It's 4.40pm on a Thursday in October, in a twelve-person practice. A client's management pack is due in the morning. One of your best seniors has found a free chatbot. It turns a messy trial balance into tidy commentary in about forty seconds.
Nobody told them not to. Nobody told them they could. The pack goes out on time. It reads rather well.
But before that pack left the building, it had already walked past several rulebooks. Most weren't written with AI in mind. They still apply.
Nobody holds a launch meeting for shadow AI
AI rarely arrives because the partners decided to bring it in. Someone finds a tool that saves an hour. Word spreads at the kettle. The policy turns up later, if it turns up at all.
66%
had used AI tools they thought weren't allowed
PagerDuty/Wakefield, 2026
34%
said they'd put customer data into public AI tools
PagerDuty/Wakefield, 2026
29%
of the larger firms ICAEW discussed AI with had a formal AI policy
ICAEW Practice Assurance Monitoring Report 2025
PagerDuty/Wakefield asked 1,250 office workers at large firms (revenue of at least $500m) in the UK, US, Australia and Japan. Fieldwork ran in April 2026. The results came out in June 2026. ICAEW's figure covers the larger firms it held AI discussions with in its 2024 monitoring; it doesn't say how many that was. Read these numbers as signs of risk, not a measure of your own practice.
Closer to home, ICAEW's Practice Assurance Monitoring Report 2025 reports on the larger firms it held detailed AI discussions with during its 2024 monitoring. Only 29% of them had a formal AI policy at all. Where there was a policy, it usually covered protecting confidential data.
Only 20% monitored staff access to AI tools. And 22% restricted access to what the report calls open-source tools, such as ChatGPT.
We haven't found a reliable survey of how many UK accountants paste client data into public tools. So we won't quote one. You don't need one to see the pattern. AI saves time. Policy lags behind. Few firms can see what's really happening.
There's no UK AI Act, and that's less comforting than it sounds
In January 2026 the Government confirmed that existing law and existing regulators apply at the point of use. So you don't have one new rulebook to learn. You have several old ones. They already reach the prompt box.
Read as a list
All five sets of rules reach the prompt box, what your team types:
- Ethics
- Data protection
- Tax conduct
- AML
- Audit quality
1. Ethics and confidentiality
The ICAEW Code of Ethics 2026 has been in force since 1 July 2026. Its fundamental principles apply to technology too. Section 114, on confidentiality, says you may need permission to use confidential information for training or building new technology.
ICAEW's generative AI guidance is more direct: don't put confidential information into public AI tools. Its own words: "not loading confidential information into public Generative AI tools". And ACCA's March 2026 guidance says members "cannot abdicate nor outsource their responsibilities for professional scepticism and judgement to technology".
If a prompt contains client information, you've used or disclosed that information.
2. Data protection
UK GDPR and the Data Protection Act 2018 cover the personal data in prompts, uploaded ledgers, payroll, emails and KYC (know-your-customer) files. You need a lawful basis, minimisation, accuracy and security. And you must be able to show it.
If an AI provider acts as your processor, Article 28 requires a contract covering instructions, confidentiality, security, sub-processors, deletion and audits. It can be in electronic form. Not every AI supplier is a processor. So read the actual terms instead of assuming.
Keeping data in the UK is a sensible control. But it isn't a rule everyone must follow. And it doesn't replace anything above.
The Data (Use and Access) Act 2025 is now fully in force for data protection. It lets automated systems make more big decisions on their own, as long as there are safeguards in place.
Where a person is part of the decision, their involvement has to be meaningful. The ICO says the reviewer needs the information, the competence and the authority to change the result. A quick click-through doesn't count as oversight.
The Act also expects you to acknowledge data-protection complaints within 30 days. So if a client asks "what did your AI do with my data?", someone at your practice needs to be able to answer.
If a tool screens CVs, the Equality Act 2010 still applies to the outcome.
3. Tax conduct and Making Tax Digital
PCRT 2026 has been in force since 1 January 2026. It's mandatory for members of the seven PCRT bodies who advise on UK tax. The bodies' AI guidance of 19 January 2026 says members stay ultimately responsible for work made with AI. They must check the output for bias, correctness and whether it fits with current law.
MTD for Income Tax has applied since 6 April 2026. It covers sole traders and landlords with qualifying income over £50,000. MTD for VAT has applied since April 2022. Neither creates an AI duty. But both raise the risk of AI copying figures without anyone checking them. You need an accurate, traceable route from the source record to the submission.
Tax adviser registration is now law. The rollout is happening in phases (the dates are in Part 2). HMRC's standard for agents asks you to access client data only with permission. It also asks you to keep timely notes of your reasoning on tax-planning judgements.
4. Money laundering and economic crime
The Money Laundering Regulations 2017 require due diligence, ongoing monitoring and records good enough to reconstruct a transaction. You usually keep those records for five years. Then, with some exceptions, you delete them (regulation 40).
"The model said low risk" won't do as a customer due diligence (CDD) record. Breaking one of these rules can be a criminal offence.
The Proceeds of Crime Act 2002 still governs suspicious activity reports and tipping-off. If AI touches material related to money laundering, it mustn't reveal a suspicion to a client. The decision to report stays with a person.
Companies House identity verification became mandatory on 18 November 2025. That started a 12-month transition for existing directors and people with significant control, so check when each person is due. Authorised corporate service providers must follow the verification standard. They must also usually keep the evidence for seven years.
5. Audit quality
If you do audit or assurance work, three standards already apply: ISQM (UK) 1 (effective 15 December 2022), ISA (UK) 315 and ISA (UK) 230. They require a quality-risk system, plus documented work, evidence and judgements.
For audit work, the FRC's AI guidance of June 2025 and March 2026 expects you to have the right amount of confidence in what a tool produces. It also expects documentation and human review in proportion to the risk. In its words, "humans in the loop can mitigate the risk".
Back to Thursday
None of this means banning your senior's forty seconds. The rules ask for something more practical. Keep client data under your control. Match oversight to the task and its risk. Keep a record someone could reconstruct. And have a policy people actually follow.
No rule says a partner has to approve every output. For audit work, the FRC's guidance supports proportionate documentation and appropriate human review. And the Data (Use and Access) Act allows some decisions to be made by automation alone, with safeguards. The rules expect you to be able to say who checked it, what they checked, and why that was enough.
