Skip to content
← All posts
6 min readBy

What the TPB's AI guidance asks of your practice

TPB(GS) 55/2026 requires less than its headlines suggest, and asks for one thing most firms have not noticed. What is required, what is recommended, and what to do.

  • AI
  • TPB
  • Compliance
A printed government guidance document lying on a desk beside a cup of coffee, a few pages flagged with coloured tabs, all text out of focus.

The email from the Tax Practitioners Board arrived on 22 July. Subject line about artificial intelligence, a link, a PDF. It went into the folder where regulator emails go to wait for a quiet week, and there has not been a quiet week since.

In the meantime it has reached you second-hand, and the second-hand versions tend to land in one of three places: that you now need an AI consent from every client, that some tools are "TPB compliant", or that the Board has banned ChatGPT. None of those is quite what the document says.

So here is what TPB(GS) 55/2026 actually asks, read the way a practice principal would want it read: what you must do, what the Board would like you to do, and what it doesn't say at all.

First, what kind of document it is

It is guidance, not a new rule. It creates no obligation that did not already exist in the Code of Professional Conduct. What it does is tell you how the Board will read the obligations you already have when AI is involved — which is worth knowing, because that is how it will read them when something goes wrong.

It bans no tool and endorses none. It names no product. A vendor telling you their software is "approved" or "compliant" with it is claiming something the guidance does not do for anyone.

What you must do

Two things, and neither is new.

Get the client's permission before their information goes to a third party. This is Code item 6, confidentiality, and the guidance applies it directly. Anyone who is not you or your client is a third party. Entering client information into an AI tool can be a disclosure to one — "depending on how these tools are configured and used" (paragraph 23). The Board is not saying every AI tool is a disclosure. It is saying you need to know whether yours is, which is a question about its settings and its terms, not about how clever it is.

Stay responsible for the work. You remain accountable for the accuracy of what you lodge, you apply your own professional judgement, and AI output is not a substitute for your own analysis. Anyone who has signed a return already believes this. The guidance simply closes off "the software did it" as a position.

A single sheet of paper split down the middle by a pen line, a short handwritten list on one side and a longer one on the other, the writing illegible.
Two columns worth keeping apart: what the guidance requires, and what it recommends.

What you almost certainly don't need

A separate AI consent form for every client. You do need each client's permission before their information goes to a third party — the guidance says so plainly. What it does not say is that the permission has to be a new, AI-specific document. Paragraph 24 lists the forms permission can take — a signed engagement letter, a signed consent, a fact-find with consent — and adds that "a general authority consenting to disclosure to third parties may also be acceptable".

Many engagement letters already carry an authority like that. If yours does, you may well have the permission you need for a tool you have chosen deliberately, without sending anybody a new form. Check the wording against your professional body's template and your PI insurer's view, but start from the letter you already have rather than from a new consent process.

What the Board recommends

Here the language changes from must to should, and it is worth noticing the change.

The guidance recommends telling clients four things: to whom their information is disclosed, where, where it is stored, and whether AI is used. Recommended, not required — but it is the easiest part of the document to satisfy, and the hardest to satisfy honestly if you do not know the answers yourself.

That is the practical test for any tool you use on client work. If the vendor cannot tell you, in a sentence, which providers process your clients' documents and in which countries, you cannot tell your client either.

The part most firms have missed

Paragraph 16 is the one worth reading twice.

It says you should verify and review AI-generated content for accuracy throughout each step of the workflow, have a process to understand and contest what the AI decided — and that each of those steps should be documented, to support the Code's requirements on record-keeping and on having a documented system of quality management.

Read that slowly. It is not enough to have checked the AI's work. The guidance expects the checking to be evidenced: what the tool produced, what you looked at, what you changed, and who signed it off.

This is where most current practice falls short, and not because anyone is being careless. The checking happens — in someone's head, in a pencilled tick on a printout, in a chat window that gets closed at the end of the day. Almost none of it leaves a record anybody could produce eighteen months later. A chat transcript shows the question and the answer; it doesn't show the review.

A stack of working papers with coloured sign-off initials in the corner of each sheet, a stamp pad and pen beside them.
The review was always done. The guidance asks for it to be visible afterwards.

What it doesn't cover

Offshoring. The AI guidance does not deal with sending work to a preparer overseas; it points you to a different, older document for that — TPB(GS) 31/2018 on outsourcing and offshoring, which some will know as TPB(PN) 2/2018. The two get confused constantly, and if someone cites the AI guidance at you on an offshoring question they have the wrong one. Our FAQ keeps both, linked to the source.

Tax file numbers, except to point elsewhere. Paragraph 26 notes that where client information includes TFNs, the separate obligations under the Privacy (Tax File Number) Rule apply as well. The guidance does not restate them. It just reminds you they come along for the ride — which, given how many client documents have a TFN somewhere in them, is most of them.

Four things to do before next season

  1. List the AI tools used on client work in your practice. Ask the team, not just yourself. The answer is usually longer than the principal expects, and every item on it is a disclosure question.
  2. Read your engagement letter for a general authority to disclose to third parties. If it is there, note which tools you are relying on it for. If it is not, add it before the next batch of letters goes out.
  3. Get a one-sentence answer from each vendor: which providers see your clients' documents, and in which countries. The guidance puts the due diligence on you — reviewing a tool to be satisfied the information stays secure and the Privacy Act is met — and this answer is also what you would tell a client who asks.
  4. Decide what your record of review looks like. Whatever the tool, somebody should be able to see afterwards what it produced and what a person did with it. If today that record is a memory, that is the gap paragraph 16 is about.

We wrote separately about the specific case of using ChatGPT on client files, which is where most firms meet these questions first.

A small practice office after hours, a whiteboard with a short numbered list on it, the handwriting out of focus, a desk lamp on.
Four items. None of them needs a consultant.

Where we sit in this

We build AI software for tax practices, so read this section with that in mind.

The two parts of the guidance we could do something about, we built around. Every provider that processes a client's documents is named, with its country, in our privacy policy, so the recommended disclosure is a sentence you can copy. And the record paragraph 16 asks for is kept as the work happens — every point the AI raised, what you did with each one, who changed what and when, and every version of the working paper — rather than being something you assemble afterwards.

The permission is still yours to get, and the review is still yours to do. The guidance is right about both.