Accounting · 11 min read

AI and client confidentiality for Australian accountants.

By James Durkin, JDCS Updated 20 July 2026

There is one question worth sitting with before any of the detail below, and most practices I speak to haven't asked it yet: do my current client permissions match my firm's current use of AI? In the practices I talk to, the engagement letter hasn't been touched since 2023 and the way the team works has changed completely. The gap between those two facts is where the risk sits, and it's cheap to close if you get to it early. What follows is general information rather than advice about your practice, so check your own position with the TPB, your professional body or a lawyer.

The short version: putting client information into an AI tool can amount to disclosing it to a third party, which means you need the client's permission first. Permission is usually obtained through a signed engagement letter or a signed consent, and clients should be told where their data is stored and whether AI tools may be used. Sanctions under the Tax Agent Services Act run from a written caution to termination of registration. The fix is administrative, and it's much easier before someone complains than after.

What TPB(GS) 55/2026 says about client information and AI

The guidance began life as exposure draft TPB(I) D62/2026, released on 24 March 2026, with consultation closing on 21 April 2026. It was finalised as TPB(GS) 55/2026.

The core obligation isn't new, which is why some practitioners have skimmed past it. A tax practitioner must obtain client permission before disclosing client information to a third party. What the guidance does is spell out something the profession had been quietly unsure about: that disclosure can include entering client information into AI models and tools. Practitioners should also inform the client where their data will be stored and whether AI tools may be used in providing the service.

Permission is generally obtained through a signed engagement letter or a signed consent. That's a practical detail worth dwelling on, because it tells you where the remedy lives. This is not a technology problem to be solved by choosing a different vendor. It's a paperwork problem, solved by updating a document your practice already sends every client.

The sanctions sit under section 30-15 of the Tax Agent Services Act 2009 and range from a written caution at the lower end to termination of registration at the upper end. Most breaches are nowhere near the top of that range. The reason to take it seriously is that the upper end removes your ability to practise, and that's an unusual risk profile for something that gets triggered by a habit rather than a decision.

The trust deed example

Accountants Daily ran a worked example on 25 June 2026 that lands better than any amount of principle. An accountant has a client's family trust deed in front of them and needs to understand the distribution clauses. They paste the deed into a chatbot and ask it to summarise. No consent was obtained.

Walk through why that's a problem, because the mechanics matter more than the verdict. The deed contains the client's information. The chatbot is operated by a third party. Passing the information to that third party is a disclosure. No permission was given, so the disclosure wasn't authorised. The quality of the summary is irrelevant, as is whether the tool was any good, as is the fact that the accountant was trying to serve the client faster.

What makes this example uncomfortable is how ordinary it is. Nobody in that scenario is careless or cutting corners. They're doing exactly what the tool is marketed for, on a document they're perfectly entitled to be reading, in service of work the client asked for. The failure is entirely in the paperwork that wasn't updated, which is why the framing question at the top of this article is the one to start with.

The same logic applies to a dozen other everyday moments. A BAS query pasted into a chatbot with the client's figures attached. A tricky Division 7A scenario typed out with names in it. A client email dropped into a tool to draft a reply. Each one is a small, well-intentioned act, and each one is a disclosure.

Tranche 2 means you're holding more, for longer

The timing here is not kind. On 1 July 2026 the AML/CTF Tranche 2 reforms commenced, and accountants became AUSTRAC reporting entities. The obligations include customer due diligence, suspicious matter reporting, staff training and seven-year record keeping, backed by civil penalties running into the millions.

Consider what that does to a practice's data holdings. You're now collecting and retaining more identity documents, more source-of-funds evidence and more customer profiling than you were a year ago, and you're keeping it for seven years. The volume of sensitive material sitting in your systems went up sharply, at exactly the moment a lot of practices started reaching for AI to handle the extra paperwork.

That combination is worth naming out loud. The new compliance burden creates a genuine incentive to automate, and the material the burden generates is precisely the material you most need permission to disclose. Automating the AML paperwork with a general cloud chatbot would be solving one obligation by walking into another.

There is honest, useful automation available in a practice, and plenty of it never touches client identity documents at all. Our guide on AI automation for accountants and bookkeepers covers where the safe wins are, and where a human has to stay firmly in the loop.

Why clients are starting to ask

Clients are raising AI far more often than they were, and it's usually the sharper ones asking. Two numbers are worth knowing when you're deciding how much of this to put in writing.

The OAIC's notifiable data breaches report for calendar year 2025 recorded 1,205 notifications, the highest annual total since the scheme began in 2018 and up 8% on 2024. Legal, accounting and management services sat among the top reporting sectors with 81 notifications. Your profession is on that list, and clients who follow the news know it.

Public sentiment has moved with it. The 2026 Australian Community Attitudes to Privacy Survey found 82% of Australians concerned about data breaches, up from 74% in 2023. That's the temperature of the room when a client asks whether you're using AI on their file.

Handled well, this is a competitive advantage rather than a threat. A practice that can answer plainly, in a sentence, what tools it uses and what happens to client data is doing something most of its competitors currently cannot. Vagueness is what damages trust here, and the answer doesn't have to be that you avoid AI entirely.

Closing the gap between your consents and your practice

Here's the work, in the order I'd do it. Most practices can get through the first three steps in an afternoon.

  1. List every AI tool actually in use. Include personal accounts, phone apps, browser extensions and anything bundled into software you already pay for. Ask the team without making it a disciplinary conversation, or you'll get an incomplete list.
  2. For each tool, write down what client information goes into it. Be specific. Names, figures, documents, identity records, whole files. This is the step that changes people's minds.
  3. Read your engagement letter against that list. If it doesn't mention third-party disclosure, data storage or AI use, you've found the gap.
  4. Decide, tool by tool, whether to stop or to get permission. Some uses aren't worth papering. Others are genuinely valuable and just need consent obtained properly, in a signed document.
  5. Update the engagement letter and consent forms. A lawyer or your professional body's template service should draft the words. Your job is to hand them an accurate description of what the practice does.
  6. Write a short internal AI policy. One page. Name the partner accountable for it, list the approved tools, and state plainly what must never be entered anywhere: trust deeds, TFNs, identity documents, source-of-funds evidence, anything covered by a client's specific instruction.
  7. Check what the approved tools do with data. Business and enterprise tiers are meaningfully different from consumer plans, a point our guides on what AI data settings actually do and whether Copilot is safe for confidential information both cover.
  8. Keep the review dated. It shows a considered process if anyone ever asks, and it doubles as the kind of record your new AML/CTF obligations expect you to be keeping anyway.

For the narrow slice of work where no cloud tool is appropriate and the value is still real, the alternative is running the model on hardware the practice controls, so no third party sits in the path at all. The OAIC's own guidance describes local deployment as "likely to be more privacy-preserving as it limits the risks of third party access to the data". Our local and private AI page covers what that involves, including when it isn't worth the money. If you'd rather start with a structured look at your whole operation, the free business assessment is a sensible first hour.

Bottom line: entering client information into an AI tool can be a disclosure to a third party, and disclosure needs permission. Get the list of what your team actually uses, compare it against your engagement letters, and close the gap with a signed consent or by stopping the use. The obligation is old, the guidance is new, and the fix is paperwork rather than technology. General information only, so confirm your own position with the TPB, your professional body or a lawyer.

Do your consents match your practice?

The first conversation is free. You'll get a plain-English read on what your team is actually using, where client information is going, and what to change first.

Start a conversation

Practice questions, answered.

Can Australian accountants use AI with client information?
With the client's permission, and having told them what they need to know. TPB(GS) 55/2026 makes the point that a tax practitioner must obtain client permission before disclosing client information to a third party, and that this can include entering client information into AI models and tools. The mechanism is consent, so the practical question is whether your engagement letters already cover what your team is doing.
Do I need client consent to put client information into ChatGPT?
That is the safe assumption. Entering client information into an AI model or tool can amount to disclosing it to a third party, which triggers the permission requirement. Permission is generally obtained through a signed engagement letter or a signed consent, and clients should also be told where their data will be stored and whether AI tools may be used. Check your own position with the TPB or your professional body.
What are the penalties for a tax agent who breaches the Code?
Sanctions under section 30-15 of the Tax Agent Services Act 2009 range from a written caution at the lower end through to termination of registration at the upper end. The range is the point worth noting: this is not a fine-and-move-on regime, and the upper end takes away the ability to practise.
Does AML/CTF Tranche 2 change how a practice should handle AI?
Indirectly, and significantly. From 1 July 2026 accountants became AUSTRAC reporting entities, with obligations including customer due diligence, suspicious matter reporting and seven-year record keeping. Practices now hold more identity documents and source-of-funds evidence, for longer, which raises the stakes on where that material gets processed.
How should a practice start using AI safely?
Map what your team is already doing before deciding anything. List every AI tool in use, including personal accounts and browser extensions, note what client information actually goes into each, then compare that against your engagement letters and signed consents. Where the two do not match, either stop the use or get the permission. The mapping is the work; the policy is the easy part.