Yes. A broker can use AI to draft a client email, and no rule in the FCA Handbook prohibits it. That is the true answer, and it settles almost nothing, because the regulator never judges the tool that wrote the email. It judges the email.

The FCA describes itself in the April 2024 AI Update as "a technology-agnostic, principles-based and outcomes-focused regulator." It has no view on which drafting tool you use and it will not issue one. What it has is a settled view on communicating with clients, and that view was written long before AI could draft a paragraph. The moment an AI-written email leaves your firm under your name, it stops being a draft and becomes a regulated communication. From there, nothing about how it was produced changes what is required of it.

The email is the regulated act, not the tool

A client email is a communication, and communications to retail customers are governed whoever, or whatever, composed them. Under the Consumer Duty, firms must "communicate in a way that meets the information needs of customers" (section 3.24). That obligation attaches to the message the client receives. It does not ask whether a person, a template, or a language model produced the words. It asks whether the words did their job.

So the useful question is not "are we allowed to use AI for emails?" It is "does the email that reached the client meet the standard the Duty already sets?" The tool is never the unit of compliance. The communication is.

Consumer Duty judges the email your client reads

The FCA's approach to consumer protection is, in its own words, "particularly relevant to fairness in the use of safe AI systems", and it rests on the Principles and the Consumer Duty (section 3.22). Two parts of the Duty bite directly on an email.

The first is consumer understanding. The Duty's rules on understanding are about "meeting the information needs of retail customers and equipping them to make decisions that are effective, timely and properly informed" (section 3.36). A fluent email is not automatically an informative one. AI writes with great confidence and even tone, which is precisely what can smooth over a missing caveat, an out-of-date figure, or a material point the client needed and did not get. Fluency is not accuracy, and a well-written message that leaves the client less than properly informed is a worse outcome, not a neutral one.

The second is good faith. There is a cross-cutting obligation under the Duty to act in good faith, "characterised by honesty, fair and open dealing with retail consumers" (PRIN 2A.2.2R, cited at section 3.36). Where the Consumer Duty does not apply to a particular piece of business, Principle 7 still requires firms to communicate "in a way that is clear, fair and not misleading" (section 3.36). Either way, the email carries a standard the sender owns.

“The AI drafted it” is not a defence

The Senior Managers and Certification Regime applies in full to the communications your firm sends. The AI Update is explicit at section 3.40 that "any use of AI in relation to an activity, business area, or management function of a firm would fall within the scope of a SMF manager's responsibilities." That sentence is framed through larger dual-regulated and Enhanced firms, but section 3.41 closes the gap: all SM&CR firms, "including solo-regulated Core and Limited Scope firms," have Senior Managers bound by the Conduct Rules to take "reasonable steps to ensure that the business of the firm... is effectively controlled." For a sole-trader broker, that Senior Manager is you.

Put those together and the position is plain. If an AI-drafted email goes out under your firm's name and it misleads, omits, or confuses, the firm answers for the outcome, and a named person answers for the firm. "The AI wrote it" is not a mitigation. It is an admission that the communication was not owned.

The quieter risk is what you feed in to make it personal

A generic email drafted from no client information is, in data terms, unremarkable. The exposure appears the moment the email is personalised. To make an AI write this email for this client, brokers reach for the client's name, their circumstances, their figures, sometimes their health disclosures, and put them into the tool. At that instant the message is no longer only a Consumer Duty question. It is a data protection one.

The AI Update points straight at it: where firms use AI systems that process personal data, they "will also need to consider obligations under data protection legislation, including the UK GDPR" (section 3.31). Where an email conveys a decision based solely on automated processing that produces "legal or similarly significant effects", the Article 22 safeguards of UK GDPR are engaged, giving the client "the right not to be subject to" such a decision (section 3.32). And for protection brokers the line is starkest: health, medical, and lifestyle detail is special category data under UK GDPR Article 9, needing a lawful condition of its own on top of the ordinary Article 6 basis. A warm, personalised renewal email can quietly carry all of this.

A generic draft and a personalised one sit differently under the rules

When a broker says "we use AI to write our emails," that sentence hides the only distinction the rules care about: how much identifiable client data went in to produce the message. The more an email is tailored with real client detail, the more of UK GDPR it engages, and the more it matters whether the tool is a consumer app on a personal account or an arrangement where the firm controls the terms.

UK GDPR draws that second line sharply. Where a provider processes personal data on the firm's behalf, the law expects the processor terms set out in Article 28, and the firm's position is judged on whether those terms exist. The consumer version of a public chatbot offers none of them. That is not small print. It is the difference between processing a firm can stand behind and processing it cannot.

What actually determines the position

It is not the task, and it is not the tool. It turns on two questions the existing rules already answer, and an email can raise both at once.

The first: does the communication meet the client's information needs, and does a named person remain accountable for it? That is a Consumer Duty and Senior Manager question, answered by whether the email was owned and reviewed, not by what drafted it. The second: is identifiable client data involved? That is a UK GDPR question, engaged the moment personal data leaves the firm's control, whatever the email was for. Answer both and the tool is a detail. Fail either and no tool is safe, and no vendor's assurance will save you.

So, can a broker use AI to write client emails?

Yes, and every word that leaves under your name is yours. The regulator did not give permission, because it was never asked to, and it will hold the email to the standard it has always held communications: clear, fair, not misleading, and meeting the client's needs.

The mistake is to treat this as a question about a writing tool. It is two questions wearing one coat. A poor email can be caught and rewritten before it is sent. But a client's identity, once it has crossed into a model you do not run in order to make the email personal, cannot be called back. That is the exposure the "can we use AI for emails" question is built to overlook, and it sits on the way in, not the way out.