AI Wrote It. You Signed It. Now What?
The gap at the heart of AI use in professional services
When a professional services firm or a freelancer say that they follow good practice when using AI, what does that actually mean? In most cases, this amounts to a policy document, a few caveats on a website and an unspoken assumption that putting something in writing is the same as living by it.
Many professionals are genuinely uncertain about what else is required. They know they need to say something about how they use AI, but are far less certain about what good practice actually looks like in their day-to-day work.
Professional services, as used here, means any work where the primary thing you are selling is your expertise and judgement. That includes the obvious categories like management consulting, research, legal and financial advisory, but also coaches, mentors, facilitators, trainers, evaluators and independent specialists of all kinds. What these roles share is that a client or commissioner is relying on your professional competence. They are trusting that a qualified human being has thought carefully about their situation and is standing behind the advice or work they are receiving. That trust relationship is precisely what is at stake when AI enters the process without adequate oversight.
This article draws on two perspectives: Andrea’s, from a boutique consultancy where AI decisions land directly with the management team, and Cécile’s, from a large international consulting firm where the governance infrastructure is substantial and the scale of the challenge is an entirely different order of magnitude.
Part of what makes dealing with AI difficult is that today’s solutions are largely opaque. When you use a language model to synthesise interview data or identify themes in a survey dataset, you typically cannot inspect how the model reached its conclusions. There is no transparent reasoning chain to follow, no methodology section to review. The output arrives as if fully formed, and the user is left to judge it on face value, or not to judge it at all. This is what is usually meant by the “black box” problem in AI, and it has real implications for how professional services work is done and defended.

In most analytical work, you can trace a finding back to the data and reasoning that produced it. With AI-assisted work, that chain of reasoning is often either unavailable or expressed in terms that are not straightforward to interpret (see screenshot above).
This creates a specific problem for professional services: clients expect work to be verifiable and the individuals doing it to take full responsibility. If a key piece of analysis cannot be explained, there is a serious gap.
This is why four principles that have always governed professional practice need to remain anchors when we use AI: responsibility (who owns the output and ensures high quality), accountability (who is named and answerable within an organisation and to clients), auditability (whether the reasoning behind a piece of work can be reconstructed) and transparency (how openly AI's role is communicated).
These principles are closely related but they are not the same thing, and AI creates distinct pressure points around each.
Responsibility Sits With People, Not Tools
The clearest principle in responsible AI use is also the most straightforward: AI tools do not take any responsibility, and treating them as if they might is a category error. A language model cannot own a flawed recommendation. It will not appear before a client review panel, explain a methodology to a sceptical stakeholder or answer for an error in a published report. The person who used the tool and signed off the work is the one who carries that weight.
This sounds obvious, but it has a practical implication that is easy to sidestep. Responsibility cannot be diluted by attributing outputs to an AI system, even informally. Saying “the AI suggested this framing” or “the model flagged this theme” as a way of distancing yourself from a finding is simply unacceptable. The individual who ran the prompt, reviewed the output and included it in a client deliverable is responsible for that content and its appropriateness to the client’s context.
Andrea's experience illustrates this directly:
A while back, a collaborator shared a draft social media post with me, written as part of a communications plan. It was not good: the message was generic and it bore little relation to what the client aimed to do or who they were trying to reach. As you would expect, I sent back some feedback. The response I received was, in essence: that’s what ChatGPT came up with.
I had to think for a moment about why that answer bothered me as much as it did. The problem clearly wasn’t that AI had been used, but that the response treated the tool’s output as somehow separate from the work, as if ChatGPT’s involvement explained or excused the quality rather than making it a more pressing question. Nobody had apparently looked at the draft and asked whether it was any good before sharing it. The AI had become a buffer between a practitioner and their own professional judgement.
This common interaction is a clear failure of professional practice, not of the tool: naming ChatGPT as the author does not change that. If anything, it just makes it clear that the review step was skipped.
The principle of ‘Responsibility’ has clear implications on how AI should be used as part of research, analysis and synthesis tasks. Here’s an example:
We asked Claude to create a list of ten references on the use of AI in professional services, formatted in APA style, where 9 were correct and one should be completely fabricated.
Then, we fed the ten references into ChatGPT, simply asking ‘Are all these citations correct?’
Finally, we gave that back to Claude, and the screenshot below is the response. Take a look at the final sentence in particular: Claude itself is making a point about the principle of ‘Responsibility’, completely unprompted.
Accountability Requires Named Ownership
When you use AI for your work, there needs to be clarity about who makes decisions at each level: which tools are approved for use, who authorises their deployment on client work and who is accountable when something goes wrong.
This could be a mix of colleagues or an individual, depending on your organisational context. But the overarching principle is that named people and clear lines of authority need to be in place.
Part of that accountability runs externally, toward clients. Being accountable means clients should know when AI has played a material role in the work they are paying for; not as a courtesy, but because they are entitled to understand what they are receiving. What counts as ‘material’ will vary, and you will need to make a considered judgement rather than applying a blanket rule in either direction. A spell-check is not worth disclosing; a machine-generated synthesis of fifty interviews probably is, and the decision about where that line falls sits with the named person responsible for the engagement.
The legal profession has been grappling with this very explicitly. Several US state bar associations issued formal ethics opinions addressing lawyers’ use of generative AI, with a consistent emphasis on client confidentiality, the need for competent supervision of AI-generated work and the importance of disclosure when AI use is substantial. Most people working in professional services face similar obligations in practice, even without the same formal regulatory framework.
Guidelines released in California in the context of legal work characterise GenAI as a “starting point” to be “critically analysed for accuracy” by a lawyer who must “critically review, validate and correct” the input and output to assure accurate content that best serves the client’s interests. The guidance indicates that lawyers “may” supplement GenAI research and argument with “human-performed” research, analysis, and review of legal authorities. As we know from several well-publicised examples, the review of any case citations must be double-checked, as some GenAI solutions may generate artificial cases that can appear authentic.
The consequences of getting this wrong are well documented beyond the legal profession too. In late 2025, a major global consultancy was required to partially refund a six-figure government contract after a researcher discovered that a published report contained hallucinated academic references and a fabricated quote. The substance of the report may have been sound, and the firm maintained that the corrections did not affect its findings, but the reputational damage was considerable. Most importantly, it was entirely preventable.
Having the right governance structures in place is a good starting point for accountability, but not enough: the gap between firm-level policy and individual practice is something that Cécile has observed directly. At her firm, AI governance at the infrastructure level is rigorous to the point of being restrictive: employees cannot access consumer AI tools on work devices, and the list of approved platforms is tightly controlled. On paper, this looks like exactly the kind of accountability framework this article is calling for. In practice, however, partners (the people who sign off on client work and are ultimately responsible for its quality) are not being meaningfully trained on what that sign-off now requires. The questions of when junior staff have used AI, how outputs were checked and who is accountable for the result are not being asked consistently. The firm has solved the tool problem and struggles to address the judgement problem because of its scale and complexity. This is probably the most common pattern in large professional services firms right now.
The Art of Asking Questions is a reader-supported publication. To support my work, please consider becoming a paid subscriber.
Auditability Means Keeping Records That Mean Something
An audit trail is only useful if it captures decisions. A log showing that a particular AI tool or model version was used on a particular date tells you very little. What matters is whether there is a record of why it was used, what the output was, what judgements were made about it and where human review or intervention occurred.
This matters in any analytical process, but it matters particularly with AI because the tool’s internal reasoning is not available for inspection. Documentation is not a bureaucratic exercise in this context, because it is the mechanism by which the lineage of a decision is made real. Without it, there is no way to reconstruct what happened.
It is worth acknowledging that human thought is not fully auditable either. Professional judgement is partly intuitive, shaped by experience and pattern recognition that practitioners themselves cannot always articulate. When a senior practitioner looks at a dataset and says something feels off, they are drawing on knowledge that would be difficult to reconstruct step by step. We accept this as a feature of expertise rather than a flaw, partly because the person making the judgement at least has access to their own reasoning in the moment: they lived the thought, even if they cannot fully narrate it afterwards. Memory fades and recollection becomes unreliable, but in the moment of judgement there is at least a mind present that can be questioned and held to account.
But AI adds a genuinely different kind of opacity on top of this. When a model produces an output, there is no mind that was present for the reasoning. There is no process that could have been questioned in the moment, no intuition that formed and could in principle be unpacked. The output exists, but the path to it does not, at least not in any form that a practitioner can access or inspect.
This means that combining human judgement with AI-assisted analysis produces something vastly more opaque: the human’s reasoning is partially recoverable, the model’s is not, and distinguishing which parts of a conclusion came from where is often impossible after the fact. A degree of documentation is an attempt to manage this, precisely because that record cannot be reconstructed later.
Deloitte’s 2026 State of AI in the Enterprise report makes these points crystal clear: “Organisations need to define where humans should remain in control, how automated decisions and data use are audited, and which records of system behaviour should be retained. Cross-functional teams—technology, legal, compliance, and business—establish governance frameworks early so that scale does not outpace control.”
Auditability is also where the skills question becomes pressing. Meaningful auditability depends on practitioners who can assess AI outputs critically, which requires maintaining the underlying expertise that makes critical assessment possible (note that this is closely related to the ‘Responsibility’ principle). A consultant who has gradually outsourced their analytical thinking to AI over an extended period will lose the capacity to judge whether the output is any good, or to notice when it is confidently wrong. The audit trail becomes meaningless if the person reviewing it no longer has the knowledge to interpret what they are looking at. Firms that are serious about auditability need to treat this as a workforce development question, too.
The research bears this out. A study by Microsoft focusing on knowledge workers found that “While GenAI can improve worker efficiency, it can inhibit critical engagement with work and can potentially lead to long-term over-reliance on the tool and diminished skill for independent problem-solving. Higher confidence in GenAI’s ability to perform a task is related to less critical thinking effort. When using GenAI tools, the effort invested in critical thinking shifts from information gathering to information verification; from problem-solving to AI response integration; and from task execution to task stewardship.”
Transparency Is a Practice, Not a Disclaimer
Transparency about AI use is not satisfied by a policy page or a footer note. It is a practice that runs through how work is discussed and delivered. This means being clear with colleagues and clients about the role AI has played, being honest about its limitations and being willing to explain your methodology when asked. Naturally, this all indicates that the ‘Transparency’ principle operates in parallel to all others.
There is also a form of internal transparency that is easy to overlook: being honest with yourself and your colleagues about where AI has genuinely added value and where it has produced outputs that required significant correction or were simply not fit for purpose. That kind of honest feedback loop is what allows practice to improve, and it is harder to maintain in organisations where there is pressure to present AI adoption as uniformly positive.
In practice, the transparency question that comes up most often for professional services practitioners is about data. Whose data is being processed, by which tool, under what terms, and does the client know? Naturally, using AI tools that process or store that data creates significant obligations around consent, security and disclosure. Clients and research participants generally need to know if their data is being processed by a third-party AI system, and the terms under which that happens (for example, could the company owning the model use the data for training purposes?). This is not a niche compliance matter, and very much part of your professional duty of care.
A good transparency statement does not need to be long, but it does need to be specific. Something like: “This report was produced with the assistance of AI tools at the analysis and drafting stages. All AI-generated or AI-supported outputs were reviewed, edited and verified by the project team, who take full responsibility for the findings and recommendations. No client data was entered into third-party AI systems without prior agreement.”
Compare that with the more common version: “We may use AI tools to support our work.” The first tells others what happened, who checked outputs and how data was handled. The second is a disclaimer that protects you without informing others. They are not equivalent, and most clients will notice the difference.
Notice that the first statement above also satisfies the other three principles discussed in this article: it names who is responsible for the outputs, it implies an accountable review process and it confirms that the work could, in principle, be reconstructed by the project team.
Policy Versus Practice
The gap between having an AI policy and practising responsible AI use is real, and it is wider than most organisations would like to admit. Policies are relatively easy to produce: they require clear thinking, a few hours of drafting and sign-off from someone senior. Practice is harder, because it requires consistent application across different people, different projects and different pressures. It is especially hard to keep all the principles we discussed in mind when we are under pressure to deliver quickly, and there is a temptation to present AI-assisted work as if it were more thoroughly reviewed than it really was.
People who treat responsibility, accountability, auditability and transparency as ongoing professional obligations rather than a compliance exercise to be completed and filed are the ones most likely to be considered trusted partners.
AI is changing quickly enough that any specific guidance will date. The underlying principles are more durable. They are the same ones that have always separated professional practice done well from professional practice done under pressure, and they do not become optional because a language model is now in the room.
If the principles above resonate, these questions are a starting point for honest reflection, whether you work alone or within a larger organisation.
If a client asked you to walk them through how AI was used in a piece of work you delivered, could you do it? And would your answer satisfy you?
Is there a named person responsible for decisions about AI use on each project, or is it effectively happening without ownership?
When you review AI-assisted outputs, are you genuinely checking them or are you reading them the way you read something you already expect to be right?
Do your clients know enough about how their data is handled when AI tools are involved? Do you know enough about the tools’ terms to answer your clients’ questions?
Where has AI genuinely improved your work this year, and where has it inadvertently lowered standards?
These questions don’t have tidy answers, and that’s the point. If any of them made you stop and think, or if you have a different take on what responsible AI use actually looks like in your practice, we’d love to hear about it in the comments.
👇 Steal My Toolkit
If you want the actionable version of this newsletter (templates you can copy, prompts you can run and frameworks you can reuse), it’s inside the paid tier.
Paid members get instant access to:
Value Proposition Workbook ($29 value): turn “I do X” into “people pay for Y”
Consulting with AI Series: the custom AI prompts I use daily as a management consultant
Course on Surveys, Interviews and Group Exercises ($199 value): the research techniques I refined in 10+ years of consulting experience
Practical Guides + Templates Library: all premium resources released in my paid posts, including templates, playbooks and AI prompts
Cozora discount (up to $360 off full price): up to 50% off a Cozora subscription to learn AI fast from creators who use it daily
Free subscribers get perks, too:
Leader Tools Cards: 10% off with code ANDREA10 via https://leadertools.co/ANDREA10
Cozora welcome discount: 10% off with code WELCOME10 via https://www.cozora.org/a/2148167109/ovrPtvuC
Heads-up: I earn a fee if you purchase through my referral links, at no extra cost to you.







“People who treat responsibility, accountability, auditability and transparency as ongoing professional obligations rather than a compliance exercise to be completed and filed are the ones most likely to be considered trusted partners.”
100% this is a fantastic point. for me i would be so much more comfortable with this attitude from my partner.
This is a timely and necessary piece – not because “AI wrote it” is new, but because “you signed it” is the part people still treat as a formality. You frame the real shift correctly: authorship is turning into accountability, and responsibility doesn’t vanish just because production got easier.
I also appreciate how you avoid the lazy binary (“ban it” vs “embrace it”) and push the practical question: what does a signature actually certify in an AI-assisted workflow – intent, accuracy, originality, or just publication? Once AI becomes an invisible layer, the easiest failure mode is moral outsourcing: “the model did it,” therefore nobody did. That’s why governance has to evolve around process (review, traceability, disclosure norms), not tool policing.