OPR Just Dropped AI Guidance — Here's What Circular 230 Now Requires From Every Tax Pro
The IRS Office of Professional Responsibility issued OPR Alert 2026-19 in late June, providing the first formal guidance on AI use in tax practice. Here's what Circular 230 now requires for due diligence, fees, competence, and client disclosure when using AI tools.

OPR Just Dropped AI Guidance — Here's What Circular 230 Now Requires From Every Tax Pro
If you've been using AI in your tax practice — and let's be honest, most of you are at least dabbling — you need to know about OPR Alert 2026-19. Issued in late June, it's the Office of Professional Responsibility's first formal word on how Circular 230 applies to artificial intelligence in tax preparation.
For months, practitioners have been asking: How much can I rely on these tools? Am I liable when the AI hallucinates? Do I need client permission to upload tax data?
OPR finally answered. And the answers are… somewhat unsatisfying, somewhat clarifying, and wholly necessary to understand.
This isn't a "would be nice to read" document. If you practice before the IRS and use AI in any capacity, these rules apply to you right now.
Due Diligence Is Still Due Diligence — AI Doesn't Change It
Circular 230 §10.22 requires practitioners to exercise due diligence in preparing returns and determining the correctness of representations made to the IRS. OPR's guidance makes clear: AI is not an exception to this rule.
The core problem is one every tax pro who's played with ChatGPT has already discovered: hallucination. AI models "fabricate" outputs — citations that don't exist, cases that were never decided, code sections that were repealed. The guidance specifically calls this out, noting that AI can generate "very convincing supports and citations that do not exist."
If an AI tool spits out a beautifully formatted answer with six citations, you need to actually go read those citations. Not glance at them. Read them. Confirm they're real. Confirm they support the conclusion.
This seems obvious. But the speed and polish of AI outputs create a dangerous trust dynamic. A tool that looks competent will get less scrutiny than a half-baked Google search. OPR is warning you not to let that happen.
The guidance also flags a subtler issue: open vs. closed systems. Tools like Thomson Reuters CoCounsel or Notebook LM are limited to specific reference libraries. Open systems like ChatGPT or Claude pull from the entire internet. If hundreds of articles have been published about a preliminary version of a bill that differs from what was ultimately passed, the AI will grab from all of it — and deliver answers that sound confident but are wrong.
Which is how we still have AI models in 2026 that insist the tips deduction reduces AGI.
Your Fees Just Got Complicated
Here's where OPR may have annoyed a lot of practitioners. §10.27(a) prohibits "unconscionable fees" related to matters before the IRS. The new guidance extends this to AI-assisted work in a specific way:
If AI saves you time, OPR expects you to pass those savings to the client.
This is straightforward for hourly billing: a task that used to take three hours now takes ten minutes. Do you bill for three hours? OPR says no — you credit the client for the cost reduction.
But what about value-based pricing? If you charge flat fees based on expertise and outcomes — not hours — does AI efficiency matter? The guidance is murky here, and frankly, the position seems to ignore that most serious AI tools for tax come with their own subscription costs.
The practical takeaway: hourly billing is going to be increasingly problematic as AI embeds into workflows. The writing is on the wall. If you're still billing by the hour, you'll either need to disclose your AI usage to justify time discrepancies or move to value-based pricing where efficiency is part of your margin — and you don't have to justify it hour by hour.
Competence Now Includes Understanding the Tools
§10.35 requires practitioners to possess the skill, knowledge, and preparation needed for engagements. We normally think of this as "don't take a foreign account reporting engagement if you don't know FBAR rules."
OPR has now added a new layer: competence includes understanding the AI systems you use.
If you don't know that OpenAI models train on data they receive, you might upload a client's entire return to a free ChatGPT session. If you don't understand that an AI tool has data privacy settings — or where to find them — you can't meaningfully protect client information.
This is a real liability issue. The guidance effectively says: ignorance of how your AI tools work is not a defense. If you hand client data to a system you don't understand, you're the one on the hook when something goes wrong.
You Need Written Policies — Yes, Really
§10.36 requires practitioners who implement systems (including AI) to have policies ensuring compliance. This isn't aspirational. It means:
- Staff training on proper AI tool use
- Vetting of all AI tools before deployment
- Documented procedures for what data goes where
For small firms and solo practitioners, this can feel like overkill. But think of it as a compliance document you can write in an afternoon — "here's how we use AI, here's what we don't feed into it, here's who's trained." A single page is better than nothing, and it's increasingly hard to argue you had "reasonable policies" if you have nothing at all.
Written Advice Generated by AI Must Be Verified
§10.37 covers written advice. OPR's guidance is clear: AI-generated written advice cannot be relied upon without independent verification.
The risk here is the same as due diligence — AI outputs are polished, professional, and formatted beautifully. It's tempting to do a cursory review and send it along. OPR says that's a violation.
If you use AI to draft client memos, tax opinions, or planning letters, you need to: (a) fact-check every legal citation in real sources, (b) verify the analysis yourself, and (c) be prepared to defend every conclusion as if you wrote it from scratch. Because in OPR's eyes, you did.
Do You Need Client Consent to Use AI? It's Complicated
IRC §7216 governs disclosure of taxpayer information. The question of whether feeding client data into an AI tool requires signed client authorization has been hotly debated.
OPR's stance is lukewarm: "GAI platforms may present risks regarding the unauthorized disclosure of sensitive taxpayer information, especially when data is uploaded to unsecured or public systems."
The key distinction is the auxiliary services exception under §7216. Filing a return through tax software (Intuit, Drake, UltraTax) doesn't require separate authorization — it's auxiliary to the core service. Whether an AI tool qualifies depends on context:
- Using a dedicated AI data-input tool built into your tax software? Probably auxiliary — no disclosure needed.
- Dumping a client return into ChatGPT or Claude? Almost certainly outside the exception — disclosure required.
Our view: get §7216 disclosures from clients when using AI. Add it to your engagement letters. It takes ten seconds of boilerplate text and saves you the headache of retroactively justifying why you fed PII into an LLM.
What This Means for Your Practice
This is the opening salvo, not the final word. AI in tax will get more regulation, not less. But here's what you can do today:
- Audit your AI tools. Do you know what data each tool trains on? Where privacy settings are? Whether client data stays within the tool or reaches broader models?
- Write a simple AI policy. One page. What tools are approved, what data is safe to upload, who's trained. Date it. You'll thank yourself if OPR ever asks.
- Get client consent. Add a §7216 disclosure paragraph to your engagement letter covering AI tool use. It's a checkbox at onboarding that eliminates a liability later.
- Verify everything. If an AI tool gave you a citation, you read it. If it drafted a memo, you reviewed every line. The polish doesn't make it correct — you do.
And maybe most importantly: talk to your clients about AI. The ones who understand you're using sophisticated tools will appreciate the efficiency. The ones who don't will appreciate the transparency. Either way, the conversation is better than the silence.
The bottom line: AI is here to stay in tax practice. OPR just gave us the first real guardrails. They're not onerous — due diligence, competence, disclosure, verification. The same standards you already follow, applied to the new tools. Know your systems, verify your outputs, disclose what you're doing, and you'll be fine.


