Back to Blog
AI

Competence Now Means Knowing the Limits of a Tool You Did Not Build

7 September, 2026
4 min read
Competence Now Means Knowing the Limits of a Tool You Did Not Build

Intuit's figures, reported by Accounting Today, put average firm technology investment at $19,000 in 2025 with $20,000 planned for 2026, and 64% of firms planning specific AI investment this year.

The Rules Already on the Books

Set next to that a much quieter publication. On 5 August 2026 the AICPA's Professional Ethics Division published a piece by Kelly D. Mullins, its communications manager, on accounting ethics in the age of AI. It contains no new rule.

What it contains is a reminder that the existing ones never had a technology exemption.

Two sections do most of the work here, and neither was written with software in mind.

The General Standards Rule, ET sections 1.300.001 and 2.300.001, requires a member to undertake only services they can complete competently and with due professional care. The Confidential Client Information Rule, ET section 1.700.001, governs what a member in public practice may do with client data.

The Ethics Division's reading is direct. Competence and due care mean that before using AI a member has to understand its strengths, limitations and risks in the specific context of the work, which may require additional research, training, or testing the tool on non-sensitive data first. Confidentiality means asking whether what is being typed into a tool is confidential client information and whether consent is required before it goes in.

Why That Is Harder Than It Sounds

Here is the part that does not survive contact with how firms actually buy software.

Understanding a tool's limitations in a specific context is not the same as watching a demo or reading a vendor page. It means knowing what the thing is bad at, on your work, with your documents. A partner who could not say where a tool's output degrades has not met the standard, and no amount of vendor documentation supplies that knowledge, because the vendor does not have your client files.

The article names the failure modes precisely, and they are cognitive rather than technical: automation bias, overconfidence bias, anchoring bias. The tendency to accept a machine's answer because it came from a machine. The tendency to trust your own review of it more than it deserves. The tendency to let the first figure you saw set the range for everything after.

Those three are not fixed by a policy document. They are fixed by a review step somebody actually performs, on a schedule somebody actually keeps.

The Consent Question Most Firms Have Not Asked

Confidentiality is the cleaner test, and the one more likely to be failed quietly.

A staff member pasting a client's trial balance into a general purpose chatbot to ask what looks odd has moved confidential client information into a third party system. Whether that needs consent depends on the tool, the terms and the jurisdiction, but the question has to be asked before the paste rather than after somebody notices.

The Ethics Division also flags independence, which is easy to miss. Providing AI-related nonattest services to an attest client can raise independence concerns in the ordinary way any other nonattest service does. A firm helping an audit client select or implement an AI system is doing something that needs thinking about, not something new.

What Answering Actually Requires

Every one of those obligations resolves into a record.

Which tool, on what engagement, with what review. Whether the client data went somewhere it should not have, and who could see it. A firm that has the answers has met a standard that predates all of this. A firm that has an impression has an ethics exposure sitting inside a productivity story.

MetaWurks is built so that half is answerable. Documents ingested into the platform are not used to train models and are not exposed to other users, which removes one of the confidentiality questions rather than requiring it to be managed. Role based access controls decide who can open which client's records, and audit logs record who opened what and when.

It does not supply competence. Nothing does except learning where a tool fails on your own work. What it supplies is the evidence that the practice you describe is the practice you run.

No new rule is coming because none is needed. The obligations that apply to an AI-assisted engagement are the ones a member accepted on the day they joined, and the only thing AI changed is how quickly a lapse can scale.

Join the Conversation

Could someone in your firm state, specifically, what the AI tool you use most is bad at on your own client work?

Subscribe now to Our Newsletter and get the Coupon code.

All your information is completely confidential