← Insights / Compliance

AI Compliance 2026: What UK Professional Services Firms Must Do Now

The regulatory ground beneath professional services businesses is shifting faster than many compliance teams have accounted for. Two major developments — the phased implementation of the Data (Use and Access) Act 2025 (DUAA) and the extraterritorial reach of the EU AI Act — are creating concrete new

Compliance 2 August 2026 6 min read

AI Compliance 2026: What UK Professional Services Firms Must Do Now

The regulatory ground beneath professional services businesses is shifting faster than many compliance teams have accounted for. Two major developments — the phased implementation of the Data (Use and Access) Act 2025 (DUAA) and the extraterritorial reach of the EU AI Act — are creating concrete new obligations right now, not at some future point on the horizon. For accountants, solicitors, HR consultancies, and marketing agencies operating in the UK and internationally, the time for preparation has largely passed. The time for action is here.

The DUAA Is Already in Force — and the Implications Are Significant

The Data (Use and Access) Act 2025 received Royal Assent in June 2025, and its provisions have been rolling into effect throughout 2026. This is not pending legislation. It is live, and it is already being enforced.

The most consequential change for professional services firms concerns automated decision-making (ADM). From 5 February 2026, the UK adopted what it calls a "permission-with-safeguards" model. Compared to the EU's approach, this is more permissive — it allows broader use of AI tools in internal processes, including HR functions such as recruitment, performance assessment, and workload allocation. However, the critical qualifier cannot be overlooked: where an AI-assisted decision carries legal or similarly significant effects for an individual, the law requires "meaningful human involvement." This is not a box-ticking exercise.

The ICO has made its position explicit. Using AI hiring tools without genuine human review is a breach of data protection law. Sixteen organisations have already made commitments to the regulator following its engagement with firms using automated decision-making for jobseekers. The message is clear: the regulator is watching this space closely, and statutory guidance on ADM is expected in Summer 2026. Firms that have deployed AI in HR workflows without revisiting their processes in light of these developments are exposed.

Separately, a new statutory regime for handling data protection complaints came into force on 19 June 2026. The DUAA also introduced "recognised legitimate interests" as a new lawful basis for processing personal data for certain specified purposes, removing the need for a full balancing test in those cases. For firms managing large volumes of client data — which includes most professional services businesses — understanding which activities qualify under this new basis, and which do not, is essential.

PECR Fines Have Reached GDPR Levels. Marketing Agencies Should Take Note.

One of the least-discussed but most financially significant changes in the DUAA is the elevation of maximum fines under the Privacy and Electronic Communications Regulations (PECR) to £17.5 million or 4% of global annual turnover — bringing them in line with UK GDPR penalties.

This is not a theoretical risk. Enforcement is already underway. In May 2026, Thermotech Wall and Loft Surveys Ltd was fined for over 575,000 unsolicited direct marketing calls. KRA Consultancy Ltd received a £300,000 fine for more than 5.5 million unsolicited marketing texts. These figures reflect the previous, lower penalty regime. Under the new PECR fines framework, the financial consequences of comparable breaches will be substantially greater.

For marketing agencies, this requires an immediate audit of outbound marketing practices, consent records, and cookie management. For any professional services firm that conducts direct marketing — even incidentally — the same applies. AI tools that generate contact lists, automate outreach, or personalise marketing at scale all carry PECR risk if the underlying data governance is not airtight.

The EU AI Act Reaches Beyond EU Borders

The EU AI Act is not solely a concern for EU-based businesses. Its extraterritorial scope means that any firm whose AI systems affect individuals in the EU must comply — regardless of where that firm is headquartered. For UK firms with EU clients, EU-facing operations, or international practices, this is a direct compliance obligation.

From 2 August 2026, transparency obligations under Article 50 of the EU AI Act take effect. These require that individuals are informed when they are interacting with AI systems — including chatbots, automated communications, and AI-generated content. Fines for violations reach €35 million or 7% of global turnover. For a mid-sized professional services firm with EU exposure, these are material numbers.

The timeline for high-risk AI obligations — which cover AI used in employment decisions and credit scoring under Annex III — has shifted. Following the EU AI Omnibus package developments in July 2026, these rules have been delayed until 2 December 2027. This provides a longer runway for preparation, but it does not reduce the obligation. Firms should use the additional time purposefully: mapping which of their AI systems fall into high-risk categories, assessing compliance gaps, and building the necessary governance infrastructure.

The UK's Approach: Sector-Led, Pro-Innovation — but Not Risk-Free

Unlike the EU, the UK has not enacted a single overarching AI statute. A proposed AI Bill targeting the most powerful AI models was announced in July 2024, but no specific legislation is imminent in the short to medium term. For now, AI in the UK is regulated primarily through existing frameworks: UK GDPR, the DUAA, and sector-specific guidance.

This pro-innovation stance offers flexibility, but it does not mean the absence of risk. Existing law still applies in full to AI deployments. The Clearview AI case is instructive: the Upper Tribunal upheld the ICO's appeal, confirming that UK GDPR applies extraterritorially to foreign companies that monitor UK individuals through data scraping. The principle extends beyond that specific case — any organisation, wherever located, that processes the personal data of UK individuals is within scope.

Firms should also note that in March 2026, the UK government abandoned plans for a broad text and data mining exception for commercial AI training. Developers and AI vendors operating in the UK must now rely on existing copyright law and licensing agreements. For professional services firms building or procuring AI tools, this affects due diligence obligations — particularly around the provenance of training data.

What Professional Services Firms Should Prioritise Now

Across jurisdictions, the compliance priorities are consistent, even if the specific rules differ:

Audit your ADM processes. Any AI system making or materially influencing decisions about people — employees, candidates, clients — requires a documented review. Identify where human oversight exists in practice, not just in policy.

Review PECR compliance immediately. If your firm conducts any form of direct marketing, verify that consent records are accurate, up to date, and properly documented. The financial exposure under the new fine structure is significant.

Map your EU AI Act obligations. If your AI systems reach EU individuals, Article 50 transparency requirements apply now. High-risk obligations apply from December 2027 — begin your gap analysis today.

Conduct AI vendor due diligence. Procurement decisions must account for data governance, training data provenance, and contractual obligations around AI transparency and human oversight.

Document everything. Across UK GDPR, the DUAA, and the EU AI Act, demonstrable accountability is central to compliance. Regulators expect evidence, not assurances.


The compliance landscape in 2026 is characterised by overlapping frameworks, accelerating enforcement, and rules that routinely cross borders. Professional services firms cannot manage this complexity reactively.

Ops Intel helps professional services businesses understand and meet their AI compliance obligations — across the UK, EU, and internationally. If your firm needs a clear picture of where it stands and what it needs to do, speak to our team today.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit