← Insights / Compliance

UK AI Compliance 2025: What Professional Services Firms Must Do Now

The UK's AI regulatory landscape has shifted decisively. New legislation, a more aggressive enforcement posture from the Information Commissioner's Office, and the extraterritorial reach of the EU AI Act have combined to create a compliance environment that professional services firms can no longer

Compliance 26 July 2026 6 min read

UK AI Compliance 2025: What Professional Services Firms Must Do Now

The UK's AI regulatory landscape has shifted decisively. New legislation, a more aggressive enforcement posture from the Information Commissioner's Office, and the extraterritorial reach of the EU AI Act have combined to create a compliance environment that professional services firms can no longer afford to treat as background noise. Whether you are running an accountancy practice in London, a law firm in Dubai, an HR consultancy in Toronto, or a marketing agency in Singapore with UK or EU clients, the obligations are real and the penalties are substantial.

This briefing sets out what has changed, why it matters, and what your firm needs to do about it.

The Data (Use and Access) Act 2025: Flexibility With Accountability

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent in June 2025, with key provisions commencing from December 2025 and broader changes taking effect by February 2026. It makes significant amendments to the UK GDPR framework and represents the most consequential update to UK data protection law in several years.

For professional services, the headline development is increased flexibility around automated decision-making (ADM). The Act permits greater use of AI-driven tools in CV screening, creditworthiness assessments, and employment-related decisions — areas directly relevant to HR consultancies, recruiters, and financial services providers globally who process data relating to UK individuals.

However, this liberalisation is not a relaxation of accountability. The DUAA reinforces individual rights and sharpens the obligation on organisations to document, justify, and defend their automated processes. If your firm uses AI to filter candidates, assess client risk, or make recommendations that affect individuals, you must be able to explain precisely how those systems work, what data they use, and why the outcomes are fair. Vague references to "algorithmic efficiency" will not satisfy a regulator.

The ICO Is Enforcing, Not Just Advising

The ICO's enforcement trajectory in 2025 signals a clear strategic shift: fewer fines, but far larger ones. In the first half of 2025 alone, the ICO issued six fines totalling approximately £5.6 million — more than double the £2.7 million collected across eighteen fines throughout the whole of 2024. The average fine now exceeds £2.8 million.

Two enforcement actions deserve particular attention. First, the ICO's reinstatement of the £7.5 million fine against Clearview AI in October 2025 confirmed a critical principle: using a third-party AI tool hosted overseas does not insulate your firm from UK compliance obligations. If the AI system processes data relating to UK residents, UK law applies — regardless of where the vendor is incorporated or where their servers sit. For any firm using AI tools built and hosted outside the UK, this is a direct and unambiguous warning.

Second, the alignment of Privacy and Electronic Communications Regulations (PECR) fines with serious UK GDPR penalties has raised the maximum sanction to £17.5 million or 4% of annual worldwide turnover, whichever is higher. This matters acutely for marketing agencies and any firm using AI-powered email platforms, automated outreach tools, or communications analytics. The ICO's February 2026 investigation into xAI (Grok) for personal data processing failures — with potential fines up to that £17.5 million threshold — confirms that AI developers and the firms using their tools are both in scope.

Capita's £14 million fine for a data breach affecting over six million individuals is a further reminder that inadequate security measures attract serious consequences, independent of any AI-specific failings.

The EU AI Act: A Global Obligation, Not a European One

UK firms with any connection to EU clients, employees, or operations must treat the EU AI Act as binding. It came into force on 1 August 2024, and since February 2025, prohibitions on certain AI practices have been enforceable. One of the most significant for professional services is the ban on emotion analysis of employees in the workplace — a capability present in some HR and productivity monitoring tools that firms may have adopted without fully assessing what the system actually does.

The Act's extraterritorial scope is broad. If your AI system produces outputs used within the EU, or if you are placing an AI system on the EU market, you are subject to its requirements. Potential fines reach €35 million or 7% of worldwide annual turnover for the most serious violations. For a mid-sized accountancy or legal firm, that is an existential financial risk.

The Act also introduces tiered obligations based on risk classification. Professional services firms need to assess every AI tool they deploy — not just the obvious ones — against those risk categories. An AI system used for legal research may sit in a different risk tier than one used to generate client-facing advice or assess credit eligibility. The classification determines the compliance obligations, and misclassifying a system is itself a risk.

What the ICO Expects Next

The ICO's AI and Biometric Plan of Action for 2025–2026 confirms that the regulator is moving from guidance to active scrutiny. The ICO is updating its automated decision-making and profiling guidance and is developing a statutory Code of Practice on AI and ADM, expected in Summer 2026. That Code will set clear expectations on how data protection law applies to AI systems — and once published, firms without documented compliance programmes will have no credible defence.

The direction of travel is clear: regulators expect AI governance to be embedded in how firms operate, not bolted on after the fact.

What Professional Services Firms Must Do Now

The regulatory environment is no longer ambiguous. The question is whether your firm has the governance structures to meet the expectations that are already in force, and those that are coming. Practically, that means addressing the following as a matter of priority:

Audit your AI tools. Map every system that touches personal data, makes recommendations, or supports decisions about individuals. Include third-party platforms. Understand what they do, what data they use, and where that data is processed.

Classify the risk. Under the EU AI Act framework, determine where your tools sit on the risk spectrum. High-risk applications require documentation, human oversight, and transparency measures that low-risk tools do not.

Document your ADM processes. Under the DUAA and UK GDPR, you must be able to justify automated decisions that affect individuals. That justification needs to be recorded, not improvised in response to a complaint or investigation.

Review your vendor agreements. The Clearview ruling means that using an overseas AI vendor does not transfer your compliance liability. Your contracts must address data protection obligations, and you must satisfy yourself that your vendors can meet them.

Update your PECR compliance. If your firm uses AI tools that interact with electronic communications — email marketing, automated messaging, communications analytics — your PECR compliance needs to reflect the new, higher penalty ceiling.

Train your people. Compliance frameworks fail when staff do not understand them. Anyone involved in procuring, deploying, or overseeing AI tools needs to understand the obligations attached to them.


The regulatory window for treating AI compliance as aspirational has closed. Enforcement is active, fines are material, and the extraterritorial reach of both UK and EU frameworks means that geography provides no protection.

Ops Intel works with professional services firms across the UK, EU, North America, the Middle East, and Asia-Pacific to build practical, proportionate AI compliance programmes. If your firm needs to understand its current exposure, establish a governance framework, or prepare for the ICO's forthcoming Code of Practice, contact Ops Intel to arrange an initial compliance review.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit