What the IRS’s First AI Guidance Means for ACA Compliance

What the IRS’s First AI Guidance Means for ACA Compliance

What the IRS’s First AI Guidance Means for ACA Compliance

Margaret Duvall | July 15, 2026

The IRS has issued its first formal guidance on artificial intelligence in tax practice, and the standard it sets for tax preparers applies just as directly to anyone using AI to manage Affordable Care Act data and filings.

On June 24, 2026, the IRS Office of Professional Responsibility (OPR) released Alert 2026-19, addressed to CPAs, enrolled agents, and tax attorneys. The risks it flags, however, aren’t unique to tax practitioners. 

They’re the same risks any ALE faces when AI touches eligibility data, affordability calculations, or 1095-C coding.

What Did the IRS Just Say About AI in Tax Practice?

The OPR identifies two core limitations of generative AI: fabricated outputs, commonly called hallucinations, and the risk of data crossing between unrelated matters. 

Both carry direct ACA parallels.

On hallucinations, the OPR points to a real-world case: in July 2025, the Australian government published a 230-page AI-generated report from Deloitte Australia that contained invented quotes, references to nonexistent sources, and misattributed authorship. 

Deloitte agreed to refund part of its fee. 

A hallucinated affordability calculation or a wrong offer-of-coverage code carries the same structural risk, except the IRS catches it through the IRS AIR System.

On data crossing, the OPR warns that information generated for one client can be repurposed by an AI tool to answer a question about another client. 

For ACA compliance, that’s the same risk as mixing benefit years, entity groups, or employee populations inside a tool with no domain-specific guardrails.

How Does Circular 230 Map to ACA Compliance?

The OPR ties its guidance to six existing Circular 230 provisions. Each has a direct ACA reporting analog:

  • § 10.22 (Due Diligence): AI-created documents require human review before submission. For ACA, that means a verification layer on every AI-assisted eligibility determination.
  • § 10.35 (Competence): Practitioners must understand how an AI system generates its output, not just trust the result. The same applies to any vendor calculating affordability safe harbors.
  • § 10.36 (Firm Procedures): Firms must document staff training, data protocols, and third-party AI vetting. Employers should expect the same documentation from any ACA vendor using AI in their workflow.
  • § 10.37 (Written Advice): The OPR states that blind reliance on AI output, when the underlying logic is unclear, may be unreasonable reliance. The same logic applies to FTE determinations or safe harbor calculations with no audit trail.
  • IRC §§ 6713 and 7216(a) (Data Privacy): Client data must stay on secure, enterprise-approved systems. Uploading employee benefit or hours data into an unsecured or public AI platform is a direct exposure risk.

How Much Is Already at Stake in ACA Penalty Exposure?

The OPR alert doesn’t address ACA enforcement directly, but the financial context is worth stating plainly. ESRP penalties under IRC § 4980H scale across entire workforces, not individual employees, and the 2026 penalty amounts reflect another year of upward adjustment. 

For ALEs managing hundreds or thousands of workers, data errors in AI-assisted workflows don’t produce isolated exposure — they produce enterprise-level liability.

What makes this more relevant now is where the IRS is investing. According to a March 2026 GAO report, the IRS had 126 active AI use cases as of June 2025, with the largest share aimed at tax compliance and fraud detection. The enforcement side of ACA compliance is becoming more data-driven at the same time AI tools are becoming more common in how employers manage their own filings. 

The OPR’s guidance lands in that context — and the gap between what AI produces and what an IRS automated data-matching scan expects is where penalty exposure lives.

What Does Responsible AI Use Look Like for ACA Compliance?

The OPR’s best-practices list translates directly into an ACA compliance checklist:

  • Vet any third-party AI tool before it touches benefit eligibility or hours data
  • Document how AI is used in eligibility determinations and coding decisions
  • Treat AI-generated affordability calculations and FTE counts as drafts, not final answers
  • Keep sensitive employee data off unsecured or general-purpose AI platforms
  • Maintain a human review step before any AI-assisted output reaches an IRS filing

The OPR’s own framing applies well beyond tax practice: AI is a tool, not a substitute for professional judgment.

Where Human Review Still Decides Your ACA Risk

The OPR’s guidance doesn’t ask practitioners to avoid AI. It asks them to be able to explain and defend what it produces. That’s the same standard ACA Complete® is built around: certified Workday and UKG integrations that preserve data integrity at the source, and a team that reviews coding logic before it reaches the IRS, not after a Letter 226J arrives. 

If AI is already touching your ACA workflow, whether yours or a vendor’s, a Penalty Risk Assessment is the fastest way to see exactly where that data stands before the IRS does.