Home · Business · Legal & Compliance · Terms & policies

NO

As of 13 August 2026, AI cannot audit your UK website cookies for compliance.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

n/ait cannot be self-verified.

Cost, all in£0

Skill neededpower-user

Who has to check ita professional

What the alternative costsiubenda generates and maintains privacy and cookie compliance documents as a purpose-built alternative.

If this goes wrong, non-essential cookies or tracking can run without valid consent and your organisation carries the compliance consequences.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface gets you a draft, but you cannot verify it yourself. That is the catch.

    How to actually do it

    1. Open the website in a private browser window and record the cookies and network requests before making any consent choice.
    2. Repeat the visit after refusing non-essential cookies, accepting selected categories and withdrawing consent, then save the cookie and network scan for each state.
    3. Gather the consent-management-platform settings, tag-manager configuration, relevant JavaScript, cookie policy, privacy policy and current vendor list.
    4. Paste the evidence into the prompt and ask the model to separate observed facts, assumptions and unresolved questions.
    5. Compare every finding against the current ICO guidance and your actual implementation, then ask your developer to reproduce each issue in a test environment.
    6. Send unresolved legal questions and the proposed fixes to a UK privacy solicitor or data-protection specialist before describing the site as compliant.

    Prompt

    Act as a UK cookie-compliance audit assistant, not a solicitor. This is not professional advice. Analyse only the evidence I provide: [website URL], [cookie and network scan], [consent-management-platform settings], [JavaScript and tag-manager configuration], [cookie policy], [privacy policy], [analytics and advertising vendor list], and [test results for first visit, refusal, partial consent, withdrawal and later visits].
    
    Produce a table with these columns: finding, evidence, affected cookie or script, whether it appears necessary or non-essential, consent state observed, relevant stated purpose, missing evidence, severity, recommended technical fix, and evidence needed to close the finding. Separate observations from assumptions. Do not invent cookie names, vendors, purposes, legal requirements or test results. Do not state that the site is compliant. Flag every point that needs checking against current ICO guidance, the Privacy and Electronic Communications Regulations, UK GDPR and the site's actual implementation. Highlight any case that needs review by a UK privacy solicitor or data-protection specialist. End with a short evidence checklist for a human reviewer and a list of questions for the website developer. If the evidence is incomplete, say exactly what cannot be concluded.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot observe every cookie, script, iframe, server-side call or vendor change across your site's real browsing journeys.
  • AI cannot establish from a policy document whether the live consent mechanism blocks non-essential tracking before consent.
  • AI cannot make a binding legal determination about your particular purposes, vendors, consent wording or risk.
  • AI cannot take responsibility for the compliance of the site or for consequences arising from an incorrect audit.
  • AI cannot replace a specialist's judgement where evidence is incomplete or the tracking arrangement is unusual.

What makes this a NO: legal accountability, verification cost and real time truth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output1
Inputs1
Verification0
Liability0
Effort delta1
Total3 / 10

FAQ

Can ChatGPT check if my website cookies are GDPR compliant?
It can organise a cookie scan, compare your stated practices with supplied guidance and flag apparent gaps. It cannot reliably inspect all live tracking behaviour or give a binding compliance conclusion, so this is not professional advice.
Do I need consent for cookies on my UK website?
The answer depends on what the cookie or tracker does and whether it is strictly necessary for a service you requested. Have a UK privacy solicitor or data-protection specialist assess uncertain cases rather than relying on a chatbot's classification.
Can AI scan my website for cookies?
AI can analyse scan results that you provide, but a chatbot does not replace a browser and network test across refusal, acceptance and withdrawal journeys. You need technical evidence from the live site before treating any result as an audit.
What should I check in a UK cookie audit?
Check what loads before consent, whether refusal works, whether withdrawal works, what each tracker does, who receives data, and whether your notices match the live configuration. A solicitor or data-protection specialist should resolve the legal conclusions and serious gaps.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.