All insights
Cyber compliance

Your engagement letter probably doesn't mention AI. The TPB now says it should.

In July 2026 the Tax Practitioners Board finalised its guidance on AI and the Code of Professional Conduct. Buried in it is a line that changes a quiet daily habit in most firms: putting a client's information into an AI tool counts as disclosing it to a third party, and that needs the client's permission first.

Nathan James
Founder, Worktopia
4 August 20267 min read
Code Item 6
The tool is the third party.

Here's what the guidance actually says, and the part almost nobody is talking about, which is that you can't write the consent clause until you can answer three questions about your own systems.

The short answer

Yes, you need client consent before client information goes into an AI tool, and it needs to be in place before, not after.

Code Item 6 of the Code of Professional Conduct is blunt: unless you have a legal duty to do so, you must not disclose any information relating to a client's affairs to a third party without your client's permission. The TPB's guidance confirms that entering client information into an AI tool is that kind of disclosure. The tool is the third party.

That consent can live in a signed engagement letter, a signed consent form, or another clear communication. What it cannot be is vague.

Why “we may use third-party providers” doesn't cover it

This is the detail that catches firms who think they're already covered.

Most engagement letters carry a general clause about outsourcing or third-party service providers. The TPB's position is that a generic clause like that is not enough on its own, because consent has to be informed. To be informed, the client needs to be told:

Who
The information is being disclosed to.
Where
That disclosure happens.
Where stored
The data will be kept.

Read that list again with your own firm in mind. It isn't asking you to promise the tool is safe. It's asking you to state, in writing, facts about a piece of software your staff opened in a browser tab.

The three questions behind the clause

Here's the part the compliance coverage keeps missing. Before anyone can draft that wording for your firm, someone has to be able to answer three questions, and none of them are legal questions:

1
Which tool, on which account?
A brand name on its own is not an answer. ChatGPT, Claude, Copilot and Gemini sit on different terms, and each of them has a personal tier and a business tier that behave differently: one may retain what your staff type and use it to improve a model, the other contractually does not. Same logo, different product, and the consent clause you can honestly write is different in each case.
2
Where does the processing happen?
The servers handling that information are usually offshore, most often in the United States. That's the “where” the TPB wants named, and it's also what engages the cross-border disclosure rules under the Privacy Act.
3
Where is the data stored, and for how long?
Retention settings differ by tier and can often be changed. Whatever the setting is, it's the fact you're attesting to.

A firm that can answer those three can have a consent clause drafted in an afternoon. A firm that can't, can't, no matter how good its lawyer is.

The uncomfortable bit

Most firms cannot answer them today.

Not because anyone did anything wrong, but because the AI use in most practices grew from the bottom up. Staff found tools that made their work faster and used them, on personal logins, without anyone deciding it should happen. If that's your firm, then right now nobody can tell you which tools hold client data, on whose accounts, under which terms, or in which country.

It's also rarely just one tool, and rarely the one you would guess. Partners tend to assume this is a question about ChatGPT, because that is the name everyone knows. In practice the list usually runs longer: Claude, Copilot, Gemini, a meeting notetaker nobody approved, and at least one AI feature quietly switched on inside software the firm already pays for. The less famous the tool, the less likely anyone upstairs knows it is being used, which is precisely backwards from how the risk works.

Which means the honest position isn't that your engagement letter is wrong. It's that there is no set of words you could put in it that would be true, because the underlying facts aren't known yet.

If your staff are using AI on client data and your letters don't carry informed consent, that's a gap worth closing deliberately, before a client, an insurer or a Board review asks the question for you.

The order of operations most firms get backwards

The instinct is to call the lawyer or grab a template clause. That's the second step, not the first.

1
Find out what's actually in use
An honest look at which AI tools your people use and on what accounts. This is the step firms skip, and it's the one everything else depends on.
2
Fix the accounts before you paper it over
Move firm AI use onto business or enterprise tiers where the terms are known and the retention is controlled, so the facts you're about to write into a consent clause are facts you'd be happy to have quoted back to you.
3
Write the policy
Which tools are approved, what client data may go into them, what never leaves the firm, and who to ask when something falls outside the rules.
4
Then update the engagement letters
Now the clause can name the tool, the place and the storage, because someone knows.

Do it in that order and the wording is straightforward. Do it in reverse and you're describing a system nobody has mapped.

Where we stop, and where we help

Worktopia doesn't draft consent wording. That's a job for your professional body's templates, your licensee, or your own advisers, and they'll do it better than any IT provider would.

What we do is the part that makes the wording possible, and true: finding what's in use, moving your firm onto AI accounts with terms you can stand behind, setting the retention and access controls, and writing the policy your staff will follow. The words are theirs. The facts that go into them are ours.

The short version
The TPB's July 2026 AI guidance treats client information entered into an AI tool as a disclosure to a third party under Code Item 6, so it needs the client's permission first.
A general outsourcing or third-party clause is not enough on its own. Consent has to be informed: who, where, and where the data is stored.
You can't write that clause until you know which tool, on which account, processing where, storing what and for how long. And it's rarely just ChatGPT: Claude, Copilot, Gemini and bundled AI features are usually on the list too.
Most firms can't answer that today, because AI arrived bottom-up on personal logins.
Fix the accounts first, then the policy, then the engagement letters. In that order the wording is easy.
Read next
How secure is data in ChatGPT? What accountants need to know
Read it →

Common questions

Do accountants need client consent to use AI?
Yes. The Tax Practitioners Board's July 2026 guidance on AI and the Code of Professional Conduct treats client information entered into an AI tool as a disclosure to a third party. Code Item 6 requires the client's permission before that disclosure happens, unless you have a legal duty to disclose.
Is a general outsourcing clause enough to cover AI use?
No, not on its own. The TPB's position is that consent must be informed, which means telling the client who the information is disclosed to, where that happens, and where the data is stored. A generic reference to third-party providers doesn't meet that bar.
What does informed consent require for AI?
Three specifics: the identity of the third party receiving the information, where the disclosure takes place, and where the data will be held. In practice that means naming the tool and the account tier, the jurisdiction the processing happens in, and the retention arrangement.
Can a tax agent use ChatGPT or Claude at all?
Nothing in the guidance bans AI, and it doesn't single out any tool. The obligations are about doing it knowingly: get the client's informed consent first, exercise due diligence over the tool's security and privacy handling, and keep responsibility for the work yourself. That applies equally to ChatGPT, Claude, Copilot, Gemini and whatever arrives next. A ban tends to push use onto personal devices where the firm has no visibility at all.
Where does the consent need to be recorded?
It can sit in a signed engagement letter, a signed consent form, or another clear communication with the client. The form matters less than whether the client was actually informed about who receives their information, where, and where it is stored.
Nathan James
Founder, Worktopia
Nathan started Worktopia after years inside a Brisbane accounting firm, moving it off legacy systems and into the cloud. He writes about the practical side of security and IT for practices that would rather be doing the work.
Kip, the Worktopia mascot, holding a shield

Not sure what your staff are using?

Our free Cyber Compliance Health Check shows you where your firm stands, including what's happening with AI tools and client data. Read-only. Nothing in your tenant changes. You approve access, and revoke it any time.

Book your free Health Check or call 1300 856 912