⚖️ The EU AI Act Is Now Law — What It Means for Accounting Firms
From 2 August 2025, new rules under the EU AI Act will directly affect how accountants use tools like ChatGPT, Claude, and Gemini—especially if you operate in the EU or serve EU-based clients. Here’s what small firm owners need to know (wherever you’re based): ✅ What You Need to Do 1. Be Transparent with Clients If you use AI to generate insights, draft reports, or summarise accounts, you must let clients know—either in the final deliverable or engagement letter. 2. Avoid Prohibited Uses The following are banned, even for internal use: - Emotional profiling - Behavioural manipulation - Biometric surveillance (e.g. emotion detection or facial recognition) 3. Complete a Risk Assessment Each use of AI needs to be classified: - Minimal risk (e.g. summarising public info): little action needed - Limited risk (e.g. AI-assisted report drafting): requires documentation and transparency - High risk (e.g. credit scoring, fraud detection): needs human oversight and strict controls Most AI use in small firms will fall into the limited risk category. 4. Apply the Same Logic as GDPR Treat AI tools like you treat personal data: - Record what you use, when, and why - Note who reviews AI outputs - Add disclaimers or checks where needed 5. Choose Compliant Tools Use AI platforms that: - Offer enterprise-grade security - Allow opt-outs from training - Ideally use EU-based data processing Good options: ChatGPT Team or Enterprise, Claude via Amazon Bedrock, or a local model via Ollama. 🌍 Regional Differences EU Firms: Full compliance required. Treat it like GDPR—document, assess, disclose. UK Firms : If you serve EU clients, the Act applies. If not, you’re exempt—but similar UK guidelines may still apply. Canada / US: You’re only affected if you serve EU clients or use EU-based tools—but similar laws are coming. 🧭 Practical Example A firm in Ireland must fully comply. A firm in the UK must comply only if it serves EU clients. A firm in Canada is exempt—unless it processes EU data or uses EU tools.