HMRC sets expectations for generative Artificial Intelligence in tax software
On 28 January 2026, HM Revenue & Customs (HMRC) published guidance aimed directly at software developers using generative AI in products that help customers submit information to HMRC. The message is clear: innovation is welcome — but only where it follows five concepts HMRC calls out: transparent, legally grounded, human-supervised, secure, and ethical.
See how we are VATCalc are following this in areas such as AI VAT advice and AI item classifications.

Below is what matters for tax-software vendors — and why this guidance materially changes how AI features must be designed and governed.
1) Transparency is mandatory, not optional
HMRC expects users to know when generative AI is being used and to understand:
- what source data the model relies on
- how that data is processed
- the model’s limitations (including bias and “hallucinations”)
- how human review is applied to outputs
- how users can challenge or correct results
This is a direct response to the risk that AI outputs can look authoritative while being factually wrong. In a tax context, that is unacceptable.
For vendors, this means UI/UX changes: clear disclosure banners, explainability prompts, and visible audit trails for how answers were produced.
2) “Reliable source data” means legislation, case law, and HMRC publications
HMRC is explicit about acceptable data sources for GenAI used in tax software:
- Official HMRC publications and manuals
- Primary legislation
- Established case law
Training on blogs, forums, or generic web content is not aligned with expectations for tools that influence tax returns.
Developers are also expected to implement:
- strong testing before deployment
- continuous monitoring of outputs
- version control of models and data sources
- timely updates as law and guidance change
In practice, this pushes vendors toward legislation-coded or curated knowledge architectures rather than open-internet LLM behaviour.
3) AI must support — never replace — human judgement
HMRC requires “strong human oversight and control at appropriate stages.”
Software should:
- prompt users to review outputs
- allow corrections and challenge mechanisms
- flag complex or nuanced scenarios
- recommend seeking professional advice where appropriate
- remind users that they remain responsible for return accuracy
This is a critical design principle: AI is an assistant, not an authority.
4) Security, privacy, and SSDLC are non-negotiable
Because tax tools handle sensitive personal and financial data, HMRC expects:
- compliance with UK GDPR
- privacy by design
- Secure Software Development Lifecycle (SSDLC) practices
- clear visibility to users on how their data is processed
This has architectural implications for how prompts, logs, and model interactions are stored, processed, and audited.
5) Ethical AI and continuous auditing
HMRC expects developers to:
- use diverse, representative training data (GDPR-compliant)
- continuously audit for bias or harmful outputs
- ensure outputs comply fully with legal requirements
- demonstrate fairness, accountability, and public-good purpose
This aligns tax software with emerging global AI-governance norms — but with a uniquely strict tax-compliance lens.
Why this matters for tax-technology vendors
This guidance effectively defines the minimum governance standard for AI in tax products used for HMRC submissions. It favours platforms that:
- rely on authoritative, curated legal sources
- maintain tight version control over rules and data
- embed explainability and auditability into the product
- are architected for human-in-the-loop workflows
Conversely, tools that rely on generic LLM outputs without legal grounding, explainability, or oversight will struggle to meet HMRC’s expectations.
What “good” now looks like in practice
A compliant GenAI-enhanced tax product should be able to demonstrate:
-
Clear disclosure that AI is used and how
-
Traceability back to legislation, case law, or HMRC guidance
-
Human checkpoints before submission
-
Continuous legal content updates and model monitoring
-
GDPR-compliant data handling with SSDLC controls
-
Ongoing bias, accuracy, and ethics auditing
This is as much about software governance as AI capability.
The direction of travel for AI and tax authorities
HMRC’s position signals where tax administration is heading: AI is acceptable — even encouraged — only when it is legally anchored, transparent, and supervised.
For developers, this is not a constraint on innovation. It is a blueprint for building AI that tax authorities can trust.
Key takeaways
-
HMRC welcomes GenAI in tax software, but only with strict transparency, legal sourcing, and human oversight.
-
Acceptable data sources are limited to HMRC materials, legislation, and case law — with continuous monitoring and updates required.
-
Security, GDPR compliance, and ethical auditing are core expectations, not optional extras.
See how AI is adopted in tax authorities around the world.