers this.
That framing matters. It signals that enforcement will not wait for a purpose-built "AI rule." A practitioner who submits a flawed AI-assisted position today can be evaluated under the same standards as any other Circular 230 matter.
Mapping Circular 230 Duties to AI Tools
Competence. Circular 230 requires practitioners to possess the knowledge and skill reasonably necessary for the engagement. Using an AI tool you don't understand — its training cutoff, its tendency to fabricate authority, its data-handling practices — is itself a competence problem. Firms should expect that "I trusted the AI" will not be treated as a defense.
Diligence as to accuracy. Section 10.22 of Circular 230 obligates practitioners to exercise due diligence in preparing and filing documents and in determining the correctness of representations made to the IRS or to clients. AI-generated output is a representation being made through you. Verifying every citation, computation, and regulatory reference against a primary source becomes non-negotiable.
Confidentiality. Feeding client data — names, EINs, financial detail, K-1 information — into a consumer AI product may constitute an unauthorized disclosure. Practitioners need to know exactly where prompts are being sent, whether inputs are used for model training, and whether the vendor's contractual terms are compatible with professional obligations and Section 7216.
Liability When AI Hallucinates a Citation
The most concrete risk is a familiar one: generative AI will confidently invent case names, Revenue Rulings, or Code sections that do not exist. When those fabrications land in a client memo, a protest letter, or a Tax Court filing, the practitioner — not the model — signed the document. Under Circular 230, that exposes the practitioner to sanctions ranging from censure to suspension or disbarment from practice before the IRS, entirely independent of any malpractice claim from the client.
The lesson is uncomfortable but simple: an unverified AI citation is a practitioner-authored citation. The tool provides no safe harbor.
The Client Disclosure Question
OPR's introductory guidance doesn't mandate a specific client disclosure regime, but it raises the question every firm should now be asking: do clients know AI is being used on their engagement, and do they need to consent? Engagement letters that were drafted before ChatGPT became a research assistant likely don't address the topic. Firms should consider whether to update engagement letters to describe AI usage, restrict transmission of client data to particular vetted platforms, and clarify how AI-assisted work product is reviewed.
Workflow Guardrails to Adopt Now
Practitioners waiting for more detailed rules should not wait to implement basic controls. A defensible AI workflow generally includes:
- An approved-tools list, with consumer chatbots excluded from any workflow that touches client data.
- A written AI use policy covering permitted tasks, prohibited inputs, and the human-review standard for AI output.
- Mandatory verification of every legal citation, statutory reference, and numerical result against primary authority before it leaves the firm.
- Training so that staff understand hallucination risk, prompt hygiene, and the confidentiality implications of each platform.
- Engagement-letter language and, where appropriate, client conversations about how AI is used.
- Audit trails — retained prompts, outputs, and reviewer sign-offs — so the firm can reconstruct how a position was developed if questioned.
The Bigger Picture
OPR's introductory guidelines are best read as an early warning rather than a final word. More detailed guidance will almost certainly follow as the IRS and Treasury observe how practitioners are actually deploying these tools. In the meantime, the practical takeaway is stable: Circular 230 was written to be technology-neutral, and OPR is signaling that it intends to apply it that way. Firms that treat AI as a supervised junior researcher — useful, fast, and occasionally wrong — will be far better positioned than those that treat it as an oracle.













Comments
No comments yet — be the first to share your thoughts.
Join the discussion