This content is provided for informational purposes and does not constitute legal advice. Consult qualified counsel for your firm's specific obligations.
Consulting firms have largely approached the EU AI Act as a client topic: something to advise on, build a practice around, and include in a governance deck. Fewer have assessed what it requires of the firm itself. Several obligations already apply, and the provisions with the most direct effect on a consultancy are three provisions on literacy, banned practices and provider status rather than the headline rules on high-risk systems.
Key takeaways
- The Act entered into force on 1 August 2024. Under Article 113, its general provisions and prohibitions (Chapters I and II, which include Articles 4 and 5) have applied since 2 February 2025.
- Article 4 requires providers and deployers to ensure adequate AI literacy among staff and anyone using AI on their behalf. Weak literacy can aggravate other penalties, and it reads as poor governance.
- Article 5 bans specific practices and carries the Act's highest penalty: up to EUR 35 million or 7% of worldwide annual turnover. For a consultancy the realistic risk is accidental, through a third-party tool with a prohibited feature.
- Article 25 sets out when an organisation becomes the provider of a high-risk system. A consultancy that builds, brands or repurposes a system for a client can cross that line without noticing.
- The UK has no single AI law and relies on five non-binding principles, but UK GDPR, consumer law, financial services rules, the Online Safety Act and the EU Act itself (for EU work) all still apply.
Where the Act stands today
Regulation (EU) 2024/1689, the Artificial Intelligence Act, entered into force on 1 August 2024. It works by risk tier: a short list of AI practices is banned outright, a defined category of high-risk systems carries detailed obligations, and lighter transparency duties apply to the rest. Application is staggered. Under Article 113, the general provisions and the prohibitions, which include the literacy duty in Article 4 and the banned practices in Article 5, have applied since 2 February 2025.[1] A substantial part of the Act therefore already applies: literacy, prohibited practices, governance rules, penalties and transparency requirements.
Everything discussed here is in the consolidated text published in the Official Journal of the European Union, which is the authoritative reference: Regulation (EU) 2024/1689 on EUR-Lex.
Article 4: AI literacy is now a duty
Article 4 requires providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy among their staff and anyone else using AI on their behalf. A consulting firm that gives its people ChatGPT Enterprise, Copilot or an internal agent platform is a deployer. The duty applies to the firm itself, independently of the advice it gives clients.
Our 2026 report gives two reasons to take the duty seriously. Weak literacy can aggravate other penalties: a firm that cannot show its people understood the tools they used is in a poor position when something else goes wrong. It also reads as weak governance more broadly. The practical response is role-specific training, because a partner, an analyst and an IT administrator need different things, together with a record of who was trained, when, and on what.
Article 4 addresses a failure the industry has recently experienced in public. In the hallucinated-citation cases that Deloitte, EY and KPMG published in 2025 and 2026, people trusted output they had no basis to trust. Literacy in the Article 4 sense means knowing that a model will invent a source rather than admit it has none, and checking as a matter of habit. The training record is the evidence of compliance; the habit is what the article is meant to produce.
Article 5: prohibited practices and the accidental-adoption risk
Article 5 bans certain uses of AI outright and carries the highest fine in the Act: up to EUR 35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. The banned list includes emotion recognition in the workplace, social scoring and certain forms of biometric identification, among others set out in the Article.
A consultancy is unlikely to build an emotion-recognition system deliberately. The risk our report identifies is accidental: a team adopts a third-party tool for HR analytics, sales intelligence or a client project, and one of its features falls under Article 5. The exposure arises through procurement rather than intent.
| Prohibited practice (Article 5, examples) | Where a consultancy might meet it | Control |
|---|---|---|
| Emotion recognition in the workplace or education | HR analytics or employee-engagement tools with sentiment or emotion features; call-analysis tools used internally | Screen the tool's feature list before adoption; disable or exclude the feature in scope |
| Social scoring | Client projects in public-sector or lending contexts that rank individuals across unrelated data | Engagement-level review against Article 5 before scoping |
| Certain biometric identification uses | Security, access or identity tools procured for offices or client sites | Vendor due diligence; explicit exclusion in the AI policy |
Two controls follow: screen AI tools before adoption, and write the banned uses into the firm's AI policy in plain language, so that a team recognises one when it sees it.
Article 25: how a consultancy becomes a provider
The Act separates providers, who develop an AI system or place it on the market, from deployers, who use one. Most consultancies think of themselves as deployers. Article 25 lists the circumstances in which an organisation is treated as the provider of a high-risk system anyway: putting its name on it, substantially modifying it, or changing its intended purpose so that it becomes high risk. Once reclassified, the firm carries the obligations of a provider of a high-risk system, including the risk-management, documentation and conformity duties in the Regulation.
This is the provision most likely to affect a growing AI practice unexpectedly. The trend that turns AI into revenue, clients asking for systems built and running rather than advice, is the same trend that turns a consultancy into a provider. A firm that fine-tunes a model for a client's credit process, brands it and hands it over may have crossed the line without legal review. The check belongs in the scoping conversation, well before the delivery review.
The UK: principles, not a single law
The UK went another way. There is no single AI law. Regulators apply five non-binding, cross-sector principles: safety, transparency, fairness, accountability and contestability.[3] On paper that looks lighter for UK consultancies.
In practice UK consultancies operate within adjacent rules that govern how AI can be used: UK GDPR, consumer law, financial services regulation and the Online Safety Act, plus the EU AI Act itself when they work for EU clients or place systems on the EU market. Pressure for firmer rules is growing. An executive director of the Financial Conduct Authority has urged UK authorities to keep pace with AI and to consider bringing AI tools within financial services regulation.[2]
| European Union | United Kingdom | |
|---|---|---|
| Instrument | Regulation (EU) 2024/1689, directly applicable | No single AI law; five non-binding principles applied by existing regulators |
| Literacy duty | Article 4, in force | No equivalent statutory duty; accountability principle and sector rules |
| Prohibited practices | Article 5, penalties up to EUR 35m or 7% of turnover | No AI-specific prohibitions; UK GDPR, consumer and equality law apply |
| Exposure for a consultancy | Deployer duties now; provider duties if Article 25 is triggered | Adjacent regimes (UK GDPR, consumer law, FS regulation, Online Safety Act) plus the EU AI Act for EU work |
A practical checklist for consulting firms
What the report's findings imply, in order of urgency
| Action | Provision | Why now |
|---|---|---|
| Run role-specific AI literacy training and keep a record of who was trained and on what | Article 4 | Already in force; the record is your evidence of governance |
| Screen every AI tool before adoption against the Article 5 list; list banned uses in the AI policy | Article 5 | Highest penalty in the Act; the risk is procurement, not intent |
| Add a provider-status check to the scoping of any engagement that builds, brands or repurposes an AI system | Article 25 | Growing AI revenue is what triggers reclassification |
| Map which adjacent UK regimes apply to each AI use if you operate in the UK, and apply the EU Act to EU work | UK framework | Principles-based is still regulated |
| Make source verification a mandatory delivery step for AI-assisted work | Article 4, in spirit | The 2025 to 2026 incidents show the cost of skipping it |
Chapter 6[4] of The State of AI in Consulting 2026 covers the same ground in more depth. For why Article 4 matters in practice, see AI hallucinations in consulting.
This content is provided for informational purposes and does not constitute legal advice. Consult qualified counsel for your firm's specific obligations.
Notes and sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act), Official Journal of the European Union. Articles 4, 5, 25 and 113
- UK Financial Conduct Authority, remarks by an executive director on AI and financial services regulation, as reported in 2026
- UK government framework for AI regulation: five cross-sector principles (safety, transparency, fairness, accountability, contestability)
- Spaik, The State of AI in Consulting 2026, chapter 6
Figures attributed to third parties are their own reported data; Spaik did not produce those statistics. Where the text offers an interpretation, it is Spaik's own.
Continue reading
- The State of AI in Consulting 2026The full report this analysis is drawn fromRead
- AI hallucinations in consultingWhy Article 4 literacy matters in practiceRead
- AI agents in consultingDeploying agents and the provider questionRead
- AI advisory and implementationGovernance and tool selection with SpaikRead
Working with Spaik
AI literacy is now a compliance line item
Spaik designs role-specific AI literacy and governance programmes for consulting firms: what the tools do, where they fail, what must never go into them, and how to document who was trained on what. An article is no substitute for counsel, but a trained team is the first thing counsel will ask for.