AI in the Tax Firm: What § 203 StGB Permits and What It Does Not

An employee pastes a case into ChatGPT to reach an assessment faster. Client name, revenue figures, the disputed audit question. Two minutes later a usable answer is on screen. Nobody acted in bad faith, and in many firms this happens daily. It is still a legal problem, and not for the vendor but for the professional.
Key takeaway: The dividing line does not run between permitted and forbidden tools, but between use with and without client data. General research without client reference is unproblematic. The moment protected facts enter a system, § 203 StGB and § 62a StBerG apply: the service provider must be carefully selected, bound to confidentiality in text form, and instructed about the criminal consequences. If the professional intentionally omits this obligation and the provider subsequently discloses a secret, the professional becomes criminally liable. With providers outside Germany, two further hurdles apply.
Can I use ChatGPT in a tax firm at all?
Yes, but the question is framed wrongly. What matters is not the tool but what goes into it. Asking a language model how case law distinguishes maintenance expenses from production costs discloses no secret. Entering the same case with the client name, property address and figures does.
The distinction sounds obvious but is crossed constantly in daily practice, because the second version produces better answers. That is precisely where the risk lies: the incentive points the wrong way.
How widespread the use has become is shown by the Bitkom survey of April 2026: 41 percent of German companies actively deploy AI, a further 48 percent plan to. For the tax advisory sector, a 2025 study by SWI Finance reports that over 80 percent of AI-minded firms use generative systems for research, for instance on Federal Fiscal Court rulings and Federal Ministry of Finance circulars. Research without client reference is the uncritical case here.
What exactly does professional confidentiality protect?
Everything entrusted to or learned by the tax adviser in the course of practising the profession. The duty is set out in § 57 paragraph 1 StBerG as a professional obligation, and § 203 paragraph 1 number 3 StGB makes its breach a criminal offence. Tax advisers are named there explicitly, alongside lawyers, doctors and other professions.
More is protected than most people assume. Not only figures and documents, but the very fact that a particular engagement exists. A case from which the client can be inferred, even without the name appearing, can also be a protected secret. In a firm with a regional client base, the industry plus the revenue bracket is sometimes enough.
Who becomes criminally liable when something goes wrong?
The professional, not the vendor. This is the point that regularly gets lost in debates about AI tools.
§ 203 paragraph 3 sentence 2 StGB permits disclosure of protected facts to participating persons, to the extent necessary for their work. IT service providers fall under this. The legislator created the rule in 2017 to make outsourcing legally viable at all; before that, every instance of external IT maintenance sat in a grey area.
The permission comes with a condition. The professional must bind the participating person to confidentiality. If they intentionally fail to do so and the provider subsequently discloses a third party's secret, the professional is themselves liable under § 203 paragraph 4 sentence 2 number 1 StGB. The penalty range is imprisonment of up to one year or a fine.
So there is no configuration in which one can say the vendor is responsible and I have nothing to do with it. Responsibility for the obligation rests with the professional and cannot be delegated away.
What does § 62a StBerG require of an AI provider?
Five things, concrete enough to turn into a checklist. § 62a StBerG is the professional-law counterpart to § 203 StGB and governs the use of external services in detail.
| Paragraph | Requirement | What it means in practice |
|---|---|---|
| 1 | Access only as far as necessary for the service | No blanket full access to the data holdings |
| 2 | Careful selection of the provider | Documented review before signing, not after |
| 2 | Termination on non-compliance | Right of termination and audit rights in the contract |
| 3 | Contract in text form | A verbal arrangement is not enough; email is |
| 3 | Confidentiality obligation with instruction on criminal consequences | One sentence about confidentiality is not enough; the instruction must be explicit |
Paragraph 3 adds the duty to limit knowledge to what is necessary and to govern whether and how the provider may bring in further parties. That last point matters particularly with AI providers, because many build on third-party compute. Without contractual clarity there, you do not know how many parties are actually involved.
Data protection comes on top, not instead. A processing agreement under Article 28 GDPR does not automatically satisfy the professional-law requirements, because it does not contain the criminal-law instruction. Both are needed.
What applies if the provider is based abroad?
Then two further hurdles arise, and this is where spontaneous use of common tools breaks down.
§ 62a paragraph 4 StBerG permits engaging a provider delivering from abroad only if the protection of secrets existing there is comparable to protection in Germany. That is a separate assessment, not settled by standard contractual clauses.
§ 62a paragraph 5 StBerG goes further: if the foreign service serves a specific engagement, the client's consent is required. That is exactly the case when a client matter is entered into a system outside the EU in order to work on it.
In practice this means that using a third-country provider to handle specific engagements would require the consent of each client concerned. Practically nobody has obtained that consent. Anyone using such tools with client data anyway should do so knowingly, not out of ignorance.
The clean alternative is a provider processing inside the EU who signs the obligation under § 62a paragraph 3 StBerG. Paragraphs 4 and 5 then fall away, leaving the five requirements in the table above.
Which tasks can be automated with legal certainty?
More than the previous section suggests. The key is to sort tasks by their data exposure rather than by their technology.
| Task | Permitted | Condition |
|---|---|---|
| Technical research without client reference | Without further ado | Enter no client data |
| Drafting and phrasing help without names or figures | Without further ado | Anonymise the case beforehand |
| Call handling with appointments and callback requests | With a contract | § 62a paragraph 3 StBerG, EU processing, AI disclosure |
| Pre-qualifying incoming client enquiries | With a contract | As above, plus tight topic boundaries |
| Document pre-capture and filing | With a contract | As above, access limited to what is necessary |
| Answering a client's specific tax question | No | Tax advice remains reserved to the professional |
| Entering a client matter into a third-country system | Only with consent | § 62a paragraph 5 StBerG |
The most productive applications lie not in advice but upstream of it: in everything that costs time without requiring professional judgement. Call handling is the clearest example, because it creates the same bottleneck in tax firms as in medical practices. How that is solved there is described in our guide to the AI phone assistant for medical practices; the professional-law construction differs, the organisational problem is identical.
One point applies to every such application: the system may only draw on stored knowledge and must escalate rather than improvise. How such a knowledge base is built, and why it is the decisive difference between useful and dangerous, is covered in our article on the knowledge base of AI agents.
What belongs in a firm policy on AI use?
Six points, and they fit on two pages. Such a policy is not bureaucratic decoration but the practical way to document the duty of care under § 62a paragraph 2 StBerG.
- Name the approved tools explicitly. Anything not on the list is not approved. Without that, every employee decides for themselves.
- Draw the data line expressly. Which details may never be entered: client name, tax number, addresses, amounts, file references, anything from which the client can be inferred.
- Make anonymisation binding. Anyone abstracting a case needs instructions on exactly what to replace.
- Record the review duty. Every output is checked by the professional before it enters an engagement. Language models invent citations, including convincingly formatted ones.
- Name who is responsible. One person decides on approvals and maintains the list.
- Document training. Who was trained, when, on what, with a signature.
The last point is not optional. Since 2 February 2025, Article 4 of the EU AI Act has required every company deploying AI systems to ensure adequate AI literacy among the people involved. The provision prescribes no curriculum but an organisational responsibility: training, internal guidelines or multiplier programmes are equally recognised measures. From 3 August 2026, the competent market surveillance authorities monitor compliance.
What else does the EU AI Act change for firms?
Less than is often feared. Tax advice is not listed as a high-risk area in Annex III of the regulation, so those obligations do not apply.
Two points are relevant. First, the AI literacy requirement under Article 4 just mentioned. Second, the transparency obligation under Article 50, in force since 2 August 2026: anyone interacting directly with an AI system must be able to recognise it. For a firm this mainly concerns call handling and website chat. The details are covered in our article on the AI disclosure duty under Article 50.
The professional-law requirements remain untouched by this. They are older, stricter, and for firms they are the real benchmark.
Frequently asked questions
Can I use ChatGPT in a tax firm? For research and phrasing without client reference, yes. As soon as protected facts are entered, § 203 StGB and § 62a StBerG apply. With a provider outside the EU, § 62a paragraph 5 StBerG adds the client's consent if the use serves a specific engagement.
Is a GDPR processing agreement sufficient? No. An agreement under Article 28 GDPR covers the data protection side, not the professional-law side. § 62a paragraph 3 StBerG additionally requires a confidentiality obligation with explicit instruction on the criminal consequences. Both are needed, not one instead of the other.
Who is liable if data leaks through an AI provider? The provider is liable contractually and under data protection law. In criminal law it additionally reaches the professional if they intentionally omitted the obligation under § 203 paragraph 3 StGB; § 203 paragraph 4 sentence 2 number 1 StGB then applies, with imprisonment of up to one year or a fine.
Is leaving out the client name enough? Not necessarily. A case from which the client can be inferred is also protected. In a firm with a regional client base, industry, legal form and revenue bracket may already suffice. Anonymisation means attribution is ruled out, not that the name is missing.
May an AI phone assistant take calls in a tax firm? Yes, for organisational tasks such as appointments, callback requests and general information. The conditions are processing within the EU, a contract under § 62a paragraph 3 StBerG with a confidentiality obligation and instruction, and telling callers they are speaking to an AI system. Tax information remains excluded.
What about Microsoft 365 Copilot if we already use Microsoft? That too is a use of a service within the meaning of § 62a StBerG and needs the same review. What matters is the place of processing, the contractual obligation with criminal-law instruction, and whether and which further parties the provider brings in. An existing business relationship does not replace that review.
Conclusion
Professional confidentiality is not an obstacle to AI in a tax firm but a design constraint. In 2017 the legislator deliberately created a route for engaging external service providers, and that route is open. It only requires that you take it rather than work around it.
What goes wrong in practice is rarely a deliberate decision in favour of a risky tool. It is the unnoticed everyday: a pasted case, a quick test, a helpful answer. That is why a two-page firm policy achieves more than any technology decision.
The first step takes half an hour: write down which tools are actually in use in the firm, and for each one check where processing happens and whether an obligation under § 62a paragraph 3 StBerG exists. The list is usually longer than expected, and usually at least one entry is missing its contract.
This article reflects the state of knowledge as of 11 August 2026 and does not constitute legal advice. For assessment of an individual case, consult the competent chamber of tax advisers or a lawyer.
Sources
- § 57 paragraph 1 Steuerberatungsgesetz (professional confidentiality)
- § 62a Steuerberatungsgesetz (use of external services), in particular paragraphs 1 to 5
- § 203 Strafgesetzbuch (violation of private secrets), in particular paragraph 1 number 3, paragraph 3 sentence 2 and paragraph 4 sentence 2 number 1
- Regulation (EU) 2024/1689 (EU AI Act), Article 4 (AI literacy, since 2 February 2025) and Article 50 (transparency obligations, since 2 August 2026)
- Regulation (EU) 2016/679 (GDPR), Article 28 (processing on behalf of a controller)
- Bitkom, AI study April 2026 (41 percent of companies with active AI deployment)
- SWI Finance, 2025 survey on AI use in tax firms
AI automation for your back office
Email routing, document OCR and automatic ERP/CRM entries - up to 80% less routine work.
More Articles

AI Agents in Customer Service: Revolutionizing Digital Communication in 2025
Discover how AI agents are revolutionizing customer service in 2025, enabling 24/7 intelligent communication and boosting business efficiency.

AI Automation for SMEs: A Guide to Boosting Efficiency in 2025
Our 2025 guide for SMEs on using AI agents to increase efficiency, reduce operational costs, and overcome labor shortages. Calculate your ROI.
