494 days, 8 hours, 28 minutes until FileCabinet CS reaches end of life. Learn why Denari is the industry’s leader in smooth FileCabinet CS migrations. →

Denari
← Dispatch

The IRS Recently Issued AI Guidelines for Tax Practitioners. Here's What Your Firm Needs to Do.

On June 24, 2026, the IRS Office of Professional Responsibility (OPR) issued Alert 2026-19, “Introductory Guidelines for Responsible AI Use in Federal Tax Practice.” It's the first time the OPR has formally addressed how AI fits into the professional obligations every tax practitioner already carries under Treasury Circular 230.

The short version: the alert doesn't create new rules. It maps six existing Circular 230 obligations onto AI-generated work, and removes any argument that firms weren't sure those obligations applied. If your team is using AI without a documented policy, that gap is no longer a gray area, it's exposure waiting to be found.

Here's what changed, and what to do about it.

The six obligations the OPR mapped to AI use

None of these are new rules. They're existing Circular 230 sections, now explicitly applied to AI-generated content.

  • Due diligence (§10.22): You must independently verify every AI-generated fact, citation, and calculation before it reaches a client or the IRS. “Reviewed by X” in the file isn't enough, the OPR expects documentation of what the review actually consisted of.

  • Competence (§10.35): Understanding how your AI tools work, and where they fail, is now part of professional competence, not an IT afterthought.

  • Fees (§10.27(a): Billing full manual-labor time for work AI materially accelerated may constitute an unconscionable fee. Cost savings need to show up in what clients are charged…or at least be disclosed.

  • Firm supervisory procedures (§10.36): Partners and firm leadership are personally on the hook for training staff, vetting AI tools, and documenting protocols…not just the individual preparer.

  • Written advice (§10.37): If an AI system's reasoning is opaque and you can't trace it back to verified authority, relying on that output may itself be unreasonable reliance.

  • Confidentiality (IRC §6713 / §7216): Uploading client data – SSNs, financial details, or return information to a public or consumer-grade AI tool creates real civil and criminal exposure. Only enterprise-approved, secure systems are acceptable for client data.

Why “introductory” doesn't mean optional

Some practitioners have read the word “introductory” in the alert's title as a sign this guidance is tentative. It isn't. The underlying Circular 230 sections were already binding – the OPR is simply confirming they apply to AI-assisted work. “Introductory” signals more guidance is coming as the technology evolves, not that this round is skippable.

That matters because it changes what an investigation looks like. Before June 24, a firm could argue genuine uncertainty about how these rules applied to AI. That argument is gone.

Where most firms are exposed right now

In practice, this alert lands hardest on three gaps that are extremely common and rarely addressed head-on:

  • Staff using consumer-grade AI tools (ChatGPT, general-purpose assistants) with client data, with no firm policy governing what can and can't be uploaded.

  • No documented review protocol – AI-assisted work gets a quick read, not a defensible, written verification trail.

  • Billing that hasn't changed even though AI is doing real work – which is exactly the double-billing pattern §10.27(a) flags.

None of these require exotic fixes. They require a system that was built with this obligation in mind, instead of retrofitted onto tools that weren't designed for regulated client data in the first place.

A six-step compliance checklist

This is the practical version of what the OPR expects a firm to have in place. None of it requires waiting on further guidance.

  • Inventory every AI tool currently in use across the firm – research, drafting, document review, and anything embedded in existing software.

  • Build an approved-tools list. For each tool touching client data, confirm: Is it enterprise-approved? Does the vendor commit, in writing, not to retain or train on client data? Is that commitment documented?

  • Define and document a due-diligence review standard for each type of AI-assisted work product – what “adequate review” actually means, not just that it happened.

  • Train all staff on the six obligations above, the firm's approved-tools list, and the review protocol. Document who was trained and when.

  • Review recent billing where AI materially reduced effort. Where fees weren't adjusted or the AI use wasn't disclosed, address it going forward.

  • Assign ownership of ongoing monitoring – this is introductory guidance, and the OPR has signaled more is coming.

Where Denari fits

Of the six obligations above, confidentiality under IRC §6713 and §7216 is the one most firms can't just “policy” their way out of – it depends on what the underlying platform actually does with client data. Denari is built to be compliant with §6713 and §7216 by design, not retrofitted after the fact. Getting there wasn't trivial – it shaped real product and infrastructure decisions, not just a line in a privacy policy.

In practice, it means verifiable safeguards rather than a policy promise – Denari is SOC 2 Type II audited, client data never leaves the U.S. or gets disclosed to third parties, client-identifying information is never used to train any models, and data is protected with dual server-side encryption. That's the kind of infrastructure decision that holds up when a firm's compliance argument actually gets tested.

FAQ

What is IRS OPR Alert 2026-19?

Alert 2026-19, issued June 24, 2026, is the IRS Office of Professional Responsibility's first formal guidance on how AI use fits within existing Circular 230 obligations for tax practitioners. It doesn't create new rules – it clarifies how six existing sections apply to AI-generated work.

Does this apply to my firm?

Yes, if any staff practice before the IRS – CPAs, EAs, tax attorneys, and enrolled actuaries are all covered. It applies regardless of firm size, and it applies to any AI tool, not just generative AI used for drafting.

Is this guidance actually enforceable, or just a recommendation?

It's enforceable. The alert is labeled “introductory” because more guidance will follow as AI evolves, not because the underlying Circular 230 sections are optional. Those sections were already binding before this alert – the OPR is now applying them explicitly to AI use.

What's the fastest way to reduce exposure?

Start with the confidentiality gap – it's the highest-severity, most common issue. Confirm no staff are uploading client data to consumer AI tools, then work through the six-step checklist above.

Does using an enterprise practice management platform make a firm compliant automatically?

Not entirely. Due diligence review, staff training, and billing transparency remain the firm's responsibility under Circular 230, regardless of platform. But the confidentiality obligation under IRC §6713 and §7216 is different – it's a function of how the platform itself handles client data. Denari is built to be compliant with §6713 and §7216 by design, which closes that specific gap for firms using it.