A more assertive ICO reset the AI compliance bar
The regulatory ground beneath AI-using businesses shifted considerably in 2025. New legislation, sharper enforcement, and a more assertive ICO have created a compliance environment that rewards preparation and penalises complacency. For professional services firms — whether you are an accountancy pr
AI Compliance for Professional Services: What Changed in 2025 and What's Coming
The regulatory ground beneath AI-using businesses shifted considerably in 2025. New legislation, sharper enforcement, and a more assertive ICO have created a compliance environment that rewards preparation and penalises complacency. For professional services firms — whether you are an accountancy practice in Manchester, a law firm in Singapore, an HR consultancy in Toronto, or a marketing agency in Dubai — understanding what has changed and what is coming is no longer optional. It is a business-critical requirement.
The Data (Use and Access) Act 2025: What It Means for Automated Decisions
The most significant piece of UK legislation to land in this space is the Data (Use and Access) Act 2025, which came into force on 19 June 2025. Crucially, its provisions relating to automated decision-making became operative on 1 December 2025, giving businesses a hard deadline that many will have underestimated.
The Act amends the UK GDPR framework for automated decision-making. In broad terms, it introduces a more permissive regime — loosening some of the more restrictive constraints on solely automated decisions — while simultaneously strengthening individual rights safeguards. These two things happening together is not a contradiction; it is a deliberate policy choice that places greater responsibility on organisations to demonstrate that their automated processes are fair, explainable, and subject to meaningful human oversight.
For professional services firms, the implications are direct. If your practice uses AI tools to screen job applicants, assess client risk profiles, generate financial recommendations, or flag compliance issues, you are likely making or informing automated decisions. Your existing frameworks need to be reviewed against the Act's revised provisions now. The ICO is updating its guidance accordingly, with final updated guidance expected by Summer 2026 — but waiting for that guidance before acting is not a defensible position.
The ICO's Enforcement Posture Has Hardened
One of the clearest signals of the new compliance reality is the ICO's enforcement trajectory. While the overall number of actions fell in 2025 compared to 2024, the financial severity of those actions increased dramatically. The average data protection fine rose from approximately £150,000 in 2024 to approximately £1.45 million in 2025. That is not a statistical quirk — it reflects a deliberate shift toward proportionate but significant consequences for serious failures.
High-profile fines in 2025 included a combined £14 million penalty for Capita and Capita Pension Solutions following a cyber-attack that exposed the data of over six million people, and a fine exceeding £1.2 million for LastPass UK Ltd arising from security failures affecting 1.6 million UK customers. Neither of these is an AI-specific case, but both underscore that data governance failures — which AI deployments frequently implicate — now carry substantial financial exposure.
On AI specifically, the ICO has taken enforcement action against organisations misusing biometric technologies, including Clearview AI and Serco Leisure. It has also published findings from audits of AI-powered recruitment tools, identifying recurring weaknesses in accuracy testing and data minimisation. If your firm uses AI in any part of its hiring process, those audit findings should be required reading for your HR and compliance teams.
Generative AI and the Web Scraping Question
In December 2024, the ICO published its response to a comprehensive five-part consultation on generative AI and data protection. The conclusions have consequences for any firm either building AI tools or procuring them from third-party developers.
On the question of lawful basis for training AI models on web-scraped data, the ICO's position is that legitimate interest is likely the only viable basis — but developers face a, in the ICO's own words, "difficult hurdle" in establishing it. Transparency obligations and the ability to respond to individual rights requests are heavily emphasised, and the ICO has signalled concerns about whether current developer practices meet the required standard.
This matters to professional services firms not only if you are developing AI systems — most firms are not — but because it affects the compliance posture of the tools you buy and deploy. If a vendor's AI model was trained on data in ways that cannot withstand ICO scrutiny, your organisation may face exposure as a data controller. Due diligence on AI procurement is now a compliance obligation, not merely a commercial consideration.
Frontier Model Regulation: A Policy Direction to Watch
The UK government has signalled a meaningful shift in its approach to AI regulation. Historically, the UK has favoured a principles-based, sector-specific framework without overarching AI legislation. That position is evolving. The King's Speech in July 2024 proposed binding measures targeting developers of the most powerful AI models, and the Labour government has reiterated its intention to introduce targeted regulation for frontier models. A formal consultation was expected in early 2025.
This does not create immediate obligations for most professional services firms. However, it shapes the landscape of the tools you will be using. Organisations that are proactive in understanding how their AI vendors will be regulated — and what compliance obligations may flow downstream — will be better positioned than those who treat this as a future problem.
The AI Hallucination Risk Is Now a Legal and Reputational Issue
The growing number of AI hallucination incidents in the legal sector deserves particular attention. By November 2025, the UK had recorded twenty-four reported cases of AI-generated inaccuracies in legal proceedings, with the High Court issuing formal warnings to lawyers who had cited fabricated case law produced by AI tools. Four new cases were reported in 2025 alone.
This is not a technology problem — it is a professional accountability problem. Solicitors, barristers, and legal professionals who rely on AI output without adequate verification processes are exposing themselves to professional sanction, reputational harm, and potential liability. The same logic applies to accountants presenting AI-generated analysis and HR consultancies using AI to produce contractual documentation. The professional duty of care does not diminish because a tool produced the output.
International Reach: The UK Is Not an Island
For firms operating across multiple jurisdictions, the UK picture sits alongside significant regulatory developments elsewhere. The EU AI Act — which came into force in August 2024 — carries extraterritorial reach, meaning UK-based firms with EU clients or operations must assess their obligations under that framework as well. In the United States, Canada, the Middle East, and Asia-Pacific, AI governance frameworks are at varying stages of development, but the direction of travel is consistent: greater scrutiny, clearer obligations, and sharper consequences for non-compliance.
Operating in multiple jurisdictions does not mean managing these obligations independently. A coherent, principle-led AI governance framework — one that identifies your AI use cases, assesses their risk profiles, and maps obligations across relevant jurisdictions — provides a far more efficient and defensible approach than treating each regulatory regime as a separate project.
Act Now, Not When Guidance Finalises
The ICO's statutory Code of Practice on AI and Automated Decision-Making is expected by Summer 2026. Final updated guidance on the Data (Use and Access) Act is anticipated on the same timeline. But compliance work that waits for final guidance is compliance work that starts too late. The obligations under the Act are already live. Enforcement is already active.
If your firm uses AI in any client-facing or operational capacity — and in 2025, most professional services firms do — your compliance framework needs to reflect the current regulatory reality, not the one that existed two years ago.
Ops Intel works with professional services businesses globally to assess AI risk exposure, review compliance frameworks, and build governance structures that hold up under scrutiny. If you are not certain your firm is compliant with the obligations outlined above, get in touch with our team to arrange an initial compliance assessment. The cost of preparation is considerably lower than the cost of enforcement.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.