Products
Pricing

Network Security Pricing

Network DDoS Protection
Partners
About Myra
Login
Emergency Demo

Updated 11 October 2026

AI for accountants: what UK and Irish firms may do with client data

As of 11 October 2026

Accountants can use AI, and none of the professional bodies forbids it. The line they draw is around client data and responsibility. Client information belongs in tools the firm has vetted, contracted and approved, never in a public chatbot without the client's consent. Whatever the tool produces, the firm answers for it as if a person in the firm had written it. This guide collects what ICAEW, the PCRT bodies, Chartered Accountants Ireland, the UK Information Commission (formerly ICO) and the Irish Data Protection Commission say, and turns it into rules a practice can adopt this month.

What the professional bodies say

The ICAEW Code of Ethics 2026 has applied since 1 July 2026. Its confidentiality section, R114, requires accountants to “maintain confidentiality of information within the firm” and to take reasonable steps so that “personnel under the accountant's control” comply too. The prohibition on disclosure in R114.2(a) used to apply to disclosure “outside the firm or employing organisation”. ICAEW has removed those words, so the duty now reaches inside the firm as well. That matters for AI tools that index shared drives: a junior who can ask the assistant about any client file can also see any client file.

Two further passages fit AI closely. Paragraph 114.3 A3 lists using confidential information “for training purposes, in the development of products or technology” as a case where the firm needs authorisation. And R320.11 says that before using “the output of technology” in a professional activity, the accountant must determine whether that use is appropriate for the purpose.

ICAEW spelled out the practical side in a regulatory news item in July 2026. Confidential client information should “not [be] entered into systems without appropriate due diligence, contractual protections and internal approval”. Firms should understand where data is stored, who can access it and “whether it may be used to train models”. A month later, on complaints, ICAEW was blunter: AI does not reduce a firm's responsibility for the work it issues.

For tax work, the seven bodies behind Professional Conduct in Relation to Taxation, ICAEW and ACCA among them, issued topical guidance on AI in January 2026. Its central sentence: “The input of client data into publicly available AI tools is likely to constitute a breach of client confidentiality, unless the client has consented to this.” The same guidance notes that some firms run “internal, ring-fenced AI models with strict controls”, and it asks members to treat AI output like the work of “a less experienced junior colleague”.

In Ireland, Chartered Accountants Ireland published a guide for members in August 2026. Members are responsible for understanding how an AI tool “will share, retain, or reuse data they input (including for model training or analytics)”. The CAI Code of Ethics on its website still applies from 1 March 2020 and keeps the older wording: no disclosure outside the firm “without proper and specific authority”.

Data protection in the UK and in Ireland

Client files are full of personal data: payroll, tax returns, bank statements of sole traders. When staff put them into an AI tool, the firm is usually the controller and the AI vendor its processor. That means a contract under Art. 28 UK GDPR (or GDPR in Ireland) that covers the AI service, and an answer to where the data is processed.

The Information Commission, which took over the functions of the Information Commissioner on 30 September 2026, is clear about impact assessments. “In the vast majority of cases”, it says, the use of AI involves processing likely to result in a high risk, which triggers the legal requirement for a DPIA; where you decide otherwise, document why. Its consultation response on generative AI adds a line worth pinning to the wall: “There is no ‘AI exemption’ to data protection law.” Note that its AI guidance is currently marked as under review following the Data (Use and Access) Act 2025. That Act's new rules on automated decision-making, Arts 22A to 22D UK GDPR, have been in force since 5 February 2026.

The Irish Data Protection Commission asks organisations to understand, before they start, what personal data an AI system uses, where it goes when a third party is involved and whether the provider retains or reuses it. Irish firms are also deployers under the EU AI Act. Since 27 July 2026, Art. 4 requires them to take measures to support the AI literacy of their staff. A short, recorded training session alongside the firm's AI policy covers that.

Engagement letters

ICAEW updated its Terms of Business in March 2026 to refer to the use of AI. Its accompanying guidance covers three points: whether AI or other software tools will be used in delivering the service, the limitations of those tools, and responsibility for data protection, confidentiality and due diligence on technology providers. The clause wording is available to members.

The PCRT guidance goes in the same direction. A statement in the engagement letter that “AI-enabled software may be used” helps with transparency, and where AI is fundamental to a deliverable it may be appropriate to tell the client before the work begins. Writing for ACCA's In Practice, solicitor Polly Coram added a warning that applies to every firm: “Simply inserting an AI clause into the terms of business will not make an unsafe process safe.”

Eight rules for a practice

Rule Basis
1. Approve specific tools; everything else is off limits for client work ICAEW July 2026: due diligence, contractual protections, internal approval
2. No client data in public AI tools unless the client has consented PCRT 4.2
3. Know where each tool stores data, who can access it and whether it trains on inputs ICAEW July 2026; CAI guide
4. Limit access inside the firm to the people working on the engagement ICAEW Code R114.1(b), R114.2(a)
5. Review every output like a junior's draft before it reaches a client PCRT 3.4; ICAEW Code R320.11
6. Keep a record of which tool was used on which deliverable PCRT safeguards
7. Update engagement letters and say how you use AI ICAEW Terms of Business 2026; PCRT 1.3
8. Carry out a DPIA and train staff, with records of both Information Commission; Art. 4 AI Act for Irish firms

Audit firms have additional expectations. When the FRC published its guidance on generative and agentic AI in March 2026, it stressed that “the human auditor is always accountable”, and its June 2025 guidance sets out what to document about AI tools. Both are aimed at audit work; for bookkeeping and tax they are useful reading, nothing more.

Where a workspace helps, and where the firm stays responsible

Lawyers and tax advisers are entrusted with data that needs the highest level of protection. When Myra's indicator shows green, that data does not leave our own infrastructure. Sascha Schumann, CEO Myra Security

Rules 1 to 4 are easier to follow when the tool enforces them. In Myra AI Workspace, a project for client work can be set to the access tier “Local only”. The model picker then shows only Myra models, which run on Myra's own EU infrastructure, and cloud models, web search and external tools are blocked. Myra-hosted models need the “EU-Gov” add-on if you are on a paid self-service plan. Myra does not use customer data to train AI models, which answers the training question in rule 3 for Myra itself; for external models, check the provider's terms.

Next to the model picker, a coloured indicator shows before anything is sent where it will go. Green (“Local model”, “Local + masking”) means the text stays with Myra models. Yellow (“Privacy on”) means an external model answers, and names, IBANs and similar identifiers are first replaced by placeholders and restored in the answer. Red (“Privacy off”) means the text goes to the external provider unmasked. Masking is available in every plan and supports English fully. Under UK GDPR it is pseudonymisation, so the masked text is still personal data, and the CAI guide's warning about re-identification still applies.

Admin changes and security events are logged, tamper-evident via a hash chain on request. That helps with rule 6 at the level of settings, but it does not record which tool produced which paragraph, and customer admins have no view of the audit log themselves. The engagement record stays the firm's job. Hosting in your country is possible on request, and so is on-premises deployment.

What no tool does for you: obtain client consent, write the engagement letter, carry out the DPIA or review the output. More on the product on the Myra AI Workspace page, and a policy you can adapt in our AI policy template.

Frequently asked questions

Can accountants put client data into ChatGPT?

Not into a public version without the client's consent. The PCRT guidance of the seven tax bodies, including ICAEW and ACCA, says entering client data into publicly available AI tools “is likely to constitute a breach of client confidentiality, unless the client has consented to this”. Firm-approved tools with contractual protections are a different matter, provided the firm has done its due diligence.

Do we have to tell clients that we use AI?

No rule requires a fixed wording, but the bodies point that way. PCRT suggests a statement in the engagement letter, for example that “AI-enabled software may be used”, and ICAEW updated its Terms of Business in March 2026 to refer to the use of AI. Where AI is fundamental to a deliverable, PCRT suggests telling the client before the work starts.

Is a DPIA required before a firm uses AI?

Usually, yes. The Information Commission (formerly ICO) says that “in the vast majority of cases” AI use involves processing likely to result in a high risk, which triggers the legal duty to carry out a DPIA. If you conclude that a particular use is not high risk, you still need to document how you reached that view.

Does the EU AI Act apply to accounting firms?

To Irish firms that use AI systems, yes, as deployers. Since 27 July 2026, Art. 4 requires them to take measures to support the AI literacy of their staff; no certificate is needed. A UK firm is covered only in specific cases, for example with an EU establishment or where AI output is used in the EU. Check the scope with counsel.

Sources

This guide gives an overview of professional and data protection guidance as of October 2026. It is not legal or ethical advice. For your firm, check the current Code of your professional body and ask its ethics helpline or your own counsel.