---
title: "August 2 Reaches the Role-Selection Scorecard You Built for a Client's Reorg — Even at 22 People in Charlotte"
description: "EU AI Act August 2, TRAIGA and SB 53 in plain terms for a 22-person consulting firm: the six documents to hold, and what is genuinely out of scope for you."
canonical: https://callsphere.ai/blog/august-2-reaches-the-role-selection-scorecard-you-built-for-a-client-s
category: "Business & Strategy"
tags: ["management consulting", "eu ai act", "texas traiga", "california sb 53", "client security review", "ai governance"]
author: "CallSphere Team"
published: 2026-06-17T13:06:54.000Z
updated: 2026-07-25T23:21:41.563Z
---

# August 2 Reaches the Role-Selection Scorecard You Built for a Client's Reorg — Even at 22 People in Charlotte

> EU AI Act August 2, TRAIGA and SB 53 in plain terms for a 22-person consulting firm: the six documents to hold, and what is genuinely out of scope for you.

Here is the objection, and it is a fair one. You do not build software. You build operating models, cost baselines, org charts, and 90-slide steering committee decks. Your firm is twenty-two people in Charlotte. The 2026 AI rules are for technology companies, and you have a busy fall.

Two engagements your firm delivered last quarter say otherwise, and one of them has a date attached: August 2, 2026.

## The two projects that break the objection

The first is the reorg. A client asked you to redesign a shared services organization, and your team scored roughly 1,900 job descriptions against a new operating model to produce a role-mapping recommendation. Part of that scoring was done with an AI tool that read job descriptions and matched them to new role profiles. Your Engagement Manager reviewed the output, adjusted it, and handed the client a selection recommendation. The client's shared services center is in Dublin.

The second is quieter. Your Business Analysts ran 4,000 employee survey verbatims through an AI tool to produce theme rankings by department, and the deck that came out of it ranks managers by engagement score. It went to the client's Chief Human Resources Officer.

Neither of those is software development. Both of them touch decisions about individual people, and that is the line the 2026 statutes draw. **For a US consulting firm, the new rules are mostly a documentation problem rather than a technology problem: you have to be able to say which tool touched which client data, who reviewed the output before it went into a decision, and what the affected people were told.**

## What took effect, in calendar order

On January 1, 2026, the Texas Responsible Artificial Intelligence Governance Act and California SB 53 both took effect. Colorado, New York, Utah, Nevada, Maine, and Illinois each have their own AI statutes on the books, several of which reach employment-related decisions. Federal preemption of state rules remains unsettled as of this July, which means state law still binds you — you cannot wait for Washington to sort it out.

On August 2, 2026, the EU AI Act's high-risk and transparency obligations carry their compliance date. Those obligations reach US companies whose systems affect users in the EU, which is how a twenty-two-person firm in North Carolina ends up in scope through a Dublin shared services center. Systems already on the market before the Act applied may be grandfathered from some obligations, which is a real carve-out and also not something to lean on without counsel.

Treat everything in this column as a columnist's map. Your professional liability carrier and an employment lawyer who reads these statutes for a living are the people who tell you where your firm actually sits.

```mermaid
flowchart TD
  A["New engagement scoped"] --> B{"Will an AI tool touch client data?"}
  B -->|No| C["Standard statement of work, no AI exhibit"]
  B -->|Yes| D{"Does the output feed a decision about a person?"}
  D -->|No| E["Log the tool, note human review in QA checklist"]
  D -->|Yes| F{"Are any affected people in the EU?"}
  F -->|No| G["State-law disclosure and human review documented"]
  F -->|Yes| H["Counsel review before kickoff, client signs off"]
```

## What is genuinely out of scope for a twenty-two-person firm

This matters as much as the obligations, because firms waste real money over-complying out of fear. California SB 53's obligations are aimed at frontier model developers — organizations training the very largest models, measured against compute and revenue thresholds you are nowhere near. You are a customer of those models, not a developer of them. You do not owe anyone a safety report on Claude or Gemini, and you are not required to audit the vendors.

Using ChatGPT Work to build a store-level margin analysis, or Claude Cowork to turn interview notes into a first-draft findings pack, is not a high-risk system. Neither is a demand forecast, a network optimization model, a procurement spend cube, or a facility layout study. The risk concentrates in a narrow band: hiring and selection, performance and promotion, pay, credit, insurance, education, essential public services, and anything law-enforcement adjacent. If your practice is supply chain and cost reduction, most of your work sits outside the band — but your HR practice does not, and neither does the reorg.

## Six documents to have in the folder before the next client security review

None of these takes a week. All of them get asked for.

- **A tool register.** One page: which AI tools your firm uses, which vendor, who holds licenses, and what class of data each is approved for. Include the transcription tools your Analysts already use for interview notes, because they are the ones nobody remembers to list.
- **A client-data rule.** Which tools may touch client-confidential material, and confirmation that your account settings keep client content out of model training. The Claude enterprise governance update from July 2, 2026 added spend and usage controls, model defaults, and entitlements at the organization level — those settings are evidence of control, so keep a screenshot with the register.
- **An engagement-level AI exhibit** for the statement of work: plain sentences saying what AI assistance will be used for, what it will not be used for, and that a named human reviews output before delivery.
- **A human review sign-off.** Add one line to your quality assurance checklist: the Engagement Manager initials and dates any AI-assisted analysis before it goes to the client. This single line answers more questionnaire items than anything else on this list.
- **Subject notice language** for interviews and surveys, approved by the client's HR lead, covering recording, transcription, and analysis.
- **Retention and deletion terms** matched to your master services agreement, including where transcripts and working files live and when they are destroyed.

Add a seventh, informally: a training record. Roughly seven in ten owners say their people need more training on this, and a half-day session with a signed attendance sheet is both genuinely useful and the cheapest evidence you will ever produce.

## The arithmetic is about cash timing, not fines

Most small firms will never see a regulator. What they will see is a client's third-party risk team sending a 41-question AI addendum two weeks before kickoff. Here is what that costs when you have to answer it from scratch. Assumptions: a $180,000, twelve-week engagement; 2.5 consultants already staffed at a loaded cost of $6,500 per consultant-week; kickoff slips three weeks while the questionnaire goes back and forth.

| **Item** | **Unprepared** | **Folder ready** |
| --- | --- | --- |
| Weeks kickoff slips | 3 | 0 |
| Idle staffed cost (2.5 consultants x 3 weeks x $6,500) | $48,750 | $0 |
| Partner and Controller hours answering the questionnaire | 22 hrs / $4,600 | 3 hrs / $600 |
| First milestone invoice | Slips a quarter | On schedule |
| One-time cost to build the folder (16 hrs) | - | $3,400 |

The folder pays for itself on the first questionnaire and then answers the next twenty. That is the whole business case; there is no need to dress it up as risk management.

## Where a lawyer, not a checklist, is the answer

Four situations. Any engagement where your deliverable selects, ranks, or scores individual people. Any client with EU staff, especially where a works council is involved, because the consultation happens before the work, not after. Anything you package and resell as a tool rather than deliver as advice, because that is where you risk stepping from adviser into provider. And the indemnity language in your master services agreement — do not accept open-ended indemnity for a client's later use of a model you helped build, and check whether your errors and omissions policy has picked up an AI exclusion at renewal.

One more, practical: do not sign a client addendum promising no AI was used in the delivery of services if your Analysts are running interview recordings through a transcription tool. Somebody will eventually ask, and the answer needs to be the same as what you signed.

## Frequently asked questions

### We only use AI for first drafts. Do we still have to tell the client?

Disclose it anyway, in one sentence in the statement of work. It costs nothing, it is almost never refused, and it removes the worst outcome — a client discovering it midway through and reopening the whole contract. Firms that disclose early find the conversation takes four minutes.

### Our client is a US company with a plant in Poland. Are we in scope for August 2?

Possibly, and it depends on whether your work produces an outcome affecting those EU workers. A cost model that never touches an individual is a different situation from a role-selection recommendation covering the Polish site. Sort the engagement into one of those two categories, then take the second category to counsel.

### Does using ChatGPT Work or Claude Cowork make us a developer under SB 53?

No. Those obligations are aimed at organizations training frontier models at a scale measured in compute and revenue thresholds. You are a customer. Your obligations come from how you use the output, particularly in employment-related work, not from the fact that you subscribed.

### What do we do about the interview recordings we already have?

Inventory them, decide a retention period, write it down, and delete on schedule. An old shared drive full of employee interview recordings from a 2024 restructuring engagement is the single most awkward thing a client security review can find, and it takes an afternoon to fix.

## One disclosure most firms forget

If your own phone line or web chat is answered by an AI agent, that is a transparency obligation you own directly, not one you inherit from a client. [CallSphere](https://callsphere.ai) builds AI voice and chat agents that answer business lines and web chat, book appointments, and capture leads around the clock — and they identify themselves as AI and log the transcript, which is exactly the record you want in the folder when the next questionnaire arrives.

---

Source: https://callsphere.ai/blog/august-2-reaches-the-role-selection-scorecard-you-built-for-a-client-s
