Using AI under your own rules is now a requirement, not a choice

There's no UK AI Act. But rules on confidentiality, data, tax conduct, money laundering and audit already cover how your team uses AI. Here's what applies today.

Article

A partner's hand, pen poised, over an open management pack on a wooden desk beside a brass lamp and a cup of coffee, the busy office softly blurred behind.

It's 4.40pm on a Thursday in October, in a twelve-person practice. A client's management pack is due in the morning. One of your best seniors has found a free chatbot. It turns a messy trial balance into tidy commentary in about forty seconds.

Nobody told them not to. Nobody told them they could. The pack goes out on time. It reads rather well.

But before that pack left the building, it had already walked past several rulebooks. Most weren't written with AI in mind. They still apply.

Nobody holds a launch meeting for shadow AI

AI rarely arrives because the partners decided to bring it in. Someone finds a tool that saves an hour. Word spreads at the kettle. The policy turns up later, if it turns up at all.

  • 66%

    had used AI tools they thought weren't allowed

    PagerDuty/Wakefield, 2026

  • 34%

    said they'd put customer data into public AI tools

    PagerDuty/Wakefield, 2026

  • 29%

    of the larger firms ICAEW discussed AI with had a formal AI policy

    ICAEW Practice Assurance Monitoring Report 2025

PagerDuty/Wakefield asked 1,250 office workers at large firms (revenue of at least $500m) in the UK, US, Australia and Japan. Fieldwork ran in April 2026. The results came out in June 2026. ICAEW's figure covers the larger firms it held AI discussions with in its 2024 monitoring; it doesn't say how many that was. Read these numbers as signs of risk, not a measure of your own practice.

Closer to home, ICAEW's Practice Assurance Monitoring Report 2025 reports on the larger firms it held detailed AI discussions with during its 2024 monitoring. Only 29% of them had a formal AI policy at all. Where there was a policy, it usually covered protecting confidential data.

Only 20% monitored staff access to AI tools. And 22% restricted access to what the report calls open-source tools, such as ChatGPT.

We haven't found a reliable survey of how many UK accountants paste client data into public tools. So we won't quote one. You don't need one to see the pattern. AI saves time. Policy lags behind. Few firms can see what's really happening.

There's no UK AI Act, and that's less comforting than it sounds

In January 2026 the Government confirmed that existing law and existing regulators apply at the point of use. So you don't have one new rulebook to learn. You have several old ones. They already reach the prompt box.

Five sets of rules already reach the prompt box. Most of them weren't written with AI in mind.
Read as a list

All five sets of rules reach the prompt box, what your team types:

  1. Ethics
  2. Data protection
  3. Tax conduct
  4. AML
  5. Audit quality

1. Ethics and confidentiality

The ICAEW Code of Ethics 2026 has been in force since 1 July 2026. Its fundamental principles apply to technology too. Section 114, on confidentiality, says you may need permission to use confidential information for training or building new technology.

ICAEW's generative AI guidance is more direct: don't put confidential information into public AI tools. Its own words: "not loading confidential information into public Generative AI tools". And ACCA's March 2026 guidance says members "cannot abdicate nor outsource their responsibilities for professional scepticism and judgement to technology".

If a prompt contains client information, you've used or disclosed that information.

2. Data protection

UK GDPR and the Data Protection Act 2018 cover the personal data in prompts, uploaded ledgers, payroll, emails and KYC (know-your-customer) files. You need a lawful basis, minimisation, accuracy and security. And you must be able to show it.

If an AI provider acts as your processor, Article 28 requires a contract covering instructions, confidentiality, security, sub-processors, deletion and audits. It can be in electronic form. Not every AI supplier is a processor. So read the actual terms instead of assuming.

Keeping data in the UK is a sensible control. But it isn't a rule everyone must follow. And it doesn't replace anything above.

The Data (Use and Access) Act 2025 is now fully in force for data protection. It lets automated systems make more big decisions on their own, as long as there are safeguards in place.

Where a person is part of the decision, their involvement has to be meaningful. The ICO says the reviewer needs the information, the competence and the authority to change the result. A quick click-through doesn't count as oversight.

The Act also expects you to acknowledge data-protection complaints within 30 days. So if a client asks "what did your AI do with my data?", someone at your practice needs to be able to answer.

If a tool screens CVs, the Equality Act 2010 still applies to the outcome.

3. Tax conduct and Making Tax Digital

PCRT 2026 has been in force since 1 January 2026. It's mandatory for members of the seven PCRT bodies who advise on UK tax. The bodies' AI guidance of 19 January 2026 says members stay ultimately responsible for work made with AI. They must check the output for bias, correctness and whether it fits with current law.

MTD for Income Tax has applied since 6 April 2026. It covers sole traders and landlords with qualifying income over £50,000. MTD for VAT has applied since April 2022. Neither creates an AI duty. But both raise the risk of AI copying figures without anyone checking them. You need an accurate, traceable route from the source record to the submission.

Tax adviser registration is now law. The rollout is happening in phases (the dates are in Part 2). HMRC's standard for agents asks you to access client data only with permission. It also asks you to keep timely notes of your reasoning on tax-planning judgements.

4. Money laundering and economic crime

The Money Laundering Regulations 2017 require due diligence, ongoing monitoring and records good enough to reconstruct a transaction. You usually keep those records for five years. Then, with some exceptions, you delete them (regulation 40).

"The model said low risk" won't do as a customer due diligence (CDD) record. Breaking one of these rules can be a criminal offence.

The Proceeds of Crime Act 2002 still governs suspicious activity reports and tipping-off. If AI touches material related to money laundering, it mustn't reveal a suspicion to a client. The decision to report stays with a person.

Companies House identity verification became mandatory on 18 November 2025. That started a 12-month transition for existing directors and people with significant control, so check when each person is due. Authorised corporate service providers must follow the verification standard. They must also usually keep the evidence for seven years.

5. Audit quality

If you do audit or assurance work, three standards already apply: ISQM (UK) 1 (effective 15 December 2022), ISA (UK) 315 and ISA (UK) 230. They require a quality-risk system, plus documented work, evidence and judgements.

For audit work, the FRC's AI guidance of June 2025 and March 2026 expects you to have the right amount of confidence in what a tool produces. It also expects documentation and human review in proportion to the risk. In its words, "humans in the loop can mitigate the risk".

Back to Thursday

None of this means banning your senior's forty seconds. The rules ask for something more practical. Keep client data under your control. Match oversight to the task and its risk. Keep a record someone could reconstruct. And have a policy people actually follow.

No rule says a partner has to approve every output. For audit work, the FRC's guidance supports proportionate documentation and appropriate human review. And the Data (Use and Access) Act allows some decisions to be made by automation alone, with safeguards. The rules expect you to be able to say who checked it, what they checked, and why that was enough.

Part 2 sets out what changes over the next 24 months. Part 3 shows what a well-run setup looks like, with five things you can do this quarter.

Frequently asked questions

Is there a UK AI Act our practice has to follow?

No. There's no single UK AI Act that covers every industry, including ordinary accountancy practices. In January 2026, the Government said existing rules already apply. These include data protection, competition, equality law and rules for specific sectors. It also said most AI should be regulated where it's actually used. Professional codes, plus tax, money-laundering and fraud rules, are examples of sector rules that already reach how your team uses AI.

Can our staff use a public chatbot for client work?

Not with confidential client information. ICAEW's generative AI guidance says confidential client information shouldn't go into public generative AI tools. That's because you have limited control over how it's shared, secured and kept. Under the ICAEW Code's confidentiality principle, a prompt with client information counts as using or disclosing that information.

If our client data stays in the UK, are we following the rules?

Not on its own. Keeping data in the UK is a sensible risk control. But it isn't a rule everyone must follow. And it doesn't replace a lawful basis, a proper processor contract where you need one, or a look at any onward transfers.

Our practice is small. Do the corporate 'failure to prevent' offences apply to us?

The Economic Crime and Corporate Transparency Act (ECCTA) failure-to-prevent-fraud offence usually only reaches large organisations. But the Criminal Finances Act 2017 offence of failing to prevent the criminal facilitation of tax evasion is different. It has no size threshold. It covers companies and partnerships. So AI-assisted tax work belongs in that risk assessment, whatever your size.

If a partner signs off AI-prepared work, who is responsible for it?

The member and the firm. PCRT's AI guidance says members stay ultimately responsible for work made with AI. And ACCA says professional scepticism and judgement can't be handed over to technology.

One practice first

Start with one workflow, over six weeks, with us alongside

For a UK practice of 5 to 20 staff, with a partner who'll own the review. We run one workflow, measure it before and after, and agree in writing how it ends. Send an enquiry or email us today.

Sources

Show all 40 sourcesHide sources
  1. UK Parliament, written answer on AI legislation (January 2026)
  2. PagerDuty / Wakefield, 2026 Shadow AI Survey
  3. PagerDuty, 2026 Shadow AI Survey: methodology and findings
  4. ICAEW, Practice Assurance Monitoring Report 2025
  5. ICAEW Code of Ethics 2026
  6. ICAEW, Generative AI and ethics
  7. ACCA, Key areas of risk when adopting AI
  8. UK GDPR, consolidated text
  9. UK GDPR, Article 28 (processor contracts, including electronic form)
  10. ICO, Controller and processor contracts
  11. ICO, Maximum fines under UK GDPR and DPA 2018
  12. GOV.UK, Data (Use and Access) Act 2025: plans for commencement
  13. ICO, The Data (Use and Access) Act 2025: what does it mean for organisations?
  14. SI 2026/82, Data (Use and Access) Act 2025 commencement regulations
  15. Data (Use and Access) Act 2025, section 80 (automated decision-making)
  16. ICO, How do we ensure individual rights in our AI systems?
  17. DSIT, Responsible AI in recruitment
  18. ICAEW, PCRT
  19. PCRT topical guidance: ethical use of AI tools
  20. HMRC, Making Tax Digital for Income Tax
  21. HMRC, Get ready for MTD: an agent toolkit
  22. HMRC, Check if and when you need to register as a tax adviser
  23. HMRC, Mandatory Tax Adviser Registration Manual, MTAR10100 (Finance Act 2026 s.224)
  24. HMRC, The HMRC standard for agents
  25. Money Laundering Regulations 2017
  26. Money Laundering Regulations 2017 (as made, PDF)
  27. Money Laundering Regulations 2017, regulation 40 (record-keeping)
  28. Money Laundering Regulations 2017, regulation 86 (criminal offence)
  29. Proceeds of Crime Act 2002, section 333A (tipping off)
  30. HM Treasury, Anti-money laundering guidance for the accountancy sector
  31. Companies House, Verifying your identity
  32. Companies House, How to meet the identity verification standard
  33. HMRC, Corporate offences for failing to prevent criminal facilitation of tax evasion
  34. Criminal Finances Act 2017, section 44 (relevant body)
  35. Criminal Finances Act 2017, section 45 (defence of reasonable prevention procedures)
  36. Home Office, Guidance to organisations on the offence of failure to prevent fraud (accessible version)
  37. FRC, ISQM (UK) 1
  38. FRC, Auditing standards (ISAs (UK), including ISA (UK) 230 and 315)
  39. FRC, AI in Audit
  40. FRC, Generative and Agentic AI Guidance
Contact us