Yes. A broker can use AI to chase clients for outstanding documents, and no rule prohibits it. That is the true answer, and it settles almost nothing, because the chase is the least interesting part of the question. The reminder that goes out carries almost nothing. The exposure is in what comes back.
What comes back is the most identity-dense material a broker ever holds: passports and driving licences, bank statements, payslips, tax records. Chasing them is a scheduling problem. Handling them is a data protection one, and the two get confused because they happen in the same breath. The moment those documents arrive and meet an AI tool, to read them, sort them, pull a figure out of them, the firm is processing the raw material of a person's financial identity, and UK GDPR has a great deal to say about that.
The reminder is harmless. What comes back is the risk.
A chaser message, "we are still missing your last three months of bank statements," is low-stakes. If AI drafts it, the analysis is much the same as any client communication: a person still owns what goes out under the firm's name. That is not where the difficulty sits.
The difficulty appears when the documents return and something automated touches them. A tool that reads a passport, extracts figures from a payslip, or checks a bank statement is processing personal data, and it is doing so on some of the most sensitive information a client will ever hand over. The question stops being "can we chase with AI?" and becomes "where do these documents go, and who can reach them once they have gone there?"
Why these documents sit at the top of the risk scale
ID, bank statements, payslips and tax records are, between them, almost everything an impostor would need to become a client or empty their accounts. In law they are personal data, and while they are not usually special category data in the Article 9 sense, that term is reserved for health, biometric and a short list of others, their practical sensitivity is about as high as ordinary personal data gets. A document that reveals a health condition, a disability adaptation, or medication, which a bank statement or a benefits letter easily can, pulls Article 9 in as well, and with it the need for a lawful condition of its own on top of the ordinary basis.
The point is not to frighten. It is that the rules already scale their expectations to how damaging a breach would be, and for these documents that expectation sits near the ceiling.
What UK GDPR actually asks of them
The data protection principles in Article 5 of UK GDPR are the plain-English test here, and three of them bite hardest on document handling. Data minimisation requires personal data to be "adequate, relevant and limited to what is necessary" for the purpose. Purpose limitation requires it to be "collected for specified, explicit and legitimate purposes", placing a mortgage, say, not training a model or anything else the tool might do with it. And integrity and confidentiality require it to be "processed in a manner that ensures appropriate security... against unauthorised or unlawful processing and against accidental loss, destruction or damage." Article 5(2) adds the sting: the firm, as controller, must be "able to demonstrate compliance" with all of it.
The AI Update points at exactly this. Firms using AI systems that process personal data "will also need to consider obligations under data protection legislation, including the UK GDPR" (section 3.31), and the FCA reminds firms at section 3.12 that the SYSC sourcebook requires "sound security mechanisms in place relating to data." None of that is new, and none of it was written with AI in mind. It applies to a client's documents whether they sit in a filing cabinet, an inbox, or a chatbot.
The moment a document crosses into a model you do not run
The sharpest question is where the file physically goes. When a document is uploaded to a consumer AI tool, it leaves the firm's controlled environment and lands on infrastructure the firm does not run, cannot audit, and often cannot compel to delete. On a free tier it may be used to improve the model. There is typically no data processing agreement, which is the very thing UK GDPR expects where a provider processes personal data on the firm's behalf: the processor terms set out in Article 28, judged on whether they exist at all.
Whatever the tool does, the firm stays the controller. The lawful basis under Article 6 is still the firm's to hold, the security duty is still the firm's to meet, and the accountability under Article 5(2) is still the firm's to evidence. The tool's terms of service do not carry any of it away. An enterprise arrangement with training switched off and a processing agreement in place sits in a completely different position from a personal account on a public app, and the distinction is not decoration. It is the difference between processing the firm can stand behind and processing it cannot.
Reading a document is one thing. Deciding from it is another.
There is a second line, beyond storage. If an AI tool does not just hold a payslip but reads it and its output drives an affordability call or a verification result, the firm may have stepped into automated decision-making. Where a decision is based solely on automated processing and carries "legal or similarly significant effects," the Article 22 safeguards of UK GDPR are engaged (FCA AI Update section 3.32), and section 3.37 expects the data subject to be given "meaningful information about the logic involved in the decision." A broker who cannot explain how a figure was reached, because the tool produced it and the working is gone, has a problem that is not really about documents at all.
What actually determines the position
It is not the chase, and it is not the tool. It turns on questions the existing rules already answer. Is identifiable client data involved? With these documents the answer is yes, and of the most damaging kind. Is it minimised, kept only as long as needed, and genuinely secured, on infrastructure the firm controls or has contracted for? And is a named person accountable for any decision drawn from it? Answer those and the tool is a detail. Fail them and no tool is safe, and no vendor's assurance will save you.
So, can a broker use AI to chase clients for documents?
Yes, chase away. The reminder was never the exposure. The exposure is the payload it brings back, the cleanest, most complete picture of a client's identity that exists anywhere, and where that picture ends up.
The mistake is to treat this as a question about chasing. It is a question about custody. A misdirected reminder can be resent. But a passport scan or a full bank statement, once it has crossed into a model the firm does not run, cannot be pulled back, and the firm still answers for it. That is the exposure the "can we use AI to chase?" question is built to overlook, and it sits in what returns, not in the asking.