Can an AI roll-up use client data from the firms it acquires?
Usually not for AI training or licensing without client consent. Buying an accounting or services firm transfers the rights the firm had, and client files are typically bound by engagement letters, privacy promises, professional confidentiality and, for tax work, federal limits on return information. The firm's own operating records are a separate question and may be licensable.
The short answer
Usually not, at least not for AI training or licensing, unless clients have consented. Buying a firm transfers the rights the firm had; it does not widen them. Client files at an accounting, bookkeeping or other professional services firm are normally bound by engagement letters, privacy promises, professional confidentiality duties and, for tax work, federal limits on how preparers use return information. The firm's own operating records, such as procedures, templates, workflow history and internal communications with client details removed, raise a different question and may be licensable.
The question comes up as soon as an AI roll-up approaches a firm, because the thesis depends on rebuilding delivery with AI. It also mirrors one of SourceX's red flags: data that belongs to someone else, such as an outsourcer's or agency's clients, is out of scope without that party's consent.
What the rules actually say
Four sets of rules drive the answer. Each turns on the facts and, for professional rules, on the state.
Promises to clients are enforceable. FTC staff wrote in January 2024 that a company's promises not to use customer data for undisclosed purposes, such as training or updating AI models, are enforceable whether they appear in a privacy policy, terms of service or marketing (FTC staff post on privacy and confidentiality commitments). That post is staff guidance, not a rule, but it signals how an acquirer that ignores the target's promises could be viewed.
Tax preparers carry security duties. The FTC's Safeguards Rule treats many non-bank businesses, including tax preparation firms, as financial institutions that must run a written information security program for customer information (FTC Safeguards Rule business guide). Moving client data into new systems or new uses has to fit that program.
Professional confidentiality and tax return information. CPAs owe confidentiality duties under their professional code and their state board's rules, and federal tax law separately restricts how tax return preparers use or disclose return information without the taxpayer's consent. Read the current text of each with counsel; this page does not summarize them.
Who owns firm-created material. Documents employees prepare within the scope of their jobs are generally works made for hire owned by the employer, while material from outside contractors may not be unless rights were assigned in a signed writing (Copyright Office Circular 30). Copyright ownership can also be transferred in parts, and exclusive rights can be held separately (17 U.S.C. 201), which is why a firm can license a defined slice of its own records while keeping the rest. Ownership does not override confidentiality: a staff memo on a client's tax position is the firm's document and the client's confidential information at the same time.
How it applies in common roll-up situations
| Situation | What to check | Typical outcome to confirm with counsel |
|---|---|---|
| Client tax returns and workpapers | Engagement letters, client consent forms, federal limits on return information | Not usable for AI training or licensing without specific client consent |
| Client ledgers kept in the client's own accounting software subscription | Who holds the subscription and admin rights; the services agreement | The client's data, outside any license the firm could grant |
| Firm SOPs, checklists, templates and training decks written by staff | Authorship, embedded client examples, third-party content | Often the firm's own records and a candidate for licensing after review |
| Practice-management history: tasks, review steps, turnaround, staffing | Whether entries name clients or carry client figures | Possibly licensable once identifiers are removed under agreed redaction rules |
| Internal email and Teams or Slack channels | The mix of client content and firm operations | Partly usable after review and redaction; client content stays out |
| Work produced by offshore or freelance contractors | A written assignment of rights in each contract | Depends on the assignment; without one, the right is unclear |
| A target whose privacy notice ruled out third-party sharing | Exact wording and date of each notice version | Not usable for new purposes without fresh consent |
Training the acquirer's own internal tools on client files is a different question from licensing records to a third party, but it starts from the same documents: engagement letters, privacy notices and professional rules.
Disclosure and consent good practice
- Keep client data inside the acquired firm's environment until counsel has classified it; do not bulk-copy it into a shared holdco tenant on day one.
- If you want a new use of client information, ask clients plainly and separately, describing the purpose, rather than relying on a revised engagement letter signed in passing.
- Separate the firm's own operating records from client material before anyone discusses licensing. SourceX works only with material the company has rights to; de-identification and redaction requirements are agreed with the company before any work begins, and nothing is delivered without an executed agreement and the company's authorization.
- Write down who in the combined business can authorize a license; the delegation of authority matrix template includes a ready row.
The AI roll-up due diligence checklist turns these checks into buy-side questions, and the AI roll-up integration playbook covers keeping records intact after closing.
If you are a CPA advising the owner and would refer the firm
CPA advisors who introduce a firm, or any other client, to SourceX should read their own fee rules first. Under the AICPA Code's commissions and referral fees rule (ET 1.520), a member in public practice may not accept a commission for recommending a product or service to a client when the member's firm also performs an audit, review, certain compilations or an examination of prospective financial information for that client, and permitted referral fees must be disclosed to the client (AICPA Code of Professional Conduct). State boards of accountancy can be stricter than the AICPA Code (NJCPA on commissions and contingent fees), so check your own state's rule. The partner page for accountants explains how the program works for firms.
Partner rewards are 25% of the eligible platform fees SourceX collects from a referred company's licensing deals, capped at $100,000 per referred company, and are paid only after the buyer pays and SourceX receives its fee. The reward is never deducted from the company's proceeds.
Questions to ask your counsel or professional body
- Which records at the acquired firm are client-owned, which did the firm create, and which are mixed?
- Do the engagement letters and each version of the privacy notice allow any use beyond delivering the services?
- Which federal and state rules on tax return information apply to the datasets under discussion, and what form of consent would they require?
- Does our written information security program cover moving data between the acquired firm and the holdco?
- Were any materials produced by contractors without a written assignment of rights?
- If I refer this firm, does my firm perform attest work for it, and what does my state board require me to disclose?
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
Next step
If the firm's own operating records look clean once client material is set aside, check it against who qualifies, then register as a partner to make the introduction. The owner can also apply directly at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does an asset purchase give the buyer more rights to client data than a stock purchase?
Neither structure gives the buyer more rights than the firm had. In a stock purchase the same entity keeps its contracts and obligations; in an asset purchase, client engagements and files move only as the contracts and any client consents allow. Either way, confidentiality duties and privacy promises travel with the data, so the structure changes the paperwork, not the underlying limits.
Can an acquired firm use anonymized client data to train its own AI tools?
Possibly, but anonymizing does not settle the question on its own. Counsel will look at what engagement letters and privacy notices promised, professional confidentiality rules, and federal limits on tax return information, some of which turn on consent rather than on whether names are removed. Re-identification risk matters too. Get a written opinion before any client-derived data enters a training pipeline.
Which firm records are usually the safest to consider for licensing?
Material the firm created about how it runs, rather than what it learned about clients: procedures, checklists, templates, training content, workflow and review history, scheduling and quality-control records, with client identifiers removed. Even these need review, because client names and figures often appear inside tasks, emails and file notes. Redaction rules are agreed with the company before any work begins.
Does a roll-up need client consent just to migrate files into new software?
Moving client data into new systems to keep serving those clients is a different question from using it for a new purpose, and engagement terms often address storage and service providers. The move must still fit the firm's information security program and any contractual limits. Ask counsel whether existing terms cover the migration, or whether clients need notice or must consent first.
Would SourceX accept client files if the firm's owner signs off?
No. An owner's sign-off cannot supply rights the firm does not hold. SourceX treats data that belongs to someone else, without that party's consent, as a red flag. The licensing conversation covers only the firm's own operating records, with de-identification and redaction agreed before any work and delivery only after an executed agreement and the company's authorization.
Related pages
- What AI roll-ups look for in acquisitions, and what that means for your clients
- Delegation of authority matrix template, with a row for signing a data license
- AI roll-up due diligence checklist for client-data rights and operating records
- AI roll-up integration: how to preserve pre-automation work records before rebuilding
- Referral opportunities for accountants and bookkeeping firms
- Which US businesses are a fit for a SourceX data licensing introduction
Free resources
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- Enterprise value calculator — Enterprise value from equity value, debt and cash.
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment