RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 4, 2026

Nobody Decided to Owe Sales Tax in Eleven States. Your Signup Form Did.

Sales tax is the one compliance obligation a software company can incur entirely through success. No office, no hire, no filing — just customers, distributed across states that each define your product differently. The liability accrues quietly and is usually discovered by someone else's accountant.

No physical presence
Economic nexus attaches on sales volume alone, in states you've never visited
50 classifications
Software, data processing, information service — or exempt, by state
Open lookback
Unfiled periods often lack the protection filed returns get

The Obligation Arrives Without a Decision

Most compliance duties start with an act: you hire someone, you open an entity, you sign a contract, you process a category of data. Sales tax nexus is different. Once states were permitted to base collection obligations on economic activity rather than physical presence, a company could cross a threshold purely because a marketing post did well and a few dozen customers in one state signed up on the same plan.

Thresholds vary — some states use a revenue figure, some pair it with a transaction count, some have dropped the count entirely — but they share a structure that punishes exactly the business model AI startups favor. A low-priced, self-serve, credit-card product generates high transaction counts across many jurisdictions long before it generates meaningful revenue in any one of them.

Then the Harder Question: What Is Your Product?

Nexus tells you where you have an obligation. Classification tells you whether the thing you sell is taxable there, and this is where AI products get genuinely complicated. States did not write their software definitions with generative systems in mind, so the categories in play were drafted for an earlier era: prewritten computer software, software accessed remotely, data processing services, information services, and various professional-service exclusions.

An AI product can plausibly sit in several of them at once. A tool that lets a customer run their own analysis looks like remotely accessed software. The same engine sold as "we analyze your documents and deliver findings" starts to look like a data processing or information service. A version with human review attached may look like a professional service. The technology did not change. The description did — and in several states, the description is what the classification follows.

This is the uncomfortable overlap: the marketing language that makes an AI product sound most valuable — "we handle it for you," "fully managed analysis," "done for you" — is also the language most likely to push it out of a software category and into a taxable service category. Positioning has a tax consequence, and almost no one models it.

Bundling Makes It Worse

Very few AI products are one thing. A typical plan bundles platform access, a usage allotment, storage, support, onboarding and sometimes a human service component. Where a bundle mixes taxable and non-taxable elements, states apply different resolutions: some tax the entire bundle if any part is taxable, some allow allocation when the components are separately stated and separately priced, and some look to the "true object" of the transaction.

That has a design implication for pricing pages and invoices. A single line item reading "Pro Plan — $99/mo" gives you nothing to allocate with. Separately stated components, priced consistently with how you actually sell them, preserve the option to treat them differently. Retrofitting that separation after the fact — with no contemporaneous pricing to support it — is a much weaker position.

Where Customers Are, Not Where You Are

Sourcing rules generally look to where the customer receives the benefit of the service, which for software usually means where the user is located. That is a data problem before it is a tax problem. If billing records capture only a card and an email address, the company cannot determine its own exposure without reconstructing customer location from evidence it did not deliberately collect.

  • Collect a billing address at checkout — not as a fraud control afterthought, but as the primary sourcing record.
  • Handle multi-state customers deliberately: an enterprise buyer headquartered in one state with users in twenty raises an allocation question that varies by jurisdiction.
  • Track exempt purchasers properly: resellers, government and certain nonprofits can be exempt, but only if you hold a valid certificate — the exemption belongs to the document, not the customer type.
  • Keep historical location data: exposure is assessed for past periods, so overwritten customer records make the eventual quantification harder and more expensive.

Why It Surfaces During Diligence

Uncollected sales tax is a standard diligence item because it is one of the few liabilities a buyer can quantify from the seller's own revenue data in an afternoon. Take revenue by state, apply thresholds and rates, and you have a number — one that typically lands in escrow or as a purchase price reduction. Founders are often surprised that a compliance gap nobody ever raised becomes a line item in a term sheet.

The same math runs in reverse in your favor. You can compute your own exposure from the same data at any time, and the cost of doing it early is a fraction of what it costs when someone else does it during a transaction with a signing deadline.

If You Find Exposure, Act Before the Notice

The single most valuable fact about this area is that the remedies are better before a state contacts you than after. Voluntary disclosure programs generally require that the state has not already reached out, and they typically trade a limited lookback period and penalty relief for coming forward. That option is binary and it expires silently — a notice from any one state can end it for that jurisdiction.

  1. Pull revenue and transaction counts by customer state for every completed year.
  2. Compare against each state's threshold to identify where and when nexus was established.
  3. Determine taxability of your specific product in those states, based on what the service actually does and how you describe it.
  4. Quantify the exposure with interest and penalties so the number is known rather than feared.
  5. Decide state by state between voluntary disclosure, prospective registration or a documented position that the product is not taxable — and write down the reasoning.

That last step matters more than it looks. A documented, reasoned taxability position is a defensible posture even if a state later disagrees. Silence is not a position; it is an absence of one, and it reads that way in an audit.

Frequently Asked Questions

We're pre-revenue with a few hundred users on a free tier. Any exposure?

Free usage generally does not create a taxable sale, and thresholds are based on sales. The reason to care now is architectural: capture customer location and structure your plans and invoices before you have thousands of historical transactions with no address data. Doing it at 200 customers costs nothing; doing it at 20,000 is a migration project.

Our customers are mostly businesses. Doesn't that make it B2B exempt?

There is no general business-to-business exemption in US sales tax. Sales for resale can be exempt, and specific purchaser types can be exempt, but both usually require a valid exemption certificate on file. Selling to companies rather than consumers changes very little on its own.

We use a tax automation service. Are we covered?

Those platforms calculate and file well, but they apply the product classification you give them. If you told the system your product is non-taxable software and a state would treat it as a taxable information service, the automation will confidently produce the wrong answer at scale. The classification decision is yours and it should be documented.

What if we're a non-US company selling into the States?

Economic nexus rules generally do not depend on where the seller is organized. A foreign company with sufficient sales into a state can have the same collection obligation as a domestic one, and being outside the US does not put you beyond reach — it mostly makes registration and remittance more procedurally awkward.

Does per-token or usage-based pricing change the analysis?

It can affect which category applies, because consumption-based pricing sometimes reads more like a processing service than like access to software. It does not change the nexus math, which cares about revenue and transaction counts. If anything, high-frequency usage billing inflates transaction counts toward count-based thresholds faster than subscription billing does.

Should we tell customers we're starting to charge tax?

Yes, ahead of the first invoice that includes it, with a plain explanation. Adding a line item silently generates support tickets, chargebacks and the impression that prices rose. A short notice framed as a registration change is unremarkable to customers who buy other software.

Your Pricing Page Is Evidence

How you describe and package what you sell — managed service versus tool, bundled plan versus separately stated components — is exactly what a state examiner reads when deciding which category your product falls into. Most teams have never looked at their public pages with that question in mind.

Review what your site actually claims to deliver. Run a free scan and pull every page that describes your plans, deliverables and included services.

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.