← Insights / Compliance

AI Compliance for UK Professional Services: Your 2026 Roadmap to the ICO Code, DUAA, and Shadow AI Risks

The compliance landscape for professional services businesses has shifted materially in 2026. Whether you run a law firm in London, an accountancy practice in Dubai, an HR consultancy in Toronto, or a marketing agency in Sydney, the regulatory developments now unfolding in the UK and EU carry direct

Compliance 5 August 2026 6 min read

AI Compliance for UK Professional Services: Your 2026 Roadmap to the ICO Code, DUAA, and Shadow AI Risks

The compliance landscape for professional services businesses has shifted materially in 2026. Whether you run a law firm in London, an accountancy practice in Dubai, an HR consultancy in Toronto, or a marketing agency in Sydney, the regulatory developments now unfolding in the UK and EU carry direct consequences for how you deploy AI in client-facing and internal work. This is not a future problem. Enforcement is already happening.

Here is what you need to understand and act on now.

The UK's Regulatory Framework Is Hardening

The UK has not passed a comprehensive AI Act, and none is expected before late 2026. However, that does not mean there is a regulatory vacuum. Existing regulators are progressively integrating AI governance into their mandates, and the pace is accelerating.

The most significant structural change is the Information Commissioner's Office (ICO) now operating under a statutory duty — effective 12 May 2026 — to produce a Code of Practice on AI and Automated Decision-Making (ADM). This code, once finalised, will carry evidential weight in enforcement proceedings. If your firm cannot demonstrate alignment with it, you will be exposed in any regulatory investigation. The ICO also launched a consultation on updated ADM and profiling guidance on 31 March 2026, directly reflecting reforms introduced by the Data (Use and Access) Act 2025 (DUAA).

For international businesses with UK operations, UK clients, or UK data subjects, this code is not optional background reading. It is the standard against which your AI practices will be measured.

What the DUAA Changes — and What It Demands From You

Key provisions of the Data (Use and Access) Act 2025 came into force in February 2026. The Act introduces a more permissive framework for automated decision-making under UK GDPR, but permissive does not mean unregulated. The conditions attached are substantive.

Where AI systems make decisions with legal or similarly significant effects — think credit assessments, recruitment screening, contract eligibility, or client risk profiling — the DUAA mandates transparency, human intervention mechanisms, and genuine opportunities for challenge. Firms that have automated these processes without building in those safeguards are already non-compliant.

The Act also introduces new criminal offences, including those related to non-consensual deepfake intimate images, which has direct relevance for marketing agencies and HR consultancies handling sensitive personal data or generating AI-assisted content. A further tranche of measures, including a new right to complain for employees, is scheduled for June 2026.

If you have not reviewed your GDPR and PECR policies since the DUAA came into force, that review is overdue.

The EU AI Act's Extraterritorial Reach Affects You Too

Professional services businesses operating internationally cannot treat the EU AI Act as someone else's problem. Its extraterritorial provisions mean that if you provide AI-assisted services to EU clients, or if AI systems you use process data belonging to EU residents, you fall within scope. The first tangible enforcement actions under the Act have already emerged in 2026.

For firms advising clients in Germany, France, the Netherlands, or across the Gulf states with EU business relationships, understanding your obligations under the EU AI Act — particularly around high-risk AI applications and transparency requirements — is now a baseline compliance task, not an advanced one.

Shadow AI: The Risk That Is Already Costing Firms

The most immediate and underappreciated compliance threat in professional services right now is Shadow AI — the use of unapproved AI tools by employees without organisational knowledge or oversight.

Research published in April 2026 found that 59% of UK fee earners admit to using unapproved AI applications, including free consumer versions of tools like ChatGPT, for client work. This figure alone should concern any managing partner, compliance officer, or HR director. The legal consequences are no longer theoretical.

A landmark Upper Tribunal decision — Munir v Secretary of State for the Home Department UKUT 81 (IAC) — confirmed that using such tools permanently waives legal professional privilege and breaches client confidentiality. That is a catastrophic outcome for any law firm. The decision also confirmed that such conduct merits referral to the Solicitors Regulation Authority (SRA) and reporting to the ICO.

The risk extended further in May 2026, when multiple law firms, including Pinsent Masons and AML Legal, were referred to the SRA for submitting fake legal authorities to courts — citations suspected to be AI-generated. The clear message from regulators is that supervisory responsibility for AI-assisted work sits with the individuals and firms submitting it. Ignorance of what your fee earners are using is not a defence.

For accountancy practices, marketing agencies, and HR consultancies, the specific legal privilege question may not apply, but the data protection exposure, client confidentiality obligations, and reputational consequences are just as severe.

Financial Services and HR: Sector-Specific Pressures

In financial services, the Treasury Committee has recommended that the Financial Conduct Authority publish comprehensive guidance — by end of 2026 — on how existing consumer protection rules, including Consumer Duty, apply to AI use. Accountability under the Senior Managers and Certification Regime (SMCR) for AI-induced harm is also under active scrutiny. The Financial Services AI Adoption Plan, presented to government in July 2026, sets out a framework for safe adoption, but safe adoption requires governance infrastructure that many firms have not yet built.

For HR and payroll functions, the stakes are equally concrete. The Fair Work Agency, established on 7 April 2026, consolidates enforcement of minimum wage and labour standards with enhanced regulatory powers. HMRC's position on AI payroll systems is unambiguous: employers carry full legal responsibility for the accuracy of Real Time Information submissions, regardless of whether those submissions were generated by an AI system. Errors mean penalties, interest, and audit exposure.

In March 2026, HMRC publicly named 389 employers who had underpaid approximately 60,000 workers due to data errors. If AI-generated payroll data is producing inaccurate outputs, the employer — not the software — is liable.

What Your Business Needs to Do Now

The pattern across every sector is consistent: regulators are not waiting for new legislation before taking action. They are using existing powers, new statutory duties, and sectoral guidance to enforce accountability for AI use today.

The practical priorities for professional services firms are clear. You need a complete audit of the AI tools currently in use across your organisation — including those being used without formal approval. You need updated data processing agreements that reflect DUAA requirements. You need documented human oversight mechanisms for any AI system making consequential decisions. And you need governance structures that make clear who is accountable when AI-assisted work goes wrong.

For international businesses, the additional layer is mapping your EU AI Act exposure and ensuring your UK and EU compliance frameworks are aligned rather than operating in silos.


Ops Intel works with professional services businesses globally to build AI compliance programmes that are practical, auditable, and regulator-ready. If you need an AI governance audit, a Shadow AI risk assessment, or support aligning your policies with the DUAA and ICO Code of Practice, contact the Ops Intel team to find out how we can help.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit