TPB(GS) 55/2026 · finalised 22 July 2026

Private AI for Accounting Practices Who Can't Afford a Client Data Leak

Under TPB(GS) 55/2026, finalised 22 July 2026, entering a client's information into an AI tool can count as a disclosure to a third party under Code Item 6 of the Code of Professional Conduct. Althorn runs AI entirely on hardware inside your office, so your team gets the speed without that disclosure risk. If you don't currently have documented client permission for your AI use, your practice may already be exposed.

Your clients don't hand you their tax return because they enjoy paperwork. They hand you their income, their debts, their family trust structures, sometimes things they haven't told their own family, because they trust you specifically, not "an accountant" in the abstract. Althorn is built so your practice can use AI to move faster without ever putting that trust at risk, and the TPB's new guidance is exactly why that matters right now.

What TPB(GS) 55/2026 actually requires

  • Code Item 6: you must not disclose information relating to a client's affairs to a third party without the client's permission, unless there's a legal duty to do so.
  • "Third party" includes AI tools: the TPB has confirmed that entering client information into an AI model can constitute disclosure to a third party, depending on how the tool is configured and where the data goes.
  • A generic privacy policy is not permission: permission needs to be specific, documented, and reproducible if the TPB ever asks for it.
  • Existing obligations, new scrutiny: confidentiality, competence, and reasonable care were always there. What's new is the TPB stating, in writing, exactly how it expects those duties to be met when AI is involved.

Most firms haven't caught up yet. That's not a criticism, it's a genuinely new interpretation of an old rule, and it moved fast. But "we didn't realise that counted as disclosure" isn't going to hold up if the TPB comes asking.

How Althorn closes the gap

You don't need to ban AI in your practice. You need it to never leave the building.

Althorn sets up private AI that runs on hardware inside your own office, not a cloud subscription, not a model hosted overseas. Your team still gets to draft correspondence, summarise files, and move faster. The difference is that a client's information never becomes a "disclosure to a third party," because it never leaves your network.

If you're already using an Australian-hosted AI tool, that's a real step up from a public chatbot, but it's still someone else's infrastructure, someone else's backup process, someone else's support staff with access. On-premise means there's no third party in the picture at all.

What this looks like in practice

  • Faster file review and drafting without a single client file leaving your premises.
  • A straightforward answer for engagement letters: "your information is processed on our own systems, in our office, and never sent to a third-party AI provider."
  • No sub-processor chain to untangle.

The reputation case, not just the compliance case

Compliance gets you out of trouble. Trust is what actually grows your practice. Being able to say, plainly, that your practice runs AI entirely in-house is a stronger client-retention story than any fee discount.

Book a 20-minute AI & confidentiality audit

For your practice, no obligation.

Common questions

Does this mean I can't use AI at all right now?

No. The guidance doesn't ban AI use. It requires client permission for the disclosure and the ability to explain where the data goes.

What if my software already has AI features built in?

AI functionality embedded in existing software (email, document management, practice tools) can process client data without anyone actively deciding to "use AI." An audit identifies where this is already happening in your stack.

Is this specific to tax agents, or does it apply to BAS agents too?

The Code of Professional Conduct under the Tax Agent Services Act applies to both, so the same considerations apply.