The IRS Can’t Tell Who’s Real Anymore

 

The IRS is drowning. Not in paperwork. In comments.

According to a recent GAO report, covered by Michael Cohn in Accounting Today, the IRS is being swamped by public feedback on proposed tax regulations.

A growing share of it is AI-generated. And the agency has no reliable way to tell which comments come from real people and which come from a chatbot with an agenda.

My co-host, David Leary, and I discussed the story on Episode 498 of The Accounting Podcast.

 
 

The IRS feedback system used to work just fine

Rulemaking in this country runs on public comment. Congress passes a law. The Treasury and the IRS write the regulations that actually implement it. Before those regulations become final, the public gets to weigh in.

That feedback should shape the outcome.

For years, the system had a built-in safeguard against manipulation: laziness.

If someone wanted to flood the comment period, they'd copy and paste the same message over and over. The IRS could spot duplicates instantly and discount them. Bots did this, too. Same text, different name, easy to filter out.

That safeguard is gone.

AI doesn't copy and paste

Feed a large language model one opinion and a prompt, and it will generate a thousand comments that all say the same thing in a thousand different ways. Each one reads as an original, individually written submission.

None of them is.

As David and I talked about on the show, this is bigger than the IRS. Every agency that relies on public comment has this problem: the SEC, PCAOB, and FASB.

So does every professional body that collects feedback from its own members, including NASBA and the AICPA. The comment box has become a place where one person can show up as an army.

Think about what that means for rulemaking

A single person with a laptop can generate thousands of unique-sounding comments arguing for one outcome. Regulators use those comments to gauge public opinion.

If one side looks organic but isn't, the rule gets written to reflect a position almost nobody actually holds. One person, artificially amplified, can outweigh an entire industry's real feedback.

The GAO's response so far is a recommendation, not a fix. It's telling Treasury and the IRS to create policies for reviewing large volumes of identical or near-identical comments. That's a reasonable start. But it assumes the comments will still look similar enough to flag.

AI-generated text doesn't have to.

Here’s an analogy

Twitter, now known as X, used to be a place for actual conversation.

Now, post anything with real engagement potential, and you're buried under bot replies. Many people have stopped reading replies altogether because they know most of them aren't real.

Public comment periods are heading down the same road. Once regulators can't trust the comments, the whole point of collecting them disappears. And once the public suspects the process is already gamed, they stop participating.

That's the real cost here. A process built on individual, sincere feedback breaks down the moment feedback can be manufactured at scale.

Once that trust is gone, it doesn't come back by hiring more reviewers.

So what needs to happen?

Flagging duplicate comments, which is all the GAO is recommending, won't be enough on its own. Agencies need a way to verify that a comment came from an identifiable person or organization, not a script.

That could mean requiring authenticated submissions. It could mean building tools that catch AI-generated patterns even when the wording varies. Either way, agencies need to start treating public comments as something that can be gamed.

 
Next
Next

Is AI Cutting Accounting Jobs? Or Creating Them?