What the rule says, what it means for AI-assisted tax work, which technical facts Proxara enforces, which deployment assumptions the reading depends on, and which questions belong to the firm's own tax counsel.
Updated July 2026
For a firm's tax principal, its security and privacy owners, and the counsel they forward this to: what § 7216 says, how Proxara Connect is built against it, what a firm's deployment must satisfy for the reasoning to hold, and what remains for counsel.
Every statement carries one of five labels. Statute and regulation is what the law says, with the provision cited. Reasoned interpretation is how that text bears on AI-assisted tax work, never a conclusion about the reader's own facts. Product behavior is what the software does and a firm can test. Deployment assumption is what must be true of a firm's deployment for the reasoning above it to hold. For counsel is an unresolved interpretation and the question to put to the firm's own tax counsel.
Statute and regulation. § 7216(a) makes it a misdemeanor for a person in the business of preparing returns, or of providing services in connection with that preparation, to knowingly or recklessly disclose information furnished for or in connection with preparing such a return, or use it for any purpose other than preparing the return. The penalty is a fine of up to $1,000, up to a year of imprisonment, or both. § 6713(a) adds a civil penalty for the same conduct. Treas. Reg. § 301.7216-1 defines the terms, § 301.7216-2 lists what may be disclosed or used without consent, and § 301.7216-3 governs consent. It predates AI by decades.
| Term | Provision | What it says |
|---|---|---|
| Tax return information | § 301.7216-1(b)(3)(i) | Any information, including a name or identifying number, furnished in any form for or in connection with preparing that taxpayer's return, including what the preparer derives or generates. |
| Disclosure | § 301.7216-1(b)(5) | "the act of making tax return information known to any person in any manner whatever." |
Statute and regulation. § 301.7216-2(d)(2) permits disclosure to a contractor for the programming, maintenance, testing or procurement of tax return preparation software, only so far as necessary, and only where each individual receiving it first gets written notice that §§ 6713 and 7216 apply. That contractor is itself a preparer, as is anyone developing software used to prepare or file a return.
Statute and regulation. Where consent is required it is per purpose: it names the preparer and the taxpayer, identifies the purpose and the specific recipient or particular use, specifies the information covered, and is signed and dated (§ 301.7216-3(a)(3)(i)). It cannot be retroactive (§ 301.7216-3(b)(1)). For Form 1040 series filers, Rev. Proc. 2013-14 prescribes a separate written document, its format, and mandatory language. The client consent template is a starting point for counsel, not a prescribed form.
Reasoned interpretation. The definition turns on the connection to preparation, not on whether a fragment identifies anyone: information counts if the taxpayer would not have furnished it but for engaging the preparer (§ 301.7216-1(b)(3)(i)(D)). It also covers what the preparer derives or generates. Removing names is therefore not by itself an argument that what remains falls outside it, and the regulation makes that point against itself: statistical compilations are tax return information "even in a form that cannot be associated with, or otherwise identify, directly or indirectly, a particular taxpayer" (§ 301.7216-1(b)(3)(i)(B)).
Reasoned interpretation. Disclosure is making the information known to any person in any manner whatever, so three patterns reach the same analysis: a preparer pasting client figures into a consumer assistant; a tax-specific AI vendor receiving the material, since specialization does not change who receives it; and the firm's own system calling an external model endpoint, since an API call is not materially different from a paste. Absent a boundary, the firm's options are a signed, purpose-specific, prospective consent from every client, or a ban, after which staff paste client facts into consumer tools anyway. The second is the broader disclosure.
Product behavior. Connect retrieves permitted context from the systems the firm already runs: Karbon; Microsoft 365, covering Outlook mail and calendar, Teams, OneDrive and SharePoint, and To Do and Planner; a CRM where the firm runs one; selected tax systems; and document stores. Parsing, classification, identity resolution, correlation and exact computation over that raw material run inside the firm's own environment. Activating a connector is not blanket permission to read that system: authority is assigned to an exact source capability, for one role, in one approved kind of work.
Reasoned interpretation. A residual span is a violation on transmission regardless of intent, which makes a filter the wrong shape for this statute. A filter is a denylist: its residual risk is whatever it failed to recognize, and the absence of something never looked for cannot be shown.
Product behavior. The payload is therefore constructed rather than filtered. The model does not receive the firm's documents with the sensitive parts removed; it receives a payload assembled only from claims the firm's policy authorized, and anything the system cannot account for never leaves. Coverage is verified structurally, and a residual check over the assembled result is one step among several. Insufficient coverage produces less work rather than a leaky payload: the work stays local, drops that source with the gap recorded, or stops. The system's worst case is less useful, never less private. What the model sees sets out the payload.
Reasoned interpretation. § 7216 governs the disclosure of tax return information to third parties. Where no tax return information is disclosed, there is nothing to consent to. Whether a particular payload in a particular workflow is tax return information is a question about the firm's own facts, and this page does not answer it.
Reasoned interpretation. Removing direct identifiers is not sufficient. A rare industry, a location, an entity form, an employee count, an unusual transaction, an exact date and amount, an address fragment, a document combination, a persistent stand-in, or an earlier release can identify a taxpayer between them where no single item does.
Product behavior. Proxara evaluates cumulative disclosure into the actual external destination context rather than each prompt in isolation. The model-facing substitute for a protected reference is a stand-in: stable inside one authorized piece of work and its destination context so multi-step work stays coherent, rotated at the work, purpose or destination boundary. The mapping to the real value stays inside the firm's environment, so nothing can be assembled across tasks or days. Where a further release would be unsafe, or the host cannot evidence that a new conversation is isolated, the system rotates the destination, keeps the work local, omits, or blocks.
For counsel. The threshold for indirect identification in a release schema is a policy the firm sets and Proxara enforces, not one the software decides.
Statute and regulation. § 7216(a)(2) reaches use for any purpose other than preparing the return, and use means referring to or relying upon tax return information as the basis to take or permit an action (§ 301.7216-1(b)(4)(i)). Nothing has to be transmitted anywhere.
Reasoned interpretation. Cross-selling from return data, training a general model on client data, analyzing returns for third-party financial products, and letting one client's information influence another client's work are all capable of being violations with no transmission at all. Consent remains genuinely required for purposes of that kind.
Product behavior. Proxara does not remove that requirement; it enforces the line. Purpose is bound before retrieval, so a purpose outside tax preparation does not compile, or does not run until the authority the firm's policy requires is on file. A request to identify clients from return data for an unrelated pitch fails before retrieval, and no list is produced.
Product behavior. Exact computation and comparison stay inside the firm's environment. Random perturbation and generalized bucketing are prohibited where they could alter tax logic, a filing, a reconciliation, or an employee's understanding; an external model may receive symbolic variables, typed relationships, a threshold crossed, or a locally computed conclusion.
Product behavior. Clear values render only in a first-party, customer-authorized origin under the firm's own single sign-on, bound to the exact recipient and artifact revision. A host adapter or MCP app may open that workspace, but no clear value enters host tool output, host-visible structured content, host-controlled messaging, the URL, the referrer, client telemetry, or support logs. MCP sandboxing protects a host from app code; it is not a demonstration that a host provider cannot read what it renders, which is why the workspace is first party rather than embedded.
Product behavior. In an action the model names only opaque references; the firm's own environment resolves the real client, recipient and record, revalidates authority and target state, executes, and reads the provider state back. Intervention follows consequence: reads, local reasoning, private artifacts and reversible internal updates run under delegated authority, while client sends, filings, payments, finalizing a return, destructive effects, widened recipients, and unresolved ambiguity require fresh confirmation. Every tool and sub-agent result is recompiled before it re-enters an external context, and the same boundary serves the firm's own agents and a versioned Work API. See what the connector can and cannot do.
Reasoned interpretation. Rendering a clear value on an authorized employee's own screen, inside an environment the firm controls, is offered as reasoning rather than as a settled conclusion. And because the real client, recipient and record are never made known to the model during the tool cycle, the act the regulation calls disclosure does not occur at that step. Both readings depend on the deployment assumptions below.
Reasoned interpretation. § 7216 is the clearest of several obligations in the same path. None is satisfied by deploying software. § 6713 is the civil companion. Circular 230 reaches diligence, competence and confidentiality in AI-assisted work, attributable to a named person. Under the FTC Safeguards Rule, tax and accounting firms are financial institutions, and the AI chapter of the written information security plan names approved tools, named users, and what left the boundary. AICPA ET 1.700 reaches confidential client information and the third-party service provider step, and peer review finds AI use answerable where the firm has an audit practice. Proxara's contribution is to make the firm's own rules enforceable where AI retrieves data and works, and to produce the record of what happened.
Deployment assumption. The reasoning above holds only where all six of the following are true.
Deployment assumption. Material an employee types or uploads directly into an outside assistant does not pass through this boundary. Connect governs the connected path.
Product behavior. The control facts are documented per deployment rather than inferred: account ownership, root and tenant administration, key ownership, the revocable Proxara role, support access and its authorization, network paths, model and container provenance, and the suspend, export and removal paths. The Connect security review walks the architecture in assessment order.
| Stated | Not stated |
|---|---|
| The external model receives no client names, no identifiers and no return figures | Any removal percentage, or an assurance that nothing is ever missed |
| The mapping between stand-ins and real values stays inside the firm's environment | That replacing identifiers removes any obligation |
| The same client is a different stand-in in a different piece of work | That an external model is incapable of inference |
| Clear values return only on the authorized employee's screen, in a view the model does not receive | That a host provider is technically incapable of reading what it renders |
| If part of the context cannot be accounted for, that part never leaves | That the firm is thereby compliant, or that a legal requirement is eliminated |
| Every piece of work leaves a record of what was consulted, released, under which policy, and confirmed in the source system | Any IRS approval or certification, and any legal or tax conclusion on the firm's behalf |
For counsel. The interpretations this page does not settle.
Proxara does not provide tax or legal advice. Firms should confirm the treatment of their own workflows with their counsel.