# The regulatory mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.View full definition → every firm now has to read
A partner at a mid-size accounting firm uses an AI tool to draft a client's transfer pricing memo. The tool was trained partly on OpenAI's GPT models, hosted on Microsoft infrastructure, used to serve a client incorporated in Ireland with operations in California, and reviewed by a UK-qualified associate. Five different rulebooks may apply to that one memo, and none of them agree on what "AI use" even means. This is not an edge case in 2026. It is Tuesday.
Professional services firms (law, audit, consulting, tax, financial advisory) now sit at the intersection of at least four overlapping regulatory logics: horizontal AI law, sector-specific financial and legal regulation, professional conduct rules, and private contract law. Reading only one of these maps will get a firm lost.
The EU AI Act (Regulation (EU) 2024/1689, official text here) is the first comprehensive, cross-sector AI law. It classifies AI systems by risk tier, not by industry:
For professional services, the sharpest edge is indirect: if a client uses your firm's AI-assisted output to make a high-risk decision (say, an AI-scored creditworthiness assessment feeding a bank's lending decision), the classification travels with the use case, not the vendor. A consulting firm building that scoring tool can become a "provider" under the Act with full high-risk obligations, even if it thinks of itself as a service firm, not a software company.
Key term: GPAI (General-Purpose AI models, like GPT-4 or Claude) face their own separate transparency and systemic-risk obligations under the Act, layered on top of whatever your firm does with them.
Financial and legal regulators were writing AI-adjacent rules before the AI Act existed, and they keep moving independently.
None of these bodies use the EU AI Act's risk tiers. A tool that is "minimal risk" under the Act can still trigger a full SEC enforcement action if marketing claims about it are false, or a bar complaint if it leaked privileged client data.
This is the layer non-technical readers often miss. Professional obligations (duty of competence, confidentiality, independence, professional skepticism) attach to the licensed individual, not the software vendor.
Example: a lawyer using an AI research tool that hallucinates a fake case citation is still personally sanctionable, as seen in multiple US court sanctions since 2023 (the *Mata v. Avianca* case remains the reference point). The AI Act's conformity assessment does nothing to protect that lawyer. Professional discipline is a separate, parallel track.
For consultants and auditors, the equivalent risk is over-reliance: using AI-generated analysis without the professional judgment step that the client is actually paying for and that regulators expect.
Increasingly, client engagement letters and master service agreements specify:
These clauses are not harmonized across jurisdictions or even across clients of the same firm. A firm serving 200 clients can face 200 slightly different private AI policies layered on top of public law. This is why many firms now maintain an internal AI use register: a log of which tools are approved, for which task types, under which client contract terms.
Example: minimal AI use register schema
tool_name, vendor, data_residency, client_data_allowed (Y/N),
approved_use_cases[], risk_tier_eu_ai_act, human_review_required (Y/N)This kind of structured register is the practical bridge between all four layers: it is the artifact a regulator, a bar investigator, or a client audit will ask to see.
Knowledge check
1. Under the EU AI Act, how is the risk tier of an AI system primarily determined?
2. A consulting firm builds a scoring tool that a bank later uses to make lending decisions. What does this scenario illustrate about the AI Act's high-risk classification?
3. Why does the opening example of the transfer pricing memo (multiple jurisdictions, vendors, and reviewers) matter conceptually for professional services firms?
4. Select ALL correct answers about the EU AI Act's risk-tier system as described in the lesson.
Select all the correct answers.
5. Select ALL correct answers about why professional services firms face a complex regulatory landscape for AI use.
Select all the correct answers.
A firm advising a client with EU, US, and UK touchpoints cannot pick "the strictest rule" and apply it everywhere; the rules are not stacked, they are different in kind. The EU AI Act asks "what risk tier is this system?" The SEC asks "did you misrepresent it?" The FCA asks "which senior manager is accountable?" The bar asks "did you maintain competence and confidentiality?" The contract asks "did you disclose and get consent?"
Practical governance response, in order:
1. Map the use case, not the tool. The same GPT-based drafting assistant can be low-risk in one workflow (internal summarization) and high-risk in another (feeding a client-facing credit decision).
2. Assign a named accountable person per AI use case, mirroring the FCA's SMCR logic even outside UK-regulated entities. Diffuse accountability is the single most common finding in AI governance failures.
3. Build a human-in-the-loop checkpoint wherever professional judgment is the product being sold. This is both a conduct-rule requirement and a client trust requirement.
4. Reconcile contract clauses with the AI use register before deployment, not after a client complaint.
5. Document reasoning, not just output. Auditors and regulators increasingly ask for the "why," not just the AI-generated "what."
The EU AI Act Explained
For a live, non-invented reference point on how regulators are coordinating (or not), the OECD AI Policy Observatory tracks national AI regulatory developments in something close to real time.