The Data (Use and Access) Act breaks UK AI rules from the EU
The UK's approach to AI regulation has always been framed as pragmatic and business-friendly. That framing remains, but the practical reality for professional services firms is changing fast. Enforcement is escalating, new legislation has reshaped automated decision-making rules, and the courts are
UK AI Compliance 2026: What Professional Services Firms Need to Know About the ICO's New Enforcement Era
The UK's approach to AI regulation has always been framed as pragmatic and business-friendly. That framing remains, but the practical reality for professional services firms is changing fast. Enforcement is escalating, new legislation has reshaped automated decision-making rules, and the courts are beginning to hold firms directly accountable for how they deploy AI. Whether you are running an accountancy practice in Manchester, a law firm in Dubai, or an HR consultancy serving clients across North America and the EU, the UK's shifting compliance landscape has implications you cannot afford to ignore.
The UK's Regulatory Position: Principles-Based, But Not Passive
The UK government has consistently resisted introducing a single overarching AI Act equivalent to the EU's. Its position, reaffirmed in its February 2024 response to the AI Regulation White Paper consultation, rests on five guiding principles: safety, transparency, fairness, accountability, and contestability. Regulation remains sector-led and principles-based, with existing regulators — the ICO, the FCA, the CMA — applying their remits to AI use within their domains.
That said, the picture is not static. The Labour government, which took office in 2024, has signalled its intention to introduce binding regulation targeting the most powerful AI model developers. A formal AI Bill is anticipated around 2026. For now, professional services firms sit in a framework where the obligations are real but derived primarily from data protection law, sector-specific rules, and judicial precedent — not a single codified AI statute.
For firms operating internationally, this matters. You may be focused on EU AI Act compliance, which brought its transparency obligations into direct applicability in 2025. But UK obligations run in parallel, not beneath them. Separate frameworks require separate compliance programmes.
The Data (Use and Access) Act 2025: A Clear Break From EU GDPR
The most significant domestic legislative change for professional services firms is the Data (Use and Access) Act 2025 (DUAA), which came into force on 5 February 2026. This Act replaces Article 22 of the UK GDPR — the provision governing automated decision-making (ADM) — with a new domestic framework.
The practical effect is meaningful divergence from EU rules. The DUAA creates greater scope for automated decision-making in contexts that do not involve special category data, whilst maintaining safeguards where individuals are affected by solely automated decisions in high-stakes situations. For firms processing personal data on behalf of UK-based clients, or making automated decisions that affect UK data subjects — think AI-assisted recruitment screening, automated credit assessments, or algorithm-driven performance reviews — this is not an academic point. Your legal basis for ADM under UK law is no longer identical to your legal basis under EU GDPR.
HR consultancies and recruitment businesses should treat this as a compliance priority. AI tools used in candidate screening or workforce management now sit under a distinct UK regime. Firms will need to review their ADM policies, update their data protection impact assessments, and ensure they can demonstrate that appropriate human oversight and safeguards are in place where required.
The ICO Is Enforcing at Scale — and the Fines Are Getting Larger
The Information Commissioner's Office has moved from guidance-issuer to active enforcement body with considerable momentum. Between September 2025 and May 2026 alone, it took 22 enforcement actions. The size of penalties is increasing notably, with a particular focus on data security failures.
In October 2025, a pensions administration provider received a £14 million fine following inadequate security measures that led to a major cyber incident. A separate £1.2 million fine followed in November 2025 for comparable failures. Also in February 2026, Reddit was fined £14.47 million and Imgur/MediaLab £247,590 for failings in how children's personal information was handled, including inadequate age assurance mechanisms.
These are not abstract cautionary tales. For professional services firms, they signal several things clearly. First, data security is no longer a back-office IT matter — it is a regulatory exposure that can result in eight-figure penalties. Second, where your services involve platforms or tools accessible to minors, the ICO is prepared to act decisively. Third, criminal prosecutions against individuals for unlawful data access increased in late 2025, meaning personal liability for employees and partners is a live concern, not a theoretical one.
The ICO's June 2025 AI and biometrics strategy sharpened its focus further, identifying transparency, bias, discrimination, and rights of redress as the lens through which AI deployments will be scrutinised. Firms using AI in client-facing decisions or internal HR processes need to be able to demonstrate these properties in practice, not just in policy documents.
AI in the Courtroom: Hallucinations Have Consequences
The case of R. (on the application of Ayinde) v Haringey LBC has become a reference point in UK legal circles for all the wrong reasons. AI-generated fake case citations were submitted in legal proceedings, resulting in a wasted costs order and regulatory referrals. The court was unambiguous in its response.
For law firms, this is an immediate and direct risk. But the implications extend beyond solicitors. Any professional services firm producing written work product for clients — whether that is a tax opinion, a due diligence report, an HR policy, or a marketing document — and using AI drafting tools in that process carries exposure if the output is not rigorously checked. Clients and courts are beginning to expect that human oversight is genuine, not performative.
Firms should have clear internal policies on AI tool usage, including mandatory human review of any AI-assisted output before it is shared externally. This is not about banning AI; it is about ensuring accountability sits with the professional, not the model.
What This Means for Firms Operating Globally
International professional services firms face a layered compliance environment. EU AI Act transparency obligations apply directly where you serve EU clients or deploy AI systems in the EU. UK obligations apply in parallel under DUAA and UK GDPR for UK operations. Sector-specific requirements in the US, Canada, the Middle East, and Asia-Pacific add further dimensions, many of which are evolving quickly.
The temptation is to treat UK compliance as a subset of EU compliance and move on. That is no longer an accurate approach. The DUAA's divergence from EU GDPR is the clearest signal yet that UK-specific compliance work is necessary. Firms with cross-border operations need frameworks that are jurisdiction-aware, not jurisdiction-assuming.
The common thread across all of these regimes — EU, UK, and beyond — is transparency. Can you explain what AI systems you use, what decisions they inform, what safeguards are in place, and what recourse individuals have? If the answer to any of those questions is unclear internally, it will be unclear to a regulator too.
Get Ahead of the Next Enforcement Action
The ICO's enforcement trajectory is upward in both volume and severity. The courts are setting precedents. New legislation is in force. This is not a moment to wait for further regulatory clarity before acting.
Ops Intel works with professional services firms globally to build AI compliance frameworks that are practical, proportionate, and jurisdiction-aware. Whether you need a gap analysis against UK and EU obligations, support updating your ADM policies under the DUAA, or a clear internal governance structure for AI tool usage, we can help.
Contact Ops Intel today to find out where your firm stands — and what needs to change before the next enforcement cycle begins.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.