CONTINUING EDUCATION FOR TAX & FINANCIAL PROFESSIONALS

Today Only – Grab an extra 5% off on all conferences, online CPE, and credit packages

The Office of Professional Responsibility (OPR) issued Alert 2026-19, Introductory Guidelines for Responsible AI Use in Federal Tax Practice to illustrate how AI should be viewed in the context of existing Circular 230 rules. Circular 230 has not changed and there is no proposal to make changes, yet. What OPR did was review the existing provisions in Circular 230 and ask what each one means now that generative models are a part of our work.

AI Mishaps and Pitfalls Prompt OPR Alert

AI is already present in almost every modern practice, from commercial tax and business news services down to the research features buried in the tax software we have used for years. Generative AI is the new part. It writes original text, and it will create a citation that looks perfect, but points to nothing or something entirely different. OPR’s latest alert walks through the ways using AI goes wrong. AI’s invented answers (hallucinations) get most of the attention, but the bias in the output, and the black-box problem of not being able to see how the model got there matter just as much. The data we feed an AI tool for one client can also resurface later in an answer for another. Our innocent prompt may have given the AI tool client information that it will incorporate into its knowledge base for future use.

Whiting v. City of Athens

OPR stresses that there are real risks for tax practitioners using AI. Lawyers have been sanctioned for filing briefs built on fake, AI-generated citations. Courts have handed out fines in the thousands, public censure, forced ethics courses, even default judgments and referrals to the state bar.

Example. In Whiting v. City of Athens, Tennessee, the court sanctioned counsel for Mr. Whiting for a briefing that “repeatedly misrepresented the record, cited non-existent cases, and cited cases for propositions of law that they did not even discuss, much less support.”

The court never found that AI produced the fake citations. The attorneys were asked directly and refused to answer. The court did not need the answer and ruled without it. The panel went broader, quoting a California appellate decision with approval. No filing should contain a citation, “whether provided by generative AI or any other source,” that the lawyer has not personally read and verified. The attorneys were penalized $15,000 each.

How Circular 230 Duties Apply to AI

Here is how the familiar sections read once a model is doing part of the work.

Due diligence, §10.22, is the backbone of the whole alert. Whatever the AI produces, the facts, the citations, the math, we check it before it goes to a client or to the Service. “The software said so” has never been a defense before, and it is not one now.

Competence, §10.35, picks up a technology piece. Knowing the law is no longer the whole job. We are expected to understand the tool itself—how it builds an answer, where it tends to fail, and when what it gave us simply does not fit.

Written advice, §10.37, gets more specific. Our advice has to rest on reasonable factual and legal assumptions, so a model’s projections and cited authorities do not get a pass just because they are on the screen. Read the actual cases. Rerun the numbers. And if we cannot see how the system landed where it did, OPR’s position is that leaning on it may be unreasonable.

Firm procedures, §10.36, is the one principals should not skim. Those of us with principal authority over a firm’s practice are expected to have real procedures in place. Train the staff on what can go wrong. Lock down how client data moves and how output gets a second look. This §10.36 connects to willfulness, recklessness, and gross incompetence, so “we never got around to writing a policy” is exactly the posture it targets.

Confidentiality is where criminal statutes show up. IRC §6713 and IRC §7216(a) put civil and criminal penalties on the unauthorized disclosure or use of return information, and Circular 230 §10.51(a)(15) covers the same ground. Treas. Reg. §301.7216-1(b)(3) defines tax return information widely enough that dropping a client’s name and figures into a public chatbot can put us in jeopardy. OPR’s instruction here is simple. Client data goes only through a tool that fits inside the firm’s written information security plan (WISP), the WISP required by the Federal Trade Commission’s Safeguards Rule, and nothing sensitive gets uploaded to an open system.

Fees, §10.27(a), close things out. If AI collapses the time a task used to take, billing for hours nobody worked, or billing twice for the same AI-assisted job, it starts to look like a §10.27 problem. The OPR alert nudges us toward passing some of those savings along and being upfront about where AI did the work. Practitioners will disagree about the particulars, but the underlying duty remains.

Comment. It took us 10, 20, or 30 years of practice to know the question (prompt) to ask AI and to know that the answer is correct and complete. We would argue that’s added value, not a billing for 15 minutes. Be sure your engagement letter specifies how your firm bills for services.

The Rules Don’t Stop at Circular 230

Rules about using AI do not stop at Treasury. California, Colorado, Illinois, and Utah have their own AI governance laws now, aimed at transparency, bias, and consumer protection, and the ABA’s ethics committee added Formal Opinion 512 back in July 2024.

What Tax Practitioners Can Do

None of this is regulation. It is guidance, and it makes no new law. The OPR alert is an inventory of the exposure we are already carrying. Before the next return goes out with AI anywhere in its history, a short run-through of practitioner responsibilities:

  • Check every AI-produced citation, figure, and factual claim, and keep a record that you did.

Note. In the past, before a tax return left your office, you checked the input, rechecked it, sent the return to a reviewer, and then checked the output one more time before the return was considered final. Treat AI output in the same careful way.

  • Route client data only through a tool that fits the firm’s WISP protocols, never through a public one.
  • Keep a written AI policy, train staff on it, and document both so you can show they exist.
  • Bill for the time actually spent (if that is how your engagement letter reads) and think through disclosure and cost savings under §10.27(a).

[1] In Glenn Whiting and Van Iron v. City of Athens, et al, CA-6 No. 25-5424 March 13, 2026

Looking for more industry-leading insights from our experts on AI in your practice? Join us for our conference at the Greenbrier, August 10th – 14th. Get the latest on best practices for using AI at your firm with a variety of live classes from John Higgins, CPA, CITP:

  • The AI Revolution in 2026: What CPAs Should Know
  • Agentic AI for CPAs: Automate Workflows with Intelligence
  • Smarter Tax Services with Artificial Intelligence (AI) Tools
  • AI 101:
    1. Part 1 – Introduction to AI
    2. Part 2 – Microsoft Copilot
    3. Part 3 – ChatGPT

Recent Stories

Next Up...

Can accountants work from home and stay compliant? A practical guide for CPAs and tax
5 min read
Wealth taxes are back on the agenda, but a Fraser Institute study finds the U.S.
8 min read
From ASC 230 definitions to restricted cash and IFRS treatment, learn the rules for reporting
6 min read