By Sagar Shankaran, Founder of CallSphere
EU AI Act August 2, TRAIGA and SB 53 in plain terms for a 22-person consulting firm: the six documents to hold, and what is genuinely out of scope for you.
Key takeaways
Here is the objection, and it is a fair one. You do not build software. You build operating models, cost baselines, org charts, and 90-slide steering committee decks. Your firm is twenty-two people in Charlotte. The 2026 AI rules are for technology companies, and you have a busy fall.
Two engagements your firm delivered last quarter say otherwise, and one of them has a date attached: August 2, 2026.
The first is the reorg. A client asked you to redesign a shared services organization, and your team scored roughly 1,900 job descriptions against a new operating model to produce a role-mapping recommendation. Part of that scoring was done with an AI tool that read job descriptions and matched them to new role profiles. Your Engagement Manager reviewed the output, adjusted it, and handed the client a selection recommendation. The client's shared services center is in Dublin.
The second is quieter. Your Business Analysts ran 4,000 employee survey verbatims through an AI tool to produce theme rankings by department, and the deck that came out of it ranks managers by engagement score. It went to the client's Chief Human Resources Officer.
Neither of those is software development. Both of them touch decisions about individual people, and that is the line the 2026 statutes draw. For a US consulting firm, the new rules are mostly a documentation problem rather than a technology problem: you have to be able to say which tool touched which client data, who reviewed the output before it went into a decision, and what the affected people were told.
On January 1, 2026, the Texas Responsible Artificial Intelligence Governance Act and California SB 53 both took effect. Colorado, New York, Utah, Nevada, Maine, and Illinois each have their own AI statutes on the books, several of which reach employment-related decisions. Federal preemption of state rules remains unsettled as of this July, which means state law still binds you — you cannot wait for Washington to sort it out.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent in your browser — 60 seconds, no signup.
On August 2, 2026, the EU AI Act's high-risk and transparency obligations carry their compliance date. Those obligations reach US companies whose systems affect users in the EU, which is how a twenty-two-person firm in North Carolina ends up in scope through a Dublin shared services center. Systems already on the market before the Act applied may be grandfathered from some obligations, which is a real carve-out and also not something to lean on without counsel.
Treat everything in this column as a columnist's map. Your professional liability carrier and an employment lawyer who reads these statutes for a living are the people who tell you where your firm actually sits.
flowchart TD
A["New engagement scoped"] --> B{"Will an AI tool touch client data?"}
B -->|No| C["Standard statement of work, no AI exhibit"]
B -->|Yes| D{"Does the output feed a decision about a person?"}
D -->|No| E["Log the tool, note human review in QA checklist"]
D -->|Yes| F{"Are any affected people in the EU?"}
F -->|No| G["State-law disclosure and human review documented"]
F -->|Yes| H["Counsel review before kickoff, client signs off"]
This matters as much as the obligations, because firms waste real money over-complying out of fear. California SB 53's obligations are aimed at frontier model developers — organizations training the very largest models, measured against compute and revenue thresholds you are nowhere near. You are a customer of those models, not a developer of them. You do not owe anyone a safety report on Claude or Gemini, and you are not required to audit the vendors.
Using ChatGPT Work to build a store-level margin analysis, or Claude Cowork to turn interview notes into a first-draft findings pack, is not a high-risk system. Neither is a demand forecast, a network optimization model, a procurement spend cube, or a facility layout study. The risk concentrates in a narrow band: hiring and selection, performance and promotion, pay, credit, insurance, education, essential public services, and anything law-enforcement adjacent. If your practice is supply chain and cost reduction, most of your work sits outside the band — but your HR practice does not, and neither does the reorg.
None of these takes a week. All of them get asked for.
Add a seventh, informally: a training record. Roughly seven in ten owners say their people need more training on this, and a half-day session with a signed attendance sheet is both genuinely useful and the cheapest evidence you will ever produce.
Most small firms will never see a regulator. What they will see is a client's third-party risk team sending a 41-question AI addendum two weeks before kickoff. Here is what that costs when you have to answer it from scratch. Assumptions: a $180,000, twelve-week engagement; 2.5 consultants already staffed at a loaded cost of $6,500 per consultant-week; kickoff slips three weeks while the questionnaire goes back and forth.
Still reading? Stop comparing — try CallSphere live.
CallSphere ships complete AI voice agents per industry — 14 tools for healthcare, 10 agents for real estate, 4 specialists for salons. See how it actually handles a call before you book a demo.
| Item | Unprepared | Folder ready |
| Weeks kickoff slips | 3 | 0 |
| Idle staffed cost (2.5 consultants x 3 weeks x $6,500) | $48,750 | $0 |
| Partner and Controller hours answering the questionnaire | 22 hrs / $4,600 | 3 hrs / $600 |
| First milestone invoice | Slips a quarter | On schedule |
| One-time cost to build the folder (16 hrs) | - | $3,400 |
The folder pays for itself on the first questionnaire and then answers the next twenty. That is the whole business case; there is no need to dress it up as risk management.
Four situations. Any engagement where your deliverable selects, ranks, or scores individual people. Any client with EU staff, especially where a works council is involved, because the consultation happens before the work, not after. Anything you package and resell as a tool rather than deliver as advice, because that is where you risk stepping from adviser into provider. And the indemnity language in your master services agreement — do not accept open-ended indemnity for a client's later use of a model you helped build, and check whether your errors and omissions policy has picked up an AI exclusion at renewal.
One more, practical: do not sign a client addendum promising no AI was used in the delivery of services if your Analysts are running interview recordings through a transcription tool. Somebody will eventually ask, and the answer needs to be the same as what you signed.
Disclose it anyway, in one sentence in the statement of work. It costs nothing, it is almost never refused, and it removes the worst outcome — a client discovering it midway through and reopening the whole contract. Firms that disclose early find the conversation takes four minutes.
Possibly, and it depends on whether your work produces an outcome affecting those EU workers. A cost model that never touches an individual is a different situation from a role-selection recommendation covering the Polish site. Sort the engagement into one of those two categories, then take the second category to counsel.
No. Those obligations are aimed at organizations training frontier models at a scale measured in compute and revenue thresholds. You are a customer. Your obligations come from how you use the output, particularly in employment-related work, not from the fact that you subscribed.
Inventory them, decide a retention period, write it down, and delete on schedule. An old shared drive full of employee interview recordings from a 2024 restructuring engagement is the single most awkward thing a client security review can find, and it takes an afternoon to fix.
If your own phone line or web chat is answered by an AI agent, that is a transparency obligation you own directly, not one you inherit from a client. CallSphere builds AI voice and chat agents that answer business lines and web chat, book appointments, and capture leads around the clock — and they identify themselves as AI and log the transcript, which is exactly the record you want in the folder when the next questionnaire arrives.

Written by
Sagar Shankaran· Founder, CallSphere
LinkedInSagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
How a buyer's AI assistant screens consulting firms in 2026, why gated PDFs make you invisible, and the nine facts to publish in plain text this month.
The EU AI Act's August 2 date, Texas TRAIGA and California SB 53 all landed. What a US rehab clinic must document, disclose and log, and what it can skip.
Driver screening tools and cab-facing cameras put carriers under Illinois, Texas and NYC rules in 2026. What to document, and what is genuinely out of scope.
Why consulting firms stop routing plant-floor interviews through a bilingual supervisor, what live speech translation changes, and what it saves.
Two casino systems land in the EU AI Act high-risk bucket: face matching and marker scoring. What US gaming operators document, disclose and can ignore.
A consulting firm's main line gets eleven calls a week and two of them matter. What a 200-millisecond voice agent changes about the referral you lost.
© 2026 CallSphere Inc. All rights reserved.
Made within San Francisco
Watch how CallSphere handles real customer calls, schedules appointments, and processes payments — live.
Try Live DemoBook a DemoCalculate Your ROI