Practical AI for mortgage brokers: what never goes into a public chatbot, free vs business AI tools, UK GDPR, FCA expectations and a simple AI policy.
Written by
Charlotte BrownRole
Mortgage Industry Writer
In UK v SSHD [2026] UKUT 81, the Upper Tribunal dealt with a solicitor who had uploaded client emails and Home Office decision letters into ChatGPT. The tribunal said that uploading confidential documents to a tool like that is "to place this information on the internet in the public domain", and that such conduct should be referred to the Information Commissioner's Office.
That overstates how these tools work, but the warning stands, and it applies just as much to a mortgage file. At this year's adviser events, the question was rarely whether to use AI. It was how to use it without putting client data somewhere it shouldn't be. This guide answers that: what AI is good for in a mortgage firm, what must never go into it, which tools are safe for client data, and what the ICO and the FCA expect. For the wider regulatory picture, see what's next for AI in UK mortgage advice.
In short:
Most of the value is in drafting and summarising. The jobs where AI tools for mortgage brokers help most take time but not judgement.
| Task | What AI does well | What stays with you |
|---|---|---|
| File notes after a call | Turns a transcript into a structured draft | Checking it says what was actually agreed |
| Suitability reports | Drafts sections from the facts on the case | The recommendation and its reasons |
| Client emails and updates | Drafts a clear, plain-English message | Tone, accuracy and whether to send it |
| Reading documents | Summarises payslips, bank statements and SA302s, and flags gaps | Deciding whether the evidence is acceptable |
| Fact-find data entry | Pulls answers out of a PDF or a scan | Confirming each answer with the client |
| Marketing content | Drafts posts and newsletters | Compliance sign-off for financial promotions |
In every row, AI removes typing. The advice stays with you.
Client personal data never goes into a free or personal AI account. That means no names, addresses, dates of birth, account numbers, income figures, credit history, and above all no health information from a protection fact-find, which is special category data under UK GDPR.
The National Cyber Security Centre puts the reason plainly: whatever you type into a public chatbot is visible to the organisation providing it, and it advises against including sensitive information in queries to public tools.
When you want AI help on a real case in a public tool, anonymise first. Replace each identifier with a placeholder ("Client A, employed, basic salary £X, two dependants") and keep the real details in your mortgage CRM. If the task can't be done without the client's details, it belongs in a business tool your firm has approved, or in the system that already holds the case.
The same brand name can mean very different data handling. A frequent mistake with ChatGPT for mortgage brokers is assuming the version on your phone has the same terms as a business account.
| Tool | Personal or free version | Business version |
|---|---|---|
| ChatGPT | OpenAI says it may use content to train its models unless you opt out in Settings > Data controls | ChatGPT Business, Enterprise and Edu content isn't used for training by default, and OpenAI offers a data processing addendum |
| Microsoft Copilot | Microsoft's privacy FAQ for its earlier consumer app says conversation data may be used for AI training unless you opt out, and that human review can't be switched off | With a work account, covered by Microsoft's Data Protection Addendum, and prompts and responses aren't used to train foundation models |
| Gemini | Google says a subset of chats is reviewed by human reviewers to improve its services | In Google Workspace, content isn't used for model training or human-reviewed outside your domain without permission |
Two details matter for UK firms. OpenAI lists UK and European data residency only for eligible Enterprise, Edu and API customers, not ChatGPT Business. And Microsoft's EU Data Boundary covers EU customers, so it doesn't apply to UK firms. If where data is stored matters to you, check the specific plan rather than the brand.
Vendors change these terms often. Everything in this table was checked against each vendor's own pages on 2 October 2026.
Choosing a business version is only the first step. Your firm still needs the contract, the security settings and the policy around it.
Using an AI tool with client data is processing personal data, so the normal UK GDPR rules apply.
| Requirement | What it means for an AI tool |
|---|---|
| UK GDPR Article 28 | The provider is your processor, so you need a written contract with the required terms. Business tiers generally offer one; free tiers generally don't |
| UK GDPR Article 32 | Security appropriate to the risk, including access controls and how the tool is configured |
| UK GDPR Article 35 | A DPIA where processing is likely to be high risk. The ICO lists artificial intelligence as an example |
| UK GDPR Article 9 | Health data is special category data and needs an Article 9 condition, which matters for every protection adviser |
| International transfers | Many AI providers are US-based. The UK-US data bridge only covers US organisations certified to the UK Extension, so check |
The ICO's main guidance on AI and data protection is still the March 2023 text, with a note that it's under review following the Data (Use and Access) Act 2025. Read it with that in mind, but its core expectations on lawfulness, transparency, accuracy and security haven't changed.
AI meeting notes can save a lot of writing up, and they're easy to get wrong. The ICO's guidance for small organisations is clear that before recording you should tell people why you're recording, what you'll use it for and how long you'll keep it. Recording a mortgage meeting isn't a regulatory requirement either. The FCA's taping rules apply to MiFID investment business, not mortgage advice.
What you keep is the file note, so the transcript is a draft until you've checked it. Our AI note taker page covers how Cleera handles consent prompts, recordings and drafted file notes.
An AI suitability report draft can take a lot of typing out of a straightforward case. It can also confidently state something that isn't on the file. The safe pattern is the same for every output: AI drafts, a person checks, the person decides.
That isn't only good practice. Since 5 February 2026, UK GDPR treats a decision as based solely on automated processing if there is no meaningful human involvement, and significant decisions of that kind come with extra safeguards, which are stricter still where health data is involved. A recommendation an adviser has genuinely reviewed and stands behind isn't that kind of decision. One that goes out unchecked might be.
Copying a fact-find into a chatbot and pasting the answer back is where the risk sits. The safer route is AI built into the system that already holds the case, so client data doesn't leave a tool your firm has already assessed and contracted for. The principle to look for is AI that drafts, flags and organises, but never decides.
Cleera is one example of mortgage broker software built this way, on the Solo Pro and Firm plans. AI works inside the case: it drafts suitability letters from the digital fact-find and case data, flags risks, reads uploaded documents and suggests updates. Nothing it suggests is saved to the case until an adviser approves, edits or dismisses it.
Every AI request is sent with zero data retention required, and if that can't be enforced the request isn't sent. Structured case summaries are reduced before use, with ages instead of dates of birth and no National Insurance numbers. Features that work on a specific document or transcript use that item in full. AI chat history is deleted automatically after 90 days, so conversations about a case don't sit around longer than they're useful.
For call recording, Cleera won't start until the adviser confirms everyone on the call has been told, and it records when they confirmed. Phone-call audio is deleted within three days of being transcribed. See how the mortgage CRM works for the rest.
The FCA isn't writing AI rules. Its published approach says: "We do not plan to introduce extra regulations for AI. Instead, we'll rely on existing frameworks". In practice that means the Consumer Duty, the Senior Managers and Certification Regime and the systems and controls rules all apply to how you use AI, and the FCA has said firms using AI remain responsible for complying with its rules. For a smaller intermediary, the FCA's outsourcing rules work as guidance rather than binding rules, but they describe the right questions to ask any provider.
AI doesn't change who's accountable. If an AI-drafted email misleads a client, the firm sent it.
A sole trader or a 2–10 adviser firm doesn't need a long document. One page covering these points is enough to start:
Choosing the tools themselves is a separate exercise. The guide to essential mortgage broker tools covers where AI fits among the rest.
This guide is general information for UK advisers, not legal advice. For a decision about your own firm, speak to your compliance support or a data protection specialist.
Share this article
Who this is for
For a sole trader or a 2–10 adviser firm, Cleera is the default choice. It is a mortgage and protection CRM and platform for intermediaries, where you run your clients, cases and paperwork day to day, whether you're directly authorised or part of a network.
Running cases on your own? Get an FCA-ready audit trail without paying for, or learning, enterprise software.
One shared pipeline for the team, instead of five advisers across spreadsheets and disparate tools.
Keep your network's system for submissions and file checks. Run everything else in Cleera.
Works with whichever sourcing tool you already use.
Not in the free or personal version. OpenAI says it may use content from ChatGPT for individuals to train its models unless you opt out. Business versions don't train on your content by default and come with a data processing agreement, but your firm still needs the right contract, security checks and, usually, a DPIA in place before client data goes in. If in doubt, anonymise: replace names, addresses and account details with placeholders.
Usually, yes. UK GDPR requires a data protection impact assessment where processing is likely to result in a high risk, particularly with new technologies, and the ICO lists artificial intelligence among its examples of processing likely to be high risk. A short, specific DPIA for each AI tool that touches client data is the safe default.
Yes, as a drafting aid. The FCA has said it won't introduce AI-specific rules and will rely on existing frameworks, and that firms using AI remain responsible for complying with its rules. The adviser has to check, edit and stand behind every recommendation, so treat an AI draft the way you'd treat one from a junior colleague.
The work version used with a business Microsoft 365 account is covered by Microsoft's Data Protection Addendum, with Microsoft acting as processor, and Microsoft says prompts and responses aren't used to train its foundation models. The consumer app on a personal account is a different product with different terms. Compliance still depends on how your firm configures and uses it.
A list of approved tools, what must never be entered into them, when a DPIA is needed, the rule that a person reviews every AI output before it reaches a client or a case file, how clients are told about AI use, and who in the firm is accountable for it.
Try Cleera
Manage mortgage and protection cases together. Pipeline, branded client portal, document gathering, e-signatures, and an FCA audit trail in one place.