WellWired Journal
Is AI Safe for Banking? A UK Guide
Can AI help with your banking safely? Find out what you can ask, what to never share, and how UK banks use AI to protect you.

Quick answer: is safe for some banking tasks and risky for others. Asking a to explain an overdraft, draft a complaint letter, spot a email, or check what a charge on your statement means carries little risk. What you must never type into ChatGPT are your PIN, sort code, account number, or online banking password. UK banks run their own separate AI systems to detect fraud on your behalf. Public chatbots are not connected to those systems and never should be.
Your bank has used AI for years. Every transaction you make is watched, and anything unusual gets flagged long before you see a problem. Most people do not know this is happening.
According to research by bunq published in early 2026, around 35% of UK adults say they do not trust AI for banking matters. That concern mostly centres on public AI tools like ChatGPT, which runs entirely separately from your bank's fraud detection. Understanding the difference is the key to staying safe. This guide covers both, with plain guidance on what is safe to ask and what to keep private.
Your bank's AI and the AI you chat to are two different things
Banks have used AI for years to detect unusual patterns and block fraud before it reaches you. NatWest, Lloyds, Barclays, and most other high-street banks all run these monitoring systems in the background of every transaction you make.
This type of AI never talks to you directly. It watches patterns and alerts the bank's fraud team. You do not open a chat box to use it. Think of it like a security camera watching the lobby: it records what happens and alerts staff, but it does not expect you to talk to it.
Public AI tools like ChatGPT or Gemini are completely separate. They are general-purpose chatbots that can explain things and help you write. They have no access to your accounts and cannot move money. The two types of AI do not talk to each other.
Many people worry that asking ChatGPT a banking question somehow exposes their accounts. It does not. The risk comes from the personal details you include in the message.
What AI is safe to help with for your finances
Public AI tools handle general information well, and banking has a great deal of that. These tasks carry low risk provided you leave out any personal details:
- Explaining jargon. "What is an AER?" "How does a fixed-rate ISA work?" "What does CHAPS mean on a bank transfer?" These get clear, plain-English answers and require no personal data at all.
- Drafting letters and complaints. If you want to write to your bank about an unexplained charge or a refused mortgage, ChatGPT can write a firm, clear letter. Use placeholders such as [account number] and [date of transaction] rather than your actual details. You fill those in yourself before sending.
- Comparing products in general terms. "What is the difference between a cash ISA and a stocks and shares ISA?" is a safe factual question with no personal information involved.
- Checking a suspicious email. If you receive a message claiming to be from your bank, you can paste the email text into a chatbot and ask whether it shows scam warning signs. Paste only the email text, never your personal details alongside it.
- Building a budgeting template. A chatbot can produce a blank monthly budget spreadsheet or suggest spending categories to track, without you sharing any actual figures.
At WellWired, we've walked many readers aged 60-85 through exactly these tasks. The pattern is consistent: general questions get useful answers, and the risk stays near zero when personal details are left out entirely.
What you should never type into an AI chatbot
The rules here are short and absolute. Never enter any of the following into a public AI tool:
- Your PIN or online banking password
- Your full debit or credit card number
- Your sort code and account number together
- Your National Insurance number
- Copies of bank statements with your name, address, and account details visible
- Screenshots of your banking app showing transactions or balances
- Any one-time passcode (OTP) sent by your bank
Anything you type into a public AI tool is sent to a server run by that tool's provider. OpenAI, Google, and Anthropic store conversations by default, though each offers a setting to turn this off. Our guide on what you should never tell ChatGPT has step-by-step instructions for adjusting those settings.
A Harmonic Security report (Q3 2025) found that more than a quarter of file uploads to AI tools contained sensitive information. For bank documents, the risk is specific: a standard bank statement typically carries your full name, address, sort code, account number, and transaction history all on a single page. Uploading it to ask "what did I spend most on?" hands over far more than the answer is worth.
If you need help with a banking letter, describe the situation without specifics. "I have an unexplained charge on my account and I want a refund" gives the AI enough to write a good letter. Your account number goes in manually when you send it.
Copy-paste prompts for safe banking questions
These are safe because they contain no personal data. Copy them as they are or adapt them to your situation:
- "Explain what an early repayment charge is on a fixed-rate mortgage, in plain English."
- "Write a polite but firm complaint letter to a bank about a charge I do not recognise. Use [amount] and [date] as placeholders."
- "What should I check before switching my current account to a different bank?"
- "Explain the difference between a debit card and a credit card for someone new to banking."
- "This email says it is from my bank. Here is the text only, no personal details: [paste email text]. Are there any red flags?"
- "What is the maximum I can put into a cash ISA this tax year, and how does the allowance work?"
The pattern: general question, or situation described without real figures. Your account numbers, sort code, and balance never appear.
The new ChatGPT bank account feature and why it is not in the UK yet
In May 2026, OpenAI launched ChatGPT Finances in the United States. This lets American users link their bank accounts to ChatGPT through a service called Plaid, allowing the AI to read balances and transaction history and offer personalised financial summaries.
This feature is not available in the UK. OpenAI has not announced a UK launch date.
If it comes to the UK, it would need to operate under the Open Banking framework, regulated by the Financial Conduct Authority. Under Open Banking rules, any app reading your bank data must be FCA-authorised, must use read-only access via a secure , and must never see your actual login credentials. You give the app permission to view data; it cannot move money or change settings. That is a meaningfully different setup from typing your bank details directly into a chat window.
The FCA-regulated feature does not exist in the UK yet. If you see a website or app claiming to link ChatGPT to your UK bank account right now, check whether it holds FCA authorisation before handing over any access. Plaid Financial Ltd (FRN 804718) is FCA-authorised for account information services and is the likely route for any genuine future UK launch.
AI-generated scam messages targeting UK bank customers
While public chatbots are not directly dangerous, criminals are using AI to make scam messages harder to spot.
The National Cyber Security Centre has warned that AI now produces phishing emails with perfect spelling and convincing bank branding. They look more genuine than anything a human scammer could write. The old clues, such as odd phrasing or generic greetings, are disappearing. Our guide on AI phishing email scams covers the warning signs that remain.
Common UK targets include messages appearing to come from NatWest, Lloyds, HMRC, and the NHS. The goal is usually to get you to click a link and enter your banking credentials on a fake site, or to call a number where a fraudster pretends to be bank security staff.
The rules for these have not changed, even though the messages look more convincing:
- Your bank will never ask for your full PIN or password by phone, email, or text.
- Your bank will never ask you to move money to a "safe account".
- Any message creating urgency or requesting secrecy should be treated as a scam.
- Genuine bank communications give you time. They do not threaten to close your account if you fail to act immediately.
If you are unsure about a message, do not reply or click any links. Call your bank using the number on the back of your card or the number on the official website. Never use a number given in the suspicious message.
Fraudsters are also using AI-generated voice clones to impersonate bank staff and family members in phone calls. Our guide to AI voice scams explains how these work and how to identify them.
When AI gets financial numbers wrong
There is a specific risk with AI and money that does not apply to most other topics: AI can produce incorrect figures while sounding completely confident.
Ask ChatGPT to calculate simple interest on a savings account and it will usually get it right. Ask something more layered, or with multiple tax-year variables, and the answer can look authoritative while being wrong. For general information such as "what is this tax year's ISA allowance?" you can cross-check easily on GOV.UK. For anything involving a real financial decision, treat the AI's answer as a starting point, not a final figure.
AI is not regulated as a financial adviser. It cannot be held accountable for wrong numbers the way a professional can. For anything involving a large sum of money or a pension decision, use a qualified adviser who is authorised by the FCA. Our article on AI and your pension covers how to find regulated advice for retirement finances.
Your rights under UK law if you are defrauded
If a scam involving AI results in you losing money, UK law gives you real protections.
Since October 2024, the Payment Systems Regulator's mandatory reimbursement scheme requires most UK banks to refund victims of authorised push payment (APP) fraud up to £85,000, provided you did not act with gross negligence. APP fraud covers cases where a scammer tricks you into authorising a bank transfer yourself, which includes voice-clone scams and AI investment fraud calls. The Payment Systems Regulator publishes the full list of covered firms and how to make a claim.
If your data was exposed through an AI tool and you believe the company failed to protect it, you have rights under UK GDPR. You can ask any company to delete your data (the right to erasure) or request a copy of what they hold (a subject access request). If they mishandled your information, complain to the Information Commissioner's Office.
To report banking fraud in the UK, use Report Fraud (reportfraud.police.uk), which replaced Action Fraud at the end of 2025. For investment fraud specifically, report through the FCA website as well. Both reports help investigators build a picture of how organised fraud networks operate. We have a step-by-step guide on how to report an AI scam in the UK if you need to act quickly.
Frequently asked questions
Can AI access my bank account?
Public AI chatbots like ChatGPT or Gemini have no access to your bank account. They are entirely separate systems. A new US feature (ChatGPT Finances, May 2026) lets American users link accounts via a regulated service, but this is not available in the UK at the time of writing.
Is it safe to ask ChatGPT about my bank charges?
Yes, in general terms. Asking a chatbot to explain what a charge means or to help write a complaint letter is safe. Just do not include your actual account number, sort code, or any login details. Use placeholders like [account number] and fill them in yourself before you send anything.
My bank says it uses AI. Should I be worried?
This is a different type of AI from the chatbots you use yourself. Banks use AI internally to detect fraud and spot unusual spending patterns. It runs in the background, is regulated by the FCA, and is generally good for customers. It helps catch fraud before it reaches your account.
What should I do if I receive a suspicious email from my bank?
Do not click any links. Go directly to your bank's official website or call the number on the back of your card to check whether the message is genuine. You can paste the email text (without your personal details) into a chatbot to ask whether it shows scam warning signs. Report suspected fraud to reportfraud.police.uk.
Can AI give me financial advice?
AI can explain financial concepts and help you think through options clearly. But it is not a regulated financial adviser and cannot give regulated financial advice. For major decisions such as investing a lump sum or taking out a mortgage, use a qualified adviser authorised by the FCA.
What are my rights if I am scammed through an AI voice call?
If a fraudster using an AI-generated voice tricks you into transferring money, UK banking rules may entitle you to a refund. The PSR mandatory scheme covers most authorised push payment fraud up to £85,000 (since October 2024). Report to your bank immediately, then to reportfraud.police.uk. Our guide to AI investment scams explains what to do next.
Can AI voice cloning or deepfake photos bypass my bank's security checks?
Modern UK banks use voice recognition (Barclays Voice ID, for example) and facial recognition (Lloyds app login) for authentication. These systems are built with liveness detection, which checks for a real person in real time rather than a recording or photograph. Voice ID systems listen for specific vocal patterns that change with each utterance; a pre-recorded AI voice clone cannot replicate this. Facial-recognition systems look for micro-expressions and natural eye movement that static photos or video lack. While AI is advancing, it cannot currently fool these security systems. If you ever suspect unusual login activity on your account, contact your bank immediately. Most banks offer login alerts and transaction notifications, which help you catch unauthorised access quickly.
For a broader guide to staying safe with all AI tools, visit our staying safe with AI page. If you would like structured help learning to use AI well and safely, the WellWired Academy covers practical AI skills for everyday life, including how to handle sensitive topics without putting yourself at risk.
Was this page helpful?
Stay a step ahead of the scammers.
Join our free weekly email, written for people over 50 in plain English. Here is what lands in your inbox:
- This week's scam to watch, so you spot it before it reaches you
- One simple thing to try, in plain English, with the exact words to type
- Your free 5-page AI Starter Kit, sent the moment you join
Free forever. We never share your email, and you can unsubscribe in one click.
About the Author
Want to keep learning?
Explore more in-depth guides or start a structured learning path built for beginners.