Proxaradocs
Trust Center/Compliance

IRC § 7216 and the disclosure boundary

What the rule says, what it means for AI-assisted tax work, which technical facts Proxara enforces, which deployment assumptions the reading depends on, and which questions belong to the firm's own tax counsel.

Updated July 2026

For a firm's tax principal, its security and privacy owners, and the counsel they forward this to: what § 7216 says, how Proxara Connect is built against it, what a firm's deployment must satisfy for the reasoning to hold, and what remains for counsel.

How to read this page

Every statement carries one of five labels. Statute and regulation is what the law says, with the provision cited. Reasoned interpretation is how that text bears on AI-assisted tax work, never a conclusion about the reader's own facts. Product behavior is what the software does and a firm can test. Deployment assumption is what must be true of a firm's deployment for the reasoning above it to hold. For counsel is an unresolved interpretation and the question to put to the firm's own tax counsel.

What the rule says

Statute and regulation. § 7216(a) makes it a misdemeanor for a person in the business of preparing returns, or of providing services in connection with that preparation, to knowingly or recklessly disclose information furnished for or in connection with preparing such a return, or use it for any purpose other than preparing the return. The penalty is a fine of up to $1,000, up to a year of imprisonment, or both. § 6713(a) adds a civil penalty for the same conduct. Treas. Reg. § 301.7216-1 defines the terms, § 301.7216-2 lists what may be disclosed or used without consent, and § 301.7216-3 governs consent. It predates AI by decades.

TermProvisionWhat it says
Tax return information§ 301.7216-1(b)(3)(i)Any information, including a name or identifying number, furnished in any form for or in connection with preparing that taxpayer's return, including what the preparer derives or generates.
Disclosure§ 301.7216-1(b)(5)"the act of making tax return information known to any person in any manner whatever."

Statute and regulation. § 301.7216-2(d)(2) permits disclosure to a contractor for the programming, maintenance, testing or procurement of tax return preparation software, only so far as necessary, and only where each individual receiving it first gets written notice that §§ 6713 and 7216 apply. That contractor is itself a preparer, as is anyone developing software used to prepare or file a return.

Statute and regulation. Where consent is required it is per purpose: it names the preparer and the taxpayer, identifies the purpose and the specific recipient or particular use, specifies the information covered, and is signed and dated (§ 301.7216-3(a)(3)(i)). It cannot be retroactive (§ 301.7216-3(b)(1)). For Form 1040 series filers, Rev. Proc. 2013-14 prescribes a separate written document, its format, and mandatory language. The client consent template is a starting point for counsel, not a prescribed form.

Reasoned interpretation. The definition turns on the connection to preparation, not on whether a fragment identifies anyone: information counts if the taxpayer would not have furnished it but for engaging the preparer (§ 301.7216-1(b)(3)(i)(D)). It also covers what the preparer derives or generates. Removing names is therefore not by itself an argument that what remains falls outside it, and the regulation makes that point against itself: statistical compilations are tax return information "even in a form that cannot be associated with, or otherwise identify, directly or indirectly, a particular taxpayer" (§ 301.7216-1(b)(3)(i)(B)).

What triggers it in AI work

Reasoned interpretation. Disclosure is making the information known to any person in any manner whatever, so three patterns reach the same analysis: a preparer pasting client figures into a consumer assistant; a tax-specific AI vendor receiving the material, since specialization does not change who receives it; and the firm's own system calling an external model endpoint, since an API call is not materially different from a paste. Absent a boundary, the firm's options are a signed, purpose-specific, prospective consent from every client, or a ban, after which staff paste client facts into consumer tools anyway. The second is the broader disclosure.

The boundary in the path

Product behavior. Connect retrieves permitted context from the systems the firm already runs: Karbon; Microsoft 365, covering Outlook mail and calendar, Teams, OneDrive and SharePoint, and To Do and Planner; a CRM where the firm runs one; selected tax systems; and document stores. Parsing, classification, identity resolution, correlation and exact computation over that raw material run inside the firm's own environment. Activating a connector is not blanket permission to read that system: authority is assigned to an exact source capability, for one role, in one approved kind of work.

Reasoned interpretation. A residual span is a violation on transmission regardless of intent, which makes a filter the wrong shape for this statute. A filter is a denylist: its residual risk is whatever it failed to recognize, and the absence of something never looked for cannot be shown.

Product behavior. The payload is therefore constructed rather than filtered. The model does not receive the firm's documents with the sensitive parts removed; it receives a payload assembled only from claims the firm's policy authorized, and anything the system cannot account for never leaves. Coverage is verified structurally, and a residual check over the assembled result is one step among several. Insufficient coverage produces less work rather than a leaky payload: the work stays local, drops that source with the gap recorded, or stops. The system's worst case is less useful, never less private. What the model sees sets out the payload.

Reasoned interpretation. § 7216 governs the disclosure of tax return information to third parties. Where no tax return information is disclosed, there is nothing to consent to. Whether a particular payload in a particular workflow is tax return information is a question about the firm's own facts, and this page does not answer it.

Indirect identification

Reasoned interpretation. Removing direct identifiers is not sufficient. A rare industry, a location, an entity form, an employee count, an unusual transaction, an exact date and amount, an address fragment, a document combination, a persistent stand-in, or an earlier release can identify a taxpayer between them where no single item does.

Product behavior. Proxara evaluates cumulative disclosure into the actual external destination context rather than each prompt in isolation. The model-facing substitute for a protected reference is a stand-in: stable inside one authorized piece of work and its destination context so multi-step work stays coherent, rotated at the work, purpose or destination boundary. The mapping to the real value stays inside the firm's environment, so nothing can be assembled across tasks or days. Where a further release would be unsafe, or the host cannot evidence that a new conversation is isolated, the system rotates the destination, keeps the work local, omits, or blocks.

For counsel. The threshold for indirect identification in a release schema is a policy the firm sets and Proxara enforces, not one the software decides.

The other half of the statute: use

Statute and regulation. § 7216(a)(2) reaches use for any purpose other than preparing the return, and use means referring to or relying upon tax return information as the basis to take or permit an action (§ 301.7216-1(b)(4)(i)). Nothing has to be transmitted anywhere.

Reasoned interpretation. Cross-selling from return data, training a general model on client data, analyzing returns for third-party financial products, and letting one client's information influence another client's work are all capable of being violations with no transmission at all. Consent remains genuinely required for purposes of that kind.

Product behavior. Proxara does not remove that requirement; it enforces the line. Purpose is bound before retrieval, so a purpose outside tax preparation does not compile, or does not run until the authority the firm's policy requires is on file. A request to identify clients from return data for an unrelated pitch fails before retrieval, and no list is produced.

Figures, the private view, and actions

Product behavior. Exact computation and comparison stay inside the firm's environment. Random perturbation and generalized bucketing are prohibited where they could alter tax logic, a filing, a reconciliation, or an employee's understanding; an external model may receive symbolic variables, typed relationships, a threshold crossed, or a locally computed conclusion.

Product behavior. Clear values render only in a first-party, customer-authorized origin under the firm's own single sign-on, bound to the exact recipient and artifact revision. A host adapter or MCP app may open that workspace, but no clear value enters host tool output, host-visible structured content, host-controlled messaging, the URL, the referrer, client telemetry, or support logs. MCP sandboxing protects a host from app code; it is not a demonstration that a host provider cannot read what it renders, which is why the workspace is first party rather than embedded.

Product behavior. In an action the model names only opaque references; the firm's own environment resolves the real client, recipient and record, revalidates authority and target state, executes, and reads the provider state back. Intervention follows consequence: reads, local reasoning, private artifacts and reversible internal updates run under delegated authority, while client sends, filings, payments, finalizing a return, destructive effects, widened recipients, and unresolved ambiguity require fresh confirmation. Every tool and sub-agent result is recompiled before it re-enters an external context, and the same boundary serves the firm's own agents and a versioned Work API. See what the connector can and cannot do.

Reasoned interpretation. Rendering a clear value on an authorized employee's own screen, inside an environment the firm controls, is offered as reasoning rather than as a settled conclusion. And because the real client, recipient and record are never made known to the model during the tool cycle, the act the regulation calls disclosure does not occur at that step. Both readings depend on the deployment assumptions below.

Adjacent regimes

Reasoned interpretation. § 7216 is the clearest of several obligations in the same path. None is satisfied by deploying software. § 6713 is the civil companion. Circular 230 reaches diligence, competence and confidentiality in AI-assisted work, attributable to a named person. Under the FTC Safeguards Rule, tax and accounting firms are financial institutions, and the AI chapter of the written information security plan names approved tools, named users, and what left the boundary. AICPA ET 1.700 reaches confidential client information and the third-party service provider step, and peer review finds AI use answerable where the firm has an audit practice. Proxara's contribution is to make the firm's own rules enforceable where AI retrieves data and works, and to produce the record of what happened.

Deployment assumptions

Deployment assumption. The reasoning above holds only where all six of the following are true.

  • Compilation, classification, identity resolution and exact computation genuinely run inside an environment the firm controls, under the explicit control mode. A managed model endpoint reached over a private network link is still a managed external processor; network privacy is not customer-contained inference, and a dedicated account inside a vendor's organization is isolation rather than customer control.
  • The approved kinds of work bind purpose before retrieval. Otherwise purpose is descriptive rather than executable, and the use half of the statute is unenforced.
  • No explicitly authorized raw external route is configured for the workflow, or the firm holds its own basis for one. Otherwise raw material reaches a third party under that route.
  • The firm's own Microsoft, practice-management and tax-system permissions are sound. Delegated access is a ceiling: every read carries the signed-in employee's own credential, and Proxara does not repair over-broad grants the firm has already made.
  • Document coverage is genuinely achieved for the material in scope. Where it is not, unaccounted material stays local rather than being released, which is safe and narrows the result.
  • The firm's counsel has reviewed the exact workflows. Otherwise the interpretation here is unowned.

Deployment assumption. Material an employee types or uploads directly into an outside assistant does not pass through this boundary. Connect governs the connected path.

Product behavior. The control facts are documented per deployment rather than inferred: account ownership, root and tenant administration, key ownership, the revocable Proxara role, support access and its authorization, network paths, model and container provenance, and the suspend, export and removal paths. The Connect security review walks the architecture in assessment order.

What Proxara does and does not claim

StatedNot stated
The external model receives no client names, no identifiers and no return figuresAny removal percentage, or an assurance that nothing is ever missed
The mapping between stand-ins and real values stays inside the firm's environmentThat replacing identifiers removes any obligation
The same client is a different stand-in in a different piece of workThat an external model is incapable of inference
Clear values return only on the authorized employee's screen, in a view the model does not receiveThat a host provider is technically incapable of reading what it renders
If part of the context cannot be accounted for, that part never leavesThat the firm is thereby compliant, or that a legal requirement is eliminated
Every piece of work leaves a record of what was consulted, released, under which policy, and confirmed in the source systemAny IRS approval or certification, and any legal or tax conclusion on the firm's behalf

Questions for qualified counsel

For counsel. The interpretations this page does not settle.

  1. Is a payload constructed from typed claims derived from tax return information itself tax return information under § 301.7216-1(b)(3)(i), given that the definition covers what the preparer derives or generates and that statistical compilations stay inside it?
  2. If a release does contain tax return information, does the model provider fall within § 301.7216-2(d)(2) as a contractor, and has the written notice been given?
  3. Does the firm treat rendering a clear value to an authorized employee inside its own environment as a disclosure, and does that change where the view is opened from a third-party AI host?
  4. Which workflows fall outside preparation for the purposes of § 7216(a)(2), and which of those require consent before any data is touched?
  5. Where consent is required for a Form 1040 series filer, does the firm's form meet the separate-document, format and mandatory-language requirements of Rev. Proc. 2013-14?
  6. On the facts of the firm's own contract, does its control of the deployment environment support describing the processing as taking place inside the firm's control?

Proxara does not provide tax or legal advice. Firms should confirm the treatment of their own workflows with their counsel.