Industry-specific operational data
Tax return data for AI training: Section 7216 consent and what CPA firms can license
Quick answer
A CPA firm or other tax preparer generally cannot use or disclose client tax return information to train or license AI models without written, signed, purpose-specific taxpayer consent that meets Treas. Reg. 301.7216-3 [1] and, for Form 1040 filers, the IRS-prescribed format (Rev. Proc. 2013-14 [9] as of October 2026). Removing names and SSNs does not by itself take data outside Section 7216, because the regulations treat statistical compilations as tax return information too [3]. Buyers should therefore diligence the consent records, not just the redaction.
By SourceX Editorial · Updated
This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.
Why Section 7216 is the first gate on tax preparation data
Section 7216 makes it a federal misdemeanor for a preparer to knowingly or recklessly disclose or use return information for anything other than preparing the return [1]. Section 6713 adds a separate civil penalty for the same conduct, and the IRS analyzes the two together [2]. For a training-data deal, every record moved to a buyer is a potential separate disclosure.
The regulations define "tax return preparer" broadly. The definition reaches firms and individuals who prepare returns, and also people who provide auxiliary services such as software, e-filing or processing in connection with preparation [3]. A tax-AI vendor that already acts as a firm's software provider is itself bound, and cannot repurpose what it receives for model training without its own authorization.
"Tax return information" is also broad. It covers anything furnished in connection with preparing a return, including workpapers, organizer responses, source documents such as W-2s and 1099s, and information derived from them [3]. In practice that means the return PDF, the CCH Axcess, UltraTax CS, Lacerte or ProConnect data file, the engagement binder in a document management system and the reviewer notes are all in scope.
What a valid 7216 consent for AI use must contain
A valid consent is a separate, signed, affirmative authorization that names the recipient, the specific information and the specific purpose before any disclosure happens [1]. For Form 1040-series taxpayers, Rev. Proc. 2013-14 [9] (the current format guidance as of October 2026) adds format rules: affirmative opt-in rather than opt-out, taxpayer signatures, type and display standards for paper and electronic forms, and mandatory statements explaining the taxpayer's rights. Read the procedure itself before approving any consent template.
Consent must be knowing and voluntary, signed and dated, and obtained before the disclosure or use [1]. A clause buried in an engagement letter or a click-through on a client portal is a weak foundation for an AI license. Consent text that says "service improvement" or "analytics" does not clearly reach disclosure to a third-party model developer.
For AI deals, three consent details matter most. The purpose must say the data will be disclosed to a named recipient (or a defined class) to train, fine-tune or evaluate machine-learning models. The scope must say which information is covered, for example "Form 1040 and supporting schedules, workpapers and preparer notes for tax years 2022 through 2025." The consent should state a duration, so both sides know when the authority to keep using the records ends; under the regulations, a consent that states no duration lapses one year after signing [1].
Watch for cross-border limits as well. The consent rules contain special conditions for disclosing return information, including SSNs, to recipients outside the United States [1]. Offshore annotation vendors and non-US model teams should have counsel check these conditions before any file leaves the firm.
Which 301.7216-2 exceptions could apply, and their limits
The exceptions in 301.7216-2 are narrow and rarely support a sale of row-level return data to an AI developer. The statute and regulations carve out disclosures such as those required by other provisions of the Code, court orders, state and local return preparation, and quality or peer review [1]. None of these covers training a commercial model.
The statistical compilation exception lets a preparer compile anonymous, aggregate data and disclose it only in limited circumstances, and the final regulations tightened how compilations may be used [4]. A file of individual returns with SSNs swapped for tokens is not an aggregate compilation. Treat any seller who relies on this exception for record-level data as a red flag.
IRS rulings show how strictly permitted uses are read. Rev. Rul. 2010-4 analyzed whether a preparer could use return information to tell clients about tax law changes, a use close to ordinary practice [2]. If that needed a ruling, training a third party's model plainly needs consent. Whether a firm may use its own clients' data to build an internal preparation tool is a separate question for counsel.
Obligations beyond Section 7216
Section 7216 is not the only rule a CPA firm's data must clear; professional ethics, financial privacy law and state privacy law add their own consent and contract terms. The AICPA Confidential Client Information Rule (ET 1.700.001) bars members in public practice from disclosing confidential client information without the client's specific consent [5]. That rule covers business clients and attest clients whose information is not "tax return information" under Section 7216.
Tax preparers are also treated as financial institutions under the Gramm-Leach-Bliley Act privacy rule, which limits how nonpublic personal information may be shared and reused [6]. State law adds more. California's CCPA treats data as deidentified only when the holder takes reasonable measures, publicly commits not to reidentify and contractually binds recipients to the same [7]; state accountancy and consumer statutes can add preparer-specific rules.
Buyers face disclosure duties of their own. California AB 2013 requires developers of generative AI systems available to Californians to post documentation about training data, including whether datasets contain personal information [8]. Your provenance records must be good enough to write that disclosure accurately. For the wider map, see AI training data compliance for buyers.
Buyer diligence checklist for tax return training data
The checklist below turns the rules into evidence you can request before signing. Ask the firm to answer each line in writing and attach the artifact.
Illustrative example: invented to show structure; it does not describe an available dataset.
| Check | What to request | Failure mode it catches |
|---|---|---|
| Consent copies | Blank consent form plus a sample of signed consents, with signature method and date | Opt-out checkboxes, engagement-letter boilerplate, consents signed after disclosure |
| Purpose and recipient match | Consent text naming AI training, evaluation or both, and naming your company or a defined class | Consent limited to "analytics" or a different vendor |
| Population reconciliation | Count of returns in the extract versus count with valid, unexpired consents | Records from non-consenting or revoked clients mixed in |
| Scope of information | Field-level inventory: forms, schedules, workpapers, notes, source documents | Spouse, dependent and third-party payer data outside the consent text |
| De-identification method | Written method for SSNs, ITINs, EINs, names, addresses, bank routing and account numbers, PTINs, plus residual-risk review | Identifiers left in scanned K-1s, OCR text or free-text reviewer notes |
| Retention and deletion | Retention period and deletion or return terms tied to consent expiry or revocation | Data kept after consent lapses |
| Audit rights | Right to review consent logs and redaction QA samples | No way to prove compliance after an IRS or state inquiry |
| Cross-border flags | Location of every recipient, including annotators | SSNs disclosed to offshore recipients without the required conditions |
Deletion terms deserve their own negotiation; see deletion and return clauses for licensed training data.
Illustrative consent manifest for a tax-return dataset
A per-record consent manifest lets you prove that every training example traces to a valid consent. Ask the supplier to deliver it alongside the data.
Illustrative example: invented to show structure; it does not describe an available dataset.
{
"record_id": "rtn_000184",
"return_type": "1040",
"tax_year": 2024,
"consent_id": "c7216_55921",
"consent_form_version": "2026-01-AI",
"consent_signed_at": "2026-02-11T15:04:00Z",
"signature_method": "e-sign, knowledge-based identity check",
"purpose_text_hash": "sha256:9f2c...",
"named_recipient": "Example Tax AI Inc.",
"consent_expires": "2027-02-11",
"revoked": false,
"identifiers_removed": ["ssn", "itin", "ein", "name", "street_address", "bank_account", "ptin"],
"deid_method_ref": "DM-3.2",
"qa_sample_batch": "QA-2026-07"
}
Reject datasets where consent_signed_at is later than the extract date, where named_recipient does not match the license, or where the purpose text hash differs from the approved form. For how to evaluate consent artifacts generally, see consent and notice records for AI training data, and for redaction standards see de-identified data for AI training.
Structuring the purchase from an accounting firm
The cleanest structure is forward-looking: the firm adds an AI-specific 7216 consent to its next filing season, and only consenting returns flow into the dataset. Retroactive consent campaigns for prior years are possible but tend to produce low and skewed coverage, which can bias a preparation agent toward clients who answer email.
Write the license so data scope tracks consent scope. Define records by return type, tax year and consent version, list allowed uses (SFT, evaluation, retrieval), and tie deletion to revocation. Adjacent datasets, such as tax notice and response correspondence and tax research memos with authority citations, may carry different consent profiles and are often easier to license. The broader industry-specific operational data guide covers other regulated verticals.
For firm-side context, see Buyers by industry: Accounting, finance and accounting AI training data, data licensing rules for accounting firms and whether accounting firms can sell data to AI companies. If you need help finding a firm whose records fit, you can describe your data requirement to SourceX.
Sourcing consented tax preparation data for AI
SourceX sources operational datasets, including finance workflows and documents, from US companies on request, and does not hold them in stock, so a request does not guarantee a match. Each dataset is rights-reviewed for ownership and consents, personal details are removed or replaced before delivery with the method recorded, and the supplying company approves every release. Describe the tax preparation data you need.
Frequently asked questions
Does de-identifying tax returns remove them from Section 7216?
Not necessarily. The regulations treat statistical compilations of tax return information as tax return information even when they do not identify a taxpayer [3]. De-identification reduces privacy risk but does not replace the consent or exception analysis.
Can a business-return client consent differently from a 1040 client?
Yes. The regulations require Form 1040-series consents to follow the format the IRS prescribes in guidance (Rev. Proc. 2013-14), while other taxpayers may use any consent that meets the regulation's content rules [1]. Business clients still trigger AICPA confidentiality consent requirements [5].
Is the buyer exposed if the firm's consent was defective?
The criminal and civil penalties fall on the preparer [1][2], but a buyer holding improperly disclosed data faces deletion demands, contract disputes and inaccurate AB 2013 disclosures [8]. Warranties and audit rights in the license are the practical protection.
Sources
- Internal Revenue Service, "Guidance Regarding Disclosure or Use of Tax Return Information by Tax Return Preparers (26 CFR 301.7216 regulations)". https://www.stayexempt.irs.gov/pub/irs-regs/13724302.pdf
- Internal Revenue Service, "Revenue Ruling 2010-4" (2010). https://www.stayexempt.irs.gov/pub/irs-drop/rr-10-04.pdf
- Legal Information Institute, Cornell Law School, "26 CFR 301.7216-1 - Penalty for disclosure or use of tax return information". https://www.law.cornell.edu/cfr/text/26/301.7216-1
- Tax Notes, "IRS Publishes Final, Temporary Regs on Information Disclosures by Return Preparers". https://www.taxnotes.com/lr/resolve//czzf
- Journal of Accountancy, "AICPA confidentiality rule" (2015). https://www.journalofaccountancy.com/issues/2015/mar/aicpa-confidentiality-rule.html
- Federal Trade Commission, "How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act". https://www.ftc.gov/business-guidance/resources/how-comply-privacy-consumer-financial-information-rule-gramm-leach-bliley-act
- California Legislature, "California Civil Code section 1798.140 (California Consumer Privacy Act definitions)". https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.140
- California Legislature, "AB-2013 Generative artificial intelligence: training data transparency" (2024). https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
- Internal Revenue Service, "Revenue Procedure 2013-14: Guidance regarding the format and content of taxpayer consents" (2013). https://www.irs.gov/pub/irs-drop/rp-13-14.pdf
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.