← Insights / Compliance

AI Compliance for UK Professional Services: What the Data (Use and Access) Act 2025 and ICO's Enforcement Strategy Mean for Your Firm

The regulatory environment governing AI in professional services is no longer theoretical. It is active, enforceable, and moving faster than most firms have anticipated. If your organisation uses AI tools for HR decisions, payroll anomaly detection, CV screening, client profiling, or any form of aut

Compliance 29 July 2026 6 min read

AI Compliance for UK Professional Services: What the Data (Use and Access) Act 2025 and ICO's Enforcement Strategy Mean for Your Firm

The regulatory environment governing AI in professional services is no longer theoretical. It is active, enforceable, and moving faster than most firms have anticipated. If your organisation uses AI tools for HR decisions, payroll anomaly detection, CV screening, client profiling, or any form of automated assessment, you now have concrete compliance obligations — and the regulators have both the appetite and the authority to act on failures.

This briefing sets out what has changed, what is imminent, and what your firm needs to do about it.


The Data (Use and Access) Act 2025: A Shift in the UK's AI Framework

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent in June 2025, with its broader provisions taking effect by February 2026. For professional services firms, the most consequential element is its significant amendment to the UK GDPR framework around automated decision-making (ADM).

The Act does not simply tighten the rules — it recalibrates them. On one hand, it opens the door to greater use of AI-driven tools in areas such as CV screening and creditworthiness assessments. On the other, it reinforces individual rights and substantially sharpens the accountability requirements placed on organisations that deploy those tools.

The critical operational point is this: safeguards must be documented. The ICO has made clear that an undocumented safeguard is, in effect, no safeguard at all. If your firm cannot demonstrate — in writing, with specificity — how it protects individuals from the consequences of automated decisions, you are already in breach of the framework. Good intentions and functional systems are not enough. The evidence must exist and be retrievable.

For accountancy firms running automated credit assessments, HR consultancies using AI to shortlist candidates, or recruitment agencies relying on scoring tools, this is an immediate compliance task, not a future-proofing exercise.


The ICO's Enforcement Posture Has Changed

It would be a mistake to read the DUAA in isolation from the ICO's current enforcement trajectory. The data tells a clear story.

In the first half of 2025 alone, the ICO issued six fines totalling approximately £5.6 million — more than double the £2.7 million levied across the whole of 2024. The average fine now exceeds £2.8 million. These are not outlier figures from headline cases; they represent a sustained shift in the regulator's willingness to issue meaningful penalties.

Two enforcement actions are particularly instructive. In October 2025, the ICO reinstated a £7.5 million fine against Clearview AI. The principle established here is one that every firm using third-party AI tools must internalise: the fact that a tool is hosted overseas, developed by a foreign company, or provided as a managed service does not exempt your organisation from UK compliance obligations. You remain accountable for how that tool processes personal data on your behalf.

The ICO's February 2026 investigation into xAI (Grok) for personal data processing failures reinforces this further. Both AI developers and the firms using their products are within scope. If you are deploying a third-party AI tool — whether it is an HR platform, a document review system, or a marketing analytics engine — your due diligence on that tool's data processing practices is a compliance requirement, not optional housekeeping.

Additionally, the alignment of PECR fines with serious UK GDPR penalties has raised the maximum sanction to £17.5 million or 4% of annual worldwide turnover, whichever is higher. For firms using AI in client communications or digital marketing, this matters directly.


The EU AI Act: A Global Obligation, Not a European One

UK-based firms operating internationally must not conflate "not directly bound" with "not affected." The EU AI Act has genuine extraterritorial reach. If your firm develops, deploys, or uses AI systems that affect individuals in the European Union — including EU-based clients, candidates, or employees — you are subject to its provisions.

Several obligations are already in force or fast approaching. The prohibition on unacceptable-risk AI systems took effect from 2 February 2025. Critically for HR and payroll functions, this includes a ban on emotion analysis of employees in the workplace. If any tool in your HR technology stack includes sentiment analysis or emotional inference capabilities applied to staff, it requires immediate review.

Transparency duties for generative AI systems take effect from 2 August 2026. Full compliance requirements for high-risk AI systems — which include those used in employment, education, and essential services — apply from 2 December 2027 for standalone systems, and 2 August 2028 for AI embedded in regulated products, following the May 2026 Digital Omnibus agreement.

The penalty exposure is substantial: up to €35 million or 7% of worldwide annual turnover for the most serious breaches. For any professional services firm with EU clients or operations, building an EU AI Act compliance roadmap is not a long-term aspiration — it is a near-term business requirement.


What Is Coming Next in the UK

The ICO updated its strategic approach to AI and biometrics, Preventing harm, promoting trust, in March 2026. It has closed a consultation on updated guidance for automated decision-making and profiling, and a statutory Code of Practice on AI and Automated Decision-Making is anticipated in Summer 2026.

In November 2024, the ICO had already published six key data protection requirements for AI in recruitment, following audits of AI providers that resulted in nearly 300 compliance recommendations. That level of scrutiny is not receding — it is the baseline from which enforcement will now escalate.

Firms that treat these publications as background reading rather than operational directives are misjudging the regulatory moment.


The Practical Priorities for Professional Services Firms

Across HR consultancies, accountancy practices, solicitors, and marketing agencies — whether based in the UK, US, Canada, the EU, Middle East, or Asia-Pacific — the immediate compliance priorities are consistent:

Audit your automated decision-making processes. Identify every instance where AI or automated tools contribute to decisions affecting individuals. Map the data flows, the logic applied, and the individuals affected.

Document your safeguards. For every automated decision process, the safeguards protecting individuals must be written down, reviewed, and maintained. This is now a legal obligation under the DUAA framework, not a best practice.

Review third-party AI tools. Understand what personal data your AI vendors process, where it is processed, and under what legal basis. The Clearview precedent makes clear that vendor accountability flows upstream to the deploying firm.

Assess your EU AI Act exposure. If you have clients, employees, or operations touching the EU, map your AI tools against the Act's risk classifications. Start with the prohibited practices — emotion analysis being the most urgent for HR functions.

Prepare for the ICO's Code of Practice. When the statutory Code arrives in Summer 2026, it will set the definitive standard against which the ICO assesses compliance. Firms with documented, structured AI governance will be in a substantially stronger position than those scrambling to respond.


Work With Ops Intel

The regulatory landscape described above is complex, interconnected, and evolving in real time. Ops Intel provides AI compliance consultancy specifically designed for professional services firms navigating these obligations — from initial AI audits and gap analyses to the development of documented governance frameworks and ongoing regulatory monitoring.

If you are not confident that your firm's AI practices meet the current standards set by the DUAA, the ICO, and the EU AI Act, now is the time to act — before an investigation makes the decision for you.

Contact Ops Intel today to arrange a compliance assessment tailored to your firm's AI exposure.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit