This content is provided for informational purposes and does not constitute legal advice. Consult qualified counsel for your firm's specific obligations.
Most consulting firms met the EU AI Act as a client topic: something to advise on, build a practice around, or include in a governance deck. Fewer have worked through what it requires of the firm itself. That gap matters, because several obligations are already in force, and the ones that bite hardest for a consultancy are not the headline rules on high-risk systems but three quieter provisions about literacy, banned tools and the definition of a provider.
Key takeaways
- The EU AI Act entered into force on 1 August 2024. Under Article 113 of the Regulation, its general provisions and prohibitions (Chapters I and II, which include Articles 4 and 5) apply from 2 February 2025.
- Article 4 requires providers and deployers to ensure adequate AI literacy among staff and others using AI on their behalf. Weak literacy can aggravate other penalties and signals poor governance.
- Article 5 bans specified practices and carries the Act's highest penalty: up to EUR 35 million or 7% of worldwide annual turnover. For a consultancy the main risk is accidental: adopting a third-party tool with a prohibited feature.
- Article 25 sets out when an organisation becomes the provider of a high-risk AI system. As consultancies scale AI offerings, new engagements can reclassify them as providers, with the duties that follow.
- The UK has no single AI law; regulators apply five non-binding principles, but UK GDPR, consumer law, financial services rules, the Online Safety Act and the EU AI Act (for EU clients) still apply.
Where the Act stands today
Regulation (EU) 2024/1689, the Artificial Intelligence Act, entered into force on 1 August 2024. It is built on a risk-based framework: a small set of AI practices are prohibited outright, a defined category of high-risk systems carries detailed obligations, and lighter transparency duties apply elsewhere. Application is staggered. Under Article 113 of the Regulation, the general provisions and the prohibitions, which include the AI literacy duty in Article 4 and the banned practices in Article 5, have applied since 2 February 2025.[1] Several obligations are therefore already live: AI literacy, prohibited practices, governance rules, penalties and transparency requirements.
The consolidated text of the Regulation is published in the Official Journal of the European Union and is the authoritative reference for every provision discussed here: Regulation (EU) 2024/1689 on EUR-Lex.[1]
Article 4: AI literacy is a duty, not a nice-to-have
Article 4 requires providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy among their staff and any other persons using AI on their behalf. A consulting firm that gives its consultants ChatGPT Enterprise, Copilot or an internal agent platform is a deployer, and the duty applies to it directly, not only to its clients.
The provision matters for two reasons the 2026 report highlights. First, weak literacy can aggravate other penalties: a firm that cannot show its people understood the tools they used is in a worse position when something else goes wrong. Second, it signals poor governance more broadly. The practical response is role-specific training, since a partner, an analyst and an IT administrator need different things, and a record of who was trained, when, and on what.
Article 4 is the regulatory expression of a lesson the industry has just learned the hard way. The hallucinated citations that Deloitte, EY, KPMG and PwC Middle East published in 2025 and 2026 were not tooling failures; they were literacy failures, people trusting output they had no basis to trust. Literacy in the Article 4 sense is not knowing how a model is trained. It is knowing that it will invent a source rather than admit it has none, and having the habit of checking. A training log is the evidence; the behaviour is the point.
Article 5: prohibited practices and the accidental-adoption risk
Article 5 bans certain uses of AI outright and carries the highest penalty in the Act: administrative fines of up to EUR 35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. The prohibited practices include workplace emotion recognition, social scoring and certain forms of biometric identification, among others defined in the Article.
Few consultancies will set out to build an emotion-recognition system. The risk the 2026 report identifies is accidental: a team adopts a third-party tool, for HR analytics, for sales intelligence, for a client project, without realising that one of its features falls under Article 5. The exposure is created by procurement, not by intent.
| Prohibited practice (Article 5, examples) | Where a consultancy might meet it | Control |
|---|---|---|
| Emotion recognition in the workplace or education | HR analytics or employee-engagement tools with sentiment or emotion features; call-analysis tools used internally | Screen the tool's feature list before adoption; disable or exclude the feature in scope |
| Social scoring | Client projects in public-sector or lending contexts that rank individuals across unrelated data | Engagement-level review against Article 5 before scoping |
| Certain biometric identification uses | Security, access or identity tools procured for offices or client sites | Vendor due diligence; explicit exclusion in the AI policy |
Two controls follow: screen AI tools before adoption, and list the banned uses explicitly in the firm's AI policy so that a team can recognise one when it sees it.
Article 25: how a consultancy becomes a provider
The Act distinguishes providers, who develop or place an AI system on the market, from deployers, who use one. Most consultancies think of themselves as deployers. Article 25 sets out the circumstances in which an organisation is nonetheless treated as the provider of a high-risk AI system, for example by putting its name on it, by substantially modifying it, or by changing its intended purpose so that it becomes high-risk. Once that reclassification happens, the obligations the Act places on providers of high-risk systems apply, including the risk-management, documentation and conformity duties set out in the Regulation.
This is the provision most likely to surprise a growing AI practice. The same trend that makes AI a revenue stream, clients asking for systems built and running rather than advice, is the trend that turns a consultancy into a provider. A firm that fine-tunes a model for a client's credit process, brands it, and hands it over may have crossed the line without a single lawyer being asked. The check belongs in the scoping conversation, not the delivery review.
The UK: principles, not a single law
The United Kingdom has taken a different route. There is no single AI-specific law. Regulators instead apply five non-binding, cross-sector principles: safety, transparency, fairness, accountability and contestability.[3] On its face that looks like a lighter regime for UK consultancies.
In practice they face a web of adjacent rules that shape how AI can be used: UK GDPR, consumer law, financial services regulation and the Online Safety Act, as well as the EU AI Act itself whenever they work with EU clients or place systems on the EU market. Pressure for harder rules is also building. An executive director of the Financial Conduct Authority has urged UK authorities to keep pace with AI's growth and to consider bringing AI tools within financial services regulation.[2]
| European Union | United Kingdom | |
|---|---|---|
| Instrument | Regulation (EU) 2024/1689, directly applicable | No single AI law; five non-binding principles applied by existing regulators |
| Literacy duty | Article 4, in force | No equivalent statutory duty; accountability principle and sector rules |
| Prohibited practices | Article 5, penalties up to EUR 35m or 7% of turnover | No AI-specific prohibitions; UK GDPR, consumer and equality law apply |
| Exposure for a consultancy | Deployer duties now; provider duties if Article 25 is triggered | Adjacent regimes (UK GDPR, consumer law, FS regulation, Online Safety Act) plus the EU AI Act for EU work |
A practical checklist for consulting firms
What the report's findings imply, in order of urgency
| Action | Provision | Why now |
|---|---|---|
| Run role-specific AI literacy training and keep a record of who was trained and on what | Article 4 | Already in force; the record is your evidence of governance |
| Screen every AI tool before adoption against the Article 5 list; list banned uses in the AI policy | Article 5 | Highest penalty in the Act; the risk is procurement, not intent |
| Add a provider-status check to the scoping of any engagement that builds, brands or repurposes an AI system | Article 25 | Growing AI revenue is exactly what triggers reclassification |
| Map which adjacent UK regimes apply to each AI use if you operate in the UK, and apply the EU Act to EU work | UK framework | Principles-based does not mean unregulated |
| Make source verification a mandatory delivery step for AI-assisted work | Article 4, in spirit | The 2025 to 2026 incidents show the cost of skipping it |
This content is provided for informational purposes and does not constitute legal advice. Consult qualified counsel for your firm's specific obligations.
This analysis expands chapter 6[4] of The State of AI in Consulting 2026. For why Article 4 matters in practice, see AI hallucinations in consulting.
Notes and sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act), Official Journal of the European Union. Articles 4, 5, 25 and 113
- UK Financial Conduct Authority, remarks by an executive director on AI and financial services regulation, as reported in 2026
- UK government framework for AI regulation: five cross-sector principles (safety, transparency, fairness, accountability, contestability)
- Spaik, The State of AI in Consulting 2026, chapter 6
Figures attributed to third parties are their own reported data; Spaik did not produce those statistics. Where the text offers an interpretation, it is Spaik's own.
Continue reading
- The State of AI in Consulting 2026The full report this analysis is drawn fromRead
- AI hallucinations in consultingWhy Article 4 literacy matters in practiceRead
- AI agents in consultingDeploying agents and the provider questionRead
- AI advisory and implementationGovernance and tool selection with SpaikRead
Working with Spaik
AI literacy is now a compliance line item
Spaik designs role-specific AI literacy and governance programmes for consulting firms: what the tools do, where they fail, what must never be entered, and how to document who was trained on what. Informational content is not a substitute for counsel, but trained teams are the foundation any counsel will ask for.