Yes. A broker can use ChatGPT, and no rule in the FCA Handbook prohibits it. That is the true answer to the question, and it is almost useless, because the question is the wrong one.

The FCA does not approve tools and it does not ban them. It said as much in its April 2024 AI Update, describing itself as "technology-agnostic, principles-based and outcomes-focused" and confirming that many risks from AI "can therefore be mitigated within existing legislative and/or regulatory frameworks" (section 3.5). It has no view on ChatGPT specifically, and it will not issue one. What it has is a view on what you do, and that view does not soften because the work was done by a machine. The permission brokers are looking for is not the FCA's to give. The accountability is entirely theirs to keep.

Permission is not the same as compliance

Nothing in the Handbook stops you opening ChatGPT. Everything in the Handbook that already governs your firm governs what you produce with it. Those are two different statements, and the gap between them is where brokers get into trouble.

A broker who asks "is ChatGPT allowed?" is asking a permission question. The regulator is answering a different one: "can you evidence that what you did with it delivered a good outcome, and that you stayed accountable and kept the client's data protected?" The tool is never the unit of compliance. The workflow is.

Using ChatGPT changes nothing about who is accountable

The Senior Managers and Certification Regime applies in full. The AI Update confirms it at section 3.40: "any use of AI in relation to an activity, business area, or management function of a firm would fall within the scope of a SMF manager's responsibilities." The FCA considered a dedicated AI Senior Manager and decided against one, treating existing governance as sufficient. That paragraph makes its point through the larger dual-regulated and Enhanced firms, but section 3.41 closes any gap: all SM&CR firms, "including solo-regulated Core and Limited Scope firms," have Senior Managers bound by the Conduct Rules to take "reasonable steps to ensure that the business of the firm... is effectively controlled." For a sole-trader mortgage broker, that Senior Manager is you. For an appointed representative, the exposure is the principal's. For a network, it is firm-wide.

The Consumer Duty is the framework the FCA names for fair outcomes from AI (section 3.22), and it applies to whatever reaches the client, whoever, or whatever, drafted it. A suitability letter, a client email, a summary of a call: if ChatGPT produced it and it went out under your firm's name, the Duty holds you to the outcome it created. "The AI wrote it" is not a defence. It is an admission that you did not review it.

This is the first thing to be clear about. ChatGPT is a drafting and thinking assistant. It is not a delegate you can hand accountability to, because accountability under SM and CR and the Consumer Duty cannot be delegated to anything, let alone to a tool the regulator does not recognise.

Brokers watch the output. The risk is the input.

Most brokers worry that ChatGPT will get something wrong: an outdated rate, a misread rule, a confident sentence that is simply false. That worry is legitimate, and an unreviewed output that reaches a client becomes the firm's liability, not the tool's. But it is the smaller risk, and watching it can hide the larger one.

The larger risk is what you put in. The moment you paste a client's name, income, bank details, or medical history into the consumer version of ChatGPT, you have sent personal data to a third-party model outside your firm's control, processed and potentially retained on infrastructure you do not run, and on the free tier, potentially used to train the model further. That is a data protection event before it is anything else.

UK GDPR governed that client information already. ChatGPT did not change the law. It changed how easily, and how invisibly, a broker can breach it. The AI Update points straight at this: firms using AI to process personal data must comply with data protection law (section 3.31), and decisions based solely on automated processing that produce "legal or similarly significant effects" engage the Article 22 safeguards, which give the client the right not to be subject to such a decision (section 3.32).

For protection brokers the exposure is sharper still. Health, medical, and lifestyle information taken during a protection fact-find is special category data under UK GDPR Article 9. It needs a lawful condition of its own, on top of the ordinary Article 6 basis, and the ICO's guidance on AI and data protection addresses it directly. Pasting a client's disclosed conditions into a public chatbot is not a grey area. It is the clearest line in this whole subject.

The free version and the business version sit differently under the rules

When a broker says "we use ChatGPT," that describes almost nothing the rules care about. The consumer app on a personal account and an enterprise or API arrangement, with model training switched off and a data processing agreement in place, sit in completely different positions under data protection law. One processes personal data on terms the firm controls and can evidence. The other does not.

UK GDPR draws that distinction sharply. Where a provider processes personal data on the firm's behalf, the law expects the processor terms set out in Article 28, and a firm's use is judged on whether those terms exist. The consumer version offers none of them. That is not a small-print difference. It is the difference between processing a firm can stand behind and processing it cannot.

What actually determines the compliance position

It is not the task. The regulatory position does not change because ChatGPT was asked to draft an email rather than summarise a document. It turns on two things the existing rules already fix, and neither is about the tool.

The first is whether identifiable client data is involved. That is a data protection question under UK GDPR, and it is engaged the moment personal data leaves the firm's control, whatever the task was. The second is whether a person remains accountable for what the output does to the customer. That is a Consumer Duty and Senior Manager question, answered by whether the output was owned and reviewed, not by how it was produced. Those two questions decide the position. The rest is detail.

The test the FCA will actually apply

When a supervisor examines a firm's AI use, the question will not be "did you use ChatGPT." It will be three questions. Can you evidence good outcomes for your customers? Did you stay accountable for what the tool produced? Did the client's data stay protected? Those are Consumer Duty and data-protection questions, not AI questions. Answer them, and the tool is a detail. Fail them, and no tool is safe, and no vendor's assurance will save you.

So, can a broker use ChatGPT?

Yes, and you carry every consequence of doing so. The regulator has not given permission, because it was never asked to, and it will hold you to the same standards it always has.

The mistake is to treat this as a question about a tool. It is a question about your client's data, and who answers for it. A wrong output can be caught and corrected before it reaches anyone. A client's identity, once it has left your control and crossed to a model you do not run, cannot be called back. That is the real exposure. It sits on the way in, not the way out, and it is exactly the part the "is ChatGPT allowed" question is built to overlook.