Somewhere in your office right now, someone is probably using AI to draft a client summary, reconcile an account, or get a first read on a return, whether or not you've sanctioned it. That's not a guess; it's the predictable result of powerful, free tools meeting deadline pressure during busy season. The only real question is whether it's happening with guardrails or without them.
And the gap between use and oversight is already measurable. A survey of more than 200 compliance officers found 84 percent of financial firms have AI tools in everyday use, but the typical firm applies AI in fewer than two of twenty surveyed functions, meaning most of that use is scattered and undocumented rather than deliberate. Regulators aren't waiting for AI-specific rules to start asking about it: examiners already expect existing governance and recordkeeping obligations to apply to AI use now.
Source: AI governance gap puts financial firms at examination risk, fintech.global, August 2026.
The professional framework already exists, and it already applies to you. The AICPA has confirmed that its existing Code of Professional Conduct, competence, due care, confidentiality, and independence, already governs how CPAs use AI tools, whether or not a firm has written a single word of internal policy. No separate AI-specific rulebook is coming to replace it. Firms that get their house in order now won't be caught improvising when an examiner, a client, or a peer reviewer asks how AI fits into the existing conduct code.
In plain terms: your duty of confidentiality doesn't pause because a staff member pasted a client's financials into a public chatbot to summarize them faster. Your duty of due care doesn't pause because nobody told the office what counts as “review” for an AI-assisted number. The rules already apply. What's usually missing is a policy that tells your people how to meet them.