Introduction
Artificial intelligence is quickly becoming part of everyday accounting and tax workflows. From document processing and tax research to drafting, data analysis and automated recommendations, AI can save practitioner’s significant time. But for Australian tax practitioners, using AI also raises an important question: what does the TPB actually expect you to do when AI becomes part of client work?
NCSGX Australia supports accounting and tax practices with outsourced finance and operational support, helping firms build structured processes while keeping professional judgement and accountability with the appropriate practitioner.
The Tax Practitioners Board’s TPB(GS) 55/2026 – The use of Artificial Intelligence and the Code of Professional Conduct provides the answer. The final guidance explains how existing obligations under the Tax Agent Services Act 2009 and the Code of Professional Conduct apply when registered tax agents and BAS agents use AI in providing tax agent services.
The important point is that this is not a new standalone AI compliance regime. Instead, the TPB explains how existing professional obligations apply to modern AI tools and workflows.
What TPB(GS) 55/2026 is and who it applies to
TPB(GS) 55/2026 is guidance issued by the Tax Practitioners Board on the use of artificial intelligence and the Code of Professional Conduct.
It applies to registered tax agents and BAS agents when they use AI in providing tax agent services.
The guidance covers more than standalone generative AI platforms. AI functionality can also be built into accounting, tax, document management, and other software used by a practice.
That distinction matters because a firm may already be using AI without having formally adopted an “AI tool.”
The guidance should therefore be read alongside the Tax Agent Services Act 2009, which establishes the legislative framework governing registered tax practitioners.
The rule everything else hangs off
The simplest way to understand the TPB’s position is this:
AI can assist the practitioner, but it does not replace the practitioner’s responsibility.
If AI produces an incorrect tax interpretation, calculation, document or recommendation, the responsibility does not move to the software provider.
The practitioner remains responsible for the tax agent services they provide.
That means AI-generated information needs to be appropriately reviewed, verified and supplemented with professional judgement before it is relied upon.
For practices, this creates a simple principle:
Use AI to support professional judgement, not to outsource professional responsibility.
What the guidance requires, obligation by obligation
- Review AI-generated information
AI systems can generate incorrect, incomplete or misleading information. This is particularly relevant with generative AI, where confident-sounding answers may still be wrong.
Practitioners should therefore have processes for reviewing and verifying AI outputs before relying on them.
For example, if AI assists with tax research, a practitioner should still verify the relevant legislation, ruling or authoritative source.
If AI drafts a client communication, someone appropriately qualified should review the content before it is sent.
The higher the risk of the work, the more important appropriate human review becomes.
- Keep appropriate records
AI does not remove existing record-keeping responsibilities.
Where AI has materially contributed to client work, practices should consider how their records demonstrate the work undertaken, the review performed and the professional judgement applied.
Depending on the nature of the engagement, this may include documenting:
- How AI was used
- What information was provided to the system
- What output was generated
- What was independently checked
- What changes were made
- Who reviewed the final result
- Why the final position was considered appropriate
There is no single TPB-prescribed “AI record” that every practice must maintain. The records should instead be appropriate to the service and the associated risk.
- Protect client confidentiality
This is one of the most important issues for tax practices.
Under Code item 6, practitioners must not disclose information relating to a client’s affairs to a third party without the client’s permission, unless disclosure is otherwise permitted or required.
An AI provider may be considered a third party depending on how the AI product operates and what information is shared with the provider.
That means entering client information into an AI system cannot automatically be treated as an internal activity.
Practitioners need to understand who receives the information and why.
- Obtain client permission where required
If using an AI system involves disclosing information relating to a client’s affairs to a third party, the practitioner may need the client’s permission.
The TPB indicates that permission can be obtained through appropriate documentation such as an engagement letter, signed consent or another suitable communication.
This raises an important question for practices:
Does your existing engagement documentation actually explain how client information may be used with AI?
A generic confidentiality clause should not automatically be assumed to cover every AI-related disclosure.
Practices should review their existing documentation against the way their AI tools actually operate.
- Conduct appropriate AI vendor due diligence
Practitioners should understand the AI tools they use rather than relying solely on a provider’s marketing claims.
Vendor due diligence should consider matters such as:
- What information the tool receives
- Where information is stored and processed
- Whether data is used for model training
- Who can access the information
- Data retention periods
- Security controls
- Privacy arrangements
- Whether information is transferred overseas
- The tool’s limitations and accuracy
- How access can be controlled or removed
The OAIC’s guidance on commercially available AI products similarly recommends due diligence when selecting AI products, including assessing privacy and security risks, human oversight and who can access personal information.
The part most firms miss: AI already switched on in your software
You may think your practice does not use AI because nobody has introduced ChatGPT or another generative AI platform.
But AI may already be operating inside the software your team uses.
Examples include:
- Automated document processing
- Transaction classification
- Data extraction
- Anomaly detection
- Research assistants
- Automated summaries
- AI-generated correspondence
- Predictive recommendations
- Intelligent workflow automation
This is why an AI review should start with a technology and software inventory.
Ask your vendors:
“Does this product use artificial intelligence or machine learning to process, analyse, generate or recommend information?”
If the answer is yes, the next question should be:
“What happens to client information when that functionality is used?”
Where your client data actually goes
This is where AI governance becomes a practical issue rather than a policy exercise.
Before entering client information into an AI system, a practice should understand the complete data flow.
Consider:
- Where is the information processed?
- Where is it stored?
- Is it transferred outside Australia?
- Is it retained after the task is completed?
- Is it used to train or improve the provider’s models?
- Can the provider’s staff access it?
- Can other third parties receive it?
- Can the information be deleted?
The OAIC warns that privacy obligations apply to personal information entered into AI systems and recommends a cautious, risk-based approach. It also recommends that organisations do not enter personal or particularly sensitive information into publicly available generative AI tools as a matter of best practice.
For tax practices, that should be a significant warning against simply copying client information into a public AI chatbot.
How to vet an AI tool or a service provider
AI vendor due diligence should become part of your practice’s normal risk-management process.
Before approving a tool, ask:
Data
What client information will the tool receive?
Security
What controls protect that information?
Privacy
How does the provider address applicable privacy requirements?
Training
Will information submitted by your practice be used to train or improve an AI model?
Access
Who can access the information?
Retention
How long is information retained?
Location
Where is information stored and processed?
Accuracy
What are the known limitations of the system?
Human oversight
Where does practitioner review remain necessary?
Contractual protection
Do the provider’s terms address confidentiality, security, data use and data ownership appropriately?
The OAIC specifically recommends that due diligence should not be treated as a “set and forget” exercise. AI products should be monitored and reviewed throughout their lifecycle.
What changed between the March draft and the final guidance
The March 2026 exposure draft established the central position that AI use must be consistent with existing professional obligations.
The final guidance provides greater clarity around how those obligations apply in practice.
One important point is the recognition that AI is not limited to standalone tools. AI functionality embedded in existing software and platforms can also fall within the scope of the guidance.
The final guidance also provides clearer practical direction around reviewing AI-generated information, documenting verification and conducting due diligence on AI tools.
The fundamental position has not changed:
The practitioner remains accountable for the tax agent services provided, even when AI is involved.
A practical checklist for your practice
Before using AI on client-related work, ask:
- Have we identified all AI tools and AI-enabled features already used in our practice?
- Do we know what client information each system processes?
- Do we know where that information goes?
- Have we reviewed the provider’s privacy and security arrangements?
- Have we considered whether client permission is required?
- Does our engagement documentation adequately address relevant AI use?
- Have we established approved and prohibited AI use cases?
- Is human review required before AI output is relied upon?
- Are important review and verification steps documented?
- Have staff been trained on acceptable AI use?
- Are AI tools included in our ongoing risk and quality-management reviews?
If you cannot confidently answer these questions, your practice may be using AI without having adequate controls around it.
What happens if you get it wrong?
The biggest risk is not simply an AI-generated mistake.
Poorly controlled AI use can create several risks simultaneously:
- Incorrect tax information
- Inappropriate disclosure of client information
- Privacy breaches
- Inadequate client consent
- Weak documentation
- Insufficient professional review
- Poor vendor oversight
- Failure to meet existing professional obligations
The TPB’s position is clear: using AI does not transfer responsibility from the practitioner to the technology provider.
That means practices should focus less on asking “Can we use AI?” and more on asking “How can we use AI within a controlled professional process?”
How NCSGX Australia can help
For accounting and tax practices, implementing the right controls is only one part of managing an increasingly technology-driven workflow.
NCSGX Australia provides outsourced accounting and tax support that can help practices manage structured back-office processes while qualified practitioners retain responsibility for professional decisions, review and client relationships.
This can be particularly useful for firms looking to increase capacity without compromising process consistency, documentation or workflow controls.
Conclusion
TPB(GS) 55/2026 does not prohibit tax practitioners from using AI. Nor does it create a completely separate set of AI-specific professional obligations.
Instead, it makes an existing principle much harder to ignore:
Technology can change how tax work is performed, but it does not change who is responsible for the work.
Practices should therefore identify where AI is already being used, understand where client data goes, review their vendor arrangements, establish appropriate client permission processes and ensure AI-generated work receives appropriate human review.
If your practice is reviewing its workflows, outsourcing requirements or operational processes, speak with our team to explore how NCSGX Australia can support your practice.
Frequently Asked Questions (FAQ)
1. Does the TPB require me to tell clients I use AI?
Not automatically in every situation.
The important question is whether using the AI involves disclosure of information relating to the client’s affairs to a third party. Where that occurs, the practitioner needs to consider the requirements of Code item 6 and whether client permission is required.
Practices should also consider transparency and whether their existing privacy and engagement documentation clearly explains relevant AI use.
2. Does a standard engagement letter cover AI use?
It may, depending on its wording and the way the practice uses AI.
The key issue is whether the engagement documentation appropriately addresses the relevant disclosure and provides sufficient information for the client to understand how their information may be handled.
A practice should not assume that a generic confidentiality or technology clause automatically covers every AI-related scenario.
3. Does this apply to BAS agents?
Yes.
TPB(GS) 55/2026 applies to registered tax agents and BAS agents when they use AI in providing tax agent services.
The relevant obligations depend on the nature of the service and how the AI system is being used.
4. How do I check whether an AI tool or provider meets the TPB's expectations?
Start with due diligence.
Understand the tool’s data flows, security arrangements, privacy controls, retention policies, access arrangements, training practices and limitations.
You should also establish how human review will work and whether client permission is required.
The OAIC’s guidance provides a useful framework for assessing privacy and data-handling risks when selecting commercially available AI products.
5. Does TPB(GS) 55/2026 create new obligations for tax practitioners?
The guidance itself does not create a new standalone set of legal obligations.
Instead, it explains how existing obligations under the Tax Agent Services Act 2009 and the Code of Professional Conduct apply when practitioners use AI.
This distinction is important. The guidance changes how practitioners should think about their existing responsibilities in an AI-enabled environment rather than replacing those responsibilities with an entirely new framework.
6. What records do I need to keep when I use AI on client work?
There is no single AI-specific record template that applies to every practice.
However, existing record-keeping obligations still apply. Where AI is used materially in client work, practices should maintain appropriate evidence of the work performed, review undertaken and professional judgement applied.
For higher-risk work, it may be appropriate to record the AI tool used, the purpose of its use, the relevant output, the practitioner’s verification and any material changes made before the final work was delivered.

