Skip to main content
All resources
AI & Compliance

AI Tools and Your WISP: What Tax Preparers Need to Document in 2026

Tax preparers are adopting AI assistants faster than their WISPs are being updated. Here's what the FTC Safeguards Rule requires you to document when AI touches client data.

June 20268 min read
By the WISPWolf Compliance Team· June 2026Reviewed by WISPWolf Compliance TeamLast Updated: June 2026 · Verified August 30, 2026
Short answer

When AI tools touch client data, they become part of your information system and vendor ecosystem under the FTC Safeguards Rule. Your WISP must document which AI services are approved, what data they process, who approved them, what safeguards are in place, and how the firm monitors their use.

In a hurry? Get your free Compliance Score, then come back to this guide.

Take the Free Quiz View Sample WISP

AI adoption in tax practices is happening fast — document summarization, client communication drafting, research assistance, workflow automation. Tools like Microsoft Copilot, ChatGPT, and practice-specific AI add-ons are making their way into accounting and tax workflows. The FTC Safeguards Rule doesn't have an "AI exemption." When AI tools touch client data — names, SSNs, income figures, bank accounts — they become part of your data handling environment. That means they belong in your WISP. Most tax professionals haven't updated their security program to reflect this. The gap between adoption and documentation is widening, and regulators are not waiting for firms to catch up. If your WISP doesn't mention AI, it doesn't describe your actual information environment. The firms that act now will have a documented, defensible position. The firms that wait will be explaining gaps after a breach or audit. This article explains what you need to document and why, with specific language you can add to your WISP today.

When does AI become a WISP issue?

Any AI tool that receives, processes, stores, or retains client data — including inadvertently as training data — becomes a service provider under FTC 16 CFR Part 314. That triggers the full vendor management requirements: a security assessment, a data handling agreement, and ongoing monitoring. The threshold is not whether the AI vendor calls it an enterprise product. It is whether nonpublic personal information flows through the tool. A single prompt containing a client name, Social Security number, or income figure is enough to bring the tool into scope. The same applies to uploaded documents, transcripts, or email drafts. If the AI service retains, logs, or trains on that input, your firm has shared taxpayer data with a third party. The WISP must record that relationship, the data involved, and the safeguards in place. Ignoring it because the tool is convenient does not remove the compliance obligation. The Qualified Individual must be able to name every AI tool and explain the data it touches.

Consumer-tier AI is not the same as enterprise AI

The free version of ChatGPT, standard Copilot, and personal Claude accounts may use your prompts for model training. Enterprise tiers from the same vendors typically do not. Your WISP must document which tier is in use, because the compliance risk is completely different.

What the FTC Safeguards Rule says about vendors and AI

The FTC Safeguards Rule requires you to select service providers capable of maintaining appropriate safeguards, contractually require them to protect customer information, and monitor their compliance. These three obligations apply directly to AI vendors. The first step is understanding which tier you are using. Enterprise agreements from OpenAI, Microsoft, and Anthropic typically include data protection commitments, opt-outs from training use, and encryption standards. Consumer tiers — free ChatGPT, standard Copilot, or personal Claude accounts — often explicitly reserve the right to use prompts and outputs for model improvement. That means your client's tax data could become part of a training dataset. The WISP must document which tier is in use, the contractual protections, and the rationale for the selection. If a staff member is using a consumer account for client work, that is an ungoverned risk that the Qualified Individual must address. The difference between enterprise and consumer is not a marketing distinction. It is a compliance boundary.

The five AI tools most commonly used by tax preparers and what your WISP needs to say about each

Most tax firms are already using AI tools without realizing they need WISP documentation. Here are the five most common and what your WISP should record about each.

  • Microsoft Copilot — In the enterprise tier, data stays within your M365 tenant and inherits your existing protections. Document your subscription level and confirm that data handling terms match your firm's security standards.
  • ChatGPT by OpenAI — The consumer tier uses data for model training. The enterprise and API tiers do not. Your WISP must state which version is approved and why.
  • Claude by Anthropic — Similar enterprise and consumer split. Verify the data retention and training opt-out terms in your agreement.
  • Practice-specific AI tools — New tax and accounting AI platforms appear regularly. Do not assume they are secure. Review their data agreements, SOC 2 reports, and retention policies before adding them to your approved list.
  • Document automation tools — If an AI tool reads, summarizes, or extracts data from client documents, it is in scope regardless of whether you call it AI.

Shadow AI is the new shadow IT

A staff member can create a free AI account in minutes. That means your firm's client data can end up on a platform you do not control, with no logging or access review. Your WISP should describe the process for approving new tools and the restriction on using unapproved AI services for client work.

What to add to your WISP today

Your WISP needs an AI-specific section that is practical and enforceable. Here is template language you can adapt.

Sample WISP language
  1. AI tool inventory. The firm maintains an inventory of all AI tools approved for processing client information. The inventory includes the service name, provider, data types processed, subscription tier, and the date of the security assessment.
  2. Data handling policy for AI tools. Client data may be entered into AI tools only when the tool is listed in the approved inventory, configured to prevent training data use, and covered by a data protection agreement.
  3. Vendor security assessment requirement for AI. Before any AI tool is approved, the Qualified Individual must review the vendor's security documentation, data retention policy, and breach notification terms. The assessment is retained with the WISP records.
  4. Prohibited use policy. Staff may not paste raw Social Security numbers, bank account details, or unredacted client names into consumer-tier AI tools, free trials, or unapproved AI services. Violations must be reported to the Qualified Individual immediately.

This language maps directly to the Safeguards Rule's requirements for vendor oversight, risk assessment, and staff training. It also gives the Qualified Individual a clear basis for saying no to unapproved tools.

Review your AI tool list every quarter

AI tools change quickly. A free trial becomes a production account. A browser extension gets installed. A new integration is added to your tax software. Build a 90-day review into your WISP maintenance schedule so your documentation does not drift behind your actual environment.

How WISPWolf helps you track AI vendor risk

WISPWolf treats AI tools as service providers, not exceptions. The vendor inventory section of your WISPWolf dashboard flags any AI tool that lacks a completed security assessment, a data handling agreement, or a quarterly review date. This prevents the most common compliance failure: an approved tool that was never documented. As AI adoption accelerates, this section of the WISP becomes a focal point in FTC reviews and cyber insurance underwriting. Carriers increasingly ask whether AI tools are governed by the same controls as other software. Regulators want to see that the Qualified Individual knows what AI is in use and has assessed it. WISPWolf's structured vendor fields make it easy to demonstrate that knowledge without hunting through emails or spreadsheets. The result is a WISP that reflects your actual technology stack, including the AI layer you added last quarter. When the FTC or an insurance underwriter asks about AI, you will have the answer ready. The platform also links AI vendor records to your risk assessment and training logs, so the entire compliance story is connected.

Conclusion

AI is not a separate category in tax practice. It is a new layer of information systems that must be absorbed into the WISP you already maintain. The firms that handle this well will document their AI tools the same way they document any other vendor: with a risk assessment, written safeguards, and a review schedule. The firms that ignore it will find their WISP out of date the moment an auditor or insurance underwriter asks the question. The best time to update your WISP for AI was before the first prompt was submitted. The second-best time is now. Update your inventory, add the policy language, train your staff on the prohibited use rules, and set a quarterly review. Your WISP should describe what your firm actually does — and in 2026, that includes AI.

Get Your Compliance Score

Related resources

References

Sources & References

Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.

  1. FTC Safeguards Rule (16 CFR Part 314) — Vendor Management Section
  2. IRS Publication 5708 — Creating a Written Information Security Plan
  3. OpenAI Enterprise Terms — Data Protection and Privacy
  4. Microsoft Copilot Data Protection Documentation
  5. FTC AI and Privacy Guidance
Free Compliance Starter Kit

Get the free WISPWolf Compliance Starter Kit

Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.

Free WISP Compliance Score

Get Your Free WISP Compliance Score

See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.

IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required