On August 10, 2026, a new IRS policy took effect governing how the agency itself is allowed to use artificial intelligence — not how any taxpayer's return gets handled. Internal Revenue Manual section 10.24.1 puts a named official, the Chief Data and Analytics Officer serving as Responsible AI Official, in charge of every AI system the agency runs, and requires a documented, per-use-case decision about how much oversight that system needs before it goes live.
Nothing in IRM 10.24.1 regulates tax preparers, CPA firms, or the software they buy. But the discipline it imposes on the IRS is the same discipline every firm now quietly needs for the AI tools sitting inside its own tax review process, and most firms have none of it written down.
What the policy actually requires
IRM 10.24.1 turns AI governance into paperwork: a named official on record for every system, a documented risk call on every use case, and nothing skipped without a written waiver. Here's what that breaks down into:
Accountability
A named accountable official owns AI risk for each system — not a team, not a title.
Risk determination
Every AI use case gets a determination on the record: is this high-impact, and by what test.
Impact assessment
High-impact, rights-or-safety-touching systems require a completed Privacy and Civil Liberties Impact Assessment before they go live.
Waiver process
Skipping a minimum risk-management practice requires a written waiver approved by Treasury's Chief AI Officer — not a local judgment call.
Compliance on demand
AI project teams must be able to show compliance with the policy and its "acceptable use agreements" on request, not just assert it.
IRM 10.24.1 governs the IRS's own systems only. It creates no new obligation for tax practitioners or the software they use. The point of comparison is the discipline it models, not a rule that reaches outside the agency.
The duty CPA firms are already under
Circular 230 — the Treasury regulations governing everyone who practices before the IRS — already has a rule that reaches AI-assisted tax work without ever using the word "AI." Section 10.22, diligence as to accuracy, requires a practitioner to exercise due diligence in preparing, reviewing and signing off on returns and other IRS submissions. Critically, the regulation also addresses what happens when a practitioner relies on someone else's output:
A practitioner will be presumed to have exercised due diligence for purposes of this section if the practitioner relies on the work product of another person and the practitioner used reasonable care in engaging, supervising, training, and evaluating the person.
31 CFR § 10.22, Diligence as to accuracy
That text was written for delegating work to a junior preparer or an outside specialist, not for a large language model — the word "AI" appears nowhere in it. But the logic is not written to exclude AI-generated output, either. It sets a standard for relying on "work product" produced by something other than the reviewing practitioner, and requires "reasonable care in engaging, supervising, training, and evaluating" whatever produced it. A firm treating an AI tool's draft the way it would treat an unreviewed first-year's draft — read it in full, verify the calculations and citations, don't sign off on the strength of a summary — is applying the standard the regulation already sets. A firm that skips that step because the draft came from software rather than a person is not exempt from § 10.22; it just has not noticed that the rule still applies. The Office of Professional Responsibility enforces Circular 230 for every attorney, CPA, enrolled agent, and other practitioner who represents a taxpayer before the IRS, with sanctions running from censure to disbarment from practice.
See where this discipline lands in your own review process
IRM 10.24.1 and Circular 230 both point back to the same place: how a firm's tax return review actually works. Pernee's guide covers the five-check review model, the multi-tier process, and the obligations that make review effectively mandatory.
Confidentiality doesn't pause for a new tool, either
The same is true of IRC § 7216, the statute that makes it a crime for a tax return preparer to knowingly or recklessly disclose or use a client's tax return information for anything other than preparing that return, without the client's consent. Feeding a client's return data into a general-purpose AI tool — one whose terms of service permit the vendor to log, review, or train on submitted content — is a disclosure and a use under § 7216 the same way faxing the file to an uninvolved third party would be. The statute does not carve out an exception for "the recipient was software." A companion provision, § 6713, backs it with a $250 civil penalty per unauthorized disclosure or use, capped at $10,000 per preparer per year — the kind of number that sounds survivable until it is multiplied by every return an ungoverned tool touched in a season.
$10,000
The IRC §§ 6713/7216 penalty cap per preparer, per year — reached in as few as 40 mishandled returns at $250 each
The governance gap most firms actually have
Set the two side by side and the gap is not in the law. It is in the paper trail. The IRS, as of August 10, cannot deploy an AI system without a named official on record for it, a documented determination of its risk tier, and — for the systems that matter most — a completed impact assessment and, for any shortcut, a written waiver from Treasury. Ask a mid-size CPA firm the equivalent questions about the AI copilot its review staff has been using since tax season — who approved it for this purpose, what determination was made about the risk of relying on its output, where the record is that a partner signed off on that determination — and the honest answer at most firms is that no such record exists. The AI tool was adopted the way software usually is: someone tried it, it seemed to help, and it stayed.
That gap is invisible until someone asks for the record — a state board investigating a complaint, a malpractice carrier assessing a claim, a managing partner doing exactly the kind of internal review Circular 230's § 10.36 already requires of firm supervisory procedures. At that point, "we used reasonable care" has to be something a firm can show, not just say. The IRS's new policy is a useful preview of what that showing looks like in writing: a named owner, a determination on the record, and evidence that the review actually happened — not a memory of it.
That's the audit trail Pernee keeps for the review desk. Every AI-assisted conclusion — the return line it touched, the reviewer who checked it, and the reasoning behind the sign-off — stays attached to that line inside the systems a firm already runs, rather than living in a chat log or a memory that leaves with the reviewer. It is the same discipline the IRS just wrote into its own policy, applied one review at a time instead of one agency system at a time.
Give your firm's AI use the same paper trail the IRS just wrote for itself
See how Pernee attaches every AI-assisted review conclusion to the return line, reviewer and reasoning behind it.



