Back to Blog
Compliance & Regulation 10 min read
By Dr. Ash Khalilian ·

TPB AI Guidance 2026, What Tax and BAS Agents Must Actually Disclose

A decision guide to TPB(GS) 55/2026, not a summary. Consent, accountability, and the AI uses that cross the line.

An Australian registered tax agent reviewing a client engagement letter on screen with AI-assisted workpapers alongside, calm modern office, no text in the image
The TPB did not ban AI. It made you accountable for it, and made client permission a precondition rather than a courtesy.

Short Answer

Yes, if client information goes into an AI tool, you need the client's permission first. TPB(GS) 55/2026 treats an AI tool as a third party under Code item 6. Permission can come from a signed letter of engagement, a signed consent, a fact find and consent, or a general third-party authority. You stay accountable for accuracy either way.

Last reviewed: August 2026

Key takeaways

  • The Tax Practitioners Board issued TPB(GS) 55/2026 on 22 July 2026, finalising the exposure draft TPB(I) D62/2026 released on 24 March 2026.
  • Entering client information into an AI tool can be a disclosure to a third party, so Code item 6 requires the client's permission before it happens.
  • The final guidance added a recommendation that practitioners tell clients whether AI tools may be used, wording that did not appear in the March exposure draft.
  • Registered tax agents and BAS agents remain accountable for accuracy, whichever AI produced the draft.
  • AI embedded by default in software your practice already runs is in scope, and it is the hardest part of the guidance to comply with.

Every Australian practitioner forum has been arguing about the same thing since March. Do I actually have to tell my clients I use AI? Most of the commentary has been either a paraphrase of the guidance or a shrug. This is not a summary. It is a decision guide to the three questions that matter, written for registered tax agents and BAS agents who need to make a call this week.

The short version: the Tax Practitioners Board did not ban anything and did not create a new AI-specific rule. It did something more demanding. It confirmed that the existing Code of Professional Conduct already covers AI, so the obligations you have been meeting for outsourcing now attach to the chatbot in your browser tab. If you are choosing a dedicated AI platform for a practice, that reframing is the whole ball game: the question is no longer whether the tool is clever, it is whether you can evidence what it did.

Do I have to tell clients I use AI?

If client information is entered into an AI tool, you need the client's permission first. That rule does not come from a new AI law. It comes from Code item 6 in section 30-10 of the Tax Agent Services Act 2009: unless you have a legal duty to do so, you must not disclose any information relating to a client's affairs to a third party without your client's permission.

The move the TPB made in TPB(GS) 55/2026 was to state plainly that an AI tool can be that third party. At paragraph 23 the guidance says practitioners must obtain permission before divulging client information to a third party, "which can include entering client information into AI models and tools, depending on how these tools are configured and used". The definition is deliberately wide: for the purposes of the TASA, a third party is any entity other than the client and the tax practitioner.

Note the framing. The obligation is not "disclose that you use AI" in the abstract. It is "get permission before client information leaves you". Running AI on generic material does not trigger Code item 6. Pasting a client trial balance into a public chatbot does. Our view at Agentive, having built onshore AI for Australian finance teams, is that this distinction is where most practices are quietly non-compliant: not through bad intent, but because nobody has drawn the line on paper.

The wording that changed between draft and final

The March exposure draft TPB(I) D62/2026 recommended informing the client "to whom and where the disclosure will be made, and where data will be stored". The final guidance keeps all of that and adds four words that matter: "and whether AI tools may be used". The TPB moved AI use from something implied by a third-party disclosure to something it expects you to say out loud.

The TPB accepts four mechanisms, and it is more flexible than the forum panic suggests. Paragraph 24 of TPB(GS) 55/2026 states that client permission may be by way of a signed letter of engagement, signed consent, or other communication such as a relevant "fact find" and consent, and that a general authority consenting to disclosure to third parties may also be acceptable.

That last sentence is the one practitioners keep missing. You do not need a separate, tool-specific AI consent form from every client. What the guidance does not say is how specific the authority must be, and the professional bodies noticed. The Institute of Public Accountants asked directly in its 21 April 2026 submission: is it enough for an engagement letter to refer to third parties as an undissected cohort, or must it name AI tools generally, or the specific tools used? The final guidance did not answer that. It added the "whether AI tools may be used" phrase and left the granularity to your judgement.

The practical read for Australian bookkeepers and accountants: amend the engagement letter at renewal, and name categories rather than products. Categories survive a vendor change. Product names do not.

Five steps to get your consent position defensible

  1. Inventory where client data actually goes. List every platform that touches client information, including the ones with AI switched on by default that you did not choose.
  2. Classify each use. Decide, in writing, which uses involve disclosing client information to a third party and which do not. This is the document a reviewer will ask for.
  3. Amend the letter of engagement. Add a clause covering disclosure to third parties, the use of AI tools, where data is stored, and the jurisdiction it is stored in.
  4. Roll it out at renewal, not by email blast. A signed engagement letter is the strongest of the four accepted mechanisms. Use the renewal cycle you already run.
  5. Record the review of each tool. Paragraph 25 makes you responsible for due diligence on commercial and internally developed or modified AI tools. A short file note per tool, dated, is enough to show you did it.

What does "accountable for accuracy" mean when the AI made the error?

It means you wear it. There is no vendor defence in the TASA. Paragraph 12 of the guidance states that when using AI while providing tax agent services, tax practitioners remain accountable for the accuracy of information and advice they provide to their clients and need to ensure that services are provided to a competent standard.

The competency obligations sit across Code items 7 to 10 and sections 30, 35 and 40 of the Tax Agent Services (Code of Professional Conduct) Determination 2024. Code item 7 requires that a tax agent or BAS service you provide, or that is provided on your behalf, is provided competently. Code item 10 requires reasonable care to ensure the taxation laws are applied correctly. Nothing in there has an exception for software.

The final guidance sharpened its language on model failure. Where the exposure draft said AI "may not always be accurate or factually correct" and "should inform, not substitute" tax knowledge, the final version says AI models "may hallucinate or provide inaccurate information" and "cannot be relied on as a replacement for tax knowledge, experience or expertise". It also added a documentation requirement absent from the draft: verify and review AI generated content for accuracy throughout each step of the workflow, establish processes to understand and contest AI outputs, and document each of those steps. That is tied to sections 30 and 40 of the Determination, covering client records and your system of quality management.

Read that as an audit instruction, not a philosophy. If a reviewer asks how a figure in a lodged return was produced and checked, "the AI did it and it looked right" is not an answer. It is the discipline in our BAS automation walkthrough: AI prepares, a registered agent reviews, and the review leaves a trace.

Which AI uses cross the line, and which do not?

Disclosure and consent are triggered by client information leaving you, not by the sophistication of the task. Human review is triggered by the output informing advice or a lodgement. The table below applies those two tests to the uses Australian bookkeepers and tax agents run most often. It is an interpretation, not a TPB publication.

AI use Client consent needed? Human review required? Why
Researching a general tax question, no client details No Yes No client information disclosed, but Code items 9 and 10 still apply to anything you rely on.
Drafting an email to a named client Yes Yes Client affairs go into a third-party tool. It is a disclosure even though the task is trivial.
Categorising transactions in a client ledger Yes Yes Auto-classification is named in the guidance as AI functionality in scope. Errors flow into the BAS.
Preparing a BAS from client records Yes Yes, and document it A lodgement carries Code items 9 and 10. Review steps should be documented under sections 30 and 40.
Giving the client tax advice generated by AI Yes Yes, non-negotiable The guidance says do not rely on AI output as a substitute for your own analysis of the client's circumstances.
AI features switched on by default in your ledger or email Yes, and hardest to scope Yes Embedded AI is listed as in-scope functionality, but you often cannot see where the data goes.

The embedded AI problem the guidance still does not solve

The biggest unresolved issue is AI you never chose to switch on. The National Tax and Accountants' Association made this the centrepiece of its submission, arguing the draft assumed a practitioner actively chooses to enter information into an AI tool, when AI features are increasingly embedded by default in platforms practices already use. As Accountants Daily reported on 22 April 2026, the NTAA said this is already the most significant compliance risk many practices face, and the draft did not specifically address it.

The example is not hypothetical. Xero announced a multi-year partnership with Anthropic in March 2026 to power its JAX assistant, which analyses revenue and profit performance, tracks cash flow and flags unpaid invoices inside the ledger. MYOB, QuickBooks and Microsoft 365 have all added assistant features to products practices already run. From the practitioner's chair, the data flow is invisible. For bookkeeping teams in particular, that is the exposure worth mapping first.

Here is the honest scorecard. The TPB partly listened: the final guidance added "AI features which may be embedded within software or third-party platforms" and autonomous functionality that "may take actions on behalf of the user" to its in-scope list, neither of which appeared in the March draft. But the NTAA asked the TPB to confirm that listing your AI-enabled software providers in client correspondence would discharge the Code item 6 obligation. That confirmation is not in TPB(GS) 55/2026. Embedded AI is squarely in scope, and the proportionate disclosure standard for it is still undefined. CPA Australia supported the guidance in principle in its submission to the TPB. Both things are true: principles age well, and they leave practitioners carrying the ambiguity.

How does the Privacy Act sit on top of the TPB Code?

The Code is not the whole obligation. TPB(GS) 55/2026 reminds practitioners that the Privacy Act 1988 sets out the Australian Privacy Principles governing the use, storage and disclosure of personal information, and that some of these may have a direct impact on the requirement to obtain consent from clients. The guidance specifically footnotes APP 11, which deals with the security of personal information.

Two consequences follow. First, where client information includes tax file numbers, additional obligations under the Privacy (Tax File Number) Rule 2015 apply. Second, the Office of the Australian Information Commissioner has published guidance on privacy and the use of commercially available AI products that goes further than the TPB on vendor selection. The TPB tells you that you are responsible; the OAIC tells you what to check. We unpack the underlying data question in whether it is safe to put client data into AI at all.

What should you demand from an AI vendor to stay compliant?

Ask for what you would need to produce if a reviewer asked you to prove the service was provided competently and supervised properly. Paragraph 25 makes practitioners ultimately responsible for exercising due diligence, including appropriate review of commercial and internally developed or modified AI tools. You cannot evidence a review of a system that will not tell you how it works.

The seven questions to put to any AI vendor in writing

  • 1. In which country is my client data processed, and in which country is it stored at rest?
  • 2. Is my data ever used to train or fine-tune a model, including in aggregate or de-identified form?
  • 3. Is my deployment single-tenant, or is my client data in shared infrastructure with other customers?
  • 4. Can I export a per-action audit log showing what the AI did, when, on whose instruction, and what a human approved?
  • 5. Who are your sub-processors, and will you notify me before they change?
  • 6. Which actions can the system take autonomously, and where can I set a human review checkpoint?
  • 7. What is your data retention and deletion position when I terminate?

Question four is the one most vendors fail, and the guidance quietly made it essential when it said each review step should be documented. An AI Operation Engine that cannot show its working is a supervision problem, not a productivity tool. Agentive runs single-tenant on AWS Sydney, keeps inference inside Australia, never uses client data to train a model, and records a per-action audit log a registered agent can hand to a reviewer. Those four artefacts answer a Code item 6 and a Code item 7 question in the same breath. For lodgement work, our tax and compliance capability page sets out where the human checkpoints sit.

What should a practice do in the next month?

Do the inventory first, because everything else depends on it. Most practices discover more AI in the building than they expected, and almost none of it documented. From there: classify each use against the two tests, amend the engagement letter, write the file note per tool, and set review checkpoints wherever a lodgement or an advice is produced. That is a fortnight of work for a small practice, and it converts a forum argument into a folder you can hand to a reviewer. The AI Operation Engine overview covers how those checkpoints are configured.

One closing note, because the forums have this wrong. TPB(GS) 55/2026 opens by recognising that AI tools, used appropriately, are a significant opportunity to increase productivity for tax practitioners, the public and Australia. This is not a regulator slowing the profession down. It is a regulator saying the accountability model does not change: you are the registered agent, the service is yours, and the tool absorbs none of it.

Prove Your AI Meets the Code, Not Just the Sales Pitch

Agentive runs dedicated AI for Australian accounting and bookkeeping practices on single-tenant AWS Sydney infrastructure, with a per-action audit log you can hand to a reviewer. Data stays in Australia and is never used to train a model.