All insights
Cyber compliance

Your engagement letter probably doesn't mention AI. After the TPB's new guidance, that's a problem.

In July 2026 the Tax Practitioners Board finalised its guidance on AI and the Code of Professional Conduct. Buried in it is a line that changes a quiet daily habit in most firms: putting a client's information into an AI tool can count as disclosing it to a third party, and that needs the client's permission first.

Nathan James
Founder, Worktopia
4 August 20267 min read
Code Item 6
The tool is the third party.
The tool is the third party.

Here's what the guidance actually says, and the part almost nobody is talking about, which is that you can't write a consent clause that tells the client anything until you can answer three questions about your own systems.

The short answer

Yes, in most real cases. Client information going into an AI tool can be a disclosure to a third party, depending on how the tool is set up, and in our experience the consumer accounts most staff reach for are set up exactly that way. The client's permission needs to be in place before the information goes in, not after.

Code Item 6 of the Code of Professional Conduct is blunt: unless you have a legal duty to do so, you must not disclose any information relating to a client's affairs to a third party without your client's permission. The TPB's guidance says that can include entering client information into an AI tool, depending on how it is configured and used. In our experience, with the consumer accounts most staff use, entering client information is exactly that kind of disclosure. The tool is the third party.

That permission can live in a signed engagement letter, a signed consent form, or another clear communication. The TPB is flexible about how it is captured. What makes the difference is what the client is actually told.

Why “we may use third-party providers” tells the client nothing

This is the detail that catches firms who think they're already covered.

Most engagement letters carry a general clause about outsourcing or third-party service providers. Here is the surprise: the TPB says a general authority consenting to third-party disclosure may be acceptable. But what the guidance recommends you tell the client is specific:

Whether
AI tools may be used on the client's work at all.
Who
The information is being disclosed to.
Where
That disclosure happens.
Where stored
The data will be kept.

Read that list with your own firm in mind. Any firm can say whether it uses AI. It's the other three that bite: a clause naming no tool, no country and no storage location satisfies the form while telling the client nothing. The guidance isn't asking you to promise the tool is safe. It's asking you to tell the client facts about a piece of software your staff opened in a browser tab.

The three questions behind the clause

Here's the part the compliance coverage keeps missing. Before anyone can draft that wording for your firm, someone has to be able to answer three questions, and none of them are legal questions:

1
Which tool, on which account?
A brand name on its own is not an answer. ChatGPT, Claude, Copilot and Gemini sit on different terms, and each of them has a personal tier and a business tier that behave differently: one may retain what your staff type and use it to improve a model, the other contractually does not. Same logo, different product, and the consent clause you can honestly write is different in each case.
2
Where does the processing happen?
The servers handling that information are usually offshore. That's one of the “wheres” the guidance asks you to name, and the one most firms have never checked.
3
Where is the data stored, and for how long?
The guidance asks where the data is stored, not how long it's kept. But a storage location means little without the retention period, and retention differs by tier and can often be changed.

A firm that can answer those three can have a consent clause drafted in an afternoon. A firm that can't, can't, no matter how good its lawyer is.

The other half of this: AI in the attacker's hands
What the ASD told directors about AI attackers, and what it means for a practice
Read →

The uncomfortable bit

Most firms cannot answer them today.

Not because anyone did anything wrong, but because the AI use in most practices grew from the bottom up. Staff found tools that made their work faster and used them, on personal logins, without anyone deciding it should happen. If that's your firm, then right now nobody can tell you which tools hold client data, on whose accounts, under which terms, or in which country.

It's also rarely just one tool, and rarely the one you would guess. Partners tend to assume this is a question about ChatGPT, because that is the name everyone knows. In practice the list usually runs longer: Claude, Copilot, Gemini, a meeting notetaker nobody approved, and at least one AI feature quietly switched on inside software the firm already pays for. The less famous the tool, the less likely anyone upstairs knows it is being used, which is precisely backwards from how the risk works.

Which means the honest position isn't that your engagement letter is wrong. It's that nobody has established the facts an honest clause would need to state.

If your staff are using AI on client data and your letters say nothing about it, that's a gap worth closing deliberately, before a client, an insurer or a Board review asks the question for you.

The order of operations most firms get backwards

The instinct is to call the lawyer or grab a template clause. That's the second step, not the first.

1
Find out what's actually in use
An honest look at which AI tools your people use and on what accounts. This is the step firms skip, and it's the one everything else depends on.
2
Fix the accounts before you paper it over
Move firm AI use onto business or enterprise tiers where the terms are known and the retention is controlled, so the facts you're about to write into a consent clause are facts you'd be happy to have quoted back to you.
3
Write the policy
Which tools are approved, what client data may go into them, what never leaves the firm, and who to ask when something falls outside the rules.
4
Then update the engagement letters
Now the clause can name the tool, the place and the storage, because someone knows.

Do it in that order and the wording is straightforward. Do it in reverse and you're describing a system nobody has mapped.

Where we stop, and where we help

Worktopia doesn't draft consent wording. That's a job for your professional body's templates, your licensee, or your own advisers, and they'll do it better than any IT provider would.

What we do is the part that makes the wording possible, and true: finding what's in use, moving your firm onto AI accounts with terms you can stand behind, setting the retention and access controls, and writing the policy your staff will follow. The words are theirs. The facts that go into them are ours.

The short version
The TPB's July 2026 AI guidance says client information entered into an AI tool can be a disclosure to a third party under Code Item 6, and that disclosure needs the client's permission first.
A general third-party clause may be acceptable in form, but the TPB recommends telling the client four things: whether AI tools may be used, who the information goes to, where that happens, and where the data is stored.
You can't write one that tells them anything until you know which tool, on which account, processing where, storing what and for how long. And it's rarely just ChatGPT: Claude, Copilot, Gemini and bundled AI features are usually on the list too.
Most firms can't answer that today, because AI arrived bottom-up on personal logins.
Fix the accounts first, then the policy, then the engagement letters. In that order the wording is easy.
Read next
How secure is data in ChatGPT? What accountants need to know
Read it →

Common questions

Do accountants need client consent to use AI?
Yes, in most real cases. Code Item 6 requires the client's permission before client information is disclosed to a third party, unless you have a legal duty to disclose it, and the Tax Practitioners Board's July 2026 guidance says that can include entering client information into AI tools, depending on how the tools are configured and used. In our experience, the consumer AI accounts most staff use are configured exactly that way.
Is a general outsourcing clause enough to cover AI use?
A general clause may be acceptable in form: the TPB says a general authority consenting to third-party disclosure may be acceptable. But the guidance also recommends telling the client four things: whether AI tools may be used, who the information is disclosed to, where that happens, and where the data is stored. A generic clause tells the client none of that.
What does the TPB recommend telling clients about AI?
Four things: whether AI tools may be used, who the information is disclosed to, where that disclosure happens, and where the data will be stored. In practice, answering the last three means knowing the tool and the account tier, the country the processing happens in, and where the data is held afterwards.
Can a tax agent use ChatGPT or Claude at all?
Nothing in the guidance bans AI, and it doesn't single out any tool. The obligations are about doing it knowingly: get the client's permission first, exercise due diligence over the tool's security and privacy handling, and keep responsibility for the work yourself. That applies equally to ChatGPT, Claude, Copilot, Gemini and whatever arrives next. A ban tends to push use onto personal devices where the firm has no visibility at all.
Where does the consent need to be recorded?
It can sit in a signed engagement letter, a signed consent form, or another clear communication with the client. The form matters less than whether the client was genuinely told what the guidance recommends: whether AI tools may be used, who receives their information, where that happens, and where it is stored.
Nathan James
Founder, Worktopia
Nathan started Worktopia after years inside a Brisbane accounting firm, moving it off legacy systems and into the cloud. He writes about the practical side of security and IT for practices that would rather be doing the work.
Kip, the Worktopia mascot, holding a shield

Not sure what your staff are using?

Our free Cyber Compliance Health Check shows you where your firm stands, including what's happening with AI tools and client data. Read-only. Nothing in your tenant changes. You approve access, and revoke it any time.

Start a Health Check or call 1300 856 912