What can AI actually do in an accountancy practice?
Most practices have AI available and almost nobody using it properly. Here is what it does, what stops people, and the two things to fix first.
In an accountancy practice, AI does three separate jobs and most firms only ever meet the first one. It answers questions and drafts things, which is the chatbot everyone has already tried. It runs work end to end, taking a task through several steps without a person driving it, which is where the hours actually come back. And it reads and reasons over your own records, which is the version that needs your business data in front of it. The blocker is rarely the tool. In most practices the tools are already paid for and sitting there unused, because nobody has written down what staff are allowed to put into them. Guidance first, training second. The technology is the easy part.
Walk into most accountancy practices and you will find the same thing: artificial intelligence is available to everyone, paid for, sitting in the corner of the screen, and almost nobody is using it. Not because it does not work. Because nobody has told them whether they are allowed to.
What are practices actually doing?
We ran an artificial intelligence workshop with an accountancy practice recently. It was an early-stage picture, and a very normal one.
Most people were still finding their feet with the basics. Not prompting technique or anything advanced, just the everyday mechanics of getting a usable document out of the thing. A small number of people, three or four, had an upgraded licence and had started building their own custom assistants for particular jobs. So within one firm there was a gap between a couple of people quietly building and everyone else not really starting.
The reason for the gap was not ability. Two things were holding people back. The first was data: what is safe to put in, what is not, and nobody could say. The second was money. Everyone had the tools included with the firm’s Microsoft subscription, and people were avoiding them in case they racked up a charge and got in trouble for it.
Neither of those is a technology problem. Both are answered by a document that did not exist.
That gap between intent and practice shows up in the profession’s own numbers. Research published in 2026 by the Institute of Chartered Accountants in England and Wales, covering a sample of 35 mid-sized firms, found 86 per cent had artificial intelligence written into their technology strategy. Strategy at the top and hesitation at the desk are not a contradiction. They are the normal shape of this, and the distance between them is made of guidance nobody has written yet.
Send your staff one page: which tools are approved, how to sign in, what may go in, what may not, and whether using them costs the firm anything. Most of the hesitation in your practice disappears the day people have something to point at.
What do I write down first?
The guidance, before anything else.
It does not need to be long and it does not need a lawyer. It needs to answer the questions your people are already asking each other in the kitchen. Which tools are approved. How to get into them properly. What sort of information may go in. What must never go in. Whether using them costs the firm money. Who to ask when it is not clear.
The value is not the rules. It is the permission. Right now a sensible person in your practice is not using a tool you pay for, because using it might turn out to have been the wrong call and there is nothing to hide behind. A page with your name on it removes that entirely.
Writing it also forces the decisions. You cannot draft the section on what may go in without deciding how you feel about client records passing through someone else’s system, and that decision was coming whether or not you sat down to write it.
Is my data safe in these tools?
This is where most practices stall, and the honest answer has a wrinkle in it that matters.
For the Microsoft tools that most firms already have, the protection depends on which account the person is signed in with. Signed in with a work account, Microsoft states that prompts and responses are covered by the same contractual terms as emails in Exchange and files in SharePoint, that the data is encrypted, that existing permissions and sensitivity labels still apply, and that none of it is used to train the underlying models. Signed in with a personal account, on the same screen, in the same browser, none of that holds.
Two caveats worth knowing before you write your own rules. When the tool searches the web, that query goes off to a search service under different terms, outside the protections that cover the rest of the conversation. And custom assistants built on top carry their own terms, so each one needs checking rather than assuming it inherits the protection.
That is a specific, checkable position, and it is more permissive than most practices assume. It is also only true of one vendor’s tools. Every other product your staff might paste something into has its own answer, and free consumer tiers are usually the worst of them.
Why does training change anything?
Because reading a policy has never made anyone confident, and an hour of using the thing does.
The most striking part of that workshop was not anything we said. It was people trying the tools on their own real work and being visibly surprised at what came back. They arrived cautious. They left wanting to try things. Nothing about the software had changed between nine and four.
There is a reason it works that way. Most people’s mental model of these tools is a slightly better search box, and nothing you write down will replace that. Watching a task you would have given an hour to finish in under a minute, on your own file, with your own quirks in it, does. That is why the training has to be hands on and has to use the practice’s own work, not a generic demonstration.
What if the answer keeps being no?
Watch what accumulates in the not allowed column while you write the guidance, because that list is the most useful thing the exercise produces.
If it ends up saying no client data, no financial records, no correspondence and no working papers, stop and look at what is left. You are paying per person per month for something that can now only help with the generic half of the job. It will still draft a policy or tidy up an email. It cannot touch the work that actually fills the week.
That is not a reason to ban it and it is not a reason to relax the rules. It is a reason to ask a different question: is this subscription earning its money under our own restrictions, and if not, what would it take to lift them safely?
The answer is usually about where the model runs. Run one on your own infrastructure, and your records never leave your control, which means the restriction that was making the tool useless no longer needs to exist. The trade is real and worth stating plainly: you take on the hosting, and you pay for capacity whether or not anyone uses it that day. But the calculation is no longer subscription against nothing. It is a smaller, capable model with your actual data in front of it, against a larger, cleverer model that is not allowed to see any of it.
Which of those wins depends on your appetite for risk, and that is a partner decision rather than a technical one. It should be a decision though, taken deliberately, rather than the default that arrives when the rules quietly make the tool pointless.
Where does the real time go?
Everything above is still chat: a person, a box, a question. That is the shallowest use of this technology and it is where nearly every practice stops.
The hours are in the recurring work. The same information typed into three systems. Chasing clients for records, four times a year now rather than once. Sorting the inbox. Pulling together the same pack every month. None of that needs someone sitting at a chat window, and none of it gets fixed by a better prompt. It needs the job wired up end to end, with the model doing the one step in the middle that needs judgement, and ordinary automation doing everything either side of it.
That is the difference between having AI and using it. Most practices have it. Very few have wired it into anything.
If you want the guidance drafted quickly, the companion prompt for this article, Draft AI Guidance for Your Staff, walks you through it question by question. And if you are weighing whether your data rules point towards hosting a model yourself, self-hosted versus cloud automation covers that decision in full.
- Most practices already own more capability than they use, and the blocker is permission rather than technology.
- Write the guidance first. It costs nothing and it removes the fear that is stopping sensible people using a tool you pay for.
- With Microsoft’s business tools, protection depends on the account someone signs in with. Say which one in your guidance.
- Train people on their own real work. An hour of using it beats any amount of reading about it.
- If your rules end up excluding all the real work, the subscription cannot pay for itself, and hosting your own model becomes the question.
- The hours are not in the chat window. They are in the recurring jobs nobody has wired up yet.
Drafted by Otto, the Perkins SmartOps AI assistant. Reviewed, edited and published by David Perkins, the human.
