Why I Built AuditClaude on Claude Cowork — Not ChatGPT, Not Gemini
GARY FONGShare
Bonus post — companion to Part 4 of the series. There I argued you shouldn't trust a single AI for tax work. Here's the rest of the answer: of the three I use, why Claude is the anchor, and why I run it inside Cowork instead of a browser tab.
The day Gemini leaked a name into a stranger's tax return.
This actually happened. It's why I built AuditClaude the way I did.
In May 2026, while testing the Three-Pass System on a fake client return (the Maya Parker case I'd built for documentation), I ran the same audit prompt through ChatGPT, Gemini, and Claude. Same PDF. Same instructions. Just looking for consistency across the three models.
Two of them produced reasonable audit critiques. Gemini's response, in the middle of its analysis, dropped a personal name into the text — a name from a completely unrelated chat I'd had months earlier on a different topic. A name that had no place in a tax review for someone named Maya Parker, who didn't exist in the first place.
The wall between two unrelated chats was supposed to be there. It wasn't. The leak was right there in front of me, on my own screen, in the middle of a fictional client's audit.
If this happens to a tax review of a fake client, what happens when it's a real return with a real SSN on a real address? I don't want to find out.
The chatbot architecture problem.
Here's what every chatbot does when you paste your tax return in, whether the chatbot is ChatGPT, Gemini, Copilot, Claude.ai, or anything else:
Your file leaves your computer. It travels over the internet to a server somewhere. That server processes it, generates a response, sends the response back. Your file may sit on that server for a while. It may be used to improve the model unless you've toggled some setting off. Other chats in your account history may, depending on the platform, share context with the new chat through a memory or "personalization" feature you forgot you enabled.
None of this is sinister. It's just how web-based AI works.
For asking ChatGPT to summarize a news article, the architecture is fine. The article is public. Nothing private travels.
For asking ChatGPT to find missed deductions on your Schedule C, the architecture has a problem. Your bank statements travel. Your Social Security number travels. Your home office layout travels. Where they end up after they arrive is between you and the chatbot's terms of service, which were last updated three weeks ago and have a section you didn't read.
What I saw in the Gemini response showed me the failure mode is real, not theoretical. A name from one chat appeared in another. If the wall between chats can be that porous for one piece of context, it can be porous for others.
What Cowork does differently.
Cowork is Anthropic's desktop integration for Claude. It's not a different model. The Claude that lives inside Cowork is the same Claude that lives on the website. The difference is where the model sits and how it reaches your files.
In a browser-based chatbot, you upload files. The files leave your machine. The model lives on a server, sees the files via that upload.
In Cowork, Claude reads files from a folder you've selected on your own laptop. The files don't get uploaded. They're read in place. When the session ends, nothing migrates anywhere new. Your bank statements stay on your hard drive, where they were before you started.
Five things that matter for tax work, in plain terms:
1. Your files stop traveling. Claude reads them from your folder. They don't bounce to a server, get cached somewhere, or sit in an upload history. The SSN on page 12 of your tax return stays on page 12 of your tax return on your laptop.
2. The folder scope persists. Once you point Cowork at your tax folder, every new Claude conversation can see the files without you dragging them back in. ChatGPT makes you re-upload every time, which means more copies traveling more places.
3. You can run two Claudes against the same folder at once. While one is hunting for deductions you missed, another is auditing the deductions you took for risk. Both reading the same files. Neither waiting on the other. A web chatbot is one thread at a time.
4. Anthropic doesn't train on what passes through. Their language on this is direct and the architecture supports it. OpenAI and Google have softer language and require you to find a checkbox in account settings to opt out. With Cowork the off-by-default is structural, not a toggle.
5. Desktop-only is intentional. Cowork doesn't have a phone app. If your files had to travel to your phone, they'd have to travel through a server first. That breaks the whole privacy posture. Phones are good for chat. Files belong on the machine.
Those five points are why I chose Claude Cowork over its sibling Claude.ai (same model, different environment), and why I chose Claude at all over the alternatives.
Fresh eyes from a fresh agent.
The second thing Cowork does that matters for AuditClaude is something most chatbot users never see, because chatbots don't expose it.
Inside a Cowork session, the main Claude you're chatting with can spawn a sub-agent. That sub-agent starts with zero context. It hasn't seen your prior messages. It hasn't seen what the main agent has been thinking. It gets handed a specific task and a specific set of files, and it goes off and works the problem with completely fresh eyes.
For most things this is overkill. For audit work it's the whole game.
The way I use it in the Three-Pass System: after Pass One finishes and the main Claude has produced a list of missed deductions and the reasoning behind each one, I spawn a fresh sub-agent and hand it the same source documents plus an adversarial prompt. "Find every problem with these claims." That sub-agent has never seen the reasoning. It can't be persuaded by the main Claude's confidence. It evaluates the work cold.
About 12% of the time, the fresh sub-agent surfaces something the main agent rationalized past. A round-numbered deduction the main agent thought was supportable. A vehicle expense the main agent stacked too high. A QBI calculation that's a phase-out trap.
That 12% catch rate is the difference between an audit defense file that holds up and one that quietly falls apart on cross-examination by an IRS examiner with a risk-scoring model running behind them.
You can do this in Cowork. You cannot do it inside ChatGPT, Gemini, or Claude.ai, because all three carry the original chat context with them when you ask the same model to "now critique what you just said." It's the same model talking to itself. It rarely changes its mind.
Why this matters for your taxes specifically.
You're not asking the AI about the weather. You're asking it about a document that, between your SSN and your bank statement metadata, is more sensitive than anything else on your computer right now.
The cost of the privacy failure isn't abstract. Tax data appearing in unrelated chats. Bank statement details bleeding into recommendation algorithms. Confused training-set inclusions you can't undo because you can't unsee what someone else saw.
And the cost of the architecture failure isn't abstract either. The wrong AI nodding along with itself, missing the very thing an IRS examiner will catch, because the model that drafted your defense is the same model auditing your defense.
Two structural problems. Two structural fixes. Local files plus fresh sub-agents. That's the combination Cowork delivers and the web chatbots don't.
It's also why every prompt in AuditClaude assumes you're running Claude inside Cowork with your tax folder selected and your sub-agent privileges enabled. The prompts work in Claude.ai too. They just give up some of the protection that makes the Three-Pass System reliable on real returns.
A note about the other chatbots.
None of this is an attack on ChatGPT or Gemini. They're both impressive tools. I use ChatGPT every week for things where the privacy posture doesn't matter, and Gemini's search-grounded responses are genuinely useful for current-events questions.
Tax returns are just a category where the architecture mismatch shows up most expensively. Different tools, different jobs. The chatbots are great at chat. Cowork is built for files.
The leak didn't make Gemini bad. It made Gemini wrong for THIS job. Same way I wouldn't use a hammer to install a screw. Tools have shapes. Pick the one that fits the work.
Keep your CPA.
Same standing reminder you've seen on every post in this series. AuditClaude does not replace your CPA. A licensed preparer signing your return gives you reasonable-cause defense under Treas. Reg. §1.6664-4 that no AI provides, regardless of which AI it is or where it runs. The Three-Pass System produces the file your CPA reviews. Your CPA still signs.
Pick the AI architecture that matches the job.
For tax work, that means Claude in Cowork.
AuditClaude — The Three-Pass System for self-employed Schedule C filers.
The methodology playbook, the Maya Parker case study, twelve copy-paste prompts, and the Cowork privacy reference so you can verify Anthropic's claims yourself. Digital download.