KlarComply
HomeKnowledge › AI in tax and accounting firms

AI in the tax firm: what is allowed — and why the client file is more sensitive than it looks

Tax advisers handle other people's secrets for a living — and depending on the country, professional confidentiality is backed by criminal law, professional regulation or contract. A client file also rarely stays at plain financial data: medical expenses reveal health, union dues reveal membership. An assessment notice pasted into a general-purpose AI tool for summarising is therefore not a convenience question but a confidentiality question.

By , Founder of KlarComply · Reviewed on

Infographic: AI in tax and accounting firms: client data first — Efficiency gains, yes — but professional secrecy sets the frame.
The key points of this article as a graphic — feel free to share or download it.

What actually applies in a firm

What you doWhat appliesOrder of magnitude
Assessments, filings or client emails in a general-purpose AI toolProfessional confidentiality + GDPRcriminal/professional law · up to €20m or 4 %
Dictation/transcription via a cloud serviceProfessional confidentiality + GDPRcriminal/professional law · up to €20m or 4 %
AI features of your practice softwareArt. 28 GDPR + confidentiality undertakinga contract question — checkable
Booking bot on the firm's websiteArt. 50 AI Act — disclosureup to €15m or 3 %
AI copy and images for firm marketingArt. 50 AI Act + professional advertising ruleslabelling · reprimands
Your team uses AI toolsArt. 4 AI Act — literacyno standalone fine

For small and medium-sized enterprises, the lower of the two AI Act values applies (Art. 99(6)). Under the GDPR, the higher one does.

The client file is more sensitive than it looks

Financial data as such is "ordinary" personal data under the GDPR. A real client file rarely stops there. Three examples from everyday practice:

Feeding a complete tax return or assessment into an AI tool therefore almost always processes special categories too, with the stricter standard that attaches to them. "It's only numbers" does not hold.

Professional confidentiality: the rule that outranks convenience

Across Europe, tax advisers and auditors are generally bound by professional confidentiality — under criminal law, professional regulation, contract, or a combination — with the exact scope set by national law. The operative point for AI is the same everywhere:

The sentence that makes the difference

Confidentiality can be breached the moment client data sits on a server that the provider's staff could access. It does not depend on whether a human ever reads the text. It is not the reading that constitutes the disclosure — the possibility of it does. An assessment pasted into a general-purpose AI tool for summarising can cross that line even if the answer never leaves your firm.

If your firm is in Germany: tax advisers and auditors are named expressly in § 203(1) of the Criminal Code — up to one year's imprisonment for unauthorised disclosure — flanked by the professional duty of confidentiality in § 57 of the Tax Advisory Act for tax advisers and in § 43 of the Public Accountants Act for auditors. The lawful route exists twice over: § 203(3)–(4) of the Criminal Code and § 62a of the Tax Advisory Act both allow involving service providers where the provider is contractually bound to confidentiality; a data processing agreement alone is not enough, because it covers data protection, not criminal and professional law. Outside Germany, check your national rules — the safe baseline is the same everywhere: client data goes into no tool whose provider is not contractually bound.

The practice rule that makes everything else easy

No client reference in the prompt. "Explain the new small-business VAT scheme in plain words" is unproblematic. "Summarise the attached assessment for Mr W." is not. Strip names, tax numbers, amounts and attachments before the input — or use a provider that has signed both undertakings.

Practice-software AI and the two contracts

The AI features of established practice software are the most convenient route — if the paperwork is right. Two documents belong in your records before the feature goes live:

Booking bot and firm marketing

If a bot answers on your website, people must be able to tell a machine is writing — one sentence is enough: "You are chatting with an automated assistant." Since 2 August 2026, Article 50 of the AI Act also requires labelling AI-generated or materially AI-edited images, audio and video. And professional advertising rules for regulated advisers demand factual, unexaggerated communication in most member states — an AI that drafts sweeping success claims does not fit that frame.

And the training?

Since 2 February 2025, Article 4 of the AI Act has obliged you to take measures to foster AI literacy among your staff — since the Digital Omnibus a duty of effort, not of result, and without a standalone fine (Article 99(4) lists the sanctioned duties exhaustively; Article 4 is not among them). Why the record still matters: in a firm where client data passes through many hands daily, the first question after any incident is: did your staff know what they were doing? A dated training record answers it — to the professional body, the regulator and the client.

A roadmap you can finish in an afternoon

  1. Inventory: practice-software AI, dictation, text drafting, research tools, booking bot — including what staff use privately.
  2. Write down the client-data rule: no client reference in general-purpose tools; keep an approved-tools list.
  3. Vet providers: data processing agreement and confidentiality undertaking in writing; training use switched off.
  4. Label the bot and your content: a disclosure sentence on the bot, a label on AI content.
  5. Train the team and file the record — dated, per person.

Frequently asked questions

May I process assessments or client letters with ChatGPT?

Not with a client reference in a general-purpose tool: professional confidentiality can be breached the moment the provider's staff could access the data — actual reading is not required. It becomes workable with a provider that signs a confidentiality undertaking and a data processing agreement — or with no client reference in the prompt at all.

Is tax data even “sensitive data” under the GDPR?

Financial data as such is not — but a real client file almost always contains special categories under Article 9: medical expenses reveal health, union dues reveal membership, and in some member states tax records encode religious affiliation. Feeding whole returns or assessments into a tool therefore regularly processes Article 9 data too.

The AI feature is built into my practice software — is that enough?

It is the most convenient route if two documents are in place: the data processing agreement under Article 28 GDPR and the confidentiality undertaking your national law requires for service providers. Established professional-market vendors have both ready — ask expressly for the second, and whether inputs are used for training.

Does my booking bot have to identify itself?

Yes. Article 50 of the AI Act requires that people can tell when they are interacting with an AI system, unless it is obvious. One sentence is enough: “You are chatting with an automated assistant. For a personal conversation, call us.”

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 9 GDPR — special categories of personal data
Article 28 GDPR — processor
Article 50 AI Act — transparency obligations
Article 4 AI Act — AI literacy
Regulation (EU) 2024/1689 — official full text
Reviewed on 28 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.