Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    AI Agent Rankings
    August 23, 2026
    31 min read

    Top 10 AI Agents forAccounting Firms in 2026

    Every ranking in this category scores accuracy and hours saved. Every one of those numbers is published by the vendor about itself. This one scores only what a partner can check — and leads with the criminal statute that not one of the twenty-five vendors we examined mentions.

    AI agents for accounting and CPA firms in 2026 — ranked on verifiable compliance, pricing and integration disclosure
    879,698
    Individuals holding a current PTIN for 2026, of whom 208,519 are CPAs
    IRS Return Preparer Office, data current as of August 1, 2026
    1,449,500
    Accountants and auditors employed in the US (excludes self-employed)
    BLS Occupational Employment and Wage Statistics, May 2025 estimates, SOC 13-2011
    64.37%
    Top model score on the only independent benchmark in this field — a ceiling no vendor quotes
    Vals AI Finance Agent benchmark v1.1, 537 questions, updated June 4, 2026
    0 of ~25
    Vendors examined that mention IRC §7216; exactly one names Pub 4557 and the Safeguards Rule
    Frenchy Digital vendor documentation review, checked August 23, 2026

    Key Takeaways

    • Sending client tax data to an AI vendor is a disclosure of tax return information under IRC §7216 — a criminal misdemeanour with jail exposure if it is done wrong. The vendor is itself a tax return preparer under 26 CFR §301.7216-1(b)(2), which expressly includes a person who develops software used to prepare or file a return.
    • Model output derived from return data is itself tax return information under §301.7216-1(b)(3). A workpaper, memo or summary an agent generates from a client's 1040 data is covered, and passing it to a second vendor is a second disclosure.
    • Across roughly 25 vendors examined on 23 August 2026, exactly one — Liscio — names IRS Pub 4557 and the FTC Safeguards Rule on its own site, and not one mentions §7216. The compliance analysis is the firm's to do, not the vendor's.
    • Independent benchmarks of models exist; there is no independent benchmark of the products. Vals AI's Finance Agent benchmark v1.1 (537 questions, 4 June 2026) puts the best frontier model at 64.37% on entry-level analyst tasks — a ceiling no vendor's marketing will quote you.
    • The roster moves faster than the rankings. Klarity renamed itself Within on 6 August 2026 and left accounting entirely — seventeen days before this article published. Botkeeper shut down in February 2026. Materia was acquired in October 2024. AvidXchange went private on 15 October 2025.
    • Circular 230 was never amended for AI. REG-116610-20 remains a proposed rule published 26 December 2024, and the printed Circular 230 is still Rev. 6-2014. §10.22(b) protects reliance on a person you engaged, supervised, trained and evaluated — there is no analogue for a model.
    • The FTC Safeguards Rule makes your AI vendor a service provider under 16 CFR §314.2, triggering §314.4(f): selection diligence, contractual safeguards, and periodic reassessment. Tax preparers are financial institutions under §314.2(h) regardless of size.
    • Nothing in this category is more than about eighteen months old. BILL calls its agents its first suite. Karbon's Kai is in limited early access. Suralink's agent library launched 3 June 2026, Digits' Agentic Close on 8 June 2026, Puzzle's AI Suite on 10 July 2026.
    • Frenchy Digital cost bands: discovery and workflow audit $9k–$22k; single-workflow agent $28k–$70k; multi-workflow platform with system integration $70k–$180k; enterprise or regulated build $180k–$420k+.

    The Claim Under Test — and a Vendor That Renamed Itself 17 Days Ago

    On 6 August 2026, a company that a great many accounting firms had signed for contract-to-revenue document AI stopped being that company. Klarity renamed itself Within, moved to a new domain, and repositioned as a process-discovery and agent-enablement layer — leaving accounting document AI behind. Both of its old domains now redirect. That happened seventeen days before this article published, and it is the single cleanest argument we can make for why a ranking in this category has to be re-checked rather than copied.

    It is not an isolated event. In February 2026, Botkeeper shut down after eleven years selling specifically to accounting firms. Materia was acquired by Thomson Reuters in October 2024, and its domain now returns a 404 while the www subdomain redirects to an unrelated company. AvidXchange left the public markets on 15 October 2025 into TPG's hands, with Corpay co-investing. Keeper became Double in October 2025 after a trademark suit — a rebrand, not an acquisition, and the two are constantly confused. Yet all four of those names still appear in rankings published this year.

    The claim every ranking in this category makes is that these tools work. It is asserted with accuracy percentages, autonomy rates, hours-returned figures and close days eliminated. We chased those numbers to their sources. Every single one of them is published by the vendor about the vendor's own product. No third party has evaluated any of these commercial products on a common task set with a published methodology. So the claim does not survive, and the honest version of this article is a ranking of what can actually be checked.

    That is not a small population to write for. The Bureau of Labor Statistics' Occupational Employment and Wage Statistics programme put 1,449,500 accountants and auditors in US employment in its May 2025 estimates — a figure that excludes the self-employed — of whom 330,500 work in NAICS 5412, the accounting, tax preparation, bookkeeping and payroll services industry. On the tax side, the IRS Return Preparer Office reported 879,698 individuals holding a current PTIN for 2026, of whom 208,519 are CPAs, with the data current as of 1 August 2026. Those preparers e-filed 75,316,000 individual returns in the 2026 filing season.

    The second thing to know before reading any ranking, including this one, is that nothing in this category is more than about eighteen months old. BILL's Form 10-K describes its agents as its first suite, launched in fiscal 2026. Vic.ai has one live agent and two in beta. Karbon's Kai is in limited early access. Suralink's agent library launched on 3 June 2026, Digits' Agentic Close on 8 June 2026, Puzzle's AI Suite on 10 July 2026, and Black Ore's Tax Autopilot reached general availability on 29 April 2026. Any ranking that implies settled, proven tooling is describing a market that does not exist yet. If you want the cross-industry version of that argument, we set it out in our 2026 survey of AI agents across every vertical we cover.

    How We Ranked, and What We Refused to Rank On

    We scored eight attributes, every one of which you can re-check yourself in an afternoon, and we refused to score anything a vendor publishes about its own performance. Everything below was checked on 23 August 2026. Where a vendor did not publish something, the cell says so in plain words rather than being filled with an estimate.

    What we scored, and where you re-check it

    • Documented public integrations: the vendor's own docs or API reference — not a logo wall, not a dropdown in an intake form
    • Whether a DPA is publicly offered: the vendor's legal or trust page; a DPA referenced but not published counts as not published
    • SOC 2 Type II, ISO 27001, ISO 42001 status: the vendor's own trust centre, read for exact wording and scope
    • Pricing transparency: published tiers with figures, or the words not publicly disclosed
    • Locked to a suite versus standalone: product documentation, and specifically whether the AI layer can point at another system
    • Ownership and funding from public record: SEC filings, registry entries, press releases — never an aggregator profile
    • Whether any independent evaluation exists: the answer for every product in this table is none
    • Data residency, retention and model-training commitments: the DPA, trust page or subprocessor list

    We did not score accuracy, autonomy rate, straight-through processing, hours saved, close days eliminated or ROI. Not because those things do not matter — they matter more than anything else in the table — but because there is no source for them that is not the seller. A ranking that repeats a vendor's 99% and calls it a finding has laundered marketing into fact.

    The benchmark question, stated precisely

    Accounting is the one field in this cluster where a blanket claim that no independent evaluation exists would be false, so here is the precise version. Independent benchmarks of models exist. There is no independent benchmark of the products in the table below. No third party has tested Basis, Fieldguide, Black Ore, DataSnipper, Digits, Canopy or any comparable product on a common task set with a published methodology.

    What does exist is at the model layer, and it hands you a number no vendor will quote. Vals AI's Finance Agent benchmark, version 1.1 most recently updated on 4 June 2026, runs 537 questions covering core financial-analyst tasks — retrieval, market research, projections — pitched at entry-level analyst work. It was built with Stanford researchers, a globally systemically important bank and industry experts, and it evaluated 21 models across eleven labs. The top score was Claude Opus 4.7 at 64.37%, with Claude Sonnet 4.6 next at 63.33%.

    Read that against the marketing. The best frontier model available scores under two-thirds on entry-level financial-analyst tasks on an independent benchmark, while products built on those same models advertise accuracy above 99%. Both things can be true — a narrow, well-scoped, heavily-scaffolded product can beat a general benchmark on its own lane. But you should want to know which lane, measured how, by whom. In this market, the answer is always: by the vendor.

    Three 2026 preprints point the same direction and are worth reading in full before you buy. AuditFraudBench (submitted 6 June 2026) builds an enforcement-grounded benchmark from original and restated 10-K and 10-Q filings, structured financial statements, MD&A disclosures and SEC Accounting and Auditing Enforcement Releases, and reports that both proprietary and open models still struggle to jointly reason over financial figures, disclosure framing, restatement evidence and enforcement-grounded fraud mechanisms. ReguSim and ReguBench (submitted 20 August 2026) frames financial compliance evaluation as an audit of rule-grounded actions and evidence use, rather than a single compliance score — which is an independent research group arriving at the same conclusion this methodology asserts. Both are preprints, not peer-reviewed papers, and should be described that way.

    The Comparison Table — Ten Products, Verifiable Attributes Only

    Every cell below is either a citation you can open or the words “not publicly disclosed”. Ranking runs on the quality and completeness of what the vendor discloses, because that is the only dimension a buyer can independently verify before signing. It is not a ranking of which product is best at your work — nobody can tell you that from the outside, and anyone claiming to is selling.

    Product and 2026 ownershipWhat it actually isCompliance disclosure you can checkPricingDocumented integrationsIndependent product benchmark
    1. Ramp — private; no acquisition or rename foundAutonomous within customer-set policy boundsSOC 1 Type 2 and SOC 2 Type 2 (periods ending Oct 2025); ISO/IEC 27001:2022 certification (Oct 2025); PCI DSS v4.0 AoC (Dec 2025); LLM subprocessors named — trust.ramp.comPublished: Free $0/user/mo; Plus $15/user/mo plus a platform fee; Enterprise custom — ramp.com/pricingBroadest published ledger list in the roster, 25+ named incl. QBO, QuickBooks Desktop, Xero, NetSuite, Sage Intacct, Dynamics BC, Acumatica — ramp.com/integrationsNone
    2. BILL — BILL Holdings, Inc., NYSE: BILL, CIK 0001786352Mixed: two agents autonomous in a narrow lane, one copilot, one learned automationSOC 1 Type II and SOC 2 Type II, NIST CSF alignment, PCI DSS — stated in the FY2026 Form 10-K filed 20 Aug 2026. DPA page 404s; residency and retention not publicly disclosedPublished: AP and AR Essentials $49 / Team $65 / Corporate $89 per user/mo; accountant partner $49/mo — bill.com/pricingFrom the 10-K: QuickBooks Online, QuickBooks Desktop, Oracle NetSuite, Sage Intacct, Xero, Microsoft Dynamics 365 Business Central, two-way syncNone
    3. MindBridge — Ottawa, founded 2015; legal entity and funding not publicly disclosedNot an agent, and says so: statistical models, business rules and unsupervised MLStrongest certification stack found: SOC 1 Type 2, SOC 2 Type 2, SOC 3 Type 2, ISO/IEC 27001:2022, 27017:2015, 27018:2019 — trust.mindbridge.ai. DPA, residency, retention and training policy not publicly disclosedNot publicly disclosedNamed: Xero, Databricks, Fieldguide; connectors for Snowflake, Azure Data Factory, Microsoft Fabric. The only public developer portal in the roster — developer.mindbridge.aiNone
    4. Fieldguide — private; $75M Series C led by Goldman Sachs Alternatives announced 2 Feb 2026; total $125MGenuine agent, supervised: executes engagement testing, mandatory review and sign-offSOC 2 Type II (annual), ISO 42001, AIUC-1 attestation; DPA publicly offered with SCCs; 14 subprocessors named — fieldguide.com/trust. Retention and model-training policy not publicly disclosedNot publicly disclosed; no pricing page in the sitemapNo named partners published — the integrations page describes categories only, plus an open REST API and Fieldguide MCP. MindBridge names Fieldguide from its sideNone
    5. Canopy — Canopy Tax, Inc.; ownership and funding not publicly disclosedSupervised agent (its own word) plus assistants and learned automationSOC 2 Type II described as compliant rather than certified, no auditor or period named; automated PII masking for SSNs, birthdays and TINs; US residency. ISO 27001 and DPA not publicly disclosed — getcanopy.com/securityPublished and the most granular: Standard $74 / Plus $109 / Premium $149 per user/mo annual, plus separately metered AI — getcanopy.com/pricingBest US tax-software coverage in the roster: UltraTax, Lacerte, ProConnect, ProSeries, CCH Axcess Tax, Drake, TaxWise, QBO, Xero, IRS TransferNone
    6. Basis — trades as Basis, NYC, founded 2023; $100M Series B at $1.15B valuation, 24 Feb 2026; total $138MGenuinely agentic: background execution returning completed deliverables for reviewSOC 2 Type II, ISO 27001, ISO 42001, AES-256 at rest, US-only storage, explicit no-training pledge; GDPR and CCPA marked coming soon; DPA not stated — getbasis.ai/securityNot publicly disclosed; the pricing page 404sNone documented. The integrations and product pages both 404; trade press says only accounting systems and ERPsNone
    7. Blue J — Blue J Legal Inc., incorporated in Ontario; US$122M Series D, Aug 2025, co-led by Oak HC/FT and SapphireNot an agent by design: tax research with linked citations to primary authoritySOC 2 Type 2 maintained annually, report under NDA; DPA published as a standalone page; residency stated as AWS us-east-1; uploads older than 24 hours auto-deleted; signed no-training agreements with OpenAI and Google — bluej.comPublished: Individual $1,498/year per user; Team contact for pricing; 7-day trial — bluej.com/pricingNone named. No tax-software integrations publishedNone; and no accuracy or hallucination rate is published anywhere on the site
    8. Digits — Digits Financial, Inc., San Francisco, founded 2018; investors named on its own site as Benchmark, GV, SoftBankAgentic with bounded autonomy: clear-cut issues resolved automatically, judgement escalatedSOC 2 Type II; TLS in transit, per-secret envelope encryption, encryption at rest. ISO 27001, residency, retention, DPA, subprocessors and model-training policy all not publicly disclosed — digits.com/securityPublished, and the only vendor publishing firm tiers: Business $65 / $100 / $250 per mo; firm plans $35–$250 per client/mo — digits.com/pricing12,000+ financial institutions claimed by the vendor; named 2026 partners Ignition, Karbon, Reach Reporting; ships a developer API and an MCP server. No QBO, Xero, NetSuite or Intacct — it replaces themNone
    9. Black Ore — private; $60M out of stealth 7 Nov 2023, co-led by a16z and Oak HC/FT; Tax Autopilot GA 29 April 2026The most autonomous product found: batch-and-review 1040 preparation with CPA sign-offSOC 2 Type II audited annually against AICPA Trust Services Criteria; AES-256, TLS 1.2+, field-level RBAC, SSO/MFA, full audit logging; the roster's most specific residency commitment — US-based data centres with no offshore or third-party processing; explicit no-training-or-cross-firm-optimisation pledge — blackore.ai/securityNot publicly disclosed; Standard and Enterprise tiers named, no figuresNone documented. Tax-software names appear only in an intake-form dropdown with no live-versus-planned indication; both trade write-ups say only that it connects with major tax platformsNone; the trade write-up attributes every metric to the vendor's own early-access participants
    10. DataSnipper — HQ Amsterdam; independent and the acquirer, buying UpLink 15 Oct 2024; $100M Series B led by Index at $1B valuationMixed and honestly labelled: deterministic tick-and-tie plus a bounded agent layerSOC 2 Type II; GDPR; EU-U.S. Data Privacy Framework; versioned public DPA (current 1 June 2026) plus an AI Terms addendum and public sub-processor list; explicit no-fine-tuning-on-customer-data statement; retention specific at 24 hours. ISO 27001 not claimed on its own security page; no regional residency guaranteeNot publicly disclosed; three tiers named, no figuresNone named. The hard dependency is Microsoft Excel — it is an Excel add-in, which is a distribution model rather than an integrationNone. Its DocuMine product was named to TIME's Best Inventions 2025 — an editorial award, not an accuracy benchmark

    All attributes checked 23 August 2026 against each vendor's own published pages and against public filings. Vendor-published performance figures are excluded from the table by design.

    Three patterns fall straight out of the table.First, pricing transparency splits the field cleanly: six vendors publish enough to calculate a bill (Digits, BILL, Canopy, Liscio, Karbon, Ramp), five publish partially, and sixteen publish nothing. Second, compliance disclosure quality varies far more than compliance itself probably does — several vendors that almost certainly hold certifications have no page saying so. Third, and most usefully: the vendors with the strongest security disclosure are mostly not the ones with the strongest agent claims. The most autonomous products in this market tend to publish the least.

    “Agent” means at least six different things here

    Before the entries, a taxonomy, because the word is doing a great deal of unearned work in this market. These six categories came out of reading the vendors' own descriptions rather than their headlines — and in several cases the vendor's own documentation contradicts its homepage.

    ArchitectureProducts that fit itWhat that actually means for your firm
    Autonomous, batch-and-reviewBlack Ore Tax Autopilot; Thomson Reuters Ready to ReviewWork is queued in batches and returns review-ready. The human gate is at the end, not the keystroke
    Event-triggered autonomous execution, human reviewer downstreamSuralink's agent library; Ramp; BILL's W-9 AgentThese fire without being asked — on upload, on a policy match, on a fulfilled request. That is the real test of autonomy
    Autonomous execution with mandatory sign-offFieldguide's Field agents; Basis; DigitsThe agent runs on its own and the deliverable cannot leave without a named human approving it
    Approval-gated drafting (a copilot)Puzzle; Karbon's Kai; Canopy Coworker; Stampli; Double; Truewind; Trullion; DataSnipper's agent layerThe system drafts and a person approves each step. Useful, often excellent, and not what the word agent implies
    Not an agent at all, and honest about itMindBridge; Blue J; Liscio; NumericAnalytics, research and confidence-gated classification. Liscio's own documentation says files the system is not certain about are not renamed
    Rules-based automation marketed as an agentBooke AICustom thresholds and rules is the signature of deterministic automation. No task decomposition or multi-step planning is described

    The Ten, Entry by Entry

    Each entry below states what the product does, what is verifiable, what is not disclosed, who it fits, who it does not, and who owns it. Where a figure is the vendor's own, it is attributed to the vendor in the sentence that carries it. Where we could not confirm something, the entry says so rather than guessing.

    1. Ramp — the best-documented compliance posture in the roster

    What it does:a client-side spend platform the firm administers. Cards are issued to a client's staff, receipts and invoices are captured, transactions are auto-coded against the client's chart of accounts and synced to the ledger. The firm's benefit is that month-end coding arrives largely done.

    What is verifiable:more than any other vendor here. Ramp runs a self-serve trust centre rather than a marketing page, publishing SOC 1 Type 2 and SOC 2 Type 2 for periods ending October 2025, an ISO/IEC 27001:2022 certification achieved in October 2025 — the only ISO 27001 certification, as opposed to alignment, we verified anywhere in this research — and a PCI DSS v4.0 attestation of compliance dated December 2025. It also publishes a subprocessor list that names its LLM providers, which is unusual and worth crediting. Its integrations directory is the broadest published ledger coverage in the roster, including QuickBooks Online and Desktop, Xero, NetSuite, Sage Intacct, Sage 100 and 300, Dynamics Business Central and F&O, Workday Financial Management, Acumatica, Oracle Fusion Cloud and, notably, the AI-native ledgers Puzzle and Digits. Pricing is published: Free at $0 per user per month, Plus at $15 per user per month plus a platform fee that scales with team size, and a custom Enterprise tier.

    What is not disclosed:data residency and retention. A customer DPA download was not confirmed. And we are deliberately leaving its FedRAMP status out: the trust centre lists FedRAMP Moderate, GovRAMP, TX-RAMP and Cyber Essentials Plus, but we could not distinguish “In Process” from “Authorized” and could not retrieve the FedRAMP Marketplace record to check. If that matters to you, check it manually.

    Who it fits: firms running client-side spend for a book of business that already lives on a mainstream ledger. Who it does not:anyone hoping to buy the AI layer and point it at another card programme. The agents run on Ramp's own card and bill-pay rails; it is locked to the suite by design. Its autonomy is real — it will rebook a hotel automatically when the price drops by a set threshold — which means the policy bounds you set are the whole control surface. Ownership: private and independent; no acquisition or rename found, though that is absence of evidence rather than a cleared search, and we could not verify the legal entity because the legal pages are JavaScript-rendered.

    2. BILL — compliance claims made in an SEC filing

    What it does:two things, and the firm-facing one matters most. There is the client-side platform — bill capture to a dedicated inbound email address, coding, approval routing, payment, two-way ledger sync — and there is the Accountant Console, where a firm manages many client entities from one login at wholesale pricing it can resell.

    What is verifiable:uniquely well, because the claims sit inside a Form 10-K. BILL Holdings, Inc. trades on the NYSE under BILL, SEC CIK 0001786352, and filed its FY2026 10-K on 20 August 2026 — three days before this article. That filing states verbatim that the company has certified its platform to SOC 1 Type II and SOC 2 Type II standards, that its security program is aligned to the NIST Cybersecurity Framework, and that it maintains PCI DSS compliance for payment card data. It is the highest-accountability venue any compliance claim in this roster appears in. The same filing names the integrations — QuickBooks Online, QuickBooks Desktop, Oracle NetSuite, Sage Intacct, Xero and Microsoft Dynamics 365 Business Central, with two-way synchronisation of customers, suppliers, GL accounts and transactions — and gives the scale figures as of 30 June 2026: roughly 479,300 businesses and about $371.3 billion in total payment volume for fiscal 2026. Pricing is published, including accountant partner pricing at $49 per month for AP and AR.

    What is not disclosed:ISO 27001 is not claimed. The DPA URL returns a 404. Residency and retention are not published. Neither Pub 4557 nor the FTC Safeguards Rule is mentioned anywhere — and BILL handles W-9s, which are taxpayer-identifying, so that silence is worth a sentence in your diligence file.

    Who it fits: firms running AP for a book of clients who want a resellable console and mainstream ledger sync. Who it does not:firms expecting a mature agent layer. The 10-K itself calls this the company's firstsuite of AI agents. A launch release in October 2025 named a BILL Reconciliation Agent; the product page now calls it the BILL Transaction Agent. A renamed agent inside ten months is a fair signal of how young this is. Note also that two-way sync with QuickBooks Enterprise, NetSuite, Sage Intacct and Dynamics, plus API access, SSO and dual control, sits in the custom-priced Enterprise tier — the mid-market connectors are not in the published prices. Ownership: public and independent; no 2025 or 2026 acquisition of or by BILL is disclosed.

    3. MindBridge — the strongest certification stack, and honest about not being an agent

    What it does: ingests a full general ledger rather than a sample and scores every transaction for risk, so the auditor directs testing at the anomalous population instead of a random one. Risk assessment, journal-entry testing, continuous monitoring.

    What is verifiable:the deepest certification stack found anywhere in this research — SOC 1 Type 2, SOC 2 Type 2, SOC 3 Type 2, ISO/IEC 27001:2022, ISO/IEC 27017:2015 for cloud controls and ISO/IEC 27018:2019 for PII in the cloud, all published through a trust centre. Integrations are named: Xero, Databricks and Fieldguide, plus connectors for Databricks, Snowflake, Azure Data Factory and Microsoft Fabric, with more than 100 API endpoints. It is also the only vendor in the roster with a public developer portal, which is a real, checkable differentiator if you intend to wire anything into your own stack.

    What is not disclosed: pricing, DPA, residency, retention and model-training policy. Legal entity, funding and current CEO are not published either, so we are not printing them.

    Who it fits: assurance practices that want population-level risk scoring with an explainable method. Who it does not: anyone shopping for autonomy. MindBridge is explicit that its method is statistical models, business rules and unsupervised machine learning, with explainable insights and independent validation as headline principles. This is the vendor that could easily have relabelled itself agentic in 2026 and did not, which is why it is here: it makes the difference between analytics, a copilot and an agent concrete. Ownership: headquartered in Ottawa, founded 2015, active and independent as far as we could establish.

    4. Fieldguide — the strongest genuinely agentic audit product

    What it does: named agents by engagement phase. Field Planner handles planning with evidence; Field Auditor drafts requests and runs population analysis, sampling, substantive testing and controls testing; Field Reviewer checks completeness and exceptions before sign-off; Field Financials drafts financial statements; Field Orchestrator is the single engagement interface. There is also a Fieldguide MCP server, embedded AI, a client hub and a practice dashboard.

    What is verifiable:SOC 2 Type II audited annually, ISO 42001 and an AIUC-1 attestation; a publicly offered DPA with standard contractual clauses; and an unusually transparent subprocessor list naming fourteen parties including its cloud, model and vector-store providers. Ownership is on the public record: a $75M Series C led by Growth Equity at Goldman Sachs Alternatives announced 2 February 2026, with Geodesic joining and Bessemer, 8VC and Thomson Reuters existing, taking total funding to $125M at a $700M valuation. On the classification, the vendor's own framing is the right one — agents execute routine engagement testing, and every output runs through a review space where the team checks the work and signs off.

    What is not disclosed:pricing, retention and model-training policy — the last a notable gap against peers who commit explicitly. There are no named integration partners; the integrations page describes categories only, plus an open REST API. Do not infer US-only residency from the trust page: the subprocessor list includes a Canadian vector store and several worldwide providers. And read its FedRAMP announcement carefully. A page dated 20 August 2026 states that Fieldguide's FedRAMP Certified Class C (Moderate)federal environment is now live — but neither “FedRAMP Certified” nor “Class C” is FedRAMP's own status vocabulary, which runs Authorized, In Process and Ready at Low, Moderate and High impact levels. Quote the vendor; do not upgrade it.

    Who it fits: assurance-heavy firms with the review discipline to use supervised autonomy properly. Who it does not: tax-first practices, and anyone who needs a named integration list before they can architect anything.

    5. Canopy — the only vendor whose true cost with AI you can calculate

    What it does:the firm's client hub — client records and documents, portal uploads, workflows, invoicing and payments — plus a Tax Resolution module for IRS transcripts and notice handling that few competitors match. The AI layer is Canopy Coworker, described by the vendor as a supervised digital coworker that coordinates and executes work across tasks and workflows, alongside a Notetaker assistant, Tax Workflow Automation and Smart Intake.

    What is verifiable:the strongest US tax-software integration coverage in the entire roster — QuickBooks Online, Xero, UltraTax, Intuit ProConnect, ProSeries, Lacerte, CCH Axcess Tax, Drake Tax, TaxWise, plus IRS Transfer, Excel, Google Sheets, Zapier, Salesforce and a documented API. That contrast is worth printing on its own: Canopy ships UltraTax, Lacerte, CCH Axcess Tax and Drake today, and Karbon ships none of them. Security specifics include 256-bit encryption in transit and at rest, MFA and SSO, role-based permissions and automated PII field masking for SSNs, birthdays and TINs— a genuinely taxpayer-data-relevant control. And pricing is the most granular published anywhere here.

    What is not disclosed: ISO 27001, and a DPA is not referenced anywhere including the privacy policy. Read the SOC 2 wording: Canopy says SOC 2 Type II compliant rather than certified, and names no auditor and no report period. Neither Pub 4557 nor the Safeguards Rule appears on the security page, which for a product whose entire job is holding taxpayer documents is a legitimate criticism to raise in a sales call.

    Who it fits: US tax and advisory practices on Thomson Reuters, Intuit, Wolters Kluwer or Drake stacks that want one client hub across all of them. Who it does not:anyone budgeting from the seat price alone. The AI and automation modules are metered separately — Tax Workflow Automation from $34 per credit per client, Close Automation at $10 per connected client per month with the first five included, Tax Resolution at $50 per user per month, knowledge-based authentication at $1.25 per credit. A ranking that quotes $74 as Canopy's price understates it, and Canopy is the only vendor honest enough to let you find that out.

    6. Basis — the best certification trio on a firm-side agent, and zero documented integrations

    What it does: agents across CAS and advisory close, tax intake through review-ready workpapers, audit testing with evidence citation, and corporate accounting. It ingests client documents and ERP data, extracts, calculates, validates and produces workpapers and reconciliations.

    What is verifiable:SOC 2 Type II, ISO 27001 and ISO 42001 for AI management systems — the best certification trio on any firm-side agent here — plus AES-256 at rest, US-only data storage and an explicit pledge that customer data never trains or improves any AI model. Ownership is public record: a $100M Series B at a $1.15B valuation announced 24 February 2026 led by Accel with GV, Khosla and others, taking total funding to $138M. On architecture it is the strongest genuine claim in its category — agents run continuously in the background and return completed deliverables, putting the human at the review gate rather than the keystroke gate.

    What is not disclosed:a great deal, and the gaps are load-bearing. There is no documented integration list at all — both the integrations and product pages return 404, and trade coverage says only “accounting systems and ERPs”. Pricing is not published; that page 404s too. No DPA is stated. GDPR and CCPA are marked “coming soon”, which you should read literally if you have EU exposure. And neither Pub 4557 nor the Safeguards Rule is mentioned, despite the product preparing partnership returns.

    Who it fits: larger firms with the internal capacity to run a proof-of-concept and negotiate their own terms. Who it does not:anyone who needs to know what it connects to and what it costs before a sales call. On the widely-quoted efficiency range of 20% to 50% across practices — note who said it. That is Vinod Khosla, an investor in the round, not an independent assessor.

    7. Blue J — the best-documented data handling in the roster, and not an agent

    What it does: a practitioner asks a natural-language question about US federal, state or local, Canadian or UK tax law and gets a written answer with linked citations to primary authority. It replaces the search-and-read loop for the research step. It does not prepare returns and does not touch workpapers.

    What is verifiable:more of the things that actually matter for client confidentiality than anyone else here. Blue J Legal Inc. is incorporated in Ontario — the only vendor whose exact legal entity we confirmed from a primary source, its own terms of use. It holds SOC 2 Type 2, maintained annually with the report available under NDA. Its DPA is a public standalone page. Residency is stated with unusual precision: all data stored and processed in the United States in the AWS us-east-1 region — relevant if you are a UK or Canadian subscriber, because the company is Canadian and the data is not. Retention is committed: uploaded customer files older than 24 hours are automatically deleted daily. And the model-training statement is the strongest in the roster because it binds the subprocessors — customer data is not used to train generative AI models, and Blue J states it has supplementary signed agreements with both OpenAI and Google prohibiting them from training on any data coming from Blue J. Funding is on record: a US$122M Series D in August 2025 co-led by Oak HC/FT and Sapphire Ventures, with CPA.com among the investors, at a valuation above US$300M. Pricing is published at $1,498 per user per year for the Individual plan.

    What is not disclosed:ISO 27001, and no integrations are named at all — there is no tax-software connection published. Worth noting as an absence: no accuracy or hallucination rate is published anywhere on the site, which for a tax research product is the number a reader would most want.

    Who it fits: practitioners who want defensible answers with citations they can open. Who it does not:anyone looking for autonomy. Blue J makes no autonomy claim anywhere, and that looks like a deliberate design choice for a domain where a wrong answer is malpractice exposure. In a list called AI agents, it is the entry that is not one — and it is here because that honesty is itself a scored attribute.

    8. Digits — the only vendor publishing firm tiers, and the highest switching cost

    What it does: an AI-native general ledger that replaces QuickBooks or Xero rather than sitting on top of one. Its Agentic Close, launched 8 June 2026, runs a six-stage loop: Collect, Book, Reconcile, Schedule, Review, Report.

    What is verifiable: SOC 2 Type II compliance, TLS in transit, per-secret envelope encryption and encryption at rest. Digits Financial, Inc. is a San Francisco company founded in 2018 by Jeff Seibert and Wayne Chang, with Benchmark, GV and SoftBank named as investors on its own site. It ships a developer API and an MCP server, which is a real differentiator for a firm wiring the ledger into its own agents, and it names 2026 partners in Ignition, Karbon and Reach Reporting. Its autonomy description is the most honest in the set: clear-cut issues are resolved automatically, and issues requiring judgement are escalated to a checklist with context and a recommended action. Manage by exception. It is also the only vendor in the entire roster that publishes firm tiers — per client per month, from $35 to $250 depending on tier and book size.

    What is not disclosed:ISO 27001, residency, retention, DPA, subprocessors and — notably for a vendor training its own models — any model-training policy at all. Pub 4557 and the Safeguards Rule are not mentioned. One oddity in the published pricing to re-check on the live page before you plan around it: mid-sized firms pay more per client than solo practices at the lower tiers.

    Who it fits: CAS practices building a book on a modern ledger from the start. Who it does not: anyone with an established client base. Adopting Digits means migrating each client off QuickBooks or Xero, which is the highest switching cost in this roster. On the vendor's claim that its models outperform frontier LLMs by 43% on accounting tasks — that is a self-reported internal benchmark with no published methodology and no named comparators. Attribute it or ignore it.

    9. Black Ore Tax Autopilot — the most autonomous product, and the only real answer to the offshore question

    What it does: end-to-end 1040 preparation. It ingests W-2s, 1099s, K-1s, brokerage statements and bank records; classifies and extracts; resolves discrepancies; applies tax-code logic; computes federal and state returns; generates workpapers; auto-creates client data requests for missing items; flags anomalies; and produces an audit package. Firms queue returns in batches and come back to a review-ready product. It reached general availability on 29 April 2026 after a two-year early-access programme.

    What is verifiable: SOC 2 Type II, audited annually against the AICPA Trust Services Criteria for Security, Availability and Confidentiality, and independently corroborated in trade coverage; AES-256 at rest, TLS 1.2 and above, role-based access control with field-level granularity, SSO and MFA, full audit logging and quarterly reviews. Funding is on record: $60M out of stealth on 7 November 2023, co-led by a16z and Oak HC/FT, founded by Eyal Shinar and Pavel Kapovski. And then the field that decides the shortlist for a 1040 shop: US-based, SOC 2-audited data centres, with no offshore or third-party processing — the most specific residency commitment in the roster, and the closest thing in this market to an answer to the §7216 offshore problem, even though the vendor never says so. Its model-training statement is unusually specific too: client documents are never used for model training or cross-firm optimisation.

    What is not disclosed:pricing, ISO 27001 and a DPA. And there is a trap in the integrations. The site lists ATX, CCH Axcess Tax, CCH ProSystem fx, Drake, GoSystem Tax RS, Lacerte, ProConnect, ProSeries and UltraTax CS — in an intake-form dropdown, not as documented integrations, with no indication of live versus planned. Both trade write-ups say only that it connects with major tax software platforms, naming none. Do not plan around a connector on that basis.

    Who it fits: 1040 volume shops with review capacity and offshore concerns. Who it does not:firms whose work is advisory rather than volume compliance. On the vendor's numbers — the CEO's claims of 100% touchless for straightforward returns and about 98% touchless for complex ones are his characterisation, not a measured result, and he notes a human CPA is needed for attestation and edge cases. The independent evaluation question was checked and is explicitly absent: CPA Practice Advisor's own write-up attributes every metric to Black Ore's early-access participants.

    10. DataSnipper — the incumbent, and the most honest agent labelling

    What it does:lives inside Excel. Auditors tick and tie — match a workbook line to the underlying PDF invoice or bank statement, extract the field, leave a clickable cross-reference in the workpaper. Disclosure Agents run an IFRS or US GAAP disclosure checklist against a set of statements, linking each disclosure to evidence. DocuMine answers questions across long documents such as leases and board minutes with source text highlighted for approve or reject. ADE extracts at volume, and UpLink is the client request portal.

    What is verifiable:SOC 2 Type II, GDPR, and participation in the EU-U.S. Data Privacy Framework. The DPA is publicly offered and versioned — the current version is dated 1 June 2026 — alongside an AI Terms addendum, a Data Act addendum and a public sub-processor list. Retention is specific and good: DocuMine stores input for up to 24 hours, ADE deletes processed documents within 24 hours, and UpLink's external LLM provider operates on zero data retention. Model training is an explicit no: DataSnipper states it does not fine-tune or train any AI on customer data. It is also the acquirer rather than a target, having bought UpLink on 15 October 2024, and raised a $100M Series B led by Index Ventures at a $1B valuation.

    What is not disclosed:pricing — three tiers are named with no figures — and no regional residency guarantee. ISO 27001 is not claimed on its own security page, despite a secondary source asserting it, so we are not printing it. There are no named third-party integrations; the one hard dependency is Microsoft Excel, which is the distribution model rather than an integration. Its compliance framing is EU-first, and Pub 4557 does not appear.

    Who it fits: audit teams whose workpapers already live in Excel and who want cross-referenced evidence without changing where they work. Who it does not:firms wanting a system of record rather than an add-in. On classification, the vendor is refreshingly honest: the original tick-and-tie is deterministic matching rather than AI, and the 2025 to 2026 agent layer is prompt-driven but explicitly bounded — DocuMine's stated method is ask, review, approve. DocuMine was named to TIME's Best Inventions 2025, which is the strongest third-party signal in this roster and is an editorial award, not an accuracy benchmark.

    Five More Worth Knowing, and Four You Must Not Rank

    Five products missed the ten for reasons worth stating, because in three cases the reason is more useful than the ranking. A shortlist is built from exclusions as much as inclusions, and these are the exclusions we would want explained to us.

    Liscio — the only vendor in ~25 that names Pub 4557 and the Safeguards Rule

    Liscio is the client-document-collection layer for tax and bookkeeping firms: branded portal and mobile app, text-based messaging, a unified timeline across email, messages, files and signatures, smart client requests, a smart tax organiser and tax delivery, and e-signature. Its integrations are published in full — Adobe Sign, GruntWorx, Outlook, Gmail, OneDrive, Google Drive, SmartVault, Zoom and Calendly — and pricing is published from $19 to $99 per user per month. It is deliberately standalone: its own copy says you do not have to replace your tax software.

    It matters here for one reason. Its FAQ states that it is SOC 2 certified and built to support FTC Safeguards Rule obligations and IRS Publication 4557, and it publishes substantive editorial correctly citing the Safeguards Rule at 16 CFR Part 314 and the WISP control areas. That makes it the only vendor of roughly twenty-five examined that engages with the rules a US tax firm actually operates under. It did not make the ten because its own disclosure is thinner than theirs: the homepage says SOC 2, not SOC 2 Type II, and the “built to support” phrasing is a support claim rather than a certification; there is no dedicated security or trust page, both candidate URLs 404; and no ISO 27001, DPA, residency or retention commitment is published. Its subprocessor list also names Mistral AI SAS, a French LLM provider, processing firm document data — which, absent a residency statement, is a fair question to put to them. It is also not an agent: its File Intelligence suggests standardised filenames, and files the system is not certain about are not renamed. That is confidence-gated classification with a human fallback, which is real value and zero autonomy.

    Suralink — the most genuinely agentic PBC tooling, and the weakest disclosure

    Suralink runs the PBC request list for audit, tax, advisory and internal audit, and its agent library is the most convincingly agentic thing we found in this workflow: a Document Prescreen Agent triggered automatically on upload, a Data Vouching Agent triggered when a request is fulfilled, plus Mathematical Accuracy, Internal Consistency, Prior Year Consistency and Version Comparison agents. These fire without being asked, which is the real test. It also exposes engagement data to third-party AI assistants including Claude and Microsoft Copilot rather than only running its own, which is a genuinely differentiated 2026 posture, and integrates natively with Outlook, Trullion and DataSnipper.

    It is excluded from the ten on disclosure. Its security page defines SOC 2 — describing it as developed by the AICPA with five trust service principles — without ever stating that Suralink holds a SOC 2 Type II report; SOC 1 and SOC 3 are referenced as data-centre certifications, meaning the hosting provider's. We are not printing a SOC 2 claim for Suralink because their own page does not support one. ISO 27001, DPA, residency and retention are all absent, GDPR and CCPA are self-declared, and pricing is not published. Note also that its agent library page states no explicit human-in-the-loop gate — unlike Karbon and Stampli, which do. And its integration directory still lists Materia, which was acquired in October 2024 and whose domain returns a 404: a live illustration of how stale these directories get.

    Karbon, Thomson Reuters CoCounsel and Numeric

    Karbon is the firm's operating system — shared email triage tied to client records, job and workflow templates, capacity planning, timesheets — with a large live integration directory including QuickBooks Online Accountant, Xero, ProConnect, Ignition, Liscio, Soraban, Dext and StanfordTax, and published pricing at $59 and $89 per user per month billed annually. Two things keep it out. First, the product name most rankings use is dead: the Karbon AI URL now 404s and the 2026 product is Kai. Second, and decisively, Karbon's own site says Kai is available in limited early access with capabilities growing each week — it is not generally available, and whether it is bundled or priced as an add-on is not disclosed. Credit where it is due, though: Karbon publishes the most candid negative disclosure we found anywhere, stating plainly that an ISMS has been implemented in accordance with ISO 27001 requirements but that Karbon has not yet been independently certified as ISO 27001 compliant. Most competitors simply omit the topic. Note also that UltraTax and Lacerte are not in its directory at all, and CCH Axcess is listed as coming soon.

    Thomson Reuters CoCounsel is the suite-locked incumbent, and the 2026 product names are worth getting right: CoCounsel Tax, CoCounsel Tax Essentials, CoCounsel Audit and Accounting, plus Ready to Review — a cloud-based agentic AI tax workflow application automating 1040 preparation, generally available in the US since December 2025 — CoCounsel Document Analysis, generally available January 2026, Audit Intelligence Test, generally available November 2025 and built with Valid8 Financial, and Guided Assurance. The content moat is real: authoritative AICPA, FASB, GASB and IFRS material now sits inside it. It is excluded because it is sold to firms already inside the Thomson Reuters ecosystem, we could not fetch its trust documentation to verify any certification, and — importantly — neither product release names an integration with UltraTax CS, GoSystem Tax RS, SurePrep or Checkpoint, so we will not assert one even though TR owns those products. The structural observation is more interesting than the entry: Thomson Reuters is quietly consolidating this category, having acquired Materia, invested in Fieldguide's Series C and in Truewind through TR Ventures, and partnered with Trullion through Guided Assurance.

    Numeric is close-management software with AI features, and we rank it honestly as not an agent — two hard tells being that its own $51M funding release never uses the word agents and that its product pages market an AI assistant and an AI rule builder. It is Velocity Labs Inc. DBA Numeric, independent, with named integrations to NetSuite, QuickBooks Online, Xero and Sage Intacct and a published entry price of $30 per user per month. It is excluded on the weakest public compliance posture in the roster: no SOC 2 claim is publicly verifiable, and its security, trust and compliance URLs all fail. Given its customer list that almost certainly reflects documentation rather than reality — but we print only the verifiable version, which is that no public trust page could be found.

    Four names that appear in competing 2026 rankings and must not appear in yours. Botkeeper shut down in February 2026 after eleven years and roughly $90M raised, with CEO Enrico Palmerino describing a perfect storm of macroeconomic shifts that arrived more swiftly than the company could course-correct, and saying it did not reach a level of product-market fit strong enough to withstand rapid industry shifts. Materia was acquired by Thomson Reuters on 22 October 2024; materia.ai returns a 404 and www.materia.ai redirects to an unrelated company. Klarity became Within on 6 August 2026 and left accounting entirely. AvidXchangecompleted its go-private transaction on 15 October 2025 with TPG affiliates and Corpay co-investing, per its own Form 8-K; EDGAR now returns no ticker and no exchange, and its last filing is a Form 15-12G. Its investor relations site redirects to marketing. It is still operating — it announced a completed Workday integration in June 2026 — but any 2026 article describing it as publicly traded is wrong.

    Vendor continuity deserves to be a ranking criterion, and Botkeeper is why. Eleven years, roughly $90M raised, sold specifically to accounting firms, dead with weeks of notice. Read the funding column of any shortlist with that in mind: Double's $6.5M Series A of December 2025 is the second-smallest raise in this market, and Booke AI has no institutional funding we could verify at all. That is not a reason to avoid small vendors. It is a reason to ask, before you migrate a client book onto anything, what happens to your data and your workflow if the vendor gives you six weeks' notice.

    The Binding Constraint: IRC §7216, and Why No Vendor Mentions It

    Sending client tax data to a third-party AI vendor is a disclosure of tax return information by a tax return preparer, and getting it wrong is a criminal misdemeanour. That sentence is the most important one in this article, and it appears on no vendor website we examined.

    IRC §7216(a) provides that a person engaged in the business of preparing returns who knowingly or recklessly discloses any information furnished for, or in connection with, the preparation of any such return — or uses any such information for any purpose other than to prepare or assist in preparing the return — shall be guilty of a misdemeanor, punishable by a fine of not more than $1,000 (or $100,000 where §6713(b) applies), or imprisoned not more than 1 year, or both. Alongside it sits §6713, a civil penalty of $250 per disclosure or use, capped at $10,000 per calendar year. Two things about §6713 are routinely got wrong: those figures are not inflation-adjusted — the statute contains no adjustment provision and there is no revenue procedure updating them, so a writer who modernises them like a §6695 penalty prints a wrong number — and §6713 has no scienter requirement. The knowingly-or-recklessly language in §7216(a) is simply absent from §6713(a). For a firm piping returns through a vendor without consent, the civil penalty is effectively strict liability, per disclosure.

    The vendor is itself a tax return preparer. 26 CFR §301.7216-1(b)(2) defines the term to include any person engaged in the business of providing auxiliary services in connection with the preparation of tax returns, including a person who develops software that is used to prepare or file a tax return, and any Authorized IRS e-file Provider. Read that twice. An AI vendor that develops or operates software used to prepare a return is a tax return preparer for §7216 purposes, and the criminal exposure runs to the vendor as well as to you.

    And the agent's output is itself tax return information. §301.7216-1(b)(3) defines the term to include information the preparer derives or generates from tax return information in connection with preparing a taxpayer's return. A summary, memo, workpaper or reconciliation an AI agent generates from a client's return data is covered by the statute in its own right. Feeding that output into a second tool is a second disclosure. This is the point where a modern multi-vendor stack — document intake here, extraction there, a research tool for the position, a review layer at the end — quietly becomes four disclosures rather than one.

    The three tests a vendor must pass to be used without taxpayer consent

    1. 1.Located in the United States. 26 CFR §301.7216-2(d)(1) permits disclosure to another tax return preparer located in the United States for the purpose of preparing or assisting in preparing a return, or obtaining or providing auxiliary services. Any processing outside the US — inference, storage, support, human review — falls outside the exception and requires consent. There is no workaround.
    2. 2.Auxiliary services only, meaning not substantive determinations or advice affecting the tax liability reported by taxpayers. An agent doing OCR, data entry or organiser intake is on the right side of that line. An agent that proposes positions, elections or treatments is on the wrong side and requires written consent under §301.7216-3.
    3. 3.Or, in the software and equipment lane, §301.7216-2(d)(2): disclosure is permitted for programming, maintenance, repair, testing or procurement of equipment or software used for tax return preparation, only to the extent necessary, and only if the preparer ensures that everyone receiving the information receives a written notice informing them of the applicability of §§6713 and 7216 and describing the requirements and penalties. Almost no firm does this.

    Offshore is the constraint that catches most SaaS AI stacks. Consent is mandatory for any disclosure to a preparer located outside the United States. Beyond that, a US preparer may not obtain consent to disclose the taxpayer's Social Security number to a preparer located outside the United States — the SSN must be redacted or masked unless both ends maintain an adequate data protection safeguard. The governing consent rules are Rev. Proc. 2013-14, as modified by Rev. Proc. 2013-19, which only extended the effective date of the mandatory language. There is no successor; a newer revenue procedure number is invented.

    The consent itself has to be written, knowing and voluntary, and opt-out consents are prohibited. Rev. Proc. 2013-14 §5.04(2) states that a consent requiring the taxpayer to remove or deselect disclosures or uses the taxpayer does not wish to be made — an opt-out consent — is not permitted. A pre-ticked checkbox buried in an engagement letter is void. Where the disclosure is offshore, §5.04(1)(e)(i) prescribes the language: “This consent to disclose may result in your tax return information being disclosed to a tax return preparer located outside the United States.”

    The practical shortlist rule this produces. If any inference, storage, support or human review happens outside the United States — true of a great many SaaS AI stacks — written taxpayer consent in the Rev. Proc. 2013-14 format is mandatory, with the exact statutory language, and the SSN must be masked absent an adequate data protection safeguard. That is why Black Ore's commitment to US-based data centres with no offshore or third-party processing is the most commercially significant sentence any vendor in this roster publishes, and it is striking that the vendor itself does not appear to know why. Ask every shortlisted vendor, in writing: where does inference run, where is data at rest, where does your support team sit, and does any human ever see this data outside the United States.

    Now the finding. Across roughly twenty-five vendors examined for this article on 23 August 2026, exactly one — Liscio — names IRS Pub 4557 and the FTC Safeguards Rule on its own site, and not one mentions §7216. Not the products preparing 1040s. Not the ones holding taxpayer document custody. Not the ones running 1099 and W-9 workflows. Not the ones producing partnership returns. That absence is not evidence of bad faith; it is evidence that this market has been built by software companies for software buyers, and that the compliance analysis is yours to do. A vendor's SOC 2 Type II report supports your written information security program. It does not discharge your obligations, and no contractual indemnity turns a criminal statute into someone else's problem.

    Circular 230, the Safeguards Rule and the AICPA Code

    There is no AI-specific accounting standard in force anywhere in US audit or tax practice as of 23 August 2026 — not at the AICPA, not at the PCAOB, not in Circular 230. Every binding constraint is a pre-existing, technology-neutral rule that AI happens to trip: audit-evidence reliability, due care and supervision of anything you outsource, confidentiality of client information, the Safeguards Rule's service-provider oversight duty, and the criminal statute above. All of them applied to your vendor on the day you signed, and none of them needed an AI rule to bind an AI agent.

    Circular 230 was never amended. This is the fact most likely to be printed wrong.

    Checked against the Federal Register on 23 August 2026, every document affecting 31 CFR Part 10 published since 1 January 2024 returns exactly one result: a proposed rule, REG-116610-20, published 26 December 2024 at 89 FR 104915. The IRS's own printed Circular 230 remains Revision 6-2014, and §§10.22(b), 10.35 and 10.36 each carry an applicability date of 12 June 2014. Anyone writing that the rules were updated in 2025 or 2026 is working from memory rather than the register.

    What the existing text actually says matters more. §10.22 requires due diligence in preparing, approving and filing returns, and §10.22(b) is the AI paragraph: a practitioner is presumed diligent where they rely on the work product of another person and used reasonable care in engaging, supervising, training, and evaluating that person. There is no analogue for reliance on a model, and no IRS guidance extending it to one. That is an unresolved gap, not a safe harbour, and it is the paragraph most likely to be misquoted in your favour. §10.34 bars signing a return the practitioner knows or reasonably should know contains an unreasonable position, and §10.34(d) permits good-faith reliance on client-furnished information while forbidding the practitioner to ignore the implications or skip reasonable inquiries where the information appears incorrect. §10.35 requires competence. §10.37(b) provides that reliance on another's representations or findings is not reasonable where the practitioner knows or should know that person lacks the necessary competence or qualifications.

    The cleanest “you need a written AI policy” citation in tax practice is §10.36. Any individual with principal authority for overseeing a firm's federal tax practice must take reasonable steps to ensure the firm has adequate procedures in effect for Circular 230 compliance, and is subject to discipline for willful, reckless or grossly incompetent failure to do so where firm members engage in a pattern or practice of noncompliance. A firm-wide AI rollout with no written procedures is a §10.36 exposure for the partner in charge. And on signing: an AI agent cannot hold a PTIN and cannot be a signing preparer. §10.34(a) attaches liability to the signature. The human who signs carries the §10.22 diligence duty, the §10.34 position standards and IRC §6694 preparer-penalty exposure for whatever the agent produced.

    The Safeguards Rule makes your AI vendor a service provider

    16 CFR §314.2(h) states that an accountant or other tax preparation service in the business of completing income tax returns is a financial institution, because tax preparation services is a financial activity. The FTC's own compliance guide lists tax preparation firms among its examples, and IRS Pub 4557 puts it flatly: tax and accounting professionals are considered financial institutions regardless of size. The same section defines a service provider as any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution — which an AI vendor plainly is, by the plain terms of the definition.

    That triggers §314.4(f) in full: take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards; require them by contract to implement and maintain those safeguards; and periodically assess them based on the risk they present and the continued adequacy of their safeguards. Periodically assess is the clause with teeth here, because it makes vendor diligence a recurring obligation rather than a procurement event — and this category re-releases products every few weeks. The rest of §314.4 still applies too: a designated Qualified Individual, a written risk assessment, encryption of all customer information in transit and at rest, MFA for anyone accessing any information system, monitoring and testing, training, a written incident response plan, and an annual written report to the board or a senior officer. The small-entity relief for institutions holding information on fewer than 5,000 consumers is real but narrow — and it does not exempt §314.4(f).

    Get the breach-notification date right, because most published content does not. The amendment was published 13 November 2023 at 88 FR 77499, and its DATES section states that the amendments are effective May 13, 2024. The widely-circulated 27 October 2023 date is the FTC press release, not the rule. Substantively, §314.4(j) requires notifying the FTC as soon as possible and no later than 30 days after discovering a notification event — unauthorised acquisition of unencrypted customer information of 500 or more consumers, with unauthorised access treated as acquisition unless reliable evidence shows otherwise — and the report may be made public. Note also that Pub 4557 (Rev. 6-2024) and Pub 5708 (Rev. 8-2024) are both 2024 documents and neither mentions artificial intelligence; do not attribute AI guidance to either.

    The AICPA Code: the client has a veto

    The provision that most directly governs plugging an AI vendor into an engagement is ET 1.300.040, Use of a Third-Party Service Provider: before using one, the member should ensure it has the required professional qualifications, technical skills and other resources, and the member must adequately plan and supervise its professional services so that they are performed with competence and due professional care. Sitting above it is the General Standards Rule at ET 1.300.001 — professional competence, due professional care, planning and supervision, and obtaining sufficient relevant data to afford a reasonable basis for conclusions. Note the common citation error: ET 1.300.010 is the Competence interpretation under the rule, not the rule itself. Note also that due professional care is not an AU-C 200 requirement paragraph; in the AICPA framework it is a Code duty, and in the PCAOB framework it is AS 1000 ¶.09.

    Before disclosing confidential client information to a third-party service provider, the member should inform the client, preferably in writing, that the member may use a third-party service provider. If the client objects to the member's use of a third-party service provider, the member either should not use the third-party service provider to perform the professional services or should decline to perform the engagement.

    AICPA Code of Professional Conduct, ET 1.150.040 ¶.02

    The client gets a veto, and almost nobody knows it. There is a trap alongside it. ET 1.700.001 provides that a member in public practice shall not disclose any confidential client information without the specific consent of the client, and ET 1.700.040 ¶.02 permits either a contractual agreement with the provider to maintain confidentiality and provide reasonable assurance of appropriate procedures, or specific client consent. Read alone, that says a good master services agreement is enough. Read together with ET 1.150.040, a confidentiality clause in the vendor MSA does not obviously discharge the separate notice duty. The Journal of Accountancy's September 2024 treatment of outsourcing and professional liability is the useful AICPA-published cross-reference: the Code permits either route, and risk management recommends both.

    One genuinely open question deserves to be left open. ET 1.150.040 ¶.03 carves out administrative support requiring no client notice, naming record storage, software application hosting and authorised e-file tax transmittal services. Whether an autonomous agent that performs professional services falls inside that carve-out is unsettled, and there is no AICPA interpretation resolving it. Anyone who tells you the answer — in either direction — is guessing. A source note in fairness: the live AICPA Code viewer requires a login and the download page 404s, so these citations come from the AICPA's own published Code PDF via the Internet Archive. Treat the text as reliable and the currency as unconfirmed.

    Audit evidence, and the PCAOB position that is constantly misreported

    SAS No. 142, Audit Evidence — which supersedes the prior AU-C 500 and is the current AU-C 500, effective for audits of financial statements for periods ending on or after 15 December 2022 — names the technology explicitly. Paragraph A4 lists artificial intelligence, machine learning, remote observation tools and robotic process automation as examples of other automated tools and techniques. Paragraph A27 then holds the line: the reliability attributes of accuracy, completeness, authenticity and susceptibility to management bias are also relevant when automated tools and techniques are used to obtain audit evidence. Paragraph 6 defines audit evidence as information to which audit procedures have been applied. Paragraphs 7 and 8 require the auditor to evaluate relevance and reliability including source, and to obtain evidence about accuracy and completeness as necessary. Paragraph 10 requires the auditor to resolve doubts about reliability — which is exactly the state a non-deterministic model leaves you in.

    So the answer to “can an AI agent's output be audit evidence?” is: not by itself. It is information. It becomes audit evidence only once the auditor applies procedures to it and evaluates it for relevance, reliability and source, and tests it for accuracy and completeness as necessary. There is no AICPA standard, interpretation or practice aid stating that an AI output is or is not audit evidence, and no writer should claim one exists.

    On the PCAOB side, three corrections. First, AS 1105 ¶.10A was adopted 12 June 2024, SEC-approved 20 August 2024, and is effective for audits of financial statements for fiscal years beginning on or after 15 December 2025 — calendar-year 2026 audits are the first ones covered. Second, the PCAOB did not defer or delay it. Release No. 2025-004, dated 18 September 2025, is a Board policy statement: where the auditor concludes there is no more than a remote possibility that information used as audit evidence has been modified in a way that would render it unreliable, the PCAOB will not treat the absence of the separate testing specified in ¶.10A(b) as noncompliance through its inspection or enforcement processes — with footnote 4 preserving the AS 1000 due-care and AS 1215 documentation duties. The effective date never moved, despite a July 2025 request from the Center for Audit Quality to defer parts of it. Third, there is no 2025 or 2026 PCAOB AI Spotlight. The only one is the July 2024 staff publication, which is expressly non-authoritative — it states on its cover that it represents the views of PCAOB staff and not necessarily those of the Board, and is not a rule, policy or statement of the Board — and which reported that GenAI use in issuer audits was concentrated in administrative and research activities rather than audit execution. A writer citing a 2026 Spotlight is inventing a document.

    A Worked Example, With Real Arithmetic

    This is an illustrative scenario, not a client outcome. We are not going to tell you a firm saw a 40% reduction in anything, because we would be inventing it — and an article that refuses unsourceable industry statistics and then asserts an unverifiable client result has destroyed its own standing. What follows is arithmetic built entirely from prices the vendors publish, which you can re-check on their pricing pages today.

    Consider a twelve-seat CPA firm: three tax partners, nine staff, roughly 300 individual returns, a 60-client bookkeeping and CAS book, and one small assurance practice. The partners want the AI layer costed properly before a committee meeting.

    What the published prices actually add up to

    Practice management with AI (Canopy). Twelve seats on the Standard tier at $74 per user per month billed annually is $10,656 a year. That is the number a competing ranking would quote. It is not the number. Tax Workflow Automation is metered separately from $34 per credit per client — across 300 returns that is on the order of $10,200 a year before volume discounts. Close Automation adds $10 per connected client per month after the first five: for 60 clients, roughly $6,600 a year. Tax Resolution, if the firm handles notices, is $50 per user per month. The realistic all-in is roughly two and a half to three times the seat price, and Canopy is the only vendor here that publishes enough for you to work that out.

    An AI-native ledger (Digits). Agentic Close sits in the $250 per client per month tier. Across the 60-client book that is $15,000 a month, or $180,000 a year — before the migration cost of moving 60 clients off QuickBooks or Xero, which is the largest hidden number in this whole exercise. Compare that with the firm's current ledger spend and the decision is no longer about features.

    Research and intake. Blue J is $1,498 per user per year: three tax partners is $4,494. Liscio's Tax Team tier at $99 per user per month across twelve seats is $14,256 a year, or $2,736 on the $19 Intelligent Files tier if only document intelligence is wanted. BILL's accountant partner pricing for AP and AR is $49 a month.

    What the arithmetic shows. A defensible stack for this firm lands in the low-to-mid five figures annually if it layers onto existing systems, and in the low six figures if it replaces the ledger. Neither of those numbers appears in any vendor comparison we found, because sixteen of the vendors examined publish no pricing at all. If a shortlist has three gated vendors on it, you cannot compare it until you have three quotes in writing — and you should insist those quotes separate seats from consumption.

    What that arithmetic does not capture is the build cost of the thing no vendor sells you: the connective tissue between these products and the systems your firm already runs on. That is the work we do. Our own ScoreBiz 360 merchant credit-scoring platform case study is the closest analogue we can point at honestly: a custom fintech web application built on React, TypeScript and Supabase, delivered in three months for under $30,000, serving more than 5,000 small businesses, and reported in that case study at 99.96% platform uptime with a 185ms average response time. It is not an accounting agent, and we are not going to pretend it is. It is evidence of what a regulated-adjacent financial build costs and how long it takes when the scope is drawn tightly — which is the same discipline this article is arguing for. If the underlying financial-platform engineering is what you are weighing, our guide to fintech app development in Los Angeles covers that ground in more depth.

    What Breaks First — and How You Detect It

    The characteristic failure of an accounting agent is not a crash. It is plausible, well-formatted, confidently wrong work that looks exactly like correct work. That is the failure a firm without a sampling process will not catch, and there is now independent research documenting the mechanism.

    The FinIndices preprint, submitted 22 July 2026, benchmarks data-processing fidelity over uncropped financial statements of up to 32,000 tokens and documents two failure modes. The first is a knowledge bottleneck: despite memorising formulas during pre-training, models demonstrate fragile pattern matching, and removing explicit formula hints causes performance to collapse — the authors report one frontier model dropping from 70.70% to 38.22% on table tasks. The second is a structural bottleneck: the cognitive load of generating multi-metric, multi-period tables actively drains reasoning capacity, and under structural pressure models that flawlessly execute isolated derivations regress to shallow heuristics such as fetching incorrect adjacent columns or substituting deep accounting adjustments with lazy literal arithmetic. Read that last clause again. It fetched the wrong column and did the easy sum. It did not tell you.

    • Silent regression under load. The agent that was reliable on a four-page statement degrades on a thirty-page one, and degrades toward plausible shortcuts rather than obvious errors. Detection: a fixed known-answer sample re-run weekly, scored automatically, with the score trended. Not spot-checks by whoever is free.
    • Prompt injection through client-supplied documents. Every agent here reads untrusted input — invoices, emailed bank statements, PBC uploads, brokerage PDFs, portal messages. Any of them can carry instructions aimed at the model. This is unsolved. Treat it as blast-radius reduction: no write credential live in a session reading untrusted content, least-privilege scopes, reversible writes, per-action logging.
    • Chart-of-accounts drift. A learned coding model trained on last year's behaviour quietly mis-codes after a client restructures its accounts. Detection: monitor the rate of human overrides per client per month, and alert when it moves — that number is a leading indicator and almost nobody tracks it.
    • Vendor version drift. This category ships every few weeks. A model swap or prompt change behind the same product name changes your output distribution with no notice. Detection: your own regression set, run against production output on a schedule, plus a subscription to every vendor changelog with a named owner.
    • A vendor that disappears. Botkeeper gave weeks of notice after eleven years. Detection is contractual, not technical: an exportability clause, a data-format commitment, and a written answer to what happens to our client data on termination, obtained before signing.
    • The review that stops being a review. The real failure mode in every regulated field is rubber-stamping — the queue gets long, the outputs look right, approval becomes a click. Detection: instrument review time per item and alert when the median falls below the time it physically takes to check the work.

    Underneath all of it sits the integration question, which decides how much autonomy is even available to you. An agent can only be as autonomous as its write path allows, and in accounting the write paths into tax packages and ledgers are narrow, vendor-discretionary and frequently undocumented — Black Ore's tax-package list is a dropdown, Fieldguide publishes no named partners, Basis publishes none at all. We work through that constraint properly in our guide to integrating AI agents with legacy and closed systems of record, and it is the piece of diligence most firms skip.

    Rollback should be a credential action, not a code change. The kill switch that works is one that revokes the agent's access token and leaves the humans with the queue. If your rollback plan requires a deployment, you do not have a rollback plan.

    The Human-in-the-Loop Boundary

    Every line in this table comes from a rule that already existed, not from our judgement. That is what makes it defensible where competing versions are not — and it is the reason no AI-specific standard was needed to answer the question of what an agent may do alone.

    An agent may act aloneNeeds documented human reviewMust never touch
    OCR and classification of client-supplied filesAny coding decision that lands in the general ledgerSigning a return — §10.34(a) attaches liability to the signature, and an agent cannot hold a PTIN
    Organiser intake, chasing missing documents, status chasingReconciliations and journal entries before the close is lockedSubstantive determinations or advice affecting tax liability — §301.7216-2(d)(1) puts this outside the no-consent lane
    Footing, cross-footing and internal-consistency checks on a draftAnything that becomes audit evidence — SAS 142 ¶¶7–8 require the auditor to evaluate relevance, reliability and sourceForming or expressing an audit opinion — the auditor must obtain sufficient appropriate evidence and exercise professional skepticism
    Prior-year comparison and version-diffing of report draftsPopulation selection and sampling judgementsDisclosing client data to a vendor the client has not been told about — ET 1.150.040 gives the client a veto
    Drafting internal memos and summaries — where the PCAOB's July 2024 Spotlight reported GenAI actually sat in issuer auditsAny output used to support a conclusion; it is information until procedures are applied to it (SAS 142 ¶6)Any processing outside the United States without Rev. Proc. 2013-14 consent — and the SSN must be masked absent an adequate data protection safeguard
    Anomaly flagging for human triage — MindBridge's entire designException resolution where the exception implies a misstatementClient-facing advice issued without practitioner review — §10.37(b) bars reliance on a source lacking the necessary competence

    Boundary derived from SAS 142, AU-C 200, Circular 230 §§10.34 and 10.37, the AICPA Code and 26 CFR §301.7216-2. Checked 23 August 2026.

    The extraction-friendly version, if you want one sentence for your engagement letter: an AI agent may classify, extract, chase, foot, cross-foot, compare and flag; a licensed practitioner must review anything that becomes audit evidence or lands in a general ledger; and no agent may sign a return, form an opinion, make a substantive determination affecting tax liability, or receive client data the client has not been told about. Prompt injection is unsolved, so that boundary is not a formality — it is the control.

    Cost and Timeline for a Custom Build

    Buy first where a product genuinely fits, and build only the connective tissue no vendor sells. Most firms in this market need less custom software than they think and more diligence than they expect. Where a build is the right answer — usually because the workflow crosses three systems that will not talk to each other, or because §7216 makes a hosted multi-vendor pipeline untenable — these are our bands. They do not vary by industry.

    EngagementRangeTimelineWhat is in scope
    Discovery + workflow audit$9k–$22k2–4 weeksWorkflow census across the tax, close and assurance calendar; a §7216 disclosure map naming every vendor that touches return information and where it is processed; vendor diligence file for §314.4(f); prioritised shortlist with a measurement baseline
    Single-workflow agent$28k–$70k4–9 weeksOne workflow end to end — organiser intake, document classification, a reconciliation, a PBC loop — with read integration to the systems of record, a human commit step, audit logging, and a review queue with timing instrumentation
    Multi-workflow platform with system integration$70k–$180k9–16 weeksSeveral workflows, write paths where the vendor supports them, an evaluation harness against a labelled sample, schema-drift tests in CI, per-client data isolation, and a reporting pack a partner can take to a peer review
    Enterprise / multi-site / regulated build$180k–$420k+14–24 weeksMulti-office rollout, per-tenant isolation, full audit pipeline with attribution that survives an inspection, step-up authorisation, WISP-aligned documentation, disaster recovery and restoration testing

    Senior-led delivery at $150–$225 per hour, ongoing retainers at $2,500–$9,500 per month, a 30-day post-launch warranty, and a fixed-price phased proposal within 5 business days of the discovery call. Full source-code and IP ownership transfers to you at the end — which matters more in this category than most, given how many vendors in it changed shape in the last eighteen months. We are a senior-led, Black-owned agency in Los Angeles, and you can reach us on +1 (424) 272-5601, book directly at calendly.com/frenchydigital/discovery-call, or read more about our AI agent creation service.

    The sequencing that works. Start with the disclosure map, not the tool selection: list every workflow that touches return information, name every vendor in the path, and record where each one processes and stores data. That artefact is what §314.4(f) diligence and any §7216 analysis both need, and it usually shortens the vendor shortlist by itself. Then run one workflow read-only against live data with the outputs reviewed against a labelled sample. Then put one reversible write behind a human commit. Then, and only then, consider narrow autonomy on a bounded class of low-consequence actions with a measured error rate and an automatic reversion rule. Firms that skip to step four are the ones who discover the structural bottleneck in a client deliverable.

    Red Flags When Evaluating a Vendor

    Every red flag below was observed in this research, on a live vendor page, in August 2026. None is hypothetical, and we have deliberately described the pattern rather than naming every vendor, because the pattern is what you need to recognise on the next call.

    • A published accuracy figure with no methodology, no denominator and no named comparator. One vendor in this roster claims 99.9 to 100% extraction accuracy. Document extraction does not reach 100%, and a vendor willing to print that will print anything.
    • An undefined denominator. One vendor claims its AI performs on average 87% of finance work across 2,700+ unique fields. Finance work is not a measurable quantity, so the percentage cannot be checked in either direction.
    • Hours-saved claims from a product that is not generally available. One vendor advertises saving firms an average of 19.9 hours a week per employee — nearly half a working week — for a product its own site describes as being in limited early access with capabilities growing each week, and publishes no methodology.
    • SOC 2 language that belongs to somebody else. Read for the difference between we hold a SOC 2 Type II report, our hosting provider is SOC 2 certified, we are SOC 2 compliant, and here is what SOC 2 is. All four appear in this market and only the first is a claim about the vendor.
    • A security page that does not exist. Several vendors handling taxpayer documents have no reachable security or trust page at all. That is not a neutral absence for a product inside Pub 4557 scope.
    • Marketing that argues against copilots and then describes one. One homepage says not a copilot, not a chatbot; the product page says the AI always operates under human oversight, does the work and surfaces it for the right person to review. The second sentence is the operative one.
    • An investor quoted as an evaluator. Efficiency ranges attributed to a venture investor who led the vendor's most recent round are not independent assessments, and should be attributed to the person who said them.
    • A customer testimonial converted into a metric. When a vendor release quotes a named customer saying a process is ready for review in minutes, that is an opinion. Paraphrasing it as a measured time saving is how vendor marketing becomes industry fact.
    • Integration lists that are actually dropdowns. One vendor lists nine major tax packages in an intake form with no indication of which are live. Trade coverage of the same product names none of them. Ask for a docs URL, not a logo wall.
    • Stale directories on both sides. One PBC vendor still lists Materia as an integration; Materia was acquired in October 2024 and its domain returns a 404. If a vendor's own integration directory is stale, assume its roadmap page is too.
    • Any answer to who owns you now that is not a public record. Ownership changed for several vendors in this category during 2025 and 2026, and in two cases an aggregator database had it wrong. Ask for the filing, the press release or the registry entry.
    • Silence on §7216. No vendor in this research mentions it. That silence is not disqualifying on its own, but a vendor whose product prepares returns and who cannot discuss the statute in a sales call has not thought about your exposure.

    The five questions to send in writing before you sign. Where does inference run, and where is data at rest? Does any human, at your company or a subprocessor, ever access our client data outside the United States? Which SOC report do you hold, of which type, covering which systems, for which period, and audited by whom — and may we read it under NDA? Is our data used to train or improve any model, yours or a subprocessor's, and is that commitment contractual? And what happens to our data, in what format, on termination or wind-down? A vendor that will not answer those five in an email with a name attached has told you something useful.

    Four Numbers We Refused to Print

    Refusing a statistic is more useful than repeating one, so here is what we chased and why we would not print it. Each of these appears constantly in accounting-AI content, and each fails on inspection.

    “75% of CPAs will retire in the next 15 years”

    The most-repeated statistic in accounting-firm marketing, and it is broken four ways. The origin, as traced by Going Concern, is a 2015 AICPA exposure draft proposing a retired CPA status under the Uniform Accountancy Act, estimating that approximately 75% of its members would be eligible to retire by 2020. Eligible to retire became will retire — entitlement is not intention and neither is behaviour. Its members became CPAs, a different population. The horizon was reset twice: a 2017 restatement made it the next 15 years, pointing at 2032; repeated in 2026, it now points at 2041, from a 2015 estimate about 2020, with no new data at any step. And it is now self-contradictory in the wild, circulating simultaneously as 75% reached retirement age by 2020 and as 75% will retire in the next 15 years, both attributed to the AICPA. They cannot both be right. If you need a succession figure, use one that exists: 208,519 CPAs held a current PTIN as of 1 August 2026, and 55,152 accounting bachelor's and master's degrees were awarded in 2023–24, down 6.6%, per the AICPA's 2025 Trends Report — whose degree counts come from the Department of Education's IPEDS rather than from an AICPA survey.

    “Accountants spend 40% of their time on data entry”

    Traced to a blog post by an AI document-capture and invoice-processing vendor, dated 30 December 2025, closing with an invitation to start a free trial. The page carries a Sources section listing four items — a state-of-AP-automation report, invoice processing benchmarks, a finance automation ROI study, accounting productivity research — none linked, none attributed to an organisation, none dated, none with a sample size or methodology. They cannot be checked and may not exist. This is a vendor selling the cure quantifying the disease, with a citation apparatus that only looks like one; every variant of the form “X hours a week on manual work” shares the pattern. We found no BLS or academic time-use measurement of accountants' task mix at all — which is itself worth knowing. If you want to make this point, make it qualitatively.

    “94% of accounting jobs will be automated”

    Worth correcting rather than merely refusing, because the underlying paper is real and the misreading is precise. Frey and Osborne's The Future of Employment (Oxford Martin School, 17 September 2013) ranks 702 occupations by susceptibility to computerisation; 13-2011 Accountants and Auditors sits at rank 589 with a probability of 0.94. That is a susceptibility classification over an unspecified horizon, not a forecast — and the authors say so in their own limitations section, verbatim:

    We make no attempt to estimate how many jobs will actually be automated.

    Frey and Osborne, The Future of Employment (2013), Section V.A, Limitations

    Printing 0.94 as a prediction misstates a primary source that says the opposite about itself. For the reality check: BLS projects accountant and auditor employment growing 5% from 2024 to 2034, with about 124,200 openings a year on average over the decade. Note that the projections figure comes from the Occupational Outlook Handbook, a different BLS programme with a different base year and a definition that includes the self-employed — it is not the 1,449,500 OEWS figure in the stat tiles above, and the two must never be averaged or used interchangeably.

    Big Four AI investment figures

    The figures circulating for what each Big Four firm has committed to AI appear in a great deal of accounting content, almost always unsourced. We could not verify a single one against the firm's own announcement — the primary press-release URL we attempted returned an HTTP 403 and no substitute primary source was obtained for any of the four. So we do not print them. If you want to make the point that large firms are spending heavily, make it without a number, or fetch the specific firm's own announcement with its date first.

    Limitations — What We Could Not Verify

    Everything below is a gap in this article, stated plainly, because a ranking that refuses vendor claims and then hides its own uncertainty has learned nothing. All of it was checked on 23 August 2026 and some of it will have changed by the time you read this.

    • There is no independent evaluation of any product ranked here. We ranked disclosure quality, not performance, and disclosure quality is a proxy for institutional seriousness — not for whether the software will do your work well.
    • Several compliance postures could not be read at all. Double operates a Vanta-hosted trust centre that returns HTTP 200 but renders no certification in the page source. Numeric's security, trust and compliance URLs all fail. Stampli's security page returns 404 and its privacy policy is JavaScript-rendered. Soraban has no security or trust page we could find. Trullion has no security, trust or compliance page anywhere on its site. We printed nothing about any of them rather than inferring.
    • Ramp's FedRAMP status is deliberately omitted. Its trust centre lists FedRAMP Moderate, GovRAMP, TX-RAMP and Cyber Essentials Plus, but In Process and Authorized could not be distinguished, and the FedRAMP Marketplace is a JavaScript application whose data endpoints we could not reach.
    • Corporate status for several vendors rests on absence of evidence rather than a cleared search. Ramp, Karbon, Canopy, Trullion, MindBridge, Suralink, Stampli, FloQast, Rillet and Campfire were checked for acquisition or rename announcements and none was found; that is weaker than a positive confirmation.
    • Some funding figures were deliberately dropped. Truewind's Series A was search-summarised rather than directly fetched. Trullion's and Puzzle's totals come from aggregators. Booke AI's revenue and headcount come from a third-party listing. Vic.ai's Series C details come from private-market trackers, which are not primary and are frequently stale. Numeric's own blog and the PR Newswire dateline for the same funding round disagree by a year.
    • AICPA Code citations come from the AICPA's own published Code PDF via the Internet Archive, because the live Code viewer requires a login and the download page returns a 404. The text is reliable; its currency is not confirmed, and we make no claim that no later amendment exists.
    • Whether ET 1.150.040's software-application-hosting carve-out covers autonomous agents is unresolved. No AICPA interpretation answers it, and we did not pretend to.
    • We could not confirm a named 2026 AI product from Wolters Kluwer or Intuit from primary source — wolterskluwer.com returns HTTP 403 to automated requests — so neither is named here, despite both being significant incumbents in this market.
    • Legal entity names are unpublished for many vendors, including Fieldguide, DataSnipper, MindBridge, Karbon, Suralink, Ramp, Basis and Vic.ai. Where an entity could not be confirmed from a primary source, we did not print one.
    • Adoption and scale figures throughout — customer counts, top-firm penetration, transaction volumes — are vendor-published without exception, and are attributed in text wherever they appear.

    And the honest closing position. The products in this article are eighteen months old at most, in a market that has already lost a well-funded eleven-year-old incumbent, seen one vendor acquired and absorbed, and watched another rename itself and leave the field seventeen days before we published. The regulatory constraints, by contrast, are between twelve and forty years old and are not moving. Buy against the constraints, not against the roadmaps. Ask where the data goes, what your client was told, who signs, and what happens on termination — and treat every performance number in this category as marketing until a third party publishes a methodology, which nobody has yet done.

    Want a §7216 Disclosure Map Before You Sign Anything?

    Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned Los Angeles agency. You leave with a workflow census across your tax, close and assurance calendar, a map of every vendor that touches return information and where it is processed, a vendor diligence file that satisfies 16 CFR §314.4(f), and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.

    Want a §7216 Disclosure Map Before You Sign Anything?

    Book a free 60-minute discovery call. You leave with a workflow census, a map of every vendor that touches return information and where it is processed, and a fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Unit 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 126 U.S.C. §7216 — criminal penalty for disclosure or use of return information (Cornell LII)
    2. 226 CFR §301.7216-1 — definitions, including software developers as tax return preparers
    3. 326 CFR §301.7216-2 — disclosures permitted without taxpayer consent
    4. 4IRS Rev. Proc. 2013-14 — §7216 consent format and mandatory language
    5. 516 CFR §314.2 — definitions of financial institution and service provider
    6. 616 CFR §314.4 — required program elements, including (f) service-provider oversight
    7. 7FTC, Standards for Safeguarding Customer Information — 88 FR 77499, published 13 Nov 2023, effective 13 May 2024
    8. 8IRS Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024)
    9. 931 CFR §10.22 — Circular 230, diligence as to accuracy
    10. 1031 CFR §10.36 — Circular 230, procedures to ensure compliance
    11. 11REG-116610-20, Regulations Governing Practice Before the IRS — PROPOSED rule, 89 FR 104915 (26 Dec 2024)
    12. 12AICPA, SAS No. 142, Audit Evidence (the current AU-C 500)
    13. 13PCAOB, AS 1105 Audit Evidence (as amended, ¶.10A)
    14. 14PCAOB Release No. 2025-004 — policy statement on AS 1105 ¶.10A (18 Sept 2025)
    15. 15PCAOB Spotlight — Generative AI in Audits and Financial Reporting (staff, non-authoritative, July 2024)
    16. 16Journal of Accountancy — Outsourcing and professional liability (1 Sept 2024)
    17. 17Vals AI — Finance Agent benchmark, v1.1 (537 questions, updated 4 June 2026)
    18. 18FinIndices — financial statement data-processing fidelity (arXiv preprint 2607.28661, 22 July 2026)
    19. 19ReguSim / ReguBench — financial compliance monitoring (arXiv preprint 2608.19974, 20 Aug 2026)
    20. 20AuditFraudBench — enforcement-grounded fraud reasoning (arXiv preprint 2606.08345, 6 June 2026)
    21. 21BLS, Occupational Employment and Wage Statistics — Accountants and Auditors (May 2025 estimates)
    22. 22IRS, Return Preparer Office Federal Tax Return Preparer Statistics (as of 1 Aug 2026)
    23. 23IRS, Filing Season Statistics for week ending May 8, 2026
    24. 24Frey and Osborne, The Future of Employment, Oxford Martin School (17 Sept 2013)
    25. 25Accounting Today — Botkeeper shuts down (February 2026)
    Chris Machetto - CEO & Founder of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital. Building apps and digital products since 2019 for startups and enterprises across LA, San Francisco, Paris, Geneva, and more globally.