AI and the new BACP Ethical Framework: what therapists need to do before 3 November 2026
A practical guide to what the 2026 framework says about AI, what it means for your day-to-day practice, and a simple sequence to work through before the November deadline.
This is a question I’m getting asked more and more on calls with therapists: “Can I actually use AI in my practice, and what do the new BACP rules mean for me?” It’s a fair question. AI tools have crept into most practices over the past couple of years, whether that’s tidying up an email, drafting a blog post, or trying one of the AI note-taking apps. Until now there hasn’t been much official guidance to check yourself against.
That changed on 4 August 2026, when the BACP published its new Ethical Framework. Members have a three-month transition window, and from midday on Tuesday 3 November 2026 it becomes mandatory.
Before we go any further, one thing to be clear about. I’m not part of the BACP and I don’t speak for them. I’m a marketing consultant who has spent the past decade helping therapists with their websites, SEO, and the digital side of running a practice. What follows is my practical reading of the new framework as someone who works with these tools daily and with therapists weekly. For anything that affects your registration, always check directly with the BACP or their ethics service, as guidance can change and your circumstances are your own.
The short version: the 2026 framework doesn’t ban AI. It asks you to assess the risk of any AI or digital tool before using it, be honest with clients about how you use it, get informed consent before any client data goes in, and write down your reasoning. A few focused hours before November covers it. Here’s how.
What’s changing on 3 November 2026?
The BACP’s new Ethical Framework for the Counselling Professions 2026 becomes mandatory at midday on 3 November 2026, replacing the 2018 version. It’s a full rewrite, not a patch, and for the first time it deals directly with artificial intelligence.
The AI requirements sit in Core responsibility 2.1(e). In plain English, before using any AI tool, digital tool, or online platform, members need to assess the risk and be able to show five things:
- You’re competent to use the tool. You understand what it does well and where it gets things wrong.
- You understand where the data goes. How it’s handled, how it’s stored, and what the risks to confidentiality are, with those risks mitigated as far as possible.
- You’re honest and transparent with clients about your use of AI and digital tools, including the benefits and the risks.
- You have informed consent before putting any client personal data into an AI or digital tool. Not blanket consent buried in a contract. Informed consent.
- You haven’t handed your decision-making over to AI. You remain responsible for critically evaluating anything an AI tool produces and for every decision you make based on it.
Two other parts of the framework connect to this. Section 3.1 requires a clear, accessible privacy notice that covers digital tools and platforms that collect data. And the framework’s new emphasis on giving a rationale for your ethical decisions means you should be able to explain, and ideally record, why you judged a particular tool safe to use.
That last part is new, and worth sitting with. Under the 2026 framework, making a sensible choice isn’t quite enough. You need to be able to show your reasoning if you’re ever asked. There’s a worked example of what that looks like further down.
Again, this is my summary of a 19-page document. Read the full framework yourself, because the changes go well beyond AI, and check anything you’re unsure about with the BACP directly. Their preparing for the 2026 Ethical Framework page also has videos and resources to help members through the transition.
The four ways therapists are already using AI
In practice, AI shows up in therapy work in four places, and each one raises a different question.
1. Session notes and transcription
AI note-taking tools that listen to sessions, or general tools like ChatGPT used to summarise your rough notes, are the highest-risk use by a distance. Session content is the most sensitive information you hold. If you’re doing this, or considering it, this is where the framework’s requirements bite hardest: proper risk assessment, explicit client consent, and a tool with real contractual guarantees about data handling. More on the data question below.
2. Admin and emails
Drafting a cancellation policy, rewording an awkward email, working out a spreadsheet formula. Low risk, and a real time-saver, provided no client-identifying information goes into the tool. The moment you paste in a client’s name, email address, or anything that could identify them, you’ve inputted their personal data and the consent requirement applies.
3. Marketing and website content
Using AI to help draft blog posts, social content, or website copy is fine from where I’m sitting, with two cautions. First, anything published under your name should be reviewed and shaped by you, because your professional reputation attaches to it (and Google’s quality systems increasingly favour content with genuine human expertise behind it, which I’ve written about in my E-E-A-T guide for therapists. Second, the framework requires all communications to be accurate, so AI-drafted claims about outcomes or approaches need checking against what you actually offer.
4. Clients using AI between sessions
This one is bigger than most therapists realise. Research from Mental Health UK, polling 2,000 UK adults in late 2025, found that 37% had used an AI chatbot for mental health support, rising to 64% of 25 to 34-year-olds. Most were using general tools like ChatGPT rather than dedicated mental health apps.
So the odds are good that some of your clients are talking to a chatbot between sessions, sometimes about the same material they bring to you. This isn’t your practice using AI, so the tool requirements don’t apply directly, but it raises clinical questions worth taking to supervision: how you respond when a client says “ChatGPT told me…”, and how you talk about the limits of AI support without dismissing something the client found helpful. I can’t advise you on the clinical side. Your supervisor can.
Can I put client information into ChatGPT?
Not into the free version, no. Free consumer AI tools typically use what you type to train their models, and you have no contractual control over where that data goes. Client information is special category data under UK GDPR, which needs the highest level of protection. Pasting it into a free chatbot would be very hard to defend under the new framework’s requirement to understand and mitigate data risks.
The picture changes with paid and business-grade tools. Many offer settings or contract terms where your inputs aren’t used for training and data is handled under a proper agreement. If you want to use AI with anything client-related, this is the realistic minimum bar:
- A paid or business tier, not a free consumer account
- Training on your data switched off, confirmed in the settings or in writing
- A clear answer on where data is stored and for how long
- A data processing agreement if the tool processes client data on your behalf
One realistic caveat: AI tools change their terms and features constantly. A tool that meets the bar today may not in six months. Whatever you choose, put a reminder in your diary to re-check it. The ICO’s guidance on AI and data protection is the reference point for the legal side, and if a tool can’t give you clear answers on the points above, that’s your answer.
Do I need to tell clients I use AI?
Yes, if any of their personal data touches an AI tool, and it’s good practice even where it doesn’t. The framework requires honesty and transparency about your use of AI and digital tools, and informed consent before inputting any client personal data.
In practice, that means two updates.
Your privacy notice needs a section covering which digital and AI tools you use, what data they process, and where that data is stored.
Your client contract or working agreement should include a consent line where relevant. Here’s a starting point you can adapt:
“I use [tool name] to help me [prepare session notes / manage appointments]. The tool processes [what data] and stores it [where, for how long]. It does not use your information to train AI systems. You can ask me about this at any time, and you can decline without it affecting your therapy.”
Keep it in plain English. A consent line the client can’t understand isn’t informed consent. And because this wording sits at the edge of my lane, it’s worth running your final version past your professional body, your insurer, or a data protection specialist rather than taking my template as gospel.
Five questions to ask before using any AI tool
Having watched a lot of therapists wrestle with this over the past year, here’s the checklist I’d suggest running any new tool through:
- What data will it touch? If the answer includes anything client-identifying, everything below matters more.
- Where does the data go? Storage location, retention period, and whether your inputs train the model. If you can’t find out, that’s your answer.
- Am I competent to use it? Do you understand what it does well and where it gets things wrong?
- Have I told the people affected? Privacy notice updated, consent obtained where client data is involved.
- Am I still making the decisions? The tool can draft, summarise, and suggest. It can’t decide. You remain responsible for everything it produces.
If a tool passes all five, write down your reasoning and use it with confidence.
What a rationale note looks like
That written note is your rationale under the new framework, and it takes ten minutes per tool. Something like this, kept wherever you keep your practice records:
Tool: [Name], AI note-taking assistant.
What it does: Transcribes sessions and drafts summaries for my review.
Data it touches: Session audio, client first names, session content.
Why I judged it safe: Business tier. Training on my data switched off, confirmed by email on 14 August 2026. Data stored in the UK, deleted after 30 days. Data processing agreement in place. Clients consent through my working agreement, and can decline.
What I do with the output: I review and edit every summary before it becomes part of the record. Nothing is filed unread.
Review date: February 2027.
Six lines. If the BACP, an insurer, or a client ever asks why you trusted a tool, this is the answer, dated and on file. Do one for each tool you use, including the low-risk ones.
What to do before 3 November
You have time, and none of this is a big job on its own. A sensible sequence:
- Read the framework yourself. The full PDF is on the BACP website, and it’s 19 pages. The AI section is half a page. Don’t rely on summaries, including this one.
- Audit your current AI use. List every AI and digital tool that touches your practice, however casually. Include the ones you use “just for emails”. Run each through the five questions above.
- Update your privacy notice and contract. Add the digital tools section to your privacy notice and the consent line to your working agreement where client data is involved.
- Take it to supervision. The framework expects collaborative decision-making on ethical questions, and your supervisor should know how AI features in your practice.
- Write down your rationale. A short note per tool, like the example above: what it does, what data it touches, why you judged it safe, when you’ll review it.
- Check with the BACP on anything you’re unsure about. Their ethics service exists for exactly these questions, and their guidance is the version that counts, not mine.
Ready to see what’s working on your site?
If you would like to know how your own blogs measure up on EEAT, and get clear recommendations you can act on, book a free 30-minute call with me. We’ll look at your site together and I’ll show you where the quick wins are.
Frequently asked questions
When does the new BACP Ethical Framework come into force?
It was published on 4 August 2026 and becomes mandatory at midday on Tuesday 3 November 2026, replacing the 2018 framework. The three months in between are a transition period for members to read it and adjust their practice.
Does the new framework ban AI?
No. It doesn’t ban any tool. It asks you to assess risk, understand the data, be transparent with clients, get consent before their data goes into a tool, and keep the decisions yours. That’s a bar for thoughtful use, not a prohibition.
I only use AI for marketing, does this affect me?
Less than it affects someone using AI note-takers, but not zero. Keep client data out of the tools, review anything published under your name, and make sure claims about your work are accurate. A line in your privacy notice about the digital tools you use is still sensible.
What about tools I was already using before November?
The framework doesn’t grandfather anything in. If a tool touches your practice after 3 November, the requirements apply to it, whenever you started using it. That’s why the audit step matters.
I’m not with the BACP, does any of this apply to me?
The framework itself only binds BACP members and registrants. But UK GDPR applies to every practitioner regardless of body, and other professional bodies are producing their own guidance. The five questions above are worth asking whoever you’re registered with. Check your own body’s current position directly.
The bottom line
The 2026 framework treats AI the way it treats everything else in practice: with honesty, competence, and the client’s interests first. It’s not anti-AI, and working through this before November is a few focused hours, not a crisis.
Therapists who do it will be ahead of most of the profession. And with over a third of UK adults already turning to chatbots for support, clients increasingly notice practitioners who can talk clearly about how their information is handled.
One last reminder, because it matters: I’m a marketing consultant, not the BACP, a lawyer, or your supervisor. Use this article as a practical starting point, then check the framework itself and confirm anything registration-related with the BACP directly, especially as guidance around AI is likely to keep evolving.
Need help with the website side of this?
If the part that’s nagging at you is your privacy notice, your website’s trust pages, or how your practice presents all of this online, that’s the bit I can help with. I work exclusively with therapists, counsellors, and mental health professionals across the UK on website design and SEO, and privacy and trust pages are part of every build.
Book a free 30-minute consultation and I’ll look at your current setup and tell you honestly whether you need help or whether it’s a half-hour job you can do yourself. No pressure, no sales pitch.
Written by Theo Ruby, a digital marketing consultant with over 10 years of experience helping therapists and mental health professionals grow their practices online. Theo has worked with 300+ therapy professionals across the UK on website design, SEO, and digital marketing strategy. Theo is not affiliated with the BACP, and this article is general guidance, not legal or ethical advice. Always confirm requirements directly with your professional body.
Get in touch: www.theoruby.com/contact
Email: [email protected] | Phone: 07709 852 364