Back to Blog
industry

Claude for UK accountants: what the rules actually allow in 2026

By Jay MatharuPublished Last reviewed
Wide view of a quiet breakout area in a City of London practice, two professionals in conversation at a small round table beside floor-to-ceiling glazing

UK accountancy now has published guidance on AI use, and none of it prohibits AI while all of it is specific about client data. Four documents matter: the PCRT topical guidance on the ethical use of AI tools, published 19 January 2026 by the seven bodies that jointly prepare PCRT; the ICAEW Code of Ethics edition that came into force on 1 July 2026; an ICAEW regulatory note of 28 July 2026 that names AI tools among the systems a firm should review for confidentiality; and a draft profession-wide statement from CCAB, out for comment. The binding one is the first: it interprets PCRT, which is mandatory for members of those bodies.

This guide covers what Claude is genuinely useful for in a UK practice, what the rules require before client information goes near a model, and where judgement cannot be delegated. It is written for a partner or practice manager who would rather adopt deliberately than discover the position during a complaint.

The rule that decides everything else

On 19 January 2026 the seven professional bodies that jointly prepare Professional Conduct in Relation to Taxation published topical guidance on applying PCRT to the ethical use of artificial intelligence tools. It applies to any PCRT body member or regulated firm using or considering AI tools when advising on UK tax matters, in practice, in business or in the public sector, and where it refers to a member that includes the firm and its staff.

Its central sentence is the one to build a policy around. The guidance states that the input of client data into publicly available AI tools is likely to constitute a breach of client confidentiality, unless the client has consented to this.

Three things follow from that formulation, and all three matter commercially.

First, the qualifier is "publicly available", not "AI". The guidance is not telling accountants to avoid AI. In the same passage it notes that some organisations have established internal, ring-fenced AI models with strict controls over client data handling to mitigate the risk. The draft CCAB Statement, discussed below, is more direct still and lists among its practical tips using only enterprise-grade AI tools that guarantee data privacy and do not use your data for model training.

Second, anonymisation is treated as a real control but not a complete one. The guidance says data input into publicly available models should be anonymised and generic so the client cannot be identified, and then warns that anonymised data may still identify a client by other means or through a combination of other sources, giving the example of an uncommon service a business is known to provide. In a practice with a recognisable local client base, that caveat has teeth.

Third, the guidance is blunt about what happens to the data: when information is entered into publicly available AI tools, control over it is relinquished, and it may become part of the public domain as source information for the tool. Loss of control over storage and retention, and the possibility of data being retained by third parties or overseas, are named.

This guidance is not advisory in effect. It interprets PCRT, which is mandatory for members of the PCRT bodies, and it states that a member who fails to adhere to the PCRT principles is liable to be subject to the disciplinary process.

What ICAEW has added in 2026

A new edition of the ICAEW Code of Ethics came into force on 1 July 2026, so any practice policy written before that date should be re-pointed at the current edition. Confidentiality is covered by Subsection 114, and paragraph R114.1 requires a professional accountant to comply with the principle of confidentiality.

The wording ICAEW uses to summarise that principle is unusually well suited to an AI question. Accountants must respect the confidentiality of information acquired through professional and business relationships, and protect it during collection, use, transfer, storage or retention, dissemination and lawful destruction. Transfer, storage and retention are exactly what happens when a document is sent to a third-party model, which is why "we only used it for a summary" is not a complete answer. ICAEW also advises assuming that all unpublished information about a client's affairs, however gained, is confidential, and notes the duty extends to past and present clients and to third parties, and to ensuring that personnel under your control comply.

Worth noting alongside it: ICAEW's objectivity principle expressly names technology, requiring accountants to avoid compromise by undue influence or reliance on individuals, organisations, technology or other factors. Automation bias is not an analogy here; it is inside the principle.

On 28 July 2026 ICAEW's Regulatory Policy Director, Sophie Wales, published a regulatory note on protecting client confidentiality which states that AI and other digital tools do not reduce a firm's ethical responsibilities, that the duty applies both externally and within the firm, and that firms should review how confidential information is protected in emails, messaging platforms, document management systems and AI tools. It sets out what amounts to a vendor due-diligence list: firms should ensure confidential client information is not entered into digital systems including AI without appropriate due diligence, contractual protections and internal approval, and should understand where data is stored, who can access it, whether it may be used to train models, and how outputs are monitored.

ICAEW's Generative AI Guide adds the practical version: keep client and confidential internal data off public AI tools, include humans in the loop, review and challenge outputs with professional scepticism while avoiding automation bias, be transparent about when AI has been used, and do not abdicate responsibility. Its framing of the tools is memorable and correct: they are not fully qualified accountants.

Where Claude is actually useful in a practice

The tasks that work are the ones where a professional reads the output before it goes anywhere, and where the input can be controlled. Illustrative patterns, not case studies:

Client correspondence and explanation. Turning a technical position into a letter a client will actually read, or drafting the covering note that explains why a figure has moved. The underlying thinking is already done in this work and what remains is expression, which is the shape of task a drafting assistant handles best.

Working-paper narrative. Drafting the explanatory sections of a file from your own notes and schedules: background, approach taken, judgements applied. The numbers stay in the practice software; the prose is the part that takes an afternoon.

Long-document review. Reading a lease, a loan agreement, a shareholders' agreement or a set of board minutes and pulling out the clauses that bear on the accounting or tax treatment, so a partner starts from a shortlist rather than page one. Check the context window on the route you actually deploy before assuming a whole bundle fits in one pass, because the plans and the API differ. claude.com/pricing lists the context window as 200k tokens on Free, Pro, Max and Team, and 500k on the default model for the Enterprise tiers, while on the API Sonnet 5 and Opus 5 carry 1M. A long lease is comfortably within 200k; a full year of board minutes may not be. Our model selection guide covers the published windows per model.

Advisory drafting and engagement documentation. Structuring an advisory letter from rough notes, drafting engagement letter clauses for review, or preparing a client meeting agenda from the prior year's file.

Internal work, where confidentiality is not engaged at all. Process documentation, staff briefings on a technical change, training material, first drafts of internal policy. This is the least contentious ground and it is often the most neglected: a practice can get real value here while its client-data policy is still being agreed.

Administrative drafting around MTD. Making Tax Digital for Income Tax applies where qualifying income is over £50,000 for the 2024 to 2025 tax year, with those taxpayers due to have started from 6 April 2026; over £30,000 for the 2025 to 2026 tax year, from 6 April 2027; and over £20,000 for the 2026 to 2027 tax year, from 6 April 2028. Note the structure of that test: it is keyed to qualifying income in the stated tax year, not the year of mandation. Partnerships will be brought in, and GOV.UK says the timeline will be set out later, so there is no date to plan against yet. The AI-suitable work here is the client communication programme, not the filing: explaining the change, segmenting who is affected when, drafting the letters. Filing belongs in compatible software.

The confidentiality posture that makes this workable

Reading the PCRT guidance and the ICAEW material together produces a fairly clear operating model, and it is not "ban it".

Sanction one approved deployment. The strongest argument for this comes from ICAEW's own audit guidance of 6 May 2026, which names the risk directly: absent clear policies and controls, members of audit teams who use AI routinely in their personal life may adopt it in professional work without authorisation or the necessary oversight, risking data protection breaches and inadvertent release of client confidential information. That is a regulator describing shadow IT. A practice that has not approved a tool has not prevented AI use; it has simply lost sight of it.

Choose a business tier and read the data terms. The distinction the rules turn on is between a publicly available tool and a controlled deployment. That makes the vendor's position on training, retention, access and residency the substance of your compliance file rather than a procurement footnote. Our guide to whether Claude is GDPR compliant for UK business works through those questions, and Claude data residency for UK organisations covers where processing happens on each route.

Write down what may and may not be entered. Guidance published in ACCA's In Practice hub in March 2026 states that all firms should have firmwide policies covering responsible use of AI tools, and that employees at all levels should be aware of when a tool can be used and when it should not. That article is published by ACCA but by-lined to solicitors at Kingsley Napley, so treat it as guidance ACCA has published rather than a Code requirement. The underlying point stands on its own merits: staff cannot follow a rule that has not been written.

Complete a DPIA where personal data is involved. Client files contain personal data, so a practice rollout is a data protection question as well as an ethics one, and the Data (Use and Access) Act 2025 changed the safeguards an assessment must document. Our DPIA screening test covers whether you need one, and the current position under the Data (Use and Access) Act covers what changed in February and June 2026, including the new complaints duty that applies to your practice as a controller.

Decide the disclosure question once. The bodies are converging on disclosure. PCRT suggests an engagement letter statement and disclosure of actual use in deliverables, and says a client should be told before work commences where AI use is fundamental to the deliverable. ACCA's hub makes the engagement letter point. The draft CCAB Statement lists it among its practical tips. Adding a clause at the next engagement letter cycle is cheaper than retrofitting it after a client asks.

Where the line is: what stays with the accountant

The professional bodies are unanimous on this, in different words, and it is the part of the guidance that will not soften.

The PCRT AI guidance states that members are ultimately responsible for any work they produce, and for regulated firms any work the firm prepares, irrespective of the use of AI tools in its creation, and that it is essential to oversee AI-facilitated work appropriately and diligently. It says outputs should not be used as authoritative tax or legal advice, and that reviews must be undertaken by a qualified professional in the specific context of the client. Its framing for review is the most useful single line in the document: treat AI output as if it were prepared by a less experienced junior colleague, and review it with appropriate scepticism. It also tells members to confirm the existence of any case law or legislation referenced in output, citing Harber v HMRC [2023] UKFTT 1007 (TC).

Guidance published by ACCA puts it as members being unable to abdicate nor outsource their responsibilities for professional scepticism and judgement to technology. The draft CCAB Statement says professional accountants cannot abdicate responsibility for outputs produced by their use of AI tools, and that where an AI agent is used the accountant remains professionally responsible for the outcome.

For audit specifically, the position is settled and regulatory. The Financial Reporting Council published guidance for audit firms on using generative and agentic AI in audit engagements on 30 March 2026, which it describes as the first from any audit regulator globally, and states that regulatory accountability for AI deployment and audit output quality remains unchanged and that the human auditor is always accountable. Mark Babington, the FRC's Executive Director of Regulatory Standards, put it as: while technology changes, it is people, the firms and Responsible Individuals, who are accountable for audit quality. ICAEW's Audit Registration Committee expects all audit firms to establish appropriate policies and procedures covering AI use and to communicate them with appropriate training, and points to Audit Regulation 3.17 on continuing competence, which ICAEW says includes competence in the use of tools and technologies such as AI, and Audit Regulations 3.18 and 3.19 on procedures for the conduct of audit work.

The honest summary: AI can shorten the route to a piece of work. It cannot hold the judgement, and no body in UK accountancy suggests otherwise.

What is still moving

Two items are worth tracking rather than acting on. The Consultative Committee of Accountancy Bodies, whose five member bodies represent 285,000 professional accountants in the UK and the Republic of Ireland, published a draft Statement to the Profession on the Ethical Use of Artificial Intelligence alongside six draft case studies, announced on 2 July 2026, with responses to be discussed at an online event on 25 September 2026. It is an exposure draft, so it indicates direction rather than obligation, and its wording on confidentiality is stricter than PCRT's: client or sensitive data should never be input into an AI tool without specific consent. On that specific point, a policy built to the draft's wording is already inside the PCRT position, though the two documents are not otherwise interchangeable and PCRT remains the mandatory one.

Separately, HMRC's position sits at one remove from practices. Its guidelines of 28 January 2026 are addressed to software developers building commercial products that help customers submit information to HMRC, and expect such software to be transparent, to use reliable source data in line with legislation and established case law, to be designed with human oversight and control, to include strong data security and privacy measures, and to be ethical, and to remind users that accuracy remains the taxpayer's responsibility. HMRC also states it does not endorse or approve any software developer or product, which is worth remembering if a vendor implies otherwise. In the guidance we checked, including HMRC's standard for agents, we found nothing prohibiting or restricting an agent's own use of AI tools.

How this compares with ChatGPT in a practice

The professional rules are tool-agnostic: they turn on whether a deployment is publicly available or controlled, what happens to data in it, and whether a qualified person owns the output. Any assistant can be run compliantly or carelessly. Our companion guide on ChatGPT for UK accountants covers the same ground from the other vendor's side, and Claude for UK financial services covers the adjacent regulated-sector position. Where confidentiality is the binding constraint and cloud processing is genuinely off the table, our Private AI Concierge service runs models on-premises instead.

Where The AI Consultancy fits

Getting a practice from ad hoc use to an approved deployment means three things: a written policy staff can follow, a documented answer to the data questions the bodies now expect you to have asked, and training that covers professional scepticism rather than prompt tricks. That is what our Claude implementation engagements deliver, with the advisory and governance side handled through Claude consulting.

All professional-body positions verified on 12 August 2026 against the PCRT topical guidance on the ethical use of artificial intelligence tools (19 January 2026), ICAEW's fundamental principles and Code of Ethics pages, ICAEW regulatory news of 28 July 2026 and audit guidance of 6 May 2026, ICAEW's Generative AI Guide, guidance published in ACCA's In Practice hub (March 2026, by-lined to Kingsley Napley LLP), the CCAB draft Statement to the Profession (exposure draft, June 2026), the FRC's news release of 30 March 2026, and GOV.UK guidance on Making Tax Digital for Income Tax and HMRC's guidelines for software developers of 28 January 2026. This is general information for practices, not professional conduct, tax or legal advice; your own position should be confirmed with your professional body.

Frequently asked questions

Are UK accountants allowed to use Claude on client work?
There is no prohibition, but there is a clear condition. The PCRT topical guidance on the ethical use of AI tools, published on 19 January 2026 by the seven bodies that jointly prepare PCRT, states that inputting client data into publicly available AI tools is likely to constitute a breach of client confidentiality unless the client has consented. The word doing the work is publicly available. The same guidance notes that some organisations have established internal, ring-fenced AI models with strict controls over client data handling to mitigate that risk, and the draft CCAB Statement goes further and recommends using only enterprise-grade tools that guarantee data privacy and do not use your data for model training. So the practical answer is that a practice should deploy an approved business-tier deployment with documented data handling, not that accountants should avoid AI.
What can Claude usefully do in an accountancy practice?
The work where a professional reads the output before it goes anywhere. Drafting client correspondence and explaining a technical position in plain English. Producing a first draft of working-paper narrative from your own notes. Summarising a long lease, loan agreement or set of board minutes so a partner can find the point that matters. Turning a partner's rough notes into a structured advisory letter. Preparing questions for a client meeting from the prior year's file. Drafting internal process documentation and staff briefings. In each case the pattern is the same: Claude produces a draft that shortens the route to a finished piece of work, and a qualified person is responsible for what actually goes out. The PCRT guidance itself lists tax compliance services, tax advisory services, client due diligence, M&A and technical research as current use areas.
Can Claude prepare a tax computation or a return?
It should not be relied on to. The PCRT AI guidance is explicit that outputs from AI tools should not be used as authoritative tax or legal advice, and that reviews must be undertaken by a qualified professional in the specific context of the client. It also tells members to treat AI output as if it were prepared by a less experienced junior colleague and to review it with appropriate scepticism, and to confirm the existence of any case law or legislation the output references, citing Harber v HMRC [2023] UKFTT 1007 (TC) as the cautionary example. A general-purpose assistant is not filing software and has no connection to HMRC's systems. Use it for narrative, explanation and review support, and keep computation in your practice software where it is auditable.
Do we have to tell clients we use AI?
Not as an absolute rule, but the direction of travel across the bodies is clearly towards disclosure and it is straightforward to get ahead of. The PCRT AI guidance suggests members may include a statement in the engagement letter specifying the potential use of AI tools, supports disclosing actual use in deliverables, and says that where AI use is fundamental to a deliverable the client should be informed before work commences. Guidance published in ACCA's In Practice hub makes the same point about the letter of engagement. The draft CCAB Statement lists disclosure in the engagement letter among its practical tips. And where a client asks that AI tools are not used on their affairs, the PCRT guidance says the member should acknowledge the request, and suggests discussing what the client would regard as unacceptable use.
What should a practice check before approving an AI tool?
ICAEW's Regulatory Policy Director set out effectively this checklist on 28 July 2026: understand where data is stored, who can access it, whether it may be used to train models, and how outputs are monitored, and do not enter confidential client information into digital systems including AI without appropriate due diligence, contractual protections and internal approval. Guidance published by ACCA adds that you should understand exactly what data the system can collect, where it is stored and how long it is retained, and that a firm should think carefully before buying if a vendor cannot answer clearly. Those questions have documented answers for a business-tier Claude deployment, which is the point of running one rather than leaving staff on consumer accounts.
Does HMRC restrict accountants from using AI?
We found no HMRC statement prohibiting or restricting an agent's own use of AI tools in the guidance we checked on 12 August 2026, including HMRC's standard for agents. What HMRC has published, on 28 January 2026, is a set of guidelines for software developers building commercial products that help customers submit information to HMRC. Those guidelines are addressed to developers, not to practices, and they expect such software to be transparent, to use reliable source data in line with legislation, to be designed with human oversight and control, to include strong data security and privacy measures, and to be ethical. HMRC also states that it does not endorse or approve any software developer or product, so no AI tool can claim HMRC approval. That is an absence of evidence from the pages checked rather than proof that no such statement exists anywhere in HMRC guidance.

Get new briefings by email

The AI Consultancy newsletter delivers briefings and analysis for UK businesses. We use your address only to send it, and you can unsubscribe at any time.

By subscribing you consent to receive The AI Consultancy newsletter by email. You can unsubscribe at any time. See our privacy policy.

Related Articles

industry

Claude for Legal and Finance: What Anthropic's May 2026 Plugins Mean for UK Firms

industry

AI for private dental and medical practices: keeping patient data on-site

industry

AI for IFAs and family offices: the data sovereignty question

Ready to explore AI for your business?

Book a free 20-minute consultation. No obligation, no jargon.