Leaders Insights
Leaders Insights

Rester au meilleur niveau, un peu chaque jour.

DomainesMarketingDataFinanceIA
RessourcesApprendreTestOutilsBlogGlossaire
© 2026 Leaders Insights — Tous droits réservés.
Formations/AI in professional services/Governance, risks and checks/The regulatory map every firm now has to read
1/4+150 XP

Governance, risks and checks

10The regulatory map every firm now has to read+15011Where AI actually breaks in advisory work+15012The pre-deployment checklist partners should demand+15013Who owns the mistake when AI gets it wrong+150

The regulatory map every firm now has to read

# The regulatory mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.Voir la définition complète → every firm now has to read

A partner at a mid-size accounting firm uses an AI tool to draft a client's transfer pricing memo. The tool was trained partly on OpenAI's GPT models, hosted on Microsoft infrastructure, used to serve a client incorporated in Ireland with operations in California, and reviewed by a UK-qualified associate. Five different rulebooks may apply to that one memo, and none of them agree on what "AI use" even means. This is not an edge case in 2026. It is Tuesday.

Professional services firms (law, audit, consulting, tax, financial advisory) now sit at the intersection of at least four overlapping regulatory logics: horizontal AI law, sector-specific financial and legal regulation, professional conduct rules, and private contract law. Reading only one of these maps will get a firm lost.

Layer 1: horizontal AI regulation (the EU AI act)

The EU AI Act (Regulation (EU) 2024/1689, official text here

) is the first comprehensive, cross-sector AI law. It classifies AI systems by risk tier, not by industry:
  • Unacceptable risk: banned outright (e.g. social scoring).
  • High-risk: subject to heavy obligations (risk management, human oversight, logging, conformity assessment). This tier includes AI used in employment decisions, credit scoring, and some biometric uses. Notably, most day-to-day generative AI drafting tools used by lawyers or consultants do not automatically fall here.
  • Limited risk: transparency duties only (e.g. disclose that a chatbot is AI).
  • Minimal risk: no specific obligation.

For professional services, the sharpest edge is indirect: if a client uses your firm's AI-assisted output to make a high-risk decision (say, an AI-scored creditworthiness assessment feeding a bank's lending decision), the classification travels with the use case, not the vendor. A consulting firm building that scoring tool can become a "provider" under the Act with full high-risk obligations, even if it thinks of itself as a service firm, not a software company.

Key term: GPAI (General-Purpose AI models, like GPT-4 or Claude) face their own separate transparency and systemic-risk obligations under the Act, layered on top of whatever your firm does with them.

Layer 2: Sector regulators don't wait for horizontal law

Financial and legal regulators were writing AI-adjacent rules before the AI Act existed, and they keep moving independently.

  • SEC (U.S. Securities and Exchange Commission): has pursued "AI washing" enforcement, actions against firms overstating AI capabilities to investors, and proposed rules on conflicts of interest arising from predictive data analytics used by broker-dealers and investment advisers.
  • FCA (UK Financial Conduct Authority): applies existing frameworks, especially the Consumer Duty and SMCR (Senior Managers and Certification Regime), to AI use. There is no separate "AI Act" in the UK; the FCA's position (as of its 2024 AI update, see FCA's AI pages) is that existing principles-based rules already cover most AI harms: accountability sits with a named senior manager regardless of which model made the recommendation.
  • Bar associations and law societies: the American Bar Association's Formal Opinion 512 (2024) and various state bar guidance address generative AI competence duties, confidentiality when feeding client data into third-party tools, and billing (firms cannot bill client hours saved by AI as if unaffected).
  • Audit oversight bodies: the PCAOB (US Public Company Accounting Oversight Board) and equivalents in Europe are scrutinizing AI use in audit sampling and analytics, focused on whether AI tools undermine auditor independence or professional skepticism, a core audit quality standard.

None of these bodies use the EU AI Act's risk tiers. A tool that is "minimal risk" under the Act can still trigger a full SEC enforcement action if marketing claims about it are false, or a bar complaint if it leaked privileged client data.

Layer 3: Professional conduct rules travel with the license, not the tool

This is the layer non-technical readers often miss. Professional obligations (duty of competence, confidentiality, independence, professional skepticism) attach to the licensed individual, not the software vendor.

Example: a lawyer using an AI research tool that hallucinates a fake case citation is still personally sanctionable, as seen in multiple US court sanctions since 2023 (the *Mata v. Avianca* case remains the reference point). The AI Act's conformity assessment does nothing to protect that lawyer. Professional discipline is a separate, parallel track.

For consultants and auditors, the equivalent risk is over-reliance: using AI-generated analysis without the professional judgment step that the client is actually paying for and that regulators expect.

Layer 4: Client contracts add a fourth, private layer of law

Increasingly, client engagement letters and master service agreements specify:

  • Which AI tools may or may not touch client data.
  • Whether client data can be used to train or fine-tune models (most sophisticated clients now say no, explicitly).
  • Disclosure obligations: must the firm tell the client when AI materially contributed to a deliverable?
  • Liability allocation if AI-assisted work causes loss.

These clauses are not harmonized across jurisdictions or even across clients of the same firm. A firm serving 200 clients can face 200 slightly different private AI policies layered on top of public law. This is why many firms now maintain an internal AI use register: a log of which tools are approved, for which task types, under which client contract terms.

Example: minimal AI use register schema
tool_name, vendor, data_residency, client_data_allowed (Y/N),
approved_use_cases[], risk_tier_eu_ai_act, human_review_required (Y/N)

This kind of structured register is the practical bridge between all four layers: it is the artifact a regulator, a bar investigator, or a client audit will ask to see.

Vérification des acquis

1. Under the EU AI Act, how is the risk tier of an AI system primarily determined?

2. A consulting firm builds a scoring tool that a bank later uses to make lending decisions. What does this scenario illustrate about the AI Act's high-risk classification?

3. Why does the opening example of the transfer pricing memo (multiple jurisdictions, vendors, and reviewers) matter conceptually for professional services firms?

CHOIX MULTIPLES

4. Select ALL correct answers about the EU AI Act's risk-tier system as described in the lesson.

Sélectionnez toutes les réponses correctes.

CHOIX MULTIPLES

5. Select ALL correct answers about why professional services firms face a complex regulatory landscape for AI use.

Sélectionnez toutes les réponses correctes.

What this means for cross-border advisory work

A firm advising a client with EU, US, and UK touchpoints cannot pick "the strictest rule" and apply it everywhere; the rules are not stacked, they are different in kind. The EU AI Act asks "what risk tier is this system?" The SEC asks "did you misrepresent it?" The FCA asks "which senior manager is accountable?" The bar asks "did you maintain competence and confidentiality?" The contract asks "did you disclose and get consent?"

Practical governance response, in order:

1. Map the use case, not the tool. The same GPT-based drafting assistant can be low-risk in one workflow (internal summarization) and high-risk in another (feeding a client-facing credit decision).

2. Assign a named accountable person per AI use case, mirroring the FCA's SMCR logic even outside UK-regulated entities. Diffuse accountability is the single most common finding in AI governance failures.

3. Build a human-in-the-loop checkpoint wherever professional judgment is the product being sold. This is both a conduct-rule requirement and a client trust requirement.

4. Reconcile contract clauses with the AI use register before deployment, not after a client complaint.

5. Document reasoning, not just output. Auditors and regulators increasingly ask for the "why," not just the AI-generated "what."

The EU AI Act Explained

Watch on YouTube

For a live, non-invented reference point on how regulators are coordinating (or not), the OECD AI Policy Observatory tracks national AI regulatory developments in something close to real time.

Key Takeaways

  • Four distinct regulatory layers apply to professional services AI use: horizontal law (EU AI Act risk tiers), sector regulators (SEC, FCA, PCAOB), professional conduct rules (bar associations, audit standards), and private client contracts. They classify the same AI use case differently and do not defer to one another.
  • Risk classification follows the use case, not the vendor or tool: the same underlying model can be minimal-risk in one workflow and high-risk, or professionally sanctionable, in another.
  • Professional discipline (bar complaints, audit independence findings) is a personal, license-level risk that exists independently of whether a firm is technically compliant with the EU AI Act.
  • An AI use register, mapping tool, use case, data handling, and accountable person, is the practical governance artifact that lets a firm answer to all four layers at once.
  • Cross-border advisory work requires reconciling, not ranking, these regimes; there is no single "strictest rule" shortcut.

Suivant

Where AI actually breaks in advisory work