Can an AI roll-up use client data from the firms it acquires?

Usually not for AI training or licensing without client consent. Buying an accounting or services firm transfers the rights the firm had, and client files are typically bound by engagement letters, privacy promises, professional confidentiality and, for tax work, federal limits on return information. The firm's own operating records are a separate question and may be licensable.

The short answer

Usually not, at least not for AI training or licensing, unless clients have consented. Buying a firm transfers the rights the firm had; it does not widen them. Client files at an accounting, bookkeeping or other professional services firm are normally bound by engagement letters, privacy promises, professional confidentiality duties and, for tax work, federal limits on how preparers use return information. The firm's own operating records, such as procedures, templates, workflow history and internal communications with client details removed, raise a different question and may be licensable.

The question comes up as soon as an AI roll-up approaches a firm, because the thesis depends on rebuilding delivery with AI. It also mirrors one of SourceX's red flags: data that belongs to someone else, such as an outsourcer's or agency's clients, is out of scope without that party's consent.

What the rules actually say

Four sets of rules drive the answer. Each turns on the facts and, for professional rules, on the state.

Promises to clients are enforceable. FTC staff wrote in January 2024 that a company's promises not to use customer data for undisclosed purposes, such as training or updating AI models, are enforceable whether they appear in a privacy policy, terms of service or marketing (FTC staff post on privacy and confidentiality commitments). That post is staff guidance, not a rule, but it signals how an acquirer that ignores the target's promises could be viewed.

Tax preparers carry security duties. The FTC's Safeguards Rule treats many non-bank businesses, including tax preparation firms, as financial institutions that must run a written information security program for customer information (FTC Safeguards Rule business guide). Moving client data into new systems or new uses has to fit that program.

Professional confidentiality and tax return information. CPAs owe confidentiality duties under their professional code and their state board's rules, and federal tax law separately restricts how tax return preparers use or disclose return information without the taxpayer's consent. Read the current text of each with counsel; this page does not summarize them.

Who owns firm-created material. Documents employees prepare within the scope of their jobs are generally works made for hire owned by the employer, while material from outside contractors may not be unless rights were assigned in a signed writing (Copyright Office Circular 30). Copyright ownership can also be transferred in parts, and exclusive rights can be held separately (17 U.S.C. 201), which is why a firm can license a defined slice of its own records while keeping the rest. Ownership does not override confidentiality: a staff memo on a client's tax position is the firm's document and the client's confidential information at the same time.

How it applies in common roll-up situations

SituationWhat to checkTypical outcome to confirm with counsel
Client tax returns and workpapersEngagement letters, client consent forms, federal limits on return informationNot usable for AI training or licensing without specific client consent
Client ledgers kept in the client's own accounting software subscriptionWho holds the subscription and admin rights; the services agreementThe client's data, outside any license the firm could grant
Firm SOPs, checklists, templates and training decks written by staffAuthorship, embedded client examples, third-party contentOften the firm's own records and a candidate for licensing after review
Practice-management history: tasks, review steps, turnaround, staffingWhether entries name clients or carry client figuresPossibly licensable once identifiers are removed under agreed redaction rules
Internal email and Teams or Slack channelsThe mix of client content and firm operationsPartly usable after review and redaction; client content stays out
Work produced by offshore or freelance contractorsA written assignment of rights in each contractDepends on the assignment; without one, the right is unclear
A target whose privacy notice ruled out third-party sharingExact wording and date of each notice versionNot usable for new purposes without fresh consent

Training the acquirer's own internal tools on client files is a different question from licensing records to a third party, but it starts from the same documents: engagement letters, privacy notices and professional rules.

Disclosure and consent good practice

  • Keep client data inside the acquired firm's environment until counsel has classified it; do not bulk-copy it into a shared holdco tenant on day one.
  • If you want a new use of client information, ask clients plainly and separately, describing the purpose, rather than relying on a revised engagement letter signed in passing.
  • Separate the firm's own operating records from client material before anyone discusses licensing. SourceX works only with material the company has rights to; de-identification and redaction requirements are agreed with the company before any work begins, and nothing is delivered without an executed agreement and the company's authorization.
  • Write down who in the combined business can authorize a license; the delegation of authority matrix template includes a ready row.

The AI roll-up due diligence checklist turns these checks into buy-side questions, and the AI roll-up integration playbook covers keeping records intact after closing.

If you are a CPA advising the owner and would refer the firm

CPA advisors who introduce a firm, or any other client, to SourceX should read their own fee rules first. Under the AICPA Code's commissions and referral fees rule (ET 1.520), a member in public practice may not accept a commission for recommending a product or service to a client when the member's firm also performs an audit, review, certain compilations or an examination of prospective financial information for that client, and permitted referral fees must be disclosed to the client (AICPA Code of Professional Conduct). State boards of accountancy can be stricter than the AICPA Code (NJCPA on commissions and contingent fees), so check your own state's rule. The partner page for accountants explains how the program works for firms.

Partner rewards are 25% of the eligible platform fees SourceX collects from a referred company's licensing deals, capped at $100,000 per referred company, and are paid only after the buyer pays and SourceX receives its fee. The reward is never deducted from the company's proceeds.

Questions to ask your counsel or professional body

  1. Which records at the acquired firm are client-owned, which did the firm create, and which are mixed?
  2. Do the engagement letters and each version of the privacy notice allow any use beyond delivering the services?
  3. Which federal and state rules on tax return information apply to the datasets under discussion, and what form of consent would they require?
  4. Does our written information security program cover moving data between the acquired firm and the holdco?
  5. Were any materials produced by contractors without a written assignment of rights?
  6. If I refer this firm, does my firm perform attest work for it, and what does my state board require me to disclose?

This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

Next step

If the firm's own operating records look clean once client material is set aside, check it against who qualifies, then register as a partner to make the introduction. The owner can also apply directly at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does an asset purchase give the buyer more rights to client data than a stock purchase?

Neither structure gives the buyer more rights than the firm had. In a stock purchase the same entity keeps its contracts and obligations; in an asset purchase, client engagements and files move only as the contracts and any client consents allow. Either way, confidentiality duties and privacy promises travel with the data, so the structure changes the paperwork, not the underlying limits.

Can an acquired firm use anonymized client data to train its own AI tools?

Possibly, but anonymizing does not settle the question on its own. Counsel will look at what engagement letters and privacy notices promised, professional confidentiality rules, and federal limits on tax return information, some of which turn on consent rather than on whether names are removed. Re-identification risk matters too. Get a written opinion before any client-derived data enters a training pipeline.

Which firm records are usually the safest to consider for licensing?

Material the firm created about how it runs, rather than what it learned about clients: procedures, checklists, templates, training content, workflow and review history, scheduling and quality-control records, with client identifiers removed. Even these need review, because client names and figures often appear inside tasks, emails and file notes. Redaction rules are agreed with the company before any work begins.

Does a roll-up need client consent just to migrate files into new software?

Moving client data into new systems to keep serving those clients is a different question from using it for a new purpose, and engagement terms often address storage and service providers. The move must still fit the firm's information security program and any contractual limits. Ask counsel whether existing terms cover the migration, or whether clients need notice or must consent first.

Would SourceX accept client files if the firm's owner signs off?

No. An owner's sign-off cannot supply rights the firm does not hold. SourceX treats data that belongs to someone else, without that party's consent, as a red flag. The licensing conversation covers only the firm's own operating records, with de-identification and redaction agreed before any work and delivery only after an executed agreement and the company's authorization.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment