AI & Emerging Tech

Generative AI Acceptable Use Policy

Sets rules for using generative AI tools at your firm: approved tools, prohibited uses, client-data protection, and mandatory human review.

FTC Safeguards Rule

Template last reviewed July 2026

Format
Word & PDF
Read
~4 min
Sections
11
Maps to
FTC Safeguards Rule
Reviewed
Jul 2026
License
CC BY 4.0

What this policy does

The Generative AI Acceptable Use Policy gives your accounting or tax firm a clear, defensible framework for how staff may use tools like ChatGPT, Copilot, and Gemini in client work. Its intention is to capture the productivity of generative AI without exposing you to the single biggest risk these tools create: client data confidentiality. When a preparer pastes a client's return, trial balance, SSN, or engagement details into a public LLM, that content can be retained, logged, or used to train future models under the vendor's consumer terms, which is a breach of your professional duty of confidentiality and, potentially, of state and federal safeguards for taxpayer information. This policy solves that by defining which tools are approved, what data may never be entered, when AI output must be human-reviewed, and how AI involvement is documented, so partners can prove reasonable care. It turns an ungoverned, shadow-IT habit into an auditable, firm-approved AI workflow.

Who this is for

This policy is for any accounting, tax, or financial-services firm whose staff use ChatGPT, Copilot, Gemini, or similar generative AI tools in daily work. It matters because these tools can leak confidential client data, produce confident-sounding errors, and create professional-liability exposure if used without clear guardrails. Adopting a written policy shows clients, regulators, and staff that the firm manages AI risk deliberately.

Preview

The full template. Highlighted blanks fill in when you Personalize; whatever's left stays a [bracket] for you to complete.

Purpose

Generative AI tools can help [Short Name] draft communications, summarize documents, research issues, and work more efficiently. They also create real risks: confidential client information can be exposed, outputs can be inaccurate, and misuse can violate professional and regulatory obligations. This policy sets clear rules so staff can use these tools productively while protecting our clients and the firm.

Scope

This policy applies to all partners, employees, contractors, and temporary staff of [Organization Name] who use any generative AI tool for firm work. "Generative AI" means any system that produces text, code, images, audio, or analysis from prompts — including chatbots, writing assistants, and AI features built into other software. It applies whether the tool is accessed on firm devices, personal devices, or through another application.

Approved Tools

Staff may only use generative AI tools that the firm has reviewed and approved. Currently approved tools are: [Approved AI Tools].

  • Do not use unapproved consumer AI tools for firm work, even free ones you already have accounts on.
  • Before using a new AI tool, or a new AI feature inside existing software, get written approval from [AI Tool Approval Contact].
  • Prefer firm-licensed or enterprise versions that contractually agree not to train on our data and offer appropriate security controls.

Protecting Client and Firm Information

This is the most important rule in this policy. Never enter confidential client information or sensitive firm data into a public or unapproved AI tool. Content submitted to consumer AI services may be stored, reviewed by the vendor's staff, or used to train future models — placing it outside our control.

Do not paste or upload the following into any AI tool unless it is a firm-approved tool with a signed data-protection agreement:

  • Client names tied to financial details, Social Security numbers, EINs, or account numbers
  • Tax returns, working papers, financial statements, or source documents
  • Any personally identifiable information (PII) or nonpublic personal information
  • Passwords, credentials, or firm-internal confidential materials

When in doubt, treat information as confidential and leave it out. If you need AI help with client-specific work, de-identify the material first or use only an approved tool cleared for that data.

Prohibited Uses

Generative AI must not be used to:

  • Make final professional judgments — such as signing positions, audit conclusions, or advice — without qualified human review.
  • Generate work you present as your own analysis without verifying it.
  • Create misleading, deceptive, or fabricated content, including fake citations or authorities.
  • Circumvent confidentiality, security, or licensing obligations.
  • Produce content that is discriminatory, harassing, or otherwise violates firm conduct standards.

Human Review and Accuracy

Generative AI can produce fluent output that is wrong, outdated, or invented. The staff member using the tool is fully responsible for the accuracy and quality of any work product, regardless of AI involvement.

  • Independently verify all facts, calculations, citations, and tax or accounting positions before relying on them.
  • Treat AI output as a first draft or research aid, never as an authoritative answer.
  • Apply the same professional standards, due care, and skepticism you would to your own work.

Disclosure

Be transparent about material AI use consistent with our professional obligations and client expectations. [Client Disclosure Standard] When a client asks whether AI was used in their work, answer honestly.

Roles and Responsibilities

  • [Policy Owner] ([Owner's Title]) owns this policy, maintains the approved-tools list, and answers questions.
  • Supervisors ensure their teams follow this policy and review AI-assisted work product.
  • All staff protect client data, verify AI output, and use only approved tools.

Direct questions to [Policy Owner] at [Contact Email].

Employee Acknowledgment

By using generative AI tools for firm work, staff acknowledge they have read, understood, and agree to follow this policy. A signed acknowledgment may be required as a condition of access.

Enforcement

Violations may result in loss of AI tool access and disciplinary action up to and including termination. Exposing client data may also trigger breach-response and regulatory obligations.

Review and Revision

Given how fast AI technology changes, [Policy Owner] will review this policy at least annually, and sooner if tools or regulations change. This policy is effective [Effective Date] and is scheduled for review by [Firm's Next Review Date]. This template is a starting point; adapt it to your firm's tools, clients, and legal requirements.

✏️ Make it yours. Fill in your firm's details and download a ready-to-edit copy — or skip it and complete the [bracketed] blanks yourself.
🤖 Refine it with AI. Open this template as a starting prompt in your assistant — it'll ask about your firm and tailor a draft. Don't paste real client data.
ChatGPT Claude Gemini Copilot

How to use this template

  1. Read the whole template first so you understand what it commits your firm to.
  2. Fill in your firm's details — use the Personalize panel or edit the [bracketed] blanks in the downloaded file.
  3. Adapt the substance to how your firm actually operates. A policy you don't follow is worse than none.
  4. Add anything specific to your jurisdiction, industry, clients, or systems (see “What you'll likely want to add” below).
  5. Have it reviewed by qualified legal counsel and/or a compliance professional before you adopt it.
  6. Approve it, share it with everyone it covers, and collect signed acknowledgments where appropriate.
  7. Set a review date and revisit it at least annually or when laws, systems, or your operations change.

Not sure how to roll a policy out or train your team on it? See the free policy implementation & training guide.

For this policy specifically

  • List the specific AI tools you approve and note whether each is on a business/enterprise tier that contractually excludes training on your inputs, versus a free/consumer tier that does not.
  • Define a hard 'never paste' list: client names, SSNs/EINs, financial statements, return data, and any PII that could enter a public model.
  • Require human review and sign-off on any AI-generated calculation, tax position, or client-facing deliverable before it leaves the firm.

What you'll likely want to add or customize

These templates are written to be general and jurisdiction-neutral. They do not contain requirements specific to your state (for example California or Tennessee), to other countries (for example the UK/EU GDPR or Canada's PIPEDA), or to your particular profession, licenses, or contracts. Those obligations are real and vary widely — you and your counsel must add them. Treat this as a strong starting skeleton, not a complete, compliant policy.

Specific to this policy

  • Publish your firm's approved-tool roster by name and tier, and name a partner or IT lead who must vet any new AI tool before use.
  • Add a client-disclosure stance: decide whether engagement letters will disclose AI use, and align the wording with your state board and any client contract terms that restrict subcontractors or automated processing.
  • Map the policy to emerging state AI and automated-decision rules plus IRS Pub 4557 / GLBA safeguards for taxpayer data, and cite AICPA confidentiality guidance your staff must follow.
  • For non-US or multinational clients, add a data-transfer clause addressing GDPR/PIPEDA concerns about routing personal data through AI vendors hosted in other jurisdictions.
  • Define data-classification tiers (public, internal, confidential, client-restricted) and specify which tiers may ever touch an AI tool.
  • Set a review cadence (e.g., quarterly) to re-check vendor training/retention terms, since consumer AI privacy settings change frequently.

For almost any firm policy

  • State/provincial and national law that applies to you — data-breach notification, privacy, employment, and records rules differ by jurisdiction.
  • Your actual tools and systems by name (the practice-management, email, storage, and security software you really use).
  • The real people or roles who own each responsibility at your firm.
  • Client-contract or engagement-letter commitments you've already made.
  • How this policy fits your other policies, your employee handbook, and any professional-body or licensing requirements you're subject to.

Earn CPE on this topic

A template is the paperwork — these live and on-demand courses teach the skills behind it, for real credit.

✏️ Personalize your copy

Fill in what you know — leave the rest blank and it stays a [bracketed] fill-in you complete in the document. Nothing you type here is stored: it's merged into your download and forgotten.

⬇ Get this template

Upcoming dates

Loading…