← Back to all posts

Can Accounting Firms Use ChatGPT on Client Data?

By Rami Akeela, Ph.D., Founder and CEO, Nera Systems

The short answer: not on the public version of ChatGPT, and not safely on most paid versions either. Entering client-identifiable information into ChatGPT transmits it to a third party, which can breach the AICPA confidentiality rule and, for tax return information, IRC Section 7216. Enterprise versions reduce the risk contractually but still process your plaintext. Firms that want AI on client data need an approach where the model never sees it.

That is the two-paragraph version. The rest of this page covers what the rules actually say, what the enterprise tiers do and do not change, and what firms do instead.

What happens when you paste client data into ChatGPT

When a staff member pastes a client's trial balance or return information into ChatGPT, that data leaves the firm and is processed on the provider's systems. Depending on account settings, it may be retained, reviewed for abuse monitoring, or used to improve models. From a confidentiality standpoint, the transmission itself is the event that matters, not what happens afterward.

Two obligations are in play for accounting firms:

The AICPA Code of Professional Conduct (the confidential client information rule) requires member CPAs not to disclose confidential client information without consent. Sending client data to an AI provider's servers is a disclosure to a third party.

IRC Section 7216 goes further for tax practitioners: it imposes criminal penalties for knowingly or recklessly disclosing or using tax return information without consent. Return data pasted into a consumer AI tool is exactly the kind of disclosure the statute contemplates.

This is not a hypothetical enforcement theory. In 2026, a US bank filed the first SEC disclosure blaming a data incident on an employee who used an unauthorized AI application with customer data. The employee was not malicious. They were working faster. Every firm has the same exposure during busy season.

Does ChatGPT Enterprise or Teams fix this?

Partially, and the partial matters. Enterprise tiers offer contractual commitments: no training on your data, SOC 2 reports, admin controls, shorter retention. Those are real improvements, and for many kinds of business data they are reasonable.

The limit is structural: the model still processes your plaintext. The provider's systems still receive readable client information, and your protection is a contract, not an architecture. For data governed by professional confidentiality obligations, a promise not to look is categorically different from an inability to look. That distinction is why many firms' risk committees approve enterprise AI for internal drafting and research but continue to prohibit client-identifiable data.

What accounting firms do instead

Firms take one of three paths:

Prohibit and hope. A policy bans client data in AI tools. The industry data on this is unkind: a 2026 PagerDuty study found 88% of office workers have shared work information with public AI systems. Prohibition without an alternative mostly moves the behavior into the shadows.

Build a private environment. The Big Four route: KPMG committed over $2 billion to AI, and each of the largest firms built internal AI environments. Effective, and priced for the largest firms only.

Use confidential AI. An architecture where the model receives the question and the structure of the data, never the underlying values. The analysis runs on encrypted data under the firm's control, and only the decrypted result reaches the user's screen. The firm gets frontier-model analysis, flux analysis, budget vs. actuals, benchmarking, tax planning scenarios, and the client data is never disclosed to anyone, because it never becomes readable outside the firm.

We built Nera ChatApp on the third model. The LLM gets the query. It never gets the data. For the full breakdown of which accounting tasks are safe for public AI and which are not, see our guide: How Accounting Firms Can Use AI on Client Data Without Exposing It. For the architecture itself, see Why We Built Nera ChatApp to Never See Your Data.


Rami Akeela, Ph.D., is the founder and CEO of Nera Systems. He has spent more than 20 years in hardware, security, and cryptography. Nera lets regulated enterprises run AI on their most sensitive data without that data ever leaving their control.

Frequently asked questions

Can I use ChatGPT for accounting work that doesn't involve client data?
Yes. Research, drafting templates, summarizing published standards, and marketing content involve no client-identifiable information and are generally safe on any tier.
Is it a 7216 violation if I remove the client's name first?
Redaction helps but is not a safe harbor. Tax return information is defined broadly, and combinations of figures, dates, and circumstances can remain identifying. Redaction also breaks the analysis: a model cannot compute usefully on data with the meaningful values removed.
Does using ChatGPT Enterprise satisfy AICPA confidentiality requirements?
It reduces risk but does not eliminate the third-party disclosure question, because the provider still processes readable client data under a contractual promise. Many firms restrict even enterprise tiers to non-client data.
What about Claude or Gemini instead of ChatGPT?
The same analysis applies to any hosted model that receives your plaintext, regardless of provider. The question is never which model; it is what the model can see.
How do firms run AI on client data safely?
By using an architecture where the data is encrypted before anything leaves the firm and the model only ever receives the question and the data's structure. See the full guide at nera.systems/blogs/How_Accounting_Firms_Can_Use_AI_on_Client_Data_Without_Exposing_It, or try it on a real file at chatapp.nera.systems.