PTIN renewal season is here. Make sure your WISP documentation is current before you complete your renewal attestation.

Check your readiness
Home AI use policy

AI use policy

Your staff are already using it. The question is whether it is written down.

An AI assistant that receives client information is a service provider. It is a data flow your program has to describe, a vendor your contract clause has to reach, and a practice your staff need rules for. Most firms have all three and none of them documented.

Why this belongs in your security program, not beside it

The federal rule does not have an AI section, and it does not need one. The obligations already reach it.

Existing provisions an AI assistant falls under

314.4(f)Service provider oversightIf a tool receives customer information, you are required to select a provider capable of maintaining appropriate safeguards and to require those safeguards by contract.
314.4(c)(1)Access controlsWhich staff may send what to which tool is an access decision, and access decisions belong in the program.
314.4(b)Risk assessmentA new category of external data flow is a reasonably foreseeable risk to be identified and evaluated.
314.4(e)Personnel and trainingStaff cannot follow a rule nobody wrote or taught.
17.03(2)(i)Material changeIn Massachusetts, adopting a tool that touches personal information is the kind of change that triggers the review duty.

What gets generated

A policy your staff can actually follow

Short, specific, and about your firm. Not a page of principles.

Approved tools list

Which assistants are permitted, at which plan or tier, under whose account, and what the vendor's terms say about training on your inputs.

Prohibited inputs

The bright line. What may never be pasted into any assistant, stated in the categories your staff actually handle: Social Security numbers, client financial account details, whole return files, source documents.

Permitted uses, by role

What a preparer may do, what an administrator may do, what a partner must review. Written so a new hire can read it on day one.

Human review and attribution

Which outputs require review before they leave the firm, who signs, and how the review is recorded.

Client disclosure position

Your firm's stated position on whether and how clients are told, drafted so your attorney can adjust it rather than start from nothing.

Logging and enforcement

What use is recorded, who reviews the record, and the disciplinary measure for a violation, which the Massachusetts standards require you to state anyway.

Also tracked

The policy is only half of it

A rule with no register behind it is a wish. ProtPTX keeps the supporting record alongside the policy.

AI vendor register · Sample firm

Reviewed 2026-08-04

Approved Assistant A, business tier No training on inputs per terms · diligence record on file · safeguards clause executed In policy
Restricted Assistant B, consumer tier Permitted for non-client research only · no client data Limited
Found Assistant C, personal account discovered in use Opened as an action · approve, replace, or prohibit Unresolved
Register versioned with the policy · changes carry a date and an author

The discovery problem

The intake asks who is using what, and it asks in a way designed to surface personal accounts rather than only firm-sanctioned ones. In most firms this question turns up at least one tool nobody had told the partners about. Finding it is not a failure. Finding it after an incident is.

Watch

Writing an AI policy a small firm will actually keep

Workshop

Writing an AI use policy for a small tax practice

Coming soon

Your firm probably has an AI question it has not answered

The quiz includes it. So does the intake. Either way, you find out what is in the building before someone else does.