Skip to content
How Professional Services Firms Should Prepare for the EU AI Act's Reach Into the UK in UK
AI & Automation13 min read

How Professional Services Firms Should Prepare for the EU AI Act's Reach Into the UK in UK

Scult Team
13 min read

The EU AI Act's August 2026 transparency rules now reach UK professional services firms with EU clients, and most firms have no idea their chatbots and AI tools are in scope.

Direct answer: If your UK professional services firm serves any client based in the EU, the EU AI Act's transparency obligations that came into force in August 2026 already apply to you, regardless of where your servers sit or where your company is registered. In practice this means every chatbot, AI-drafted document, and automated client communication your firm uses needs a clear disclosure that AI was involved, plus a paper trail showing you thought about it deliberately rather than bolting on a disclaimer after the fact.

Deloitte UK's Tech Trends coverage of EU AI Act enforcement, published in August 2026, flagged something UK firms have been slow to internalise: the Act's transparency requirements are not an EU-only concern that stops at the Channel. Because the regulation applies based on where the output of an AI system is used or where the affected person is located, not where the company providing it is headquartered, a UK-based accountancy, law firm, or consultancy that has EU clients, EU-based staff, or EU counterparties in a transaction can fall inside scope purely through the relationship, not through a UK office. This is the same extraterritorial logic that made GDPR relevant to companies with no EU presence, and it's now playing out again with AI-specific obligations layered on top. For firms whose entire business model is built on trust, judgement, and defensible paperwork, "we didn't realise this applied to us" is not a posture that will survive a client audit or a regulator's first letter.

What the EU AI Act's August 2026 Rules Actually Require

The transparency provisions that took effect in August 2026 are narrower than the Act's full risk-tiered framework, but they are also the provisions most likely to touch an ordinary UK professional services firm day to day. At their core, they require that people know when they are interacting with an AI system rather than a human, and that AI-generated or AI-modified content that could be mistaken for genuine human output is labelled as such.

The Practical Scope

Concretely, this covers things a lot of firms already have running quietly in the background:

  • Chatbots and virtual assistants on client-facing websites and portals
  • AI-drafted correspondence, reports, or first-pass legal and financial documents sent to clients
  • Automated email or messaging sequences that use generative AI to personalise content
  • Voice-based AI systems used in client intake or support
  • Any system that generates synthetic text, image, audio, or video content that a reasonable person could mistake for human-created

None of this requires that a firm stop using AI. It requires that the use be disclosed, documented, and — this is the part firms tend to underestimate — consistent across every channel where the AI shows up. A chatbot that discloses its nature on the website but not inside an embedded widget on a client portal is not compliant; it's just inconsistently compliant, which in a regulatory review reads the same as non-compliant.

Why This Rule Set Is Real, Not Speculative

It is worth being precise about what is and is not established here. What's confirmed is the trend itself: enforcement of the transparency chapter began in August 2026, and Deloitte's UK Tech Trends analysis of that enforcement specifically called out the cross-border reach into UK companies serving EU customers. What is not publicly available, at least not in a form specific enough to responsibly quote, is a precise count of how many UK firms have been contacted, fined, or formally reviewed under these provisions so far — that level of enforcement-statistics detail simply hasn't been published in a way any firm should treat as settled. The safer and more useful way to reason about this is from the pattern: regulatory bodies with extraterritorial reach (GDPR being the obvious precedent) tend to start enforcement with visible, easily-detected gaps — an undisclosed chatbot, a missing label on AI-generated marketing copy — before moving to harder-to-detect internal process gaps. Firms that treat the visible surface as the whole problem are usually surprised later.

Why This Specifically Matters to Professional Services Firms in the UK

Professional services is a distinct category here, and it's worth being explicit about why, because generic "AI compliance" advice tends to undersell the exposure.

Trust Is the Product, Not a Feature

A marketing firm that gets caught with an undisclosed AI chatbot faces reputational annoyance. A law firm, accountancy practice, or consultancy that gets caught the same way faces a direct hit to the thing clients are actually paying for: the assurance that judgement, advice, and work product came from a professional who is accountable for it. If a client later discovers that a first draft of a due diligence memo, a tax position summary, or a contract review was substantially AI-generated without disclosure, the damage isn't limited to that one engagement — it invites the client to re-read everything else you've sent them with suspicion. Regulatory exposure and client trust exposure move together here in a way they don't for most other industries.

The Cross-Border Reality of UK Professional Services

UK professional services firms are unusually likely to have EU touchpoints even when they think of themselves as domestic. A mid-sized UK accountancy might serve a handful of clients with EU subsidiaries. A boutique consultancy might have EU nationals on staff who count as "affected persons" for certain provisions. A law firm might handle cross-border transactions where the counterparty is EU-based. None of these firms would describe themselves as "an EU-facing business," and yet each one plausibly has a live compliance question the moment the Act's transparency chapter is enforced with real teeth. This is precisely the blind spot Deloitte's analysis called out — the firms least likely to have already reviewed their exposure are the ones with EU relationships that feel incidental rather than central to the business.

Professional Indemnity and Contractual Exposure

There's a second-order effect worth naming plainly: professional indemnity insurers and EU-based client contracts are increasingly likely to ask, directly, whether AI disclosure practices meet current regulatory requirements. A firm that can't answer that question with documentation — not just a verbal "yes, we handle that" — is going to find it harder to renew certain client relationships or insurance terms cleanly. This is not a hypothetical extension of the rule; it's the ordinary way that regulatory requirements propagate into contract and insurance language once they're on the books.

What Actually Changes in Practice for Your Website, Portal, and Client Tools

This is where the abstract compliance question becomes a concrete build-and-fix list, and it's worth separating out by surface.

Public Website and Marketing

If your site runs a chatbot — even a simple one answering "what services do you offer" questions — it needs a clear, persistent disclosure that the visitor is talking to an AI system, not a person, at the point of first interaction, not buried in a privacy policy three clicks away. If you publish AI-assisted blog content, thought leadership, or marketing copy, the labelling bar is lower for pure text (the Act is more concerned with content that could be mistaken for authentic human testimony, like synthetic images or voice), but the underlying discipline — knowing which of your public content was AI-touched and being able to say so — still matters for audit readiness. Firms that have already invested in clean, well-structured web presences find this easier; a site built around clear Design Systems 101: Building Consistency Across Your Product principles makes it far simpler to roll out a consistent disclosure treatment across every page and component than a site where every landing page was hand-built differently.

Client Portals and Internal Tools

This is the area firms most often miss, because portals feel "internal" even when EU clients are the ones logging in. If your client portal uses an AI agent to triage support requests, summarise documents, draft responses, or surface recommendations, that disclosure obligation follows the client into the portal — it doesn't stop at your public website's front door. Firms running bespoke portal builds, including the kind of Vendor Portal Development work that connects clients, vendors, and internal teams around shared documents and workflows, need to specifically audit where generative AI sits inside that workflow and whether the disclosure is visible at the point of use, not just documented somewhere in a settings page nobody reads.

Discoverability of Your Compliance Posture Itself

There's a subtler shift worth flagging: as AI-mediated search and AI assistants become a bigger share of how prospective clients research firms before engaging one, how your firm's AI governance and transparency practices show up in AI-generated answers about your firm is becoming its own small discoverability problem, distinct from traditional search rankings. This is part of why the distinction covered in GEO vs SEO: What's the Difference? (2026) matters here — a firm that publishes clear, structured information about how it uses and discloses AI is more likely to be represented accurately when a prospective client asks an AI assistant "does this firm use AI responsibly," than a firm that has nothing public to point to at all.

Documentation, Not Just Disclosure

Disclosure is the visible half of compliance. The other half — the half regulators and increasingly clients will ask about — is the internal record: which systems use generative AI, what they're used for, what disclosure mechanism is attached to each, who owns the review of that mechanism, and when it was last checked. Firms that treat this as a one-time audit rather than a maintained inventory tend to drift out of compliance quietly as new tools get adopted by individual teams without central visibility.

What to Do About It: A Practical Roadmap

The work here breaks into four stages, and the order matters — firms that jump straight to "add a chatbot disclaimer" without doing the inventory step tend to miss the tools individual teams adopted independently.

Step One: Inventory Every AI Touchpoint

Before anything else, get a complete list of every place your firm's website, portal, and internal tooling uses generative AI or an automated agent that interacts with a person. This includes shadow tooling — the AI-powered email assistant a partner adopted individually, the transcription tool used in client calls, the AI drafting assistant embedded in a document platform. Most firms find this list is longer than expected once someone actually goes looking.

Step Two: Classify Exposure by Client Relationship

For each touchpoint, work out whether it plausibly touches an EU client, EU staff member, or EU counterparty. Be conservative here — the extraterritorial reach means "probably not EU-related" is a weaker position than firms would like it to be, and the cost of over-disclosing is trivial compared to the cost of a compliance gap surfacing in a client audit.

Step Three: Build Consistent Disclosure Into the Actual Product

This is the part that benefits from proper engineering rather than a policy memo. A disclosure notice needs to appear at the right moment, in the right place, across web, portal, and any embedded widgets, and it needs to be maintained as the underlying tools change. This is squarely the kind of work covered under AI Agents & Automation — designing the agent-facing layer of a client interaction so that transparency, logging, and disclosure are built into the automation itself rather than added as an afterthought banner. Done properly, this also gives you the audit trail from Step Four almost for free, because the disclosure logic and the usage logging live in the same system.

Step Four: Establish an Ongoing Review Cadence

Treat this as a living inventory, not a one-off project. New AI tools get adopted by teams faster than most firms' governance processes can track, and the Act's enforcement priorities will almost certainly sharpen over time as regulators see what firms are and aren't doing. A quarterly review of the AI touchpoint inventory, owned by someone specific rather than "compliance in general," is the difference between staying ahead of this and finding out about a gap from a client's legal team.

Common Mistakes Firms Make When Responding to This

Watching how firms in adjacent regulated industries handled GDPR gives a reasonably reliable preview of where UK professional services firms will stumble on this, and it's worth naming the patterns before they repeat.

Treating It as a One-Off Legal Memo Instead of a Product Change

The most common mistake is routing this entirely through legal or compliance, producing a policy document that says the firm "discloses AI use appropriately," and stopping there. A policy statement doesn't change what a client actually sees when they open the chatbot widget on a Tuesday afternoon. The disclosure has to exist in the product itself — the website, the portal, the automated email — not only in a document describing what the product is supposed to do. Firms that skip the engineering step end up with a compliance narrative that doesn't match their live systems, which is a worse position than having no narrative at all, because it looks deliberate rather than merely incomplete.

Assuming "We Don't Have EU Clients" Without Actually Checking

A surprising number of firms answer the exposure question from memory rather than from a client list. A partner might be confident the firm is "UK-only," while the client roster includes a company with an EU parent, a UK subsidiary of an EU group, or an individual client who relocated to Ireland or Germany last year. The only reliable way to answer the exposure question is to actually run the client list against it, not to reason from a general impression of the firm's market.

Fixing the Website and Forgetting the Portal

Because the website is the visible, public-facing surface, it tends to get fixed first and sometimes exclusively. Portals, embedded scheduling widgets, and AI features inside document-sharing tools are just as exposed and are consistently the last thing firms think to check, largely because they were built or adopted by a different team at a different time, often without the same level of design and governance oversight as the public site.

Letting the Fix Go Stale After the First Pass

A disclosure rollout done once and never revisited degrades quietly. A new AI feature gets switched on inside an existing tool, a portal gets a vendor update that changes how its chat widget behaves, or a team adopts a new drafting assistant — and none of it gets added to the inventory unless someone owns that specific responsibility on an ongoing basis.

What This Kind of Work Typically Falls Under

Bringing a firm's client-facing AI systems into a defensible, disclosed, well-documented state is rarely a single fixed-price task — it depends on how many touchpoints exist and how much custom engineering the disclosure and logging layer needs. As a rough guide to where this kind of engagement typically lands:

Tier Typical scope Fit for
Essential — $1,000 Single chatbot or website AI touchpoint audited and brought to a clear, consistent disclosure standard Smaller firms with one or two AI-facing tools and limited EU exposure
Growth — $2,000 Multi-surface disclosure rollout across website plus a client portal, including a basic AI-touchpoint inventory and review process Firms with an active client portal and a handful of EU relationships
Enterprise — $4,000+ Full AI Agents & Automation build-out: disclosure and logging embedded directly into agent workflows, ongoing audit trail, and a governance cadence Firms with multiple portals, several EU client relationships, and internal AI tooling across teams

These are starting reference points for scoping a conversation, not quotes — the right tier depends entirely on how many systems are in scope and how much of the disclosure logic needs to be custom-built versus configured.

Key Takeaways

  • The EU AI Act's August 2026 transparency rules reach UK firms through client, staff, and counterparty relationships with the EU — not through where your firm is registered or hosted.
  • Professional services firms carry more reputational risk from an undisclosed AI touchpoint than most industries, because trust in judgement is the core product being sold.
  • Every AI-facing surface — public website, client portal, embedded widgets, internal tools — needs a consistent, visible disclosure, not just a policy document that describes one.
  • Start with a full inventory of AI touchpoints, including tools individual teams adopted without central visibility, before building any disclosure mechanism.
  • Building disclosure and usage logging directly into your AI agents, rather than bolting on a banner, gives you the audit trail regulators and EU clients will eventually ask for.
  • Treat this as an ongoing governance cadence, not a one-time fix — new AI tools will keep entering the firm faster than informal oversight can track them.

Getting this right means auditing what you actually have running today, not guessing at it, and building disclosure into the systems themselves rather than patching it on afterward. If you want help figuring out where your firm's exposure actually sits and what a properly engineered fix looks like, book a meeting with our team.

Frequently Asked Questions

What is the EU AI Act's transparency chapter, in plain terms?

It's the section of the EU AI Act requiring that people be told when they're interacting with an AI system rather than a human, and that AI-generated content capable of being mistaken for genuine human output is clearly labelled. It applies regardless of whether the AI system itself is classified as high-risk under the Act's broader risk tiers.

Does the EU AI Act apply to a UK company with no EU office?

Yes, if the company's AI systems are used by, or produce output affecting, people located in the EU. The Act's reach is based on where the effect lands, not where the company is incorporated, which is the same extraterritorial logic that made GDPR relevant to non-EU companies.

Why did Deloitte flag August 2026 specifically?

Deloitte UK's Tech Trends coverage of EU AI Act enforcement highlighted August 2026 as the point at which the transparency chapter's enforcement activity began reaching UK companies with EU customers, marking a shift from theoretical exposure to active regulatory attention.

What counts as an "EU customer" for this purpose?

Generally, any client, counterparty, or affected individual based in the EU who interacts with your AI system or is affected by its output — this can include EU-based clients of a UK firm, EU staff, or EU parties to a cross-border transaction your firm is advising on.

Do I need to worry about this if my firm is UK-only with no EU clients?

If genuinely no client, staff member, or counterparty has any EU connection, direct exposure is lower, but firms should verify this rather than assume it, since cross-border relationships often exist further down a client's own supply chain or ownership structure than firms initially realise.

Is a website chatbot really covered by this?

Yes. A chatbot that a person could reasonably mistake for a human agent is one of the clearest examples the transparency rules target, and it needs a disclosure at the point of first interaction, not hidden in a footer link.

What about AI used only internally, never client-facing?

Purely internal tools with no client or affected-person interaction carry lower direct transparency exposure, but firms should still document their use, since internal tools have a habit of becoming client-facing (via a portal integration, for example) without a formal review.

How is this different from GDPR compliance we already have?

GDPR governs personal data handling; the AI Act's transparency provisions govern disclosure of AI involvement in interactions and content, regardless of whether personal data is processed. A firm can be fully GDPR-compliant and still have an undisclosed AI chatbot problem.

What happens if a firm is found non-compliant?

Enforcement mechanics and penalty specifics continue to develop, and a precise, UK-specific penalty figure isn't something to state with confidence here. What's clear from the general pattern of cross-border digital regulation is that early enforcement tends to focus on correction and documentation requests before escalating, which is exactly why acting proactively is cheaper than waiting for a formal notice.

Does this apply to sole practitioners and small consultancies?

Yes, in principle — the Act doesn't carve out an exemption based on firm size, only based on the nature of the AI use and the affected persons involved. A sole practitioner using an AI drafting tool for EU-based clients has the same disclosure obligation as a large firm doing the same thing.

What's the fastest way to check our own exposure?

Start with a simple inventory: list every AI-powered tool touching your website, portal, or client communications, then check each one against whether any EU client, staff member, or counterparty could interact with it. That two-part exercise surfaces most of the exposure quickly.

Does AI-drafted marketing copy need a disclosure label?

The transparency rules are primarily concerned with content that could be mistaken for authentic human testimony or interaction, such as synthetic voice, image, or video content. Plain AI-assisted text like blog posts carries a lighter labelling expectation, but maintaining an internal record of what was AI-assisted is still good practice for audit readiness.

What about AI-generated reports sent to clients?

If a report or memo is substantially AI-drafted and could be mistaken for entirely human-authored professional work, disclosure is the safer path, both for regulatory reasons and because client trust in professional services depends on knowing who — or what — actually produced the analysis.

Do voice AI systems used in client intake need disclosure too?

Yes. Voice-based AI interacting with a client or prospective client falls squarely within the kind of interaction the transparency rules are designed to cover, and the disclosure needs to happen at or before the start of the interaction.

How does this affect client portals specifically?

Any AI agent embedded in a client portal — for triage, document summarisation, or automated responses — needs the same disclosure treatment as a public-facing chatbot. Portals are the area firms most often miss because they feel internal even when EU clients log into them directly.

What's the risk of doing nothing right now?

The immediate risk is being caught flat-footed if a client, insurer, or regulator asks a direct question about AI disclosure practices before you have an answer ready. The longer-term risk is that retrofitting disclosure and documentation across multiple systems is more expensive and disruptive than building it in from the start.

Should our professional indemnity insurer know about our AI tools?

Increasingly, yes — insurers and EU-based client contracts are starting to ask directly about AI disclosure practices as part of renewal and onboarding processes. Having documentation ready before being asked is a much stronger position than scrambling to produce it under time pressure.

How long does a full AI touchpoint audit take?

It depends heavily on how many systems and teams are involved, but a focused audit covering website, portal, and the most obvious internal tools is typically a matter of a few weeks of concentrated work rather than months, provided someone owns it directly rather than treating it as a side project.

What does "building disclosure into the agent" actually mean technically?

It means the disclosure notice, the logging of when and how the AI system was used, and the underlying automation logic all live in the same system, rather than a disclosure banner being maintained separately from the tool it describes. This is core to how AI Agents & Automation work should be structured from the start.

Can Scult help with just the disclosure piece, or does it have to be a full rebuild?

Scope can start narrow — a single chatbot or website touchpoint brought into compliance — and expand from there. Not every firm needs a full agent-and-automation rebuild; many need a focused, well-scoped fix on their highest-exposure surface first.

What's the difference between "limited risk" and "high risk" AI systems under the Act?

The transparency obligations discussed here generally apply to systems the Act treats as limited-risk, meaning the main requirement is disclosure rather than the heavier conformity and oversight requirements attached to high-risk categories like biometric identification. Most professional services chatbots and drafting tools fall into the limited-risk, disclosure-focused category.

Does this affect how we present AI use in pitches and proposals?

It's worth being accurate and specific in pitches about where and how AI is used in service delivery, since overstating or understating AI involvement can create a mismatch between what was promised and what the disclosure record later shows.

Are UK regulators involved, or is this purely an EU enforcement matter?

The August 2026 enforcement activity described by Deloitte centres on the EU AI Act's cross-border reach into UK companies with EU relationships, which is a matter of EU jurisdiction over the affected-person location rather than a new UK domestic regulator. UK firms should still expect UK bodies and client contracts to increasingly reference these standards as a baseline.

What if our AI vendor already claims to be "AI Act compliant"?

A vendor's platform-level compliance claim doesn't automatically cover how your firm has configured and deployed that tool in a specific client-facing context. Disclosure obligations attach to the actual use, so firms still need to verify their own implementation, not just rely on a vendor's general claim.

How do we handle disclosure for AI used in due diligence or research work?

If AI substantially shaped a deliverable a client will rely on, the safer approach is a clear internal record of that involvement and, where the output could be mistaken for fully human-authored analysis, a disclosure to the client. This protects both the client relationship and the firm's own defensibility if the work is later questioned.

Does this apply differently to law firms versus accountancy firms versus consultancies?

The underlying transparency obligation is the same across professional services types, but the specific touchpoints differ — law firms tend to have more exposure through document drafting and e-discovery tools, accountancy firms through automated reporting and client portals, and consultancies through client-facing chat and research assistants.

What's the single most common gap firms have right now?

The most common gap is a chatbot or portal-embedded AI assistant with no disclosure at the point of interaction, paired with no internal record of which tools across the firm actually use generative AI in the first place.

Should we pause using AI tools until we're compliant?

Generally no — pausing AI use isn't necessary or realistic for most firms. The more efficient path is auditing current use and adding proper disclosure and documentation around it, rather than stopping and restarting tools that are already delivering value.

How often should we review our AI touchpoint inventory?

A quarterly review is a reasonable baseline for most firms, since new AI tools tend to get adopted by individual teams between formal review cycles, and a quarterly cadence catches drift before it becomes a larger gap.

What documentation should we actually keep?

At minimum: a list of every AI touchpoint, what it's used for, who owns it, what disclosure mechanism is attached to it, and when it was last reviewed. This is the record that turns "we handle that" into something you can actually show.

Does content generated by AI for our own marketing website need the same treatment as client-facing tools?

Marketing content generally carries a lighter disclosure bar than direct AI interactions or synthetic media, but it should still be part of your internal AI-use inventory so the firm has a complete and accurate picture, not a partial one.

How does this interact with our website's SEO and content strategy?

It doesn't restrict content strategy, but firms publishing AI-informed content should think about how their governance and transparency practices are represented to both search engines and AI-driven discovery tools, since prospective clients increasingly research firms through both.

What's the realistic cost range for bringing one chatbot into compliance?

For a single, well-defined touchpoint like one website chatbot, this typically falls into the Essential tier around $1,000, covering the audit and the disclosure implementation. Costs rise with the number of systems and the amount of custom engineering the disclosure and logging layer requires.

What does a Growth-tier engagement typically include?

A Growth-tier engagement, generally around $2,000, typically covers disclosure across multiple surfaces — for example, both a public website and a client portal — plus a basic inventory and review process rather than a single fix.

When does an Enterprise-tier build make sense?

Enterprise-tier work, generally $4,000 and up, makes sense for firms with several client portals, multiple EU relationships, and AI tooling spread across different internal teams, where disclosure and logging need to be engineered directly into the underlying agent workflows.

Can this work be done incrementally rather than all at once?

Yes — starting with the highest-exposure touchpoint (usually the most client-facing chatbot or portal assistant) and expanding from there is a sound approach, and it lets a firm show progress and documentation early rather than waiting for a single large project to finish.

What role does staff training play in this?

Staff need to understand which tools in their daily workflow are AI-powered, because informal adoption of new AI tools by individual team members is one of the most common ways firms drift out of an accurate compliance picture.

Is there a risk in over-disclosing AI use?

The practical risk of over-disclosure is minimal compared to under-disclosure — being transparent about AI involvement where it isn't strictly required rarely causes harm, while missing a required disclosure can directly damage both compliance standing and client trust.

How does this affect firms using third-party SaaS tools with embedded AI?

Firms remain responsible for disclosure around how a third-party tool's AI features are presented to their own clients, even when the underlying AI model is built and hosted by the SaaS vendor. Relying entirely on the vendor's own compliance posture doesn't cover the firm's own client-facing implementation.

What's the connection between this and design consistency on our website?

Rolling out a consistent AI disclosure notice across every page, widget, and embedded tool is far easier on a site built with clear, reusable design patterns than one where every page was built independently, which is why design system discipline and compliance rollout tend to go hand in hand.

Does this affect how our vendor or client portals are built going forward?

New portal builds should account for AI disclosure and usage logging from the design stage rather than retrofitting it later, since portals are exactly the kind of surface — used repeatedly by known clients — where an undisclosed AI touchpoint is most likely to be noticed and questioned.

What's the difference between disclosure and consent under this framework?

Disclosure means informing a person that they are interacting with or receiving AI-generated content; it does not necessarily require obtaining explicit consent in the way some data protection frameworks do, though clear disclosure naturally supports better-informed client relationships.

How does this intersect with e-discovery and litigation support tools?

AI tools used in e-discovery or litigation support that touch client-facing outputs or affect EU parties to a matter should be included in the same touchpoint inventory and disclosure review as any other client-facing AI system, given the potentially significant consequences of an undisclosed AI role in legal work product.

Will these requirements get stricter over time?

The general pattern with cross-border digital regulation, GDPR being the clearest precedent, is that enforcement tends to sharpen and expand in scope over time rather than loosen, so firms that build solid governance now are better positioned for whatever comes next rather than needing to rebuild later.

What should a firm do in the next 30 days?

Complete the AI touchpoint inventory, identify which touchpoints have EU exposure, and fix the most visible gap — typically an undisclosed chatbot — while planning the fuller review and documentation process for the following quarter.

Does this apply to AI used in recruitment or HR within the firm?

If an AI system is used in ways that affect EU-based staff or candidates — screening, scheduling, or automated communication — it can fall under the same transparency logic, so HR and recruitment tooling should be included in the firm-wide inventory rather than treated separately.

How do we know if our current chatbot vendor already has disclosure built in?

Check the actual interface your clients see, not just the vendor's marketing claims — many chatbot platforms support a disclosure message but don't enable it by default, so it needs to be explicitly configured and tested from the client's point of view.

What's the biggest mistake firms make when trying to comply quickly?

The biggest mistake is adding a generic disclaimer somewhere on the site without first completing the touchpoint inventory, which leaves other AI-powered surfaces — portals, embedded widgets, internal tools that later go client-facing — completely unaddressed.

Who inside a professional services firm should own this?

Ownership works best with a named individual — often someone in operations, compliance, or a partner with technology oversight — rather than a shared responsibility, since diffuse ownership is exactly how AI touchpoint inventories go stale between reviews.

How does Scult typically start an engagement like this?

Engagements typically start with a scoping conversation to understand how many AI touchpoints exist, which have EU exposure, and how much of the disclosure and logging work needs custom engineering versus configuration, which is the fastest way to land on the right tier and timeline.

Want results like this?

Keep reading