Opinion: The AI Trickle-Down Myth

Firm Management | July 29, 2026

Opinion: The AI Trickle-Down Myth

When we vet an AI tool, we ask for the SOC 2 report. We check whether it trains on our data. Good instincts, but the wrong question.

CPA, Sam Leon

Every week another Big Four firm announces an AI rollout, and every week a few more small-firm owners take it as their cue. If PwC and KPMG are doing it, the thinking goes, the tools must be safe by now. And if the tools are safe for the giants, they must be safe for me.

The Big Four are spending billions on AI. PwC alone committed a billion dollars. But almost none of that is the AI itself. The models are the cheap part: the same ones anyone can open in a browser for twenty dollars a month, or nothing. What the billions pay for is everything built around the model: private versions that run inside the firm’s own systems and never send anything to the outside world, software that catches a Social Security number before it can leave the network, lawyers who decide which kinds of client data are even allowed near one of these tools, and firm-wide rules that people actually have to follow. They built all of that first, and switched the AI on second, because at their size, doing it the other way around wouldn’t survive the first audit.

Here’s what actually reaches a small firm, and how fast: the AI capabilities. The same model a Big Four team runs behind millions of dollars of guardrails is one login away for a two-person shop. It’ll draft a cover letter, reconcile a basis schedule, summarize a sixty-page notice, explain a K-1 in plain English, and it’s genuinely good at all of it. For the first time, the smallest firms have the same raw power as the largest ones in the country, for the price of a streaming subscription. The excitement is earned. This part is real.

But the power is all that shows up. The protection stays at the top, because it’s expensive and slow and nobody announces it. There’s no press release about the infrastructure that keeps client data from leaving the building. So the small firm gets the capability, never sees the guardrails, and reasonably assumes they came bundled in. 

Which brings us to the part that is under-discussed.

When we vet an AI tool, we ask for the SOC 2 report. We check whether it trains on our data. Good instincts, but the wrong question.

Because there’s an older rule sitting underneath all of it, and it doesn’t care what the vendor does with the data. Section 7216 of the tax code makes it a crime — a misdemeanor, with real fines — for a preparer to disclose a client’s return information without authorization. Note the word: disclose. The violation isn’t what happens to the data later. It’s the moment the information leaves your hands and goes to an outside party at all.

Recommended Articles

So when a client’s K-1 gets pasted into ChatGPT to hit a deadline, the thing that matters already happened the instant someone hit enter. The information went to a third party. Everything you’d normally check — the SOC 2, the training promise, the privacy policy — describes what that third party does with it afterward. The disclosure already happened. And §7216 asks one question about it: was it authorized?

Authorization here isn’t a security policy or an engagement letter: it’s the client’s specific written consent to send their return information to that outside tool. Almost no firm has it, because almost no one realized that was the question.

Until recently, keeping AI inside that wall required a Big Four budget: private infrastructure, a security team, the works. That’s changing. The same protection can now be built into the platform itself: the client’s identifying information stripped out before anything reaches the AI, so there’s no disclosure to authorize because nothing identifiable ever left. Not a wall you buy and bolt on. The way the thing is built, from the first line of code.

That’s the shift that will change securitized AI use for smaller firms. Once the client’s whole context can sit in one place the firm controls — every document, every return, every note — safely enough to put AI to work on it, the question stops being which tool is safe and becomes what could the firm do if all of it lived in one place. That’s the part that decides which small firms get to use this power, and which spend the next few years explaining to a client why they couldn’t.

So the real question isn’t whether your firm should use AI. It’s the one the Big Four answered before they turned anything on: where does all of this actually live as every client’s full picture, and is it somewhere you can safely act on it? Those answers will determine which firms can pull ahead even further.

===

Sam Leon is building TaxWeave, the context layer for tax firms. He also runs The Millennial CPA, one of Accounting Today’s 2026 Best Firms for Technology.

Sign in to get access to this free resource, and all of our whitepapers and reports.

Download this content today!

Register to get free access to this content, as well as newsletters, continuing education, podcasts, and more…

Leave a Reply