◈ The Promptory Daily · Issue #037

The Regulatory Landscape Every Professional Services Firm Needs to Know About AI

Something changed in the professional services AI conversation. Six months ago, the primary conversation was adoption — how do you get your team to use AI, which tools are worth trying, how do you make a business case for the subscription. That conversation is over. Adoption happened, broadly and quickly, and in most cases without adequate controls.

The conversation now — especially in legal, financial services, healthcare, and consulting — is: what's happening to the data? Who's accountable when something goes wrong? And how do you build an AI stack that can survive a compliance audit without shutting down the productivity gains you've built?

◈ A Note Before the Frameworks

This isn't legal advice. What follows is a practical orientation to the regulatory landscape — built for firms that want to get ahead of governance rather than scramble to retrofit it later. For anything binding, involve your counsel.

The Regulatory Landscape — What's Actually In Effect Right Now

◈ EU AI Act — Full Commission Enforcement Powers Active (August 2, 2026)

Applies if you serve EU customers or partners. The world's first comprehensive AI regulation classifies systems by risk tier. High-risk systems — those used in employment decisions, credit scoring, insurance, and healthcare — face strict documentation, conformity assessment, and human oversight requirements. The penalty ceiling for the most serious violations: €35 million or 7% of global annual turnover, whichever is higher.

For most professional services firms, the immediate obligation is Article 4: AI literacy. Every person in the AI value chain — which increasingly means everyone — must have documented training on the AI tools they use and the risks they carry.

Bottom line: if you serve EU clients or have EU partners, the governance requirement isn't optional and the fine structure is designed to get board attention.

◈ US State Laws — A Patchwork Getting Faster

Texas's TRAIGA — signed June 2025, effective January 1, 2026 — uses intent-based liability and carries penalties from $10,000 to $200,000 per violation. It names NIST AI RMF compliance as an affirmative defense, which is the clearest signal yet that building to that framework is the strongest legal hedge in the US market.

Colorado's original AI Act is effectively dead — struck by a federal court in April 2026, replaced with a narrower framework effective January 2027. If a compliance plan was built around the old Colorado law, it needs a rebuild.

Bottom line: there's no single US federal rule to comply with. The only durable strategy is building to the strongest common methodology — NIST AI RMF and ISO 42001 — and documenting it.

◈ HIPAA, GDPR, CCPA — Already Apply to Every AI Tool Your Team Uses

This is where most day-to-day AI compliance risk actually lands, and it's already in force. Every pre-AI regulation attaches the moment your team pastes sensitive data into a prompt. HIPAA requires that protected health information is only processed by tools that meet specific security and privacy standards — an employee at a healthcare practice pasting patient notes into an unapproved AI tool has created a HIPAA violation, regardless of intent. The law doesn't care about intent. It cares about what happened to the data.

GDPR requires clear documentation of how personal data is processed, by whom, and under what legal basis. If a team is using AI tools the organization hasn't vetted, assessed, or documented, it cannot demonstrate compliance — full stop.

Bottom line: the new AI laws get the headlines, but these existing regulations are where most professional services firms have actual, immediate exposure today.

Ask Jordan

Reader

I'm the managing partner at a 12-person accounting firm. We've been using AI tools for about eight months — mostly ChatGPT and a couple of other things — but we've never formally assessed what our exposure is. A client recently asked us about our AI governance policies and we didn't have a good answer. Where do we actually start?

Jordan

The client question is exactly the right forcing function — and it's happening more and more as enterprise buyers add AI governance requirements to their vendor assessments. You start with two things: an inventory of what your team is actually using, and a one-paragraph policy on what data should never go into an AI tool. Those two things, done this week, close most of your immediate exposure. Then you build the formal governance layer around what you have. Do you currently know every AI tool your team is using — including the personal accounts and free tiers?

◈ The One Thing

Governance built right doesn't slow AI down. Research from BCG shows responsible AI implementation triples the rate of capturing full AI benefits. Firms that build governance in from the start spend less time in audit, less time in procurement review, and less time defending tool decisions to nervous clients. The governance layer isn't a brake on AI adoption — it's what makes adoption sustainable.

Start with the 5-question shadow AI audit to find out where your firm actually stands, or bring it to a free Jordan session for a governance assessment specific to your practice.

J

Have questions about your AI stack?

Jordan is The Promptory's free AI advisor. Describe your workflow and your challenges — Jordan will reason through your situation and tell you exactly which tools fit.

◈ Talk to Jordan — Free →
← All Issues Browse 152 Vault Tools →