Can Accounting Firms Use ChatGPT on Client Data?
The short answer: not on the public version of ChatGPT, and not safely on most paid versions either. Entering client-identifiable information into ChatGPT transmits it to a third party, which can breach the AICPA confidentiality rule and, for tax return information, IRC Section 7216. Enterprise versions reduce the risk contractually but still process your plaintext. Firms that want AI on client data need an approach where the model never sees it.
That is the two-paragraph version. The rest of this page covers what the rules actually say, what the enterprise tiers do and do not change, and what firms do instead.
What happens when you paste client data into ChatGPT
When a staff member pastes a client's trial balance or return information into ChatGPT, that data leaves the firm and is processed on the provider's systems. Depending on account settings, it may be retained, reviewed for abuse monitoring, or used to improve models. From a confidentiality standpoint, the transmission itself is the event that matters, not what happens afterward.
Two obligations are in play for accounting firms:
The AICPA Code of Professional Conduct (the confidential client information rule) requires member CPAs not to disclose confidential client information without consent. Sending client data to an AI provider's servers is a disclosure to a third party.
IRC Section 7216 goes further for tax practitioners: it imposes criminal penalties for knowingly or recklessly disclosing or using tax return information without consent. Return data pasted into a consumer AI tool is exactly the kind of disclosure the statute contemplates.
This is not a hypothetical enforcement theory. In 2026, a US bank filed the first SEC disclosure blaming a data incident on an employee who used an unauthorized AI application with customer data. The employee was not malicious. They were working faster. Every firm has the same exposure during busy season.
Does ChatGPT Enterprise or Teams fix this?
Partially, and the partial matters. Enterprise tiers offer contractual commitments: no training on your data, SOC 2 reports, admin controls, shorter retention. Those are real improvements, and for many kinds of business data they are reasonable.
The limit is structural: the model still processes your plaintext. The provider's systems still receive readable client information, and your protection is a contract, not an architecture. For data governed by professional confidentiality obligations, a promise not to look is categorically different from an inability to look. That distinction is why many firms' risk committees approve enterprise AI for internal drafting and research but continue to prohibit client-identifiable data.
What accounting firms do instead
Firms take one of three paths:
Prohibit and hope. A policy bans client data in AI tools. The industry data on this is unkind: a 2026 PagerDuty study found 88% of office workers have shared work information with public AI systems. Prohibition without an alternative mostly moves the behavior into the shadows.
Build a private environment. The Big Four route: KPMG committed over $2 billion to AI, and each of the largest firms built internal AI environments. Effective, and priced for the largest firms only.
Use confidential AI. An architecture where the model receives the question and the structure of the data, never the underlying values. The analysis runs on encrypted data under the firm's control, and only the decrypted result reaches the user's screen. The firm gets frontier-model analysis, flux analysis, budget vs. actuals, benchmarking, tax planning scenarios, and the client data is never disclosed to anyone, because it never becomes readable outside the firm.
We built Nera ChatApp on the third model. The LLM gets the query. It never gets the data. For the full breakdown of which accounting tasks are safe for public AI and which are not, see our guide: How Accounting Firms Can Use AI on Client Data Without Exposing It. For the architecture itself, see Why We Built Nera ChatApp to Never See Your Data.
Rami Akeela, Ph.D., is the founder and CEO of Nera Systems. He has spent more than 20 years in hardware, security, and cryptography. Nera lets regulated enterprises run AI on their most sensitive data without that data ever leaving their control.