EU AI Act Enforcement Live: What UK Professional Services Need to Know Now
The EU AI Act is no longer a future obligation. As of 10 July 2026, enforcement is active, and if your firm deploys AI systems that interact with users in the European Union, certain requirements apply to you today — regardless of where your business is headquartered. For accountants, solicitors, HR
EU AI Act Enforcement Is Live: What Professional Services Firms Need to Know Now
The EU AI Act is no longer a future obligation. As of 10 July 2026, enforcement is active, and if your firm deploys AI systems that interact with users in the European Union, certain requirements apply to you today — regardless of where your business is headquartered. For accountants, solicitors, HR consultancies, and marketing agencies operating internationally, the window for preparation has narrowed considerably.
Here is what has changed, what is still coming, and where the risks are sharpest.
Chatbot Disclosure: Binding Now, No Exceptions
The most immediately actionable requirement is the chatbot disclosure obligation. Any business using AI-powered chatbots, virtual assistants, or automated conversational tools that interact with EU users must clearly inform those users at the outset of the interaction that they are speaking with an AI.
This is not a recommendation. It is a legal obligation with effect from 10 July 2026.
For professional services firms, this matters more than it might first appear. Client-facing chat functions on websites, AI-assisted intake forms, automated scheduling tools, and client support portals all fall within scope if they involve EU-based users. A marketing agency running a chatbot for EU clients, or a law firm using an AI assistant to handle initial client enquiries, must now have disclosure in place. Review your client-facing AI touchpoints and confirm disclosures are clear, prominent, and present at the start of every interaction.
High-Risk AI Deadlines Have Shifted — But Have Not Disappeared
The "Digital Omnibus on AI" amendments, approved in June 2026 and effective July 2026, have extended compliance deadlines for high-risk AI systems. Obligations for high-risk systems listed under Annex III now apply from 2 December 2027, while those embedded in regulated products — such as medical devices or industrial machinery — apply from 2 August 2028.
This extension was granted explicitly because regulators recognised that organisations needed more preparation time. That acknowledgement is useful, but it should not be misread as leniency. The deadline has moved; the obligations have not been reduced. HR consultancies using AI for candidate screening, accountancy firms deploying AI for credit risk assessment, and any firm using automated decision-making tools that affect individuals in material ways are likely to be caught by Annex III provisions. If your firm has not yet mapped its AI systems against the high-risk classifications, the extra time is an opportunity to do so properly — not an invitation to defer the work indefinitely.
The European Commission's draft guidelines published in May 2026 provide further clarity on how high-risk classification applies in practice. These are worth reviewing alongside your legal advisers.
What Is Already In Force
The compliance picture is not simply about future deadlines. Several provisions are already applicable:
Prohibited AI systems have been unlawful since 2 February 2025. These include AI used for subliminal manipulation causing harm, social scoring by public authorities, and real-time remote biometric identification in public spaces outside narrow exceptions. The list has since been extended to cover systems that generate non-consensual intimate images or audio — an important expansion that reflects growing regulatory focus on generative AI misuse.
General Purpose AI (GPAI) model providers have been subject to transparency, documentation, and systemic risk assessment obligations since 2 August 2025. If your firm provides AI models to others — rather than simply using them — these obligations apply to you directly.
Synthetic content transparency requirements covering AI-generated audio, images, video, and text remain in force, with a short four-month extension granted to some systems, pushing certain obligations to December 2026.
GDPR Enforcement Against AI Has Not Slowed
Alongside the AI Act, GDPR enforcement involving AI continues at pace. Data Protection Authorities across Europe imposed fines exceeding €1.2 billion in aggregate during 2024 and 2025 alone. The enforcement focus is not exclusively on large technology companies.
Clearview AI was fined €30.5 million by the Dutch DPA in September 2024 for unlawful facial image scraping — bringing its total European fines to over €90 million. The Italian Garante's €15 million fine against OpenAI, issued in December 2024 over ChatGPT's use of personal data without proper legal basis and inadequate age verification, was annulled by a Rome court in 2026 on procedural grounds. The annulment does not signal a retreat from enforcement; it reflects the complexity of litigating these cases. Expect more actions, not fewer.
For professional services firms, the GDPR risks around AI are grounded in everyday practice: training AI tools on client data without a lawful basis, using AI outputs in decisions that affect data subjects without adequate transparency, or failing to conduct data protection impact assessments before deploying new AI systems.
Notable Regulatory Developments Worth Tracking
Two further developments merit attention. Ireland published its Regulation of Artificial Intelligence Bill 2026 in June 2026, establishing the AI Office of Ireland as the central coordinating authority and conferring supervision and sanctioning powers on Market Surveillance Authorities. For firms with Irish operations or clients, this signals that national enforcement infrastructure is being built.
Additionally, a 2026 amendment to the AI Act has introduced a regulated exemption permitting the processing of special category data for the sole purpose of detecting and correcting bias in AI models. This resolves a genuine compliance dilemma for developers and deployers who needed to audit their systems for fairness but faced GDPR barriers to doing so. If your firm is engaged in AI development or procurement, this exemption is worth understanding precisely — it is narrow and condition-bound.
The AI literacy obligation has also been softened. Providers and deployers are now required to support the development of AI literacy among relevant staff, rather than ensure a defined level is reached. This is a more proportionate standard, but it does not eliminate the expectation that your people understand the AI tools they are using and deploying on behalf of clients.
The Practical Priorities for Your Firm
Across the professional services sector globally, the immediate compliance priorities are clear:
- Audit your client-facing AI tools for chatbot disclosure compliance if you have EU users.
- Map your AI systems against Annex III high-risk categories and begin scoping what December 2027 obligations will require.
- Review your GDPR position on any AI system that processes personal data — including those used internally for HR, document review, or client analysis.
- Document everything. Regulators expect evidence of a structured, considered approach. If you cannot demonstrate how you assessed and managed AI risks, the fine landscape makes that exposure costly.
The EU AI Act is the most comprehensive AI regulatory framework currently in force anywhere in the world. Its effects extend well beyond the EU's borders. If your firm serves EU clients, employs EU staff, or operates through EU entities, you are in scope.
Ops Intel helps professional services firms understand and meet their AI compliance obligations — from initial system audits and risk classification through to regulatory documentation and ongoing monitoring. If your firm needs clarity on where it stands under the EU AI Act or GDPR, contact the Ops Intel team to arrange a compliance review.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.