← Back to Insights Leer en español

Ultreia Strategic Management

The EU AI Act and Professional Services

What audit, tax, consulting, and legal organizations need to understand now.

Professional services has been one of the fastest adopters of artificial intelligence. Document review, anomaly detection, predictive risk modeling, contract analysis, scenario planning. Across disciplines, AI has moved from experiment to infrastructure. That speed created an advantage, and an exposure that most organizations are still working to understand.

Professional services organizations face a double compliance exposure under the EU AI Act, and the organizations that understand both layers first will not just manage their own risk. They will become the advisors their clients need most.

How professional services sits differently

Most industries face one layer of AI exposure. Professional services faces two.

The first is operational. The tools your teams use every day may fall within scope if your work involves European clients, data, or entities.

The second is advisory. When you recommend, implement, or support AI for clients, you are not just using the system. You are shaping how it is used, and that carries a different kind of risk. An organization that recommends a non-compliant AI system is not only exposed to regulation. It is exposed to professional liability.

Two layers. Two different conversations. Most organizations are still focused on one.

Layer 1

Operational exposure

The tools your teams use every day. If your work involves European clients, data, or entities, those tools may fall within scope.

Examples

Audit AI, tax compliance tools, contract review platforms

Layer 2

Advisory exposure

When you recommend, implement, or support AI for clients, you are not just using the system. You are shaping how it is used.

Key risk

Recommending a non-compliant system exposes you to professional liability, not just regulation

Most industries face one layer. Professional services faces both simultaneously.

How AI tools are actually classified

This is where many conversations go off track.

There is a tendency to assume that AI in professional services is automatically high risk. It is not. Most audit and tax tools support analysis, assist human judgment, and do not directly affect individuals. These typically fall below the high-risk threshold.

HR and talent tools are a different story. AI used to screen candidates, evaluate performance, rank employees, or monitor behavior is explicitly high risk under Annex III Category 4. There is very limited room for exception under Article 6(3), and for recruitment and HR AI specifically, it is effectively closed.

The difference comes down to one question: is the system analyzing data, or is it profiling people?

A tool flagging anomalies in transactions is generally lower risk. A tool predicting behavior or outcomes for specific individuals is high risk. That line is thinner than most organizations expect, and it must be drawn and documented before deployment, not after.

Tool / SystemCommon useRisk level
AI audit sampling and anomaly detection Journal entry testing, workpaper automation, general ledger review Minimal risk
Tax compliance and transfer pricing AI VAT calculation, Pillar Two, cross-border structuring analysis Minimal risk
Contract and document review AI NLP tools for contracts, regulatory documents, due diligence Limited risk
Legal research and interpretation AI Harvey, Thomson Reuters CoCounsel - applying law to facts, litigation support Review required
Client-side financial reporting AI Expected credit loss models, insurance reserving, revenue recognition AI Audit scope item
Recruitment and performance evaluation AI Candidate screening, employee ranking, performance monitoring High risk
Individual behavior profiling AI Systems predicting fraud probability or reliability for specific individuals High risk

Where the exposure sits by discipline

The exposure is not theoretical. It sits inside how work gets done.

DisciplinePrimary AI toolsRisk levelKey exposure point
Audit Anomaly detection, workpaper review, sampling tools Minimal Client-side AI in financial reporting triggers audit scope obligations
Tax Transfer pricing, VAT, Pillar Two, compliance automation Minimal Output used in EU triggers extraterritorial scope, even without EU presence
Consulting Market modeling, due diligence AI, HR analytics Mixed Substantially modifying or embedding AI in client solutions may shift role from advisor to provider
Legal Legal research AI, contract analysis, litigation tools High risk Annex III Category 8 extends to private firms using AI to research and apply law
HR advisory Recruitment AI, performance tools, workforce planning High risk Annex III Category 4 - very limited room for exception

Audit and assurance

Most internal audit tools fall into lower risk categories. The real exposure is often on the client side. When a client uses AI in financial reporting, credit loss modeling, insurance reserving, or revenue recognition, those systems become part of the audit environment. The question shifts: not just whether the data is reliable, but whether the system itself is compliant.

A client's failure to maintain visibility and controls over its high-risk AI systems - an implicit prerequisite to meeting the deployer obligations under Article 26 - constitutes a control environment finding. That is an audit matter, not just a compliance one.

Tax

Tax is not explicitly classified as high risk, but that does not mean it is out of scope. AI used in transfer pricing documentation, cross-border structuring, and compliance analysis for EU entities can still trigger exposure. The function matters less than where the output is used. And if the classification analysis is not documented, that is already a compliance failure, regardless of the tool's risk level.

Consulting and strategy

The exposure is not just in the tools. It is in the role you play. If you substantially modify an AI system, embed it into your own solution, or place it on the market under your name, you may move from advisor to provider under the regulation.

That shift matters more than most organizations realize. Under Article 25, the trigger is substantial modification - integrating, customizing, or rebranding a system in ways that materially change its function or risk profile. A provider carries obligations that go well beyond a user or deployer: technical documentation, conformity assessments, EU database registration, and ongoing post-deployment monitoring. Most consulting organizations are not thinking about that line. They should be.

Legal

Legal sits in a category of its own. Annex III Category 8 was written for judicial authorities, but its scope extends to anyone using AI in a similar way - including private law firms researching and applying law on behalf of clients. Regulators have not formally confirmed every edge case, but the direction is clear.

That classification is not just a label. It is high risk, with everything that implies: conformity assessments, technical documentation, documented human oversight, and EU database registration. For firms working on matters involving European clients or EU-governed contracts, that applies regardless of where the firm is physically located.

Tools already in wide use, including Harvey and Thomson Reuters CoCounsel, fall squarely in this space. Organizations using them on EU-related work should understand their position before a regulator or client asks.

The vendor problem most organizations are missing

Most organizations focus on the tools they chose. The bigger risk is often the tools they did not. AI is now embedded across document platforms, practice management systems, HR tools, and client-facing technology. Many of these features were added by vendors without organizations actively evaluating them. Some cannot be turned off. Many cannot be fully explained.

Under the regulation, using the tool carries the compliance obligation. Building it is not required. Organizations need to audit not just the tools they selected, but the tools they inherited. Those are two different exercises, and most have only done one.

The layer most organizations are not addressing yet

Most internal conversations about AI compliance are focused on governance: policies, frameworks, vendor reviews, documentation. All necessary. Not sufficient.

The regulation is pushing toward a different standard: can you demonstrate that your systems behave reliably in real conditions? Not only that they are approved, but that their performance is consistent, their limitations are understood, and their outputs hold up beyond standard testing. For audit organizations, this distinction matters most. If a tool misses something material because it was never tested under adversarial conditions, governance documentation does not protect you. That is a different level of readiness, and most organizations are not there yet.

The stakes are concrete. Non-compliance with high-risk AI obligations carries penalties of up to €15 million or 3% of global annual turnover, whichever is higher. For prohibited practices, that ceiling reaches €35 million or 7%.

Governance coversSufficient?What the regulation also requires
AI use policy and documentation Partial Formal classification analysis documented before deployment
Vendor contract reviews Partial Audit rights, data quality assurances, and model governance clauses
Risk registers and AI inventories Partial Complete inventory including embedded AI in third-party platforms
Human oversight protocols Partial Documented evidence that human control is effective, not just stated
Standard performance testing Not sufficient Evidence of reliable behavior under adversarial and edge-case conditions
Internal training and awareness Yes AI literacy obligation already in force since February 2025

What to do with this

This is not a compliance exercise to delegate. It is a leadership decision.

For most Annex III high-risk AI systems, the compliance deadline is August 2, 2026. Note: the European Commission has proposed amendments that could extend certain deadlines. Worth monitoring - but not worth counting on.

What to do with this

1

Build the inventory first.

2

Draw the classification line deliberately.

3

Move beyond documentation toward evidence.

Build the inventory first.

Every AI tool the organization uses, including licensed vendor solutions and AI features embedded in platforms your teams use every day. Most organizations cannot clearly answer what AI they are actually running. Without that inventory, nothing else is possible.

Draw the classification line deliberately.

Especially for anything touching hiring, workforce decisions, financial decisions affecting individuals, and client-facing AI in regulated sectors. The classification analysis needs to happen and be documented before deployment. Finding out after the fact that a tool is high risk is a different problem entirely.

Move beyond documentation toward evidence.

Governance frameworks are the starting point. The real competitive question is whether your organization can demonstrate that its tools perform as required under real conditions. That is where scrutiny will focus.

Professional services organizations understand this dynamic well: the advisor who sees a problem clearly before their client does is not just managing risk, they are building an advantage.

The AI governance market is projected to grow from roughly $300–500 million today to between $3.6 and $5.8 billion by 2033 (Sources: Grand View Research; IMARC Group, 2025–2026). The organizations building that capacity now will capture a disproportionate share of it, but only if they move beyond documentation.

Today

$300–500M

AI governance market size

~10x

by 2033

2033

$3.6–5.8B

Projected market size

Relative market size

Today

~$400M

2033

~$4.7B

Sources: Grand View Research; IMARC Group, 2025–2026. Mid-range estimates used for bar sizing.

The next differentiator will not be who has the best governance framework. It will be who can demonstrate that their systems actually work as required.

The EU AI Act is not a future compliance problem for professional services. It is a present strategic one. The organizations that treat it that way will be in a fundamentally different position entering 2027 than those still updating their vendor contracts.

Tamary Diaz Otero is the Founder and Principal Advisor at Ultreia Strategic Management. She works with CEOs and senior leaders navigating international strategy, cross-border growth, and complex organizational decisions across Spain, the United States, Latin America, and the Caribbean. She is based between Puerto Rico and Spain.

If this raised questions relevant to your organization or your clients, she would like to hear from you.

ultreiastrategy.com/meet

Seguimos.

Notes

1EU AI Act (Regulation (EU) 2024/1689): the world's first comprehensive legal framework for artificial intelligence. Entered into force August 2024. Establishes obligations for organizations that develop or deploy AI within the EU, or whose outputs are used there.

2Annex III, Category 4: covers AI systems used in recruitment, performance evaluation, workforce management, and employee monitoring. Considered high-risk; exception pathway under Article 6(3) is very restricted for HR and recruitment AI.

3Annex III, Category 8: covers AI systems used to research and interpret law, apply it to specific facts, or assist in alternative dispute resolution. Written for judicial authorities; widely interpreted to extend to private legal practice under the "in a similar way" clause.

4In 2025, the European Commission proposed regulatory amendments (the "Digital Omnibus on AI") that could extend certain Annex III compliance deadlines into 2027. As of this writing, those amendments are under review. The direction of the regulation is clear regardless of timing adjustments.

Sources

1.European Commission. AI Act. digital-strategy.ec.europa.eu

2.Ciferi. EU AI Act: Implications for Audit Technology. March 2026.

3.Wolters Kluwer. From Innovation to Regulation: How Internal Audit Must Respond to the EU AI Act. February 2026.

4.KPMG US. How the EU AI Act Affects US-Based Companies. April 2025.

5.White & Case. EU AI Act Penalties Framework. 2024.

6.McKinsey. State of AI Survey. 2024.

7.Grand View Research. Global AI Governance Market Report. 2025.

8.IMARC Group. AI Governance Market Size, Share and Forecast. 2025–2026.

tamarydiaz@ultreiastrategy.com  ·  ultreiastrategy.com  ·  ultreiastrategy.com/meet See Clearly. Choose the Route. Walk Together.