← Insights / Compliance

The Data (Use and Access) Act 2025: What Professional Services Firms Need to Know About AI Compliance

The UK's approach to AI regulation has entered a new phase. With the Data (Use and Access) Act 2025 (DUAA) now in force, enforcement activity rising sharply, and court cases establishing real consequences for AI misuse, professional services firms can no longer treat compliance as a background conce

Compliance 22 July 2026 6 min read

The Data (Use and Access) Act 2025: What Professional Services Firms Need to Know About AI Compliance

The UK's approach to AI regulation has entered a new phase. With the Data (Use and Access) Act 2025 (DUAA) now in force, enforcement activity rising sharply, and court cases establishing real consequences for AI misuse, professional services firms can no longer treat compliance as a background concern. Whether you are a law firm in London, an HR consultancy in Dubai, an accounting practice in Toronto, or a marketing agency in Sydney with UK clients or staff, these developments have direct implications for how you use AI in your operations.

This briefing sets out what has changed, what is at stake, and what you need to do.


Automated Decision-Making Has Been Rewritten

The DUAA, which came into force on 5 February 2026, fundamentally alters the legal framework for automated decision-making (ADM) in the UK. Article 22 of the UK GDPR — which imposed a near-blanket prohibition on solely automated decisions producing legal or similarly significant effects — has been replaced by new Articles 22A through 22D.

The headline change is that solely automated decisions are now permitted. But this is not a relaxation to be celebrated uncritically. The permission comes with a corresponding obligation to implement robust, documented safeguards. Businesses must be able to demonstrate accountability, explain AI-driven decisions to affected individuals upon request, and evidence that they have considered the risks before deploying such systems.

For professional services firms, this matters immediately. HR consultancies using AI-powered shortlisting tools, law firms using AI to assess case viability, accountants using automated risk-scoring for clients, and marketing agencies using algorithmic targeting — all of these fall within the scope of the new framework. The question is no longer whether you can use these tools. The question is whether your governance structures are strong enough to justify it.


The ICO Is Building the Rulebook — and Already Enforcing It

The Information Commissioner's Office (ICO) has been mandated to produce a statutory Code of Practice on AI and Automated Decision-Making. Draft guidance closed for consultation in May 2026, with the final version expected in Summer 2026. When published, this code will function as the definitive compliance manual for any AI system processing personal data in the UK.

Critically, the ICO is not waiting for the code to be finalised before it acts. AI-driven recruitment tools have been named as a 2026 enforcement priority. The ICO is conducting audits of providers in this space and has clarified that central AI model providers are likely to be classified as data controllers — a designation that triggers Data Protection Impact Assessment (DPIA) obligations. If your firm uses or resells AI recruitment tools, you need to understand where you sit in that data controller landscape and whether your DPIA documentation reflects it.

Firms operating internationally should note that the ICO's reach extends wherever UK residents' personal data is being processed. A firm headquartered in Singapore, New York, or Riyadh that handles data relating to UK individuals is not insulated from this framework.


Fines Have Increased. Marketing Firms Should Pay Particular Attention.

The DUAA has aligned penalties for Privacy and Electronic Communications Regulations (PECR) breaches with the upper threshold that already applies to serious UK GDPR violations: £17.5 million or 4% of annual worldwide turnover, whichever is higher. The previous £500,000 cap on PECR fines has been removed.

This is a material change for marketing agencies and any professional services firm running digital campaigns involving electronic communications. The risk profile of non-compliance with cookie rules, email marketing consent requirements, and similar obligations has increased substantially.

The wider enforcement picture reinforces the seriousness of the current environment. Reddit received a £14.47 million penalty in February 2026 for failures relating to children's privacy and age assurance. LastPass UK Ltd was fined £1.2 million in November 2025 following a data breach affecting 1.6 million UK customers. The ICO has opened a formal investigation into xAI (Grok) over the processing of personal data in connection with non-consensual sexualised imagery. These are not isolated incidents; they reflect a sustained shift towards assertive, high-value enforcement.


For law firms and any professional services firm that produces formal written work product, the emerging body of case law around AI-generated errors demands serious attention.

In R. (on the application of Ayinde) v Haringey LBC EWHC 1383 (Admin), lawyers submitted court documents containing fabricated case citations produced by AI. The consequences included wasted costs orders and regulatory referrals. In Elden v Revenue and Customs Commissioners UKFTT 41 (TC), AI-generated inaccuracies in skeleton arguments led to mandatory requirements being imposed on future filings.

These cases establish something important: relying on AI output without verification is not a technical failure — it is a professional one. The individuals who signed those documents were responsible for their contents. That principle applies equally to accountants submitting AI-assisted reports, HR consultancies producing policy documents, and marketing agencies drafting compliance-sensitive material.

The practical implication is that firms need documented review processes for AI-generated content. Not informal habits, but auditable workflows that demonstrate human accountability at the point of sign-off.


What International Firms with UK Exposure Must Do Now

For professional services businesses operating globally, the UK's direction of travel matters even if London is not your headquarters. Several immediate actions are warranted.

Map your AI use. Identify every system in your business that makes or contributes to decisions affecting individuals — clients, employees, or prospects. Understand what personal data each system processes and whether it involves UK residents.

Audit your ADM governance. Under the new Articles 22A-22D framework, you need documented safeguards, not just policy statements. Accountability must be demonstrable, not assumed.

Review your DPIA position. If you use third-party AI tools, particularly in recruitment or client assessment, assess whether your firm is functioning as a data controller and whether your impact assessments reflect that.

Update your PECR compliance. If your firm sends marketing communications to UK contacts or operates digital campaigns involving UK audiences, the removal of the £500,000 PECR cap means your exposure has increased materially.

Introduce AI content verification workflows. For any formal output — legal documents, audit reports, HR policies, client proposals — establish and document the human review process for AI-assisted content.


Compliance Is Not Optional. Neither Is Getting It Right.

The DUAA marks a structural change in the UK's regulatory approach to AI. The ICO has both the mandate and the appetite to enforce it. International firms that process UK personal data, run UK marketing campaigns, or produce formal work product using AI are operating in a higher-risk environment than they were twelve months ago.

Ops Intel works with professional services businesses across the UK, EU, US, Canada, the Middle East, and Asia-Pacific to build AI compliance frameworks that are practical, auditable, and proportionate to the way firms actually work. If you are uncertain about your current position under the DUAA, or if you need to prepare for the ICO's forthcoming Code of Practice, we can help.

Contact Ops Intel today to arrange a compliance assessment and ensure your AI practices meet the standard now required.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit