The TPB Has Finally Said How AI Fits the Code — and the Riskiest AI Is the One You Never Chose to Use
The TPB Has Finally Said How AI Fits the Code — and the Riskiest AI Is the One You Never Chose to Use
Australia's first specific guidance on AI and tax practitioner obligations landed on 22 July. The obligations are clear. The blind spot is the AI already running inside the software you use every day.
On 22 July 2026 the Tax Practitioners Board published TPB(GS) 55/2026 — The use of Artificial Intelligence and the Code of Professional Conduct. It's the first Australia-specific guidance on how AI use interacts with the obligations registered tax and BAS agents carry under the Tax Agent Services Act 2009. It followed an exposure draft released on 24 March, with submissions closing 21 April.
If you're not a registered agent, don't stop reading. Most of what follows is a professional-standards articulation of things every finance function should already be doing, and the regulator has now written them down in a way you can lift straight into your own controls. And if your organisation engages a tax agent — which is most of them — this is the standard your adviser is now measured against.
The Core Principle: AI Doesn't Move Responsibility
The guidance's central proposition is simple enough to fit in a sentence: using AI does not reduce or transfer a practitioner's professional responsibilities. You remain fully accountable for the accuracy and quality of what you produce, regardless of what generated the first draft.
From there it works through how the existing Code obligations apply. Competence — AI output is not a substitute for your own analysis of a client's circumstances, and professional judgement still has to be exercised. Reasonable care — whether you took it depends on the circumstances, including whether you reviewed the output before relying on it and whether you used AI for something that should have been independently verified. Confidentiality — under Code Item 6, permission is required before disclosing information about a client's affairs to a third party, and putting client data into an AI tool is a disclosure to a third party. Supervision and control — outputs must be assessed and supplemented by professional judgement. Honesty and integrity — AI-generated content in advice or correspondence must be accurate and must not mislead a client or the ATO. The guidance also flags that the Australian Privacy Principles govern the use, storage and disclosure of personal information, which feeds back into the consent question.
The TPB has been explicit that this is not a technical guide to AI systems, and that the guidance will be updated as the technology develops. It is a statement of standards, not a product review.
|
Zero
Professional obligations that transfer to an AI vendor when you use its tool. Accountability for accuracy and quality stays where it always was.
|
Code Item 6
The confidentiality obligation doing most of the work here: client permission is needed before information about their affairs goes to a third party — including an AI tool.
|
The Gap: AI You Didn't Decide to Use
The most useful thing said about this guidance came from a critic. In its submission on the exposure draft, the National Tax and Accountants' Association argued the draft's framing broadly assumed a practitioner actively chooses to enter information into an AI tool — and that this assumption is increasingly wrong.
Its point: AI features are now embedded by default in platforms practices already run on. Xero, MYOB, QuickBooks, Microsoft 365. Xero's assistant JAX analyses revenue and profit performance, tracks cash flow and identifies unpaid invoices — processing client financial data in the background as part of the platform's ordinary operation. Microsoft 365 Copilot spans Outlook, Word, Excel and Teams and does the same thing. As the NTAA put it, the practitioner "has not made a conscious decision to disclose client information to an AI tool, yet the tool has accessed it." For many practices, it argued, this is already the most significant compliance risk they face.
There's a second, very practical problem the association raised. Paragraph 22 of the draft contemplated telling the client, when seeking permission, who the disclosure is made to, where it is made and where the data will be stored. For AI embedded inside a third-party platform, a practitioner often simply cannot obtain that information — which sub-processors are in the chain, where the data sits, how it moves between the platform and its AI partners. That's controlled by the vendor and can change without notice. The NTAA recommended the final guidance accept that naming the relevant software providers, plus a general statement about the firm's approach to AI use and data security, is a proportionate way to meet Code Item 6.
Whether the final statement adopted that position is something you should read for yourself in the guidance rather than take from a blog post — I haven't been able to verify the final wording on this specific point, and I'd rather say so than guess. But the underlying issue doesn't depend on the drafting. If AI is processing your client or participant data because a software vendor switched a feature on, the fact that you didn't choose it doesn't make the data flow disappear.
A Self-Check You Can Run This Week
This is the part worth stealing whether or not you hold a registration. Five questions, answerable in an afternoon.
1. What AI is actually running in our stack? Not "what AI tools have we bought" — what AI features are enabled in the accounting platform, the practice management system, the email client, the document suite, the payroll product. Write the list down. Most finance teams have never made this list, and it is always longer than expected.
2. For each one, what data does it touch, and does the vendor train on it? Get this in writing from the vendor or from their terms, not from a sales conversation. If a vendor won't answer plainly, treat that as an answer.
3. Have we told clients — and do our engagement terms cover it? If your engagement letter or privacy collection notice predates the AI features now running inside your software, it doesn't cover them. Naming the platforms through which client data may be processed is a reasonable, achievable disclosure. Silence isn't.
4. Where is the review step, and who signs? For anything AI touched that leaves the building — a return, a reconciliation, a letter, a set of numbers in a management reporting pack — there needs to be a named human who reviewed it against source records. Not "the team checks it." A name.
5. What does our file show? If a reviewer asked in twelve months how a particular figure was arrived at, would the working papers reveal that AI was involved, what it produced, and what the human changed? Record-keeping is one of the areas the guidance covers, and it's the one most often skipped.
Why This Matters Beyond Registered Agents
NFP, NDIS and SME finance functions aren't bound by the Code. But three things follow anyway.
The first is that a regulator has now published a defensible, Australia-specific standard for AI use in financial work. If your board asks what "good" looks like, you no longer have to invent it — you can point at something and adapt it. That's genuinely useful when you're trying to get an AI policy approved without a six-month drafting exercise.
The second is that your tax agent is now operating under it. Expect updated engagement terms, and expect a permission request that mentions AI. Read it properly rather than signing it as routine, because the scope of what you're consenting to on your organisation's behalf is a decision, not an administrative step.
The third is the embedded-AI problem, which is entirely indifferent to whether you're registered. The last time I wrote about this the framing was shadow AI — staff pasting things they shouldn't into tools the organisation never approved. The embedded version is the same risk without the staff member. Nobody pasted anything. The vendor shipped a feature.
Those two problems have the same fix and it isn't a tool: it's knowing what's running, knowing what it touches, and having a human whose name is on the output.
Do you know what AI is already running in your finance stack?
Building the inventory, the review step and the sign-off trail is unglamorous work that pays for itself the first time someone asks. PFL provides senior-level outsourced finance, management reporting, and AI automation for Australian NFP, NDIS, and SME organisations.
Talk to PFL →Sources
- Tax Practitioners Board — TPB(GS) 55/2026: The use of Artificial Intelligence and the Code of Professional Conduct
- Tax Practitioners Board — TPB(GS) 55/2026 (full guidance statement, PDF)
- Tax Practitioners Board — Exposure draft TPB(I) D62/2026 (24 March 2026)
- Accountants Daily — TPB's AI guidance fails to address 'most significant compliance risk', warns NTAA
- Accountants Daily — TPB publishes finalised guidance on AI for tax practitioners
- Office of the Australian Information Commissioner — Australian Privacy Principles
- Tax Agent Services Act 2009 (Cth)
Tomorrow: the NDIS pipeline that built Australia's allied health boom starts narrowing in October — and the access change behind it isn't law yet.
Comments
Post a Comment