For most professions this is a policy question. For a tax preparer it is a criminal statute.
By Kyle Nelson, Founder, Fazit
Most professions evaluate an AI notetaker as a confidentiality and vendor-risk decision. Tax return preparers have one more layer, and it is the layer with a prison term in it. Everything below is linked to the statute or the rule so you can read the source rather than take this page’s word for it, and none of it is legal advice.
§ 7216 is criminal, and it is older than the cloud
Congress enacted IRC § 7216 in 1971. It prohibits a tax return preparer from knowingly or recklessly disclosing or using tax return information for any purpose other than preparing that return, unless the taxpayer consents in writing or a regulation permits it. A violation is a misdemeanour carrying up to a year of imprisonment, a fine of up to $1,000, and the costs of prosecution, rising to $100,000 where the disclosure is tied to a crime involving identity theft.
Sitting behind it, § 6713 adds a civil penalty of $250 for each unauthorised disclosure or use, and the implementing rules live in 26 CFR § 301.7216-1. The IRS maintains a § 7216 information center for practitioners.
WHAT ATTACHES TO AN UNAUTHORISED DISCLOSURE
OF TAX RETURN INFORMATION
IRC 7216 criminal misdemeanour: up to 1 year and/or
$1,000 plus costs of prosecution
($100,000 if tied to identity theft)
IRC 6713 civil $250 per disclosure
AICPA conduct 1.700.001, no disclosure without
1.700.001 specific client consent
State board conduct licence exposure, varies by state
The consent that cures 7216 must be written, and must name
the purpose, the scope, the duration, and the recipients.The honest part: nobody has tested this on a notetaker
No court or IRS guidance has addressed whether running a cloud AI notetaker on a client call is itself a § 7216 disclosure. Anyone who tells you it plainly is, or plainly is not, is guessing. So here is the analysis without the conclusion.
Tax return information is defined broadly. A call in which a client explains their income, their deductions, a property sale or a filing-status question is a call that contains it. A cloud notetaker takes the audio of that call, sends it to the vendor, and typically on to a transcription provider and a language model provider. Whether that chain constitutes a disclosure requiring written consent is the live question, and it is a question you have to have an answer for before an examiner asks it, not after.
The point of this page is narrower than a legal opinion. It is that on-device processing does not answer the question. It removes it. Information that never leaves the machine has not been disclosed to anyone, so there is no consent to obtain, no recipients to name, and no chain to document.
If you do use a cloud tool, the consent has to be real
A § 7216 consent is not a checkbox. The regulations require it in writing and require it to identify the purpose of the disclosure, its scope, its duration, and the recipients. That last one is the one AI notetakers make awkward: naming the recipients means naming the vendor and its subprocessors, which for most tools means a list you have to request rather than read. We walked through what one vendor does and does not publish in what Granola’s public docs say about its subprocessors.
Two practical notes. Consent obtained after the disclosure does not fix the disclosure. And a general engagement letter that never mentions transcription, a vendor, or what happens to the audio is unlikely to be carrying the weight you need it to carry.
The AICPA rule reaches further than tax work
§ 7216 applies to tax return preparers and to tax return information. Your audit, advisory and bookkeeping calls are outside it, and inside the AICPA Code of Professional Conduct. Rule 1.700.001, the Confidential Client Information Rule, says a member in public practice shall not disclose confidential client information without the client’s specific consent.
Where a third-party service provider is involved, the guidance is to either obtain that consent or contract with the provider for confidentiality and take reasonable steps to satisfy yourself that it has appropriate safeguards. That is a workable path and plenty of firms take it. It is also ongoing work: a diligence file, a contract, and a review each time the provider changes its subprocessors. The alternative is a tool that never creates the disclosure in the first place, which is a one-time architectural decision rather than a recurring obligation.
Germany: § 203 StGB, and why a DPA is not enough
German Steuerberater are Berufsgeheimnisträger, and breaching professional secrecy under § 203 StGB is a criminal matter rather than a professional one. The 2017 reform made external service providers workable: § 203 Abs. 3 permits engaging them as mitwirkende Personen.
It permits it on conditions. The engagement has to be necessary for proper professional practice, the provider has to be obliged to secrecy in text form and expressly instructed about the criminal consequences, and you have to select and supervise it carefully. The trap worth knowing: a GDPR data processing agreement does not satisfy § 203 on its own. They are separate obligations, and signing the first does not discharge the second. The wider EU picture is in a GDPR-compliant AI notetaker is one that never creates the data.
Where Fazit sits, stated plainly
Fazit captures the call without a bot, transcribes it on your Mac, and generates the note with a local model on localhost, so neither the audio nor the transcript reaches a third party. The audio is never written to disk at all: it lives in a fixed-size RAM ring buffer with no write API and is destroyed on every exit path, which is why each note carries audio_retained: false in its frontmatter. The output is a Markdown file in a folder you choose, so your retention schedule and your workpaper practices apply to it the way they apply to anything else on your machine.
The caveats, because this page is about disclosure. Models download once from public CDNs on first run. Account, licensing and payment use our servers and are described on the security page; they are a separate lane from call content. Fazit is macOS only and is an early-stage product holding no SOC 2 or HIPAA certification, and this page describes an architecture rather than giving you a compliance opinion. Your consent duties to the client, and your professional body’s rules, are unchanged by any of it.
Neighbouring reading: the recordkeeping version of this question for financial advisers, the privilege version for lawyers, and the general on-device versus cloud comparison.
FAQ
Can accountants use AI notetakers on client calls?
Yes, but tax return preparers have an extra layer that other professions do not. IRC § 7216 makes it a criminal offence to knowingly or recklessly disclose or use tax return information for a purpose other than preparing the return, unless the client has given written consent or a regulatory exception applies. That is a different question from whether the vendor is secure, and it is answered before you get to the vendor's security page.
Does a cloud notetaker count as a disclosure under § 7216?
That specific question has not been tested, and anyone telling you it is settled is guessing. What is clear is the shape of the analysis: tax return information is defined broadly, a client call about a return routinely contains it, and sending audio to a vendor and its subprocessors puts that information in third-party hands. If the information never leaves your machine, the analysis does not start.
What does the AICPA say about third-party service providers?
Rule 1.700.001 says a member in public practice shall not disclose confidential client information without the client's specific consent. Where a third-party service provider is used, the guidance is either to obtain consent, or to contract with the provider for confidentiality and take reasonable steps to satisfy yourself it has appropriate safeguards. Note that this applies to all client work, not only tax returns.
Does a § 7216 consent form cover an AI notetaker?
Only if it actually describes one. A valid consent has to state the purpose, the scope, the duration and the recipients of the disclosure. A general engagement letter that never mentions a transcription vendor, its subprocessors, or what happens to the audio is unlikely to be doing the work you need it to do.
What about German Steuerberater and § 203 StGB?
German tax advisers are Berufsgeheimnisträger, and breaching professional secrecy is criminal. Since the 2017 reform, § 203 Abs. 3 StGB permits engaging external service providers as mitwirkende Personen, but on conditions: the engagement must be necessary, the provider must be obliged to secrecy in text form and expressly instructed about the criminal penalties, and you must select and monitor it with care. A GDPR data processing agreement on its own does not satisfy this.