I Run Drake Desktop. Here's Which AI Tax Prep Tools Actually Work With It.
- Kenneth Eremita
- 1 day ago
- 9 min read

Part 1 of a series on building AI into a boutique tax practice. (updated 7/23/2026)
There's literally nothing on the internet about user experiences with AI tax prep, so I figured I'd share my experience. The industry is headed this way so I wanted to dive in to see if my profession's actually on the chopping block (or something like that). If you're a fellow practitioner and want to connect, drop me a line: info@keneremita.com
I run a boutique CPA practice in California. Mostly solo-S-corp owners, K-1s, multi-state returns, and the personal 1040s hanging off all of it. I prepare in Drake Desktop.
That last sentence is the whole article.
I spent from May-July 2026 evaluating AI-assisted tax prep tools. Contract review, regulatory analysis, a lot of email with founders/sales people. What I expected to be a security exercise turned into something more basic: most of this market doesn't actually work with my tax software, and you cannot tell that from any vendor's website.
Here's what I found, and what I'm actually using.
"Drake integration" does not mean what you think it means
Go look at the integration pages for the major AI tax prep platforms. Nearly all of them list Drake. Black Ore lists Drake. Filed lists Drake. Juno lists Drake. If you're a Drake firm reading marketing pages, it looks like you have a full menu.
Then you get on a call and ask the follow-up question, which is: does it work with Drake Desktop, installed locally on my machine?
That is a different question, and the answers get a lot less enthusiastic. "Drake" on a vendor's integration list can mean any of several things - a hosted or cloud Drake environment, a file-based import you run manually, a browser automation layer driving the interface, or a roadmap item that made it onto the marketing page early. Some of those work fine for a desktop firm. Some don't work at all.
So when I say a tool didn't work for me, I mean specifically: it did not work with my Drake Desktop configuration when I asked about it, in June and July of 2026. That is not the same as saying it doesn't support Drake, and it's certainly not permanent. This market ships fast. Ask them yourself, about your exact setup, and make them show you live.
With that caveat carved in stone, here's how my menu shrank.
TaxGPT: When I asked about my configuration, Drake Desktop wasn't supported, and I didn't get a timeline. It sucks because I signed up and paid for their 100 return minimum. They were willing to refund me but I opted for a generous extension on the renewal instead (TAXGPT, IF YOU'RE READING THIS, YOU BETTER COME THROUGH). Worth saying clearly, though: TaxGPT handed over the strongest documentation package of anyone I evaluated - SOC 2 Type II, a real third-party penetration test with remediation tracked, a certificate of insurance, an attestation letter, no friction. That's a mature posture and it's rare this early. For now, their research product is pretty good and I like being able to securely work with real client data for specific questions.
Black Ore: Enterprise-grade, genuinely impressive, and built for firms considerably larger than mine. Their public materials list Drake. When I emailed them for a demo call in June 2026, they said they didn't support Drake desktop. Perhaps I also don't run enough volume as that contradicts their marketing. My exploration ended there.
Filed: Didn't get past the volume conversation. The return commitment I was quoted was in the neighborhood of a thousand returns, which is way more that I do. I'll note that Filed markets to firms of all sizes and doesn't publish that figure, so treat it as what came up in my sales conversation rather than a published policy.
That volume floor is worth pausing on, because it's the second filter nobody mentions and it catches a lot of solos. It isn't universal - Juno's base plan starts at 100 returns and invites smaller firms to talk, and Soraban runs a 100-return minimum at roughly $45 per return. TaxGPT has the same minimum but includes it's research product and it's cowork tool which is poised to have promising functionality - it's simply a better bargain. Unfortunately, I put money down with them before I realized it didn't work with Drake desktop. They claimed it'd happen by August 2026, so I'm working with the expectation that they'll do tax prep, research and some light cowork-style tasks for a similar price to Juno and Soraban.
Minimums are common in this category, and if you file fewer than a hundred returns a year you should ask about the floor in the first five minutes of every call. It will save you time. I have been a Gruntworx user and I think that's still a good option because it's pay per use and does most of the same forms.
Two tools survived both filters for me: Magnetic and Avalon Tax.
Quick note: Gruntworx won't import Sch C/E P&Ls, estimated payment info, PY asset schedules or anything generally outside of a K1, 1099, 1098 or W2. Magnetic does appear to load in PY data, asset schedules, P&Ls, etc. Avalon will do all of that except for asset schedules which the founder said should be available in August 2026. Anyway, Gruntworx, is a fine enough product if you're dipping your feet into automation and it got me through a few tax seasons so far.
The security work, which I've actually helped these companies shape
Before I get to how they compare operationally: I wasn't willing to send client data anywhere until the compliance question was closed, and that took most of the two months. There's no practice-based resource on how to navigate this. What I had to do was understand the regulations and understand each vendor's workflow to learn the points where failure can happen and how to mitigate them.
Once client data leaves my machine, the rules that attach are attached to me, not the vendor: IRC §7216 and Treas. Reg. §301.7216-2, the FTC Safeguards Rule at 16 CFR 314.4(f), California BPC §5063.3 and CBA Regulation §54.1, and Circular 230 - §§10.22, 10.35, 10.36, 10.37, and the one nobody wants to think about, §10.51. The OPR bulletin on AI in tax practice from June 2026 makes the direction of travel obvious. No regulator is going to ask the vendor anything. They're going to ask the practitioner.
In short, I had to make sure everything transmitted from my machine has as close zero chance of landing anywhere outside of the vendor's servers and AI subprocessors as possible. Then, I had to vet TaxGPT, Magnetic and Avalon to understand how the data flows once it's in their custody to see if there could be points of failure. For additional vetting, I wanted to make sure they had ZDR's in place with their AI subprocessors and an insurance policy as well. TaxGPT had a trust center to see all their IT security info which was helpful. From there, I had to ask for a signed agreement/DPA with these terms:
US-only processing, including every subprocessor. Not "we're a US company." Where does inference actually run, and who touches the file on the way?
No model training on client data, surviving termination. A promise that expires with the contract isn't a promise.
Direct breach notice to my firm, in hours not discovery. Not just notice to regulators but notice to me if client data could have been compromised.
Deletion on request, with written confirmation.
Item 3 was the single most revealing question I asked. Most vendor incident response plans commit to notifying regulators. Very few commit to notifying the firm whose clients' data it was.
Three things I learned:
A WISP is not a DPA. A vendor's WISP is a document the vendor wrote for the vendor. It describes what they intend to do. It creates no obligation running to you and you can't enforce it. A DPA is a bilateral contract creating duties owed to your firm. Several agreements I read said something like "Provider shall process Personal Data in accordance with the Data Processing Agreement" - which looks like protection, but if no DPA was ever executed, that section is contractually switched off. Check whether the DPA your agreement references actually exists.
The Safeguards Rule means the words it says. 16 CFR 314.4(f)(2) requires you to oversee providers by "requiring your service providers by contract to implement and maintain such safeguards." By contract. Not by security page on their website, not by a friendly email saying their approach covers most of it. I argued with myself about this for weeks, because a month of contract negotiation over four sentences feels absurd when you're one person and the software is right there. The rule says "by contract" and I couldn't argue around it.
Both surviving vendors now clear this bar. Avalon's founder read and signed the DPA I sent. Magnetic published a DPA on July 17, 2026 that closes most of the same ground - it states all processing occurs in the United States, commits to breach notice to the customer within 48 hours, binds their security program contractually, and overrides conflicting terms in the main agreement. I'd spent a month asking for exactly that and had written them off before it appeared. Credit where it's due. TaxGPT's DPA page needs work at the time of writing this and I'll let them know once their tax prep tool for Drake Desktop is live...honestly, I have to run a firm still and that'll be a priority down the line.
The last thing I learned is that these companies are really small. We're talking - CEO to customer interaction with Magnetic, Avalon and TaxGPT. I've asked for things and it's apparent they created them to satisfy my requests.
Anyone signing on, is coming in at the ground floor of their development. I suppose it's nice to wait on the sidelines but I'm more interested in giving these firms my feedback so that I can shape a product that satisfies my needs. Magnetic literally had no DPA on their website until I asked for one. I didn't want to wait until right before 2027's busy season to learn that no one else has pushed them to progress.
Based on my interactions with folks at Jason Staats' LA/OC conference in June 2026, no one has done as much digging as me on the security and contractual issues - and this guy is the AI champion for tax firms.
If you're sitting on the sidelines, don't. Get in there, do your own due diligence and push these guys to further enhance their contract and security protocols. It's a good time to crowd-source our IT security requirements.
If you're a Drake Desktop firm evaluating this, do these six things
Ask what "Drake integration" means for a local desktop install. Make them demo it on your configuration, not theirs.
Ask about the return minimum in the first five minutes. Volume floors kill more solo deals than price does.
Ask for the contract, not the security page. The security page is marketing.
Ask which direction breach notice runs - to regulators, or to your firm.
Ask whether the referenced DPA exists, then read it
Get US-only processing confirmed in writing before real client data touches anything.
FAQ
Does AI tax software work with Drake Desktop? Some does, but "Drake" on a vendor's integration page can mean a hosted environment, a file-based import, or browser automation - not necessarily a local desktop install. Ask specifically about Drake Desktop and require a live demo on your own configuration before you sign anything.
Is there a minimum number of returns for AI tax prep software? Frequently, yes, and it's the filter most solo practitioners hit first. Published minimums in this market commonly sit around 100 returns; some enterprise-oriented vendors are considerably higher. Ask early.
Does using AI tax software require client consent under IRC §7216? It depends on the structure. Disclosure to a domestic service provider performing auxiliary services can fall under Treas. Reg. §301.7216-2, and an engagement letter with a proper third-party disclosure provision may already cover it (i.e. the disclosure you may have used to run Gruntworx) - the same basis most firms already rely on for scanning and organizer vendors. Offshore processing is a different analysis, and California's CBA Regulation §54.1(b) adds an offshore-specific notice requirement. Get your own determination.
Is a vendor's SOC 2 report enough for FTC Safeguards Rule compliance? No. A SOC 2 helps satisfy the "select capable providers" prong. It does not satisfy 314.4(f)(2), which requires binding the provider by contract. Separate obligations.
Which AI tax tool is best for a solo CPA firm? There isn't a universal answer and anyone giving you one is selling something. It depends on your tax software, entity mix, state exposure, and risk tolerance. Agentic preparation for complex S-corp and multi-state work is still a real gap - most mature tools are 1040-centric.
Next in this series
Part 2 is the pilot: the review protocol I built, what these tools got right, what they got wrong, and what a return actually costs me in minutes on the other side. Running it during the off-season with real returns. I'll publish the results whether they're flattering or not.
If you're a firm working through a similar evaluation, I'm happy to compare notes info@keneremita.com
I have no financial relationship with any vendor named in this post and received no compensation from any of them. This describes my own analysis of my own practice and is not legal, tax, or professional advice. Product capabilities, integrations, pricing, and contract terms in this category change constantly - every observation here reflects what I found in June and July 2026 and should be verified directly with the vendor. Do your own due diligence and get your own counsel.
Ken Eremita, CPA Inc.
