The accounting world is abuzz with the rapid integration of Artificial Intelligence. Weekly announcements from the "Big Four" firms—Deloitte, PwC, EY, and KPMG—herald new AI rollouts, creating a palpable sense of urgency among smaller accounting practices. Many small-firm owners perceive these announcements as a validation of AI’s safety and efficacy, assuming that what works for the industry giants must be readily and safely transferable to their own operations. This widespread belief, however, overlooks a critical distinction between the advanced, secure AI ecosystems built by the largest firms and the raw AI capabilities that are now accessible to smaller entities. The billions invested by the Big Four are not primarily in the AI models themselves, but in the extensive infrastructure and stringent protocols that make their AI deployment secure and compliant.
The Billion-Dollar AI Divide: Beyond the Model
The considerable financial commitments made by the Big Four to AI, with PwC alone investing a billion dollars, are often misunderstood. The core AI models, such as large language models (LLMs), are comparatively inexpensive. These same foundational models are accessible to individuals and small businesses for a nominal monthly fee, or even for free, through readily available online platforms. The true cost and complexity of the Big Four’s AI strategy lie not in the algorithms, but in the robust ecosystem built around them.
This ecosystem encompasses several crucial elements that are prohibitively expensive and time-consuming for smaller firms to replicate:
- Private, On-Premise Deployments: The Big Four invest heavily in creating private instances of AI models that operate entirely within their own secure IT infrastructure. This ensures that sensitive client data never leaves the firm’s network and is not shared with external AI providers for training or any other purpose. This level of isolation is paramount for maintaining client confidentiality and regulatory compliance.
- Advanced Data Security and Governance: Significant resources are allocated to developing sophisticated software and protocols designed to intercept and prevent the exfiltration of sensitive information, such as Social Security numbers, from the firm’s network. This includes granular access controls and monitoring systems.
- Legal and Compliance Oversight: Dedicated teams of lawyers and compliance officers meticulously vet which types of client data are permissible for use with AI tools. They establish firm-wide policies and procedures that govern AI usage, ensuring adherence to all relevant legal and ethical standards.
The rationale behind this layered approach is rooted in risk management and audit readiness. For firms of their scale and with their regulatory obligations, implementing AI without these protective guardrails would be an untenable risk, likely failing even the initial stages of a rigorous audit. The Big Four’s approach, therefore, prioritizes security and compliance, implementing the AI capabilities only after the protective infrastructure is firmly in place.
The Accessibility Paradox: Power Without Protection
What typically filters down to smaller firms are the AI capabilities themselves, often at an astonishing speed. The same powerful AI models that are integrated into the Big Four’s multi-million dollar secure environments are, for a small two-person practice, just a login away. These tools can perform a range of tasks with remarkable proficiency: drafting cover letters, reconciling complex financial schedules, summarizing lengthy documents, and explaining intricate tax forms like the K-1 in plain English. The accessibility of this raw AI power, at a cost comparable to a streaming service subscription, is undeniably exciting and represents a genuine leap forward for smaller firms, leveling the playing field in terms of processing and analytical capabilities.
However, this accessibility comes with a significant caveat. While the raw power of AI is readily available, the expensive and complex protective measures—the "guardrails"—remain largely at the top. These are the elements that are not publicly announced. There are no press releases detailing the infrastructure that prevents client data from leaving a firm’s premises, nor the internal controls that monitor AI usage. Consequently, small firms gain the capability, but remain unaware of the absence of the protective layers. They often assume these critical safeguards are implicitly bundled with the AI tool, a dangerous misconception.
The Under-Discussed Risk: Disclosure and Section 7216
The crucial aspect that receives insufficient attention in the rush to adopt AI is a fundamental legal principle that predates current AI technologies: Section 7216 of the U.S. Internal Revenue Code. This section, often overlooked in the discourse around AI adoption, criminalizes the unauthorized disclosure of a client’s tax return information. It is a misdemeanor offense, carrying significant fines, and the violation hinges on the act of "disclosure" itself. The focus is not on what happens to the data after it is shared, but on the initial act of transmitting it to an outside party without proper authorization.
When a tax preparer, for instance, pastes a client’s K-1 into a public AI chatbot to meet a deadline, the violation occurs at the moment the "enter" key is pressed. The information has been disclosed to a third party. Standard due diligence practices, such as reviewing a vendor’s SOC 2 report or their data training policies, address what that third party does with the data after disclosure. These checks are important, but they do not mitigate the initial act of disclosure. Section 7216’s sole concern is whether that disclosure was authorized.
Authorization: The Missing Piece of the Puzzle
In the context of AI usage and Section 7216, authorization does not refer to a general security policy or a standard engagement letter. It specifically means obtaining the client’s explicit, written consent to share their tax return information with a particular outside AI tool. The vast majority of small firms, caught in the momentum of AI adoption, have not secured this specific consent, largely because the necessity of it has not been widely understood.
Historically, keeping AI within secure boundaries required the substantial investment characteristic of Big Four firms: dedicated private infrastructure, extensive security teams, and comprehensive compliance frameworks. The landscape, however, is evolving. Emerging solutions are designed to embed security directly into the platform’s architecture. This new paradigm involves stripping client-identifying information before any data reaches the AI model. In such a system, there is no disclosure of identifiable information to an external party, thus eliminating the need for specific authorization under Section 7216. This is not an add-on security layer but a fundamental aspect of the platform’s design, built from the ground up.
The Future of AI in Small Firms: Context is King
This architectural shift promises to redefine secure AI utilization for smaller accounting practices. The ability to centralize all client data—every document, return, and note—within a controlled, secure environment, making it safe for AI to process, fundamentally changes the conversation. The question shifts from "Which AI tool is safe?" to "What transformative capabilities could we unlock if our entire client context resided in one secure, AI-enabled location?" This is the question that will delineate which small firms successfully leverage AI to gain a competitive advantage and which ones, in the coming years, will face difficult explanations to clients regarding their limitations.
The ultimate inquiry for accounting firms today is not whether to adopt AI. It is the same fundamental question that the Big Four addressed before deploying any AI: Where will all of our firm’s collective client data reside, and is that location secure enough to enable us to act upon it safely and effectively? The firms that can answer this question with robust, compliant solutions will be positioned to lead the industry, while those that do not risk falling behind.
The author, Sam Leon, is actively involved in building TaxWeave, a platform designed to serve as a contextual layer for tax firms, and also leads The Millennial CPA, recognized for its technological advancements in accounting. His insights underscore a critical juncture for small and medium-sized accounting practices navigating the complexities of AI integration. The promise of AI is immense, but realizing it responsibly requires a deep understanding of the underlying infrastructure, legal obligations, and the strategic importance of data security. The ongoing advancements in AI necessitate a parallel evolution in how firms approach data management and client consent to ensure both compliance and competitive advantage.









