Tax departments are beginning to use AI faster than it can be governed, filling a technical gap and creating a significant accountability one.
Across the industry, AI tools are now being used in tax return preparation, provision modeling, research and audit risk management. Although the use case and efficiency argument is well established, ownership and responsibility are not. This is crucial because these tools can expose sensitive data, produce an undefendable position or generate incorrect answers.
So, defining who owns AI security risk in tax — using the tax AI security triad — must be managed immediately.
Why AI Risk in Tax Is Different
AI security risk in tax is not the same as general AI risk, and generic governance frameworks do not address it adequately. Tax is not a forgiving environment for mistakes and undefined accountability. The Internal Revenue Service (IRS) does not accept governance gaps as valid excuses, and audit committees do not accept vague answers about AI use when they are reviewing a tax provision.
Additionally, the data flowing through AI tax tools, like entity structures, unreported positions, and mergers and acquisitions (M&A) transaction details, is very sensitive. When AI security fails in this environment, the consequences are financial, regulatory, and reputational, often simultaneously. The exposure points are specific to how tax AI tools work and what they process.
Security and Data Confidentiality
The most immediate concern is the confidentiality of sensitive data. Certain tax tools routinely retain the input submitted to them, and in many cases use that data to improve their own models. Service agreements negotiated before the integration of AI rarely account for this. Tax teams are often submitting their most sensitive information into systems whose data handling has never been audited.
Accuracy and Model Drift
Accuracy and manipulation risk is equally serious. AI tax research tools and other AI tools that accept open-ended text are vulnerable to prompt injections, where inputs are crafted to cause the model to return misleading, incorrect or illegal outputs. More commonly, models simply drift. As tax law changes, the model that was accurate at deployment degrades and doesn’t adjust as needed. There is no warning when this happens. This will simply be noted when a mistake appears in a filed tax position that cannot be supported, a provision that requires restatement, or a penalty notice that arrives upon submission.
Privilege Escalation
Privilege is another aspect that most organizations have not yet addressed. The moment an AI tool is inserted into a workflow that previously only involved authorized humans, the analysis of what is protected changes. Most tax departments have no map of where AI touches privileged work products. Most AI vendors have not been asked to provide one.
The AI Ownership Problem for Tax Leadership
The reason AI security risk in tax goes unowned is not that organizations lack capable people, but that risk crosses functional boundaries and practices in ways that make assigning ownership seem difficult.
Tax leaders understand the regulatory stakes and the professional liability that comes with a signed document, but most were not trained to assess vendors’ AI security, data integrity or model validation. Chief information security officers (CISOs) understand how to evaluate and monitor technology risk, but they have limited visibility into what makes a tax position legally defensible.
Chief AI officers (CAIOs), where they exist, are typically measured on adoption and speed rather than governance rigor — and tax is precisely the environment where that orientation is most dangerous. This is especially hazardous when organizations would rather adopt AI and unknowingly accept the risks that come along with it than fall behind competitors.
Legal and compliance teams are crucial for regulatory monitoring but are built to be reactive. They respond to problems when they arise. They do not continuously monitor operational AI risk in a running tax function.
Each of these functions within an organization contributes to ownership. None of them are responsible for everything. When accountability is distributed without structure, it effectively belongs to no one. When accountability belongs to no one, problems arise that are expensive to fix and difficult to explain.
The Tax AI Security Triad
The solution is a defined governance structure that assigns specific, non-overlapping responsibilities across three functions, with one executive accountable for the whole. The tax AI security triad, like the AI triad defined for general AI risks, is not a committee or a group. It is a permanent structure with true authority, responsibility and accountability.

Chief Tax Officer
The chief tax officer (CTO) is accountable for the outputs from the AI tools that were used. That means maintaining a complete inventory of every AI tool touching tax workflows and documents and the outputs those tools have influenced, establishing enforceable standards that require human review of AI-generated content, and defining procedures for addressing incorrect outputs.
The chief tax officer is already in charge of communication to the chief financial officer (CFO), audit committee, and external auditors about how, and why, AI is functioning in the tax process.
Chief Information Security Officer
The CISO is accountable for the security architecture around tax AI and the vendor relationships that support it. This means enforcing data classification standards for data used in AI systems throughout its use, not just at deployment.
This role is responsible for conducting security assessments of AI tax tool vendors throughout their lifecycles that cover data retention, model training restrictions, breach notifications, incident response and access controls. It also means building the logging and monitoring infrastructure that creates a defensible audit trail: what was submitted, what came back and when.
The CISO is also responsible for initiating the renegotiation of vendor contracts that do not reflect AI capabilities.
Chief Compliance Officer and Tax Counsel
The chief compliance officer (CCO) and tax counsel together are accountable for the regulatory and legal dimensions. This means tracking IRS, Treasury, and Organization for Economic Co-operation and Development (OECD) guidance on AI use in tax compliance and translating it into governance requirements before positions are taken, not after. This role maintains documentation of AI use that can be reproduced in an audit, including a list of tools that were used, what human review occurred, and what the organization's standard was for AI-assisted positions was. Where AI-generated positions lack real legal support, exposure to other penalties is real.
Making the Triad Work
A formal structure will never work without authority and accountability from each part. The tax AI security triad only functions if each leg takes responsibility, even if it means making a difficult decision, like pausing, restricting or retiring an AI system.
That is why the CFO sits above the triad as the single executive accountable to the board and audit committee for AI security risk related to tax. The triad operates the day-to-day governance, while the CFO's role is to be a middle person to ensure the board can always get clear, accurate and complete answers to questions revolving AI in tax.
Tax leaders also need to develop enough AI literacy to effectively communicate with the CISO and vendors. This is not required for them to become security professionals, but they must be able to ask the right questions and be able to defend their positions.
The Governance Gap Is Growing and So Is the Cost of Waiting
IRS guidance on AI in tax compliance is actively developing. External auditors are beginning to ask real questions about AI-assisted provisions. As AI tools become more widely adopted in tax workflows, the cost of building governance rises, not only in price, but in effort, legal exposure, and in the difficulty of reconstructing documentation for positions that were taken without it.
The organizations that build clear AI security ownership in tax now will be better positioned to scale AI securely with confidence, defend their positions, and answer their boards clearly when they ask. The tax AI security triad is how that ownership gets defined.
Your Guide Forward
As tax departments accelerate AI adoption, governance cannot be treated as an afterthought. Cherry Bekaert's Cybersecurity and Tax professionals can help organizations evaluate AI risk, establish clear ownership structures, assess vendor controls, and develop governance frameworks that support both innovation and compliance.