The regulatory map every firm now has to read
A partner at a mid-size accounting firm uses an AI tool to draft a client's transfer pricingtransfer pricingThe prices charged when units of the same company trade goods, services or IP across borders, set to satisfy tax authorities and reflect market value.View full definition → memo. The tool was trained partly on OpenAI's GPT models, hosted on Microsoft infrastructure, used to serve a client incorporated in Ireland with operations in California, and reviewed by a UK-qualified associate. Five different rulebooks may apply to that one memo, and none of them agree on what "AI use" even means. This is not an edge case in 2026. It is Tuesday.
Professional services firms (law, audit, consulting, tax, financial advisory) now sit at the intersection of at least four overlapping regulatory logics: horizontal AI law, sector-specific financial and legal regulation, professional conduct rules, and private contract law. Reading only one of these maps will get a firm lost.
Layer 1: horizontal AI regulation (the EU AI act)
The EU AI Act (Regulation (EU) 2024/1689, official text here) is the first comprehensive, cross-sector AI law. It classifies AI systems by risk tier, not by industry:
- Unacceptable risk: banned outright (e.g. social scoring).
- High-risk: subject to heavy obligations (risk management, human oversight, logging, conformity assessment). This tier includes AI used in employment decisions, credit scoring, and some biometric uses. Notably, most day-to-day generative AI drafting tools used by lawyers or consultants do not automatically fall here.
- Limited risk: transparency duties only (e.g. disclose that a chatbot is AI).
- Minimal risk: no specific obligation.
For professional services, the sharpest edge is indirect: if a client uses your firm's AI-assisted output to make a high-risk decision (say, an AI-scored creditworthiness assessment feeding a bank's lending decision), the classification travels with the use case, not the vendor. A consulting firm building that scoring tool can become a "provider" under the Act with full high-risk obligations, even if it thinks of itself as a service firm, not a software company.
Key term: GPAI (General-Purpose AI models, like GPT-4 or Claude) face their own separate transparency and systemic-risk obligations under the Act, layered on top of whatever your firm does with them.
Layer 2: Sector regulators don't wait for horizontal law
Financial and legal regulators were writing AI-adjacent rules before the AI Act existed, and they keep moving independently.
- SEC (U.S. Securities and Exchange Commission): has pursued "AI washing" enforcement, actions against firms overstating AI capabilities to investors, and proposed rules on conflicts of interest arising from predictive data analytics used by broker-dealers and investment advisers.
- FCA (UK Financial Conduct Authority): applies existing frameworks, especially the Consumer Duty and SMCR (Senior Managers and Certification Regime), to AI use. There is no separate "AI Act" in the UK; the FCA's position (as of its 2024 AI update, see FCA's AI pages) is that existing principles-based rules already cover most AI harms: accountability sits with a named senior manager regardless of which model made the recommendation.
- Bar associations and law societies: the American Bar Association's Formal Opinion 512 (2024) and various state bar guidance address generative AI competence duties, confidentiality when feeding client data into third-party tools, and billing (firms cannot bill client hours saved by AI as if unaffected).
- Audit oversight bodies: the PCAOB (US Public Company Accounting Oversight Board) and equivalents in Europe are scrutinizing AI use in audit sampling and analytics, focused on whether AI tools undermine auditor independence or professional skepticism, a core audit quality standard.
None of these bodies use the EU AI Act's risk tiers. A tool that is "minimal risk" under the Act can still trigger a full SEC enforcement action if marketing claims about it are false, or a bar complaint if it leaked privileged client data.
Layer 3: Professional conduct rules travel with the license, not the tool
This is the layer non-technical readers often miss. Professional obligations (duty of competence, confidentiality, independence, professional skepticism) attach to the licensed individual, not the software vendor.
Example: a lawyer using an AI research tool that hallucinates a fake case citation is still personally sanctionable, as seen in multiple US court sanctions since 2023 (the *Mata v. Avianca* case remains the reference point). The AI Act's conformity assessment does nothing to protect that lawyer. Professional discipline is a separate, parallel track.
For consultants and auditors, the equivalent risk is over-reliance: using AI-generated analysis without the professional judgment step that the client is actually paying for and that regulators expect.
Layer 4: Client contracts add a fourth, private layer of law
Increasingly, client engagement letters and master service agreements specify:
- Which AI tools may or may not touch client data.
- Whether client data can be used to train or fine-tune models (most sophisticated clients now say no, explicitly).
- Disclosure obligations: must the firm tell the client when AI materially contributed to a deliverable?
- Liability allocation if AI-assisted work causes loss.
These clauses are not harmonized across jurisdictions or even across clients of the same firm. A firm serving 200 clients can face 200 slightly different private AI policies layered on top of public law. This is why many firms now maintain an internal AI use register: a log of which tools are approved, for which task types, under which client contract terms.
Example: minimal AI use register schema
tool_name, vendor, data_residency, client_data_allowed (Y/N),
approved_use_cases[], risk_tier_eu_ai_act, human_review_required (Y/N)This kind of structured register is the practical bridge between all four layers: it is the artifact a regulator, a bar investigator, or a client audit will ask to see.
Knowledge check
1. Under the EU AI Act, how is the risk tier of an AI system primarily determined?
2. A consulting firm builds a scoring tool that a bank later uses to make lending decisions. What does this scenario illustrate about the AI Act's high-risk classification?
3. Why does the opening example of the transfer pricing memo (multiple jurisdictions, vendors, and reviewers) matter conceptually for professional services firms?
4. Select ALL correct answers about the EU AI Act's risk-tier system as described in the lesson.
Select all the correct answers.
5. Select ALL correct answers about why professional services firms face a complex regulatory landscape for AI use.
Select all the correct answers.
What this means for cross-border advisory work
A firm advising a client with EU, US, and UK touchpoints cannot pick "the strictest rule" and apply it everywhere; the rules are not stacked, they are different in kind. The EU AI Act asks "what risk tier is this system?" The SEC asks "did you misrepresent it?" The FCA asks "which senior manager is accountable?" The bar asks "did you maintain competence and confidentiality?" The contract asks "did you disclose and get consent?"
Practical governance response, in order:
- Map the use case, not the tool. The same GPT-based drafting assistant can be low-risk in one workflow (internal summarization) and high-risk in another (feeding a client-facing credit decision).
- Assign a named accountable person per AI use case, mirroring the FCA's SMCR logic even outside UK-regulated entities. Diffuse accountability is the single most common finding in AI governance failures.
- Build a human-in-the-loop checkpoint wherever professional judgment is the product being sold. This is both a conduct-rule requirement and a client trust requirement.
- Reconcile contract clauses with the AI use register before deployment, not after a client complaint.
- Document reasoning, not just output. Auditors and regulators increasingly ask for the "why," not just the AI-generated "what."
The EU AI Act Explained
For a live, non-invented reference point on how regulators are coordinating (or not), the OECD AI Policy Observatory tracks national AI regulatory developments in something close to real time.
Key Takeaways
- Four distinct regulatory layers apply to professional services AI use: horizontal law (EU AI Act risk tiers), sector regulators (SEC, FCA, PCAOB), professional conduct rules (bar associations, audit standards), and private client contracts. They classify the same AI use case differently and do not defer to one another.
- Risk classification follows the use case, not the vendor or tool: the same underlying model can be minimal-risk in one workflow and high-risk, or professionally sanctionable, in another.
- Professional discipline (bar complaints, audit independence findings) is a personal, license-level risk that exists independently of whether a firm is technically compliant with the EU AI Act.
- An AI use register, mapping tool, use case, data handling, and accountable person, is the practical governance artifact that lets a firm answer to all four layers at once.
- Cross-border advisory work requires reconciling, not ranking, these regimes; there is no single "strictest rule" shortcut.