IRS's AI risk management needs to be improved

In this photo illustration, the IRS logo is displayed on a smartphone screen and in the background the flag of the United States
Jaque Da Silva/Rafael Henrique - stock.adobe.com
  • Key insight: Find out how the IRS is deploying hundreds of artificial intelligence use cases.
  • What's at stake: Taxpayers facing high-impact agency decisions driven by unassessed artificial intelligence models.
  • Expert quote: "AI risk management for high-impact use cases is critical..." — TIGTA report

The Internal Revenue Service is using artificial intelligence for hundreds of uses, and in some cases has not yet assessed the risks, according to a new report.

Processing Content

The report, released Monday by the Treasury Inspector General for Tax Administration, pointed out that the IRS has used AI for many years, including for tax return classification and issue selection. As of December 2025, the IRS had 225 AI use cases.

For the report, TIGTA reviewed five use cases that were presumed to be high impact and found the IRS did not fully document its evaluation of the possible risks in all five cases. Two of the sampled cases (40%) lacked documented impact assessments, although the remaining three AI use cases (60%) did have a documented impact assessment. 

As of July 2026, the Treasury Department has not issued guidance on minimum risk management practices. The IRS developed and is implementing its own AI governance policy, and processes to align with a memo from the White House Office of Management and Budget (Memorandum M-25-21) requiring federal agencies to implement minimum risk management practices for high-impact artificial intelligence use cases by April 2026.

The report comes as President Trump has dismissed the need for AI regulation, despite warnings from prominent AI leaders, including Anthropic CEO Dario Amodei, whom Trump reportedly met on Sunday evening for dinner after the Pentagon threatened earlier this year to blacklist the company from federal contracts.

TIGTA found that while the IRS performed data quality checks on the AI, the documentation varied. In one out of five of the sampled AI use cases (20%), the documents outlined numerous processes and procedures used in testing. But four out of five (80%) of the sampled use cases lacked testing documentation, and the IRS had not standardized the documentation nor established the baseline procedures for evaluating data quality before using data in high-impact AI models.

"High-impact AI is any AI system whose output serves as a principal basis for decisions or actions," said the TIGTA report. "These decisions or actions have a legal, material, binding or significant effect on civil rights, privacy, health, safety or access to critical government resources and services. AI risk management for high-impact use cases is critical because these use cases may have a material effect on taxpayer outcomes. The responsible use of AI depends on data that are appropriate for the AI modeling approach and use."

TIGTA made two recommendations in the report, saying the IRS should ensure that AI impact assessments for high-impact use cases are completed in accordance with OMB Memorandum M-2521; and suggesting it develop and implement standard processes for evaluating data quality for use in AI use cases. The IRS agreed with both recommendations and said it either has or plans to implement corrective actions.

"We remain committed to continuous improvement and transparency in our AI risk management practices at the IRS," wrote acting chief data and analytics officer Lucia Lykke in response to the report.

Introductory bullet points created by AI with editorial review


For reprint and licensing requests for this article, click here.
Tax Technology Artificial Intelligence Risk management
MORE FROM ACCOUNTING TODAY
Load More