AI-native playbook · Consulting and advisory

How to make a consulting firm AI-native: a playbook

A consulting firm becomes AI-native when agents draft the proposals, research and back-office work, partners still sign every price, claim and deliverable that carries the firm's name, and the firm stops pricing by the hours AI removes. This playbook sets out the stages to get there, from the firm's own unbilled work to client deliverables, with a source for every figure.

Last reviewed
October 2026
Written for
Managing partners, COOs and practice leads at firms of 50 to 2,000 people
Reading time
About 30 minutes
On this page
01

Two problems at once: what you sign and how you charge

In October 2025, an A$440,000 report Deloitte wrote for Australia's Department of Employment and Workplace Relations was found to cite academic sources that do not exist and to carry a made-up quote from a federal court judgment. Deloitte issued a revised report and agreed a partial refund[37]. A month later, a CA$1.6 million, 526-page health workforce plan Deloitte wrote for Newfoundland and Labrador turned out to cite at least four research papers that cannot be found. Two of the researchers it named said the papers attributed to them do not exist[36].

That is the first problem: what the firm signs. When an agent drafts the research, every claim and citation still goes out under the firm's name.

The second problem is in Accenture's annual report. It warns that unless new work makes up for it, AI-driven automation "will lead to reduced demand for our services and/or adversely affect the utilization rate of our professionals", and that results suffer "if our clients do not accept new pricing or commercial models that reflect the value of these AI-enabled solutions"[4]. That is how the firm charges. In most sectors AI cuts cost. In a firm that bills by the hour, it also cuts revenue on the same work.

An AI-native firm handles both. Agents draft; partners sign every price, claim and deliverable, behind a reference check no deliverable can skip; and repeatable work moves off hourly pricing.

02

AI-enabled vs AI-native

An AI-enabled firm gives its people AI tools. An AI-native firm redesigns the engagement so agents do defined steps, under the firm's rules and the client's terms, and people decide what carries the firm's name.

Who uses AI
AI-enabled firm
Individuals, in their own tools, some of them unapproved[25]
AI-native firm
Agents run defined steps of the engagement, under firm rules, for a named person
Proposals
AI-enabled firm
A consultant pastes the RFP into a chatbot
AI-native firm
An agent drafts the bid/no-bid brief, the proposal and the price from the rate card; a partner approves price and scope
Deliverables
AI-enabled firm
Drafts arrive faster; review is unchanged
AI-native firm
Every citation is resolved to a stored source before partner review, and the deliverable cannot skip that step
Client data
AI-enabled firm
Whatever the user can open
AI-native firm
One engagement at a time, and only models the client's contract allows for that data
Pricing
AI-enabled firm
Hourly, so every saved hour is lost revenue
AI-native firm
Priced by deliverable, outcome or managed service; hours become a cost measure
Back office
AI-enabled firm
Manual time entry, project setup and invoicing
AI-native firm
Agents draft time narratives, set up projects from signed SOWs and chase invoices; people approve
Evidence
AI-enabled firm
File history, if anyone looks
AI-native firm
A tamper-evident record of what each agent did, for whom, on which engagement

Most firms are on the left. No survey covers consultants directly. In a vendor survey of the neighboring professions (legal, tax, accounting and risk), 34% said they use AI tools their employer has not approved, and while 78% of corporate clients said AI-enabled quality is essential from their providers, 6% said providers deliver it[25]. Assume your Stage 0 inventory will find tools nobody approved.

03

The missing layer: who the agent works for, on which engagement

Firms will not replace their PSA, CRM or document store to become AI-native. The agents are arriving inside them. Certinia lists agents for RFP responses, estimation, SOW drafting, resourcing, shortlisting, work reallocation and project management[27]. Kantata's agent does skills matching and forecasting[28]. Copilot searches every file a user can view[26].

Each tool can govern its own agent. None answers the questions across all of them: which engagement is this agent on, whose authority is it using, did the client allow this model to see this data, and who approved what went out.

OrchKernel is built to be that layer. Agents ask it before they act. It checks the request against the firm's rules, holds it for a named person when needed, runs it with credentials the agent never sees, and writes it to a tamper-evident log. What it is not: it is not a PSA, a conflicts system or a document store. The PSA stays the system of record for projects, time and billing, and the conflicts system still decides who is conflicted. The detail is in the OrchKernel blueprint.

04

Where the hours and margin go

CRA International puts the model in one sentence: "Our revenues and profitability are largely based on the bill rates charged to our clients, compensation costs and the utilization of our consultants"[6]. Even fixed fees are usually priced as hours by role times the rate card, so margin depends on whether actual hours stay under the estimate.

The public numbers are thin, because the large strategy firms are private. What filings show: FTI Consulting billed an average of $529 an hour in Corporate Finance, $442 in Forensic and Litigation Consulting and $583 in Economic Consulting in 2025[5]. Gross margin, revenue less direct cost, was 32.1% at FTI in 2025 and 32.0% at Accenture in the fourth quarter of fiscal 2026. Operating margin was 10.3% at FTI, 10.5% at Huron and 11.1% at CRA, against 15.4% at Accenture[3,8].

A consultant's available year

Utilization, billed hours over available hours, is where AI first changes the economics. The firms that report it billed between 57% and 78% of available consultant hours in 2025:

Billed to a clientAvailable but not billed
  • Huron, Digital[7]78.2% billed · 21.8% not
  • CRA International, All consultants[6]77% billed · 23% not
  • Huron, Consulting[7]75.7% billed · 24.3% not
  • FTI Consulting, Corporate Finance[5]60% billed · 40% not
  • FTI Consulting, Economic Consulting[5]59% billed · 41% not
  • FTI Consulting, Forensic and Litigation[5]57% billed · 43% not
Utilization for 2025 as each firm defines it. FTI counts standard hours adjusted for holidays and part-time staff; CRA counts hours available. Compare your firm with itself over time, not with these bars. How the unbilled hours divide between proposals, admin, training and bench time is not published.

The unbilled 22% to 43% is business development, proposals, bench time, training and admin. It is the firm's own cost, so an agent that shortens it adds margin without touching revenue. That is why the staged path starts there.

Where the rest leaks

Proposals and RFPs
What is lost
Bid teams rebuild answers, qualifications and pricing for each bid
Evidence
UK buyers are told to plan for more bids and more clarification questions as suppliers use AI[9]
Time capture
What is lost
Late or thin time entries leak billable hours and hold up invoices
Evidence
Vendor claims of up to 30 minutes a day recovered and a 4% to 11% profit increase[29]
Bench and ramp-up
What is lost
Utilization drops when large engagements end or new hires ramp
Evidence
Named as risk factors in the CRA and Huron 10-Ks[6,7]
Scope creep on fixed fees
What is lost
Work outside the SOW done without a change order
Evidence
FTI warns that under alternative fee arrangements "the costs of providing services … may exceed the fees collected"[5]. No public loss rate
Cash collection
What is lost
Time between work done and cash received
Evidence
Accenture's days services outstanding: 50 in fiscal 2026, up from 47[3]

The pricing paradox

The same agent that saves an unbilled hour on a proposal removes a billed hour on a deliverable. Under time-and-materials billing that hour is revenue the firm no longer earns. The margin case works only if the firm moves pricing off hours, fills the freed hours with more billable work, or both. Accenture names new "pricing or commercial models" as the condition for AI to help rather than hurt[4]. Pricing when the hours shrink covers what that means for a mid-sized firm.

What the market is doing

Advisory is still growing. US employment in management, scientific and technical consulting was 1,888,100 in September 2026, up 1.5% on a year earlier, while computer systems design fell 1.3%[1]. The BLS projects 10% growth in management analyst jobs from 2025 to 2035, and 14% of the 1,077,100 analysts were self-employed[2].

At one public firm, revenue and headcount have already moved apart. FTI's billable headcount fell 3.2% in 2025, from 6,633 to 6,421, while revenue rose 2.4% to $3.79 billion[5,8]. Federal-heavy consultancies shrank for a different reason, government buying: Booz Allen's revenue fell 6.4% in its year to March 2026 and ICF's 7.3% in 2025[8].

05

What AI already does in consulting

We list categories, with vendors named in their own sources as examples, not recommendations. Their performance figures are their own.

Bids and proposals
What the tools do
Proposal tools draft answers from past bids and a content library. Certinia lists an RFP Responder agent to "Qualify deals, build proposals & SOWs"[27,30,31].
Evidence and caveats
Responsive claims answers "80% faster"; AutogenAI claims a "241% increase in success rates" with no method given (vendor claims)[30,31].
Estimates and SOWs
What the tools do
PSA agents for estimation and SOW drafting, and a sales-to-delivery handoff agent[27].
Evidence and caveats
Drafts that commit the firm to a price and scope. A partner signs.
Staffing
What the tools do
Skills matching, shortlisting and work reallocation agents. Kantata says its Expertise Agent can "act on that knowledge… to move work forward autonomously"[27,28].
Evidence and caveats
For EU staff, AI that allocates work or evaluates people is high-risk[15].
Research and drafting
What the tools do
Office assistants draft in Word and PowerPoint and search mail, chats and files, limited to what the user can view[26]. Some firms sell their own AI tools: FTI markets IQ.AI for review, investigations and antitrust work[5].
Evidence and caveats
Over-shared engagement sites become over-shared answers.
Time capture
What the tools do
Tools that capture work from calendars and documents and draft time narratives[29].
Evidence and caveats
Named customers are mostly law and accounting firms.

How much it is used

No independent survey of AI use inside consulting firms exists that we could find. Across the US workforce, 23% of employed adults had used generative AI for work in the previous week and 9% every workday, and time savings came to about 1.4% of all work hours[24]. The large firms report far more, with AI teams of hundreds behind them. BCG expected work on AI to supply 20% of its revenue in 2024 and 40% by 2026[42]. PwC became the largest customer of ChatGPT Enterprise in May 2024[40]. Accenture bought the UK AI firm Faculty in January 2026, at a reported $1 billion valuation[41], and IBM bought the data consultancy Hakkoda in April 2025[35]. None of that is a benchmark for a 200-person firm with no AI team.

Where the money went

Capital is going to two models. The first buys traditional firms and runs them with AI. Thrive Holdings raised $2 billion at a $12 billion valuation in August 2026 to do this; it owns more than 50 accounting firms with over 2,000 professionals and about 20 IT firms, and says a tax agent handled "over 7,000 returns at 98% accuracy" (company claim, reported by the press)[33]. OpenAI took a stake in December 2025 and embeds its staff in the portfolio companies[34].

The second builds engineering-heavy firms that deliver working systems rather than reports. Distyl describes itself as an AI-native operations consulting and deployment firm with "50+ Fortune 500 enterprise deployments" (vendor claim)[32]. Both sell outcomes more than hours. Neither is proven at the scale of a large consultancy yet.

06

The staged path

Six stages, in the order of the engagement and of the risk. The firm's own unbilled work comes first, because nothing reaches a client without a person and the savings are margin. Client deliverables follow, behind a reference check. Pricing changes alongside, before delivery savings leak. Agents that act across the firm's systems come last. Practices can sit at different stages: a litigation practice may keep Stage 2 tight long after the operations practice moves on.

  1. 0

    Stage 0: Foundations

    Get engagements, permissions and client AI terms on the record.

    About 1 to 2 months

    What to do

    • Get every active engagement into the PSA with its signed SOW, budget by phase, rate card and staffed team.
    • Limit each engagement site in SharePoint, Drive or Teams to the staffed team before any assistant can search across them.
    • List the AI already in use: approved tools, the agents your PSA vendor has switched on, and what people use without approval.
    • Record each client's AI terms from its MSA, DPA or tender: which models, which data, whether to disclose.
    • Write a one-page AI policy: tools, data classes, disclosure, reference checks, billing.
    • Decide what counts as "cleared for reuse" in past work, and who marks it.

    Why now

    Office assistants show people whatever they can already open. Microsoft says Copilot "only surfaces organizational data to which individual users have at least view permissions"[26]. An over-shared site from a past deal becomes an answer in someone else's chat.

    In place first

    • Nothing. Every firm starts here, even if Copilot is already on.

    What to measure

    • Share of active engagements with SOW, budget and team in the PSA
    • Share of engagement sites limited to the staffed team
    • Share of active clients with their AI terms recorded

    Common mistakes

    • Switching on firm-wide search before cleaning permissions.
    • Treating "the vendor does not train on our data" as the whole answer to what the client allowed.
  2. 1

    Stage 1: Win and run the firm

    Agents draft the firm's own unbilled work; people approve everything that leaves.

    Starts once Stage 0 permissions are clean for the practices in scope

    What to do

    • Bid/no-bid briefs from the RFP, the client's history in the CRM and the firm's capacity.
    • Proposal and SOW drafts from the rate card and past SOWs; qualifications from work cleared for reuse.
    • Time-entry drafts from calendars and documents, for each consultant to approve.
    • RAID log items from meeting notes; weekly status drafts.

    Why now

    This is the unbilled share of the consultant's year shown in the utilization chart above[5,6,7]. Hours saved here add margin without cutting billed revenue.

    In place first

    • Stage 0 permissions for the practices involved.
    • The rate card, discount limits and margin floor written down.

    What to measure

    • Hours per proposal, against your own baseline. Proposal vendors claim answers "80% faster" and a "70% increase in drafting speed" (vendor claims, no method given)[30,31]
    • Bids submitted per quarter, and win rate against your own history. There is no public win-rate benchmark
    • Time-entry lag

    Common mistakes

    • Spending the saved time on more weak bids. UK buyers are told to expect "an increase in clarification questions and tender responses" and to check AI-written bids harder[9].
    • Letting an agent quote a price to a client, even an indicative one.
  3. 2

    Stage 2: Delivery with verification

    First stage in client deliverables

    Agents draft client work; a reference check and partner release hold every deliverable.

    After Stage 1 shows drafts people keep, practice by practice

    What to do

    • Research synthesis, first-draft analyses, slides, data cleaning, and checks that summary, tables and appendix agree.
    • A reference check step that no deliverable can skip: every citation resolved to a stored source, with a named checker.

    Why now

    The best-known consulting AI failures so far were invented sources in two Deloitte government reports in 2025[36,37]. The same field experiment that found big gains for BCG consultants also found them doing worse on a task outside the model's ability[23].

    In place first

    • The reference check as a workflow state: a deliverable cannot move to "ready for partner" until it is done.
    • A task map: which kinds of analysis the practice hands to AI and which it keeps away from it.
    • Model clearance per client and data class. Under GDPR a model provider handling client personal data is a sub-processor that needs the client's written authorization[11].
    • Disclosure wording ready for clients and tenders that ask.

    What to measure

    • Reference defects caught before release, and after release (target: none after)
    • Rework rounds and hours per deliverable against the estimate. No public benchmark exists for these

    Common mistakes

    • Reviewing faster because the draft looks finished.
    • Letting analysts stop learning how an analysis is built.
  4. 3

    Stage 3: Price the work, not the hours

    Move repeatable work off hourly billing before Stage 2 savings leak to the client.

    Alongside Stage 2, starting with one repeatable offer

    What to do

    • Move repeatable work to fixed-fee, per-deliverable or subscription pricing.
    • Track estimate at completion weekly on fixed-fee engagements.
    • A scope agent flags out-of-scope requests and drafts change orders for the partner.

    Why now

    Once Stage 2 cuts hours, hourly billing hands the gain to the client. Accenture's own 10-K says results suffer "if our clients do not accept new pricing or commercial models that reflect the value of these AI-enabled solutions"[4].

    In place first

    • Stage 2 data on actual hours per deliverable.
    • A written firm policy on billing AI-assisted work, which the time agent applies.

    What to measure

    • Share of revenue not billed by the hour
    • Realization and write-offs by pricing model
    • Fixed-fee margin variance; change orders raised against absorbed

    Common mistakes

    • Cutting rates without changing the model, which gives the saving away twice.
    • Hiding AI efficiency inside hourly bills (Scenario E below).
  5. 4

    Stage 4: Agents across the firm's systems

    Agents set up projects, request staff, draft invoices and chase payment, each for a named person.

    After the log and approvals have held through Stages 1 to 3

    What to do

    • Project setup in the PSA from a signed SOW: phases, budget, rate card, team.
    • Resource shortlists, invoice drafts, collections reminders and expense checks.
    • Each agent acts for a named person (project manager, resource manager, billing lead) with no more access than that person has.

    Why now

    This is where cash moves. Accenture's days services outstanding rose from 47 to 50 in fiscal 2026[3].

    In place first

    • Approvals on anything that commits money or reaches a client.
    • A tamper-evident log of every agent action.
    • A review of staffing agents for EU staff: allocating work or evaluating people with AI is a high-risk use under the EU AI Act[15].

    What to measure

    • Days from signature to staffed kickoff
    • Invoice error rate and days sales outstanding

    Common mistakes

    • Letting a staffing agent decide rather than propose.
    • Running agents on a service account with wider access than any person in the firm.
  6. 5

    Stage 5: The AI-native firm

    Team shape, offers and pricing change to match.

    Ongoing

    What to do

    • Smaller, more senior teams, with agents doing the first draft of most work.
    • Productized methods and managed services where work repeats; client-facing agents where clients want them, disclosed.
    • An engagement AI lead on every team; a yearly review of models, sub-processors and client terms.

    Why now

    In fiscal 2026 Accenture's managed services revenue ($37.30 billion, up 6% in local currency) overtook its consulting revenue ($36.88 billion, up 3%)[3].

    In place first

    • Stages 2 to 4 running in most practices, with the log as the record.

    What to measure

    • Revenue and gross margin per professional
    • Share of revenue from fixed-fee, outcome-based and managed services

    Common mistakes

    • Cutting the analyst intake with no plan for where the next managers come from.
07

Your first 90 days

Stage 0, two Stage 1 workflows on real work, then the reference check in one practice. We suggest proposal drafts and weekly status reports: both go after unbilled hours, neither reaches a client without a person, and both give numbers you can compare within the quarter.

  1. Days 1 to 30

    Name a partner, not IT alone, as owner of AI use. List the tools in use, including unapproved ones and the agents your PSA vendor has switched on. Lock down engagement sites, starting with active engagements in the practices going first. Record the AI terms of your 20 largest clients. Publish a one-page policy: approved tools, data classes, reference checks, disclosure and billing for AI-assisted work. Record the baseline: hours per proposal, time-entry lag, status reports on time.

  2. Days 31 to 60

    Run two Stage 1 workflows on live work: proposal drafts from your rate card and past SOWs, and weekly status drafts from the PSA and the RAID log. A named person approves every output, and the log shows who. Note how much people edit each draft.

  3. Days 61 to 90

    Add the reference check to one practice's deliverables, with a named checker. Let a scope agent draft change orders on two fixed-fee engagements, for the partner to send or drop. Pick one repeatable offer to price per deliverable next quarter, and start recording actual hours on it now. Report to the partners: hours saved, reference defects caught, change orders raised, and what clients said.

At day 90, ask two questions. Have people stopped rewriting the drafts? Could you show a client who checked the sources of any deliverable, and who released it?

08

Pricing when the hours shrink

Pricing decides whether AI adds margin or only cuts revenue, and it is a partner decision. The arithmetic shows why the order of the stages matters.

Ways to price the work

Fixed fee per deliverable. Works for repeatable work with a clear output: a market scan, a diligence module, a benchmarking pack. It needs your own data on actual hours, which Stage 2 produces, and a scope agent watching for work outside the SOW, because the overrun is now yours, as FTI's 10-K warns[5].

Subscription or managed service. Recurring work, such as monthly reporting, ongoing pricing analytics or a run-the-process service, sold as a running service. Managed services overtook consulting at Accenture in fiscal 2026, $37.30 billion against $36.88 billion[3].

Outcome-based fees. Paid on a measured result, for firms with the data to price the risk. We found no public figure for how common they are.

Hourly, honestly. Some work stays hourly: testimony, open-ended advice, early-stage strategy. Bill the time actually worked, and say how AI was used if the client asks. Writing eight hours of narrative for twenty minutes of agent output is Scenario E in when it goes wrong, and it is what a client's invoice audit looks for.

09

One engagement, RFP to invoice

The path at Stage 4. Agents read, draft and check; people decide anything that commits the firm, reaches the client or affects a colleague's career.

Agent works, nothing leavesA named person decides
  1. 01
    RFP or referral arrives

    Agent reads the RFP, checks it for hidden instructions, drafts a bid/no-bid brief

  2. 02
    Accept the engagement

    Conflicts and risk review clear it before any agent touches the work

    Control point 1

  3. 03
    Proposal and price

    Agent drafts scope, team and price from the rate card; a partner sets the price

    Control point 5

  4. 04
    SOW signed

    Partner signs; the client's AI terms are recorded for this engagement

    Control point 3

  5. 05
    Staffing

    Agent proposes a shortlist; the resource manager decides

    Control point 14

  6. 06
    Delivery drafts

    Research, analysis and slides, inside this engagement's boundary only

    Control point 2

  7. 07
    Reference check

    A named checker resolves every source before partner review

    Control point 7

  8. 08
    Partner release

    The partner approves the exact version that goes to the client

    Control point 8

  9. 09
    Change orders

    Agent spots out-of-scope work and drafts the change order; the partner sends it or absorbs it

    Control point 9

  10. 10
    Time and invoice

    Agent drafts narratives and the invoice; consultants approve time, the billing lead the invoice

    Control point 10

The PSA stays the record of the engagement, the time and the invoice. The control layer holds the record of what each agent asked to do, for whom, and who approved it.
10

What not to fully automate

An agent can prepare each of these: gather the facts, draft the document, propose the answer. A named person makes the decision, and the log shows whose it was.

Accepting an engagement and clearing conflicts
Why it stays with a person
Conflicts and independence are the firm's liability, and a conflicts check needs facts about relationships that are not in any system. The PwC Australia tax leak in when it goes wrong shows what a broken wall costs, with no AI involved[40].
Price, discount and fee structure
Why it stays with a person
Profit rests on bill rates and utilization[6], and a price is a relationship call an agent cannot see.
Signing the SOW and approving change orders
Why it stays with a person
These are contract commitments, and scope disputes are where fixed fees lose money.
Releasing any deliverable to the client
Why it stays with a person
Both Deloitte reports reached their clients with invented sources[36,37]. In the EU, a person holding editorial responsibility also lifts the Article 50(4) disclosure duty[14].
Expert opinions and testimony
Why it stays with a person
The court holds the named expert responsible for every citation[38].
Staffing decisions and performance ratings
Why it stays with a person
They shape careers and pay, and for EU staff they are a high-risk AI use[15].
Sending client data to a new model or tool
Why it stays with a person
The model provider is a sub-processor the client must authorize[11], and the MSA may say more.
Reusing past client work or naming a client
Why it stays with a person
Confidentiality and reference permissions differ by client.
Invoices, write-offs and billing for AI-assisted work
Why it stays with a person
The client trusts that a billed hour was worked.
Telling a client something went wrong
Why it stays with a person
A relationship and liability decision the partner owns.
11

When it goes wrong

The failures that have cost consulting firms money and reputation so far were invented citations and broken walls. Each case names the control points that would have stopped it.

Real cases

  1. Deloitte: two government reports with invented sources (2025)

    The A$440,000 Australian report and the CA$1.6 million Newfoundland and Labrador plan described at the top of this page. In Australia, a revised report followed and Deloitte agreed a partial refund[36,37]. In both cases the errors came to light after the client had the report.

    Control: Reference check before partner review (7); partner release of the exact version (8); disclosure where the client asks (6).

  2. Kohls v. Ellison: an expert declaration rejected (Minnesota, January 2025)

    A Stanford expert paid $600 an hour filed a declaration with AI-fabricated citations. The court rejected it and said the error "shatters his credibility with this Court"[38]. Lawyers in Mata v. Avianca were sanctioned $5,000 in 2023 for six invented cases[39].

    Control: Reference check (7); every source verified by the testifying expert (13).

  3. EchoLeak: prompt injection in Microsoft 365 Copilot (June 2025)

    CVE-2025-32711: "AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network"[20]. No exploitation at a consulting firm is known, but consultants open hostile documents every week: data rooms, RFPs, client files.

    Control: One engagement at a time (2); limits on what an agent may send out of the firm (4).

  4. PwC Australia: confidential tax plans leaked (2023, not AI)

    A partner shared confidential government tax plans. Eight partners were removed and the government consulting arm was sold for $1 and renamed Scyne Advisory[40]. An agent reading across engagements could repeat it at machine speed.

    Control: Engagement acceptance (1); one engagement at a time (2); information barriers (12).

  5. The BCG experiment: worse answers on the wrong task (2023)

    In a field experiment with 758 BCG consultants, those using GPT-4 on tasks inside its ability completed 12.2% more tasks, 25.1% faster, at 40% higher quality. On a task designed to sit outside its ability, consultants without AI were right 84% of the time; with AI, roughly 60% to 70%[23].

    Control: The task map in Stage 2: decide where AI is not used.

Agent failures to design against (scenarios)

These are scenarios, not reported events. Each is something an agent with too much reach could do in a consulting firm, and each maps to one of the control points.

A. The invented source. A research agent cites a trade association study that does not exist. A busy manager sends the slide to the client.
What stops it
Control 7. The deliverable cannot move to "ready for partner" until every reference resolves to a stored source, and the log records who checked it.
B. The other client's name. A proposal agent reuses last year's deck for the prospect's competitor. Two charts keep the old client's figures.
What stops it
Control 11. Only work cleared for reuse can be retrieved, and drafts are scanned for other client names.
C. Across the wall. A partner staffed on a buy-side diligence and on a project for the target's competitor asks an assistant, running on the partner's full access, for the project deck. Diligence findings end up in it.
What stops it
Controls 2 and 12. The agent works one engagement at a time, with only the access of the team staffed on that engagement.
D. The change order that went out. A scope agent emails the client a change order with a fee that the partner meant to absorb to protect an extension.
What stops it
Control 9. The agent drafts; the partner approves the exact email and fee, or drops it.
E. The hours that were not worked. A time agent bills eight hours of analysis for twenty minutes of agent work. The client audits the invoices.
What stops it
Control 10. Each person approves their own time, and the firm's policy on billing AI-assisted work is a rule the agent applies.
F. The quiet ranking. A resourcing agent keeps giving the best projects to the same people, and the rest stall.
What stops it
Control 14. The agent proposes, a resource manager decides, and the inputs are recorded. For EU staff this is a high-risk use.
G. The poisoned RFP. Hidden text in a tender tells AI tools to attach the firm's rate card and past bids.
What stops it
Controls 3 and 4. Outbound mail is checked against allowed recipients and data classes; restricted files cannot be attached.
12

Rules that reach consulting firms

Consulting is lightly regulated as a profession. Most obligations arrive through client contracts, through public buyers and the client's own regulators, and through general law on data, employment and copyright. Public buyers moved first. Law firms and audit firms share most of this workflow but carry extra professional rules, noted once below.

Client contracts and public buyers

  • PPN 017: AI use in procurementUK central government · Guidance

    Buyers may ask suppliers "to disclose their use of AI in the creation of their tender", should stop suppliers training AI on confidential government information, and should check AI-written bids more closely[9].

    For the firm: The questions are optional for buyers. Keep a standard, truthful answer on how you use AI in bids.

  • OMB M-25-22: federal AI acquisitionUS federal agencies · In force

    Issued 3 April 2025, it governs AI that agencies buy and excludes AI "used incidentally by a contractor". It tells agencies to consider requiring "disclosure of AI use as part of any given contract's performance", and to bar training commercial AI on non-public agency data without consent[10].

    For the firm: Any disclosure duty sits in the solicitation and contract. We found no FAR clause requiring consultants to disclose AI use.

  • Australian government consultancy termsAustralia · Partly to be confirmed

    After the Deloitte case, federal agencies were reported to be tightening AI terms in consultancy contracts. The new clauses, and whether the Digital Transformation Agency's responsible AI policy binds suppliers, are to be confirmed against the primary text.

    For the firm: Ask the agency for its current AI clauses before you price.

  • Private client MSAsEverywhere · Partly to be confirmed

    Clauses that ban AI on client data, require disclosure or bar training are widely discussed, but we found no public examples. To be confirmed.

    For the firm: Your own contract files are the evidence. Record each client's terms in Stage 0.

Data protection

  • GDPR Article 28: processorsEU and EEA personal data · In force

    A processor acts only "on documented instructions from the controller" and may not engage another processor without the controller's prior specific or general written authorization[11].

    For the firm: The AI model provider is a sub-processor. Sending client personal data to a model the client has not authorized can breach the DPA.

  • HIPAA business associatesUS health data · In force

    A firm that handles protected health information for a covered entity is a business associate[21], and needs agreements that reach any model provider that sees the data.

    For the firm: Clear models for health data separately.

EU AI Act

  • Article 4: AI literacyEU deployers · In force

    Since 2 February 2025, deployers "shall take measures to support the development of AI literacy of their staff"[12,16].

    For the firm: Train people on the AI policy, reference checks and data classes, and keep a record.

  • Article 50(4): AI-generated text published on public mattersEU deployers · In force

    Deployers that publish AI-generated text "to inform the public on matters of public interest" must disclose it, unless the content "has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility"[14]. Article 50 has applied since 2 August 2026; providers of systems already on the market have until 2 December 2026 for the marking duty in Article 50(2)[16]. Any later change by the Digital Omnibus: to be confirmed against the Official Journal.

    For the firm: Public-sector reports and thought leadership fit here. A named partner who releases the text is also the route out of the disclosure duty.

  • Annex III 4(b): allocating work and evaluating peopleEU workers · Applies from a later date

    AI used "to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons" in work relationships is high-risk[15]. Deployers must assign human oversight, keep logs for at least six months and inform workers[13]. The tracker gives 2 December 2027 for Annex III systems[16]; the Official Journal text after the Digital Omnibus is to be confirmed.

    For the firm: A PSA agent that ranks consultants for projects or rates them is in scope for EU staff.

Ownership of deliverables

  • US copyright in AI-assisted workUnited States · In force

    The Copyright Office says "prompts alone do not provide sufficient human control to make users of an AI system the authors of the output", while work can be protected where a human determined its expressive elements[17]. In Thaler v. Perlmutter the D.C. Circuit upheld the refusal to register a work with no human author (March 2025), and the Supreme Court declined to hear the appeal on 2 March 2026[18].

    For the firm: Most SOWs assign deliverable IP to the client. Mostly unedited AI output may carry little copyright to assign.

Expert evidence and neighboring professions

  • Expert declarations and machine-generated evidenceUS courts · Partly to be confirmed

    Courts hold the named expert responsible for every citation (Kohls v. Ellison, below). Proposed Federal Rule of Evidence 707, on machine-generated evidence, is not among the evidence proposals out for comment in the 2026 to 2027 cycle, which lists only Rules 104 and 902[19]. Its status is to be confirmed.

    For the firm: Every source in an expert report is the expert's own check.

  • Lawyers, auditors and tax advisersFirms that also practice these · Guidance

    ABA Formal Opinion 512 (July 2024) applies competence, confidentiality, supervision and fee rules to lawyers' use of generative AI[22]; its exact wording on fees is to be confirmed. Audit and tax practice rules add their own duties.

    For the firm: Not binding on consultants, but a fair test: never bill for time an agent saved.

What they have in common

Across these rules and contracts, four duties keep coming back. The exact form differs by jurisdiction and use, but a firm that builds these four into how agents work has the base the others extend:

Disclose
Say how AI was used where the client, the tender or the law asks, with one standard wording the bid team and partners all use.
Stay inside the boundary
Client data goes only to the people and models the contract allows, one engagement at a time.
Put a name on it
A named person checks the references and releases every price, claim and deliverable the firm publishes.
Keep the record
Who did what, with which agent, on which engagement, kept as long as the contract and any dispute need it.

Hiring your own consultants. If you screen applicants with AI, the hiring rules in New York City, Illinois, Colorado, California and the EU apply to you as an employer. The staffing playbook covers them in detail.

13

How roles change

Our reading of where the work moves, not a survey finding. In a small firm several will be parts of existing jobs.

  1. 1

    The analyst pipeline narrows, and nobody knows the cost yet

    First-draft research, slide building and data cleaning were analyst work. Accenture recorded $344 million of severance in one quarter tied to "exiting people in a compressed timeline where reskilling is not a viable path"[4]. If a firm hires fewer analysts, where do its managers come from in five years? No public evidence answers that yet. Decide how juniors will learn to build an analysis that an agent now drafts.

  2. 2

    Partners spend more time on review and price

    When an agent produces the first deck in an afternoon, the partner hours go into checking that the analysis holds up and setting a price that is not hours times rate.

  3. 3

    A knowledge lead decides what may be reused

    Owns which past work is cleared for reuse, how it is cleaned of client names and figures, and who may see it.

  4. 4

    An engagement AI lead on each team

    Sets which agents run on the engagement, which models are cleared for its data under the client's terms, and what is disclosed.

  5. 5

    A pricing desk

    Moves bids from hours by role to deliverables, outcomes or a running service, using the firm's own data on what work actually costs once agents do the first draft.

  6. 6

    Forward-deployed engineers

    Some firms will build and run working systems for clients instead of handing over a deck. Distyl describes itself as working "from strategy and system design through to production deployment" (vendor description)[32]. That team needs engineers who can run a client system in production, which most strategy practices do not employ today.

  7. 7

    Utilization stops measuring productivity

    If an agent does three hours of work in ten minutes, billable hours over available hours says little about output. Track revenue and gross margin per professional and delivery quality alongside it.

14

The OrchKernel blueprint for a consulting firm

OrchKernel sits between AI agents and the systems the firm connects, as described in the missing layer. Agents ask it before they act; it checks the rules, holds what needs a person, runs what is allowed with credentials the agent never holds, and records all of it, engagement by engagement.

The mechanisms

Approvals
The action waits for a named person, who sees the exact payload: price, deliverable version, change-order email, invoice lines. It runs once, as approved.
Rules
Checked on every call: rate floors, a recorded reference check before "ready for partner", retrieval only from cleared work, allowed recipients, restricted lists. A rule allows, holds or denies, with a reason.
Acting on a named person's authority
Each agent acts for a staffed person, on one engagement, with no more access than that person has there. When they roll off, the agent loses the access too.
Data access by role and field
Rates and margins hidden from roles that do not price; compensation hidden from staffing agents; client records limited to the engagement.
Model clearance by data class
Each model is cleared for the data classes it may see, so restricted client data reaches only models the client's terms allow.
Tamper-evident audit log
Every request, approval and result, by engagement, chained so an edited or deleted entry shows, including who checked the references and who released the deliverable.
Human queue
Conflicts flags, staffing exceptions, unknown client contacts and unresolved references land with a named owner.
Memory with quarantine
Notes and documents are filed to the engagement. New knowledge waits until a person accepts it, and search respects each person's permissions.
Kill switches
Stop one agent, one practice or every agent in the firm, at once.
Connections to your systems
The firm connects its CRM, PSA (Kantata, Certinia, Deltek and others), Microsoft 365 or Google Workspace, chat, e-signature and accounting. Agents never hold the vendor keys.

Seventeen control points

Where a consulting firm needs a control whatever tools it runs, who owns it, and what enforces it.

Engagement boundaries

01
Engagement acceptance: no agent works on an engagement that has not cleared conflicts and risk review
Owner or approver
Risk or general counsel
What enforces it
A rule blocks agent work until the conflicts system shows the engagement cleared; flags go to the human queue.
02
One engagement at a time: an agent sees only that engagement's records, and only what the staffed team can see
Owner or approver
Engagement partner
What enforces it
Acting on a named person's authority, per engagement; data access by engagement.
03
Model and sub-processor clearance by client and data class
Owner or approver
Data protection lead, with the client's authorization
What enforces it
Model clearance by data class.
04
Outbound data: what an agent may send outside the firm, to whom, with which attachments
Owner or approver
IT security and engagement partner
What enforces it
Rules on recipients and attachments; anything else is held.
12
Information barriers for deal and dispute work: restricted lists honored, nothing carried across
Owner or approver
Compliance
What enforces it
Rules match restricted lists; access ends at the engagement.

What leaves the firm in its name

06
AI-use disclosure in bids and deliverables where the client, tender or law asks
Owner or approver
Engagement partner
What enforces it
A rule requires the disclosure for clients whose terms ask; approval shows it.
07
Reference and fact check before any deliverable reaches partner review
Owner or approver
Named checker and manager
What enforces it
A rule holds "ready for partner" until the check is recorded. Whether a source is real stays the checker's call.
08
Partner release of every client deliverable, on the exact version
Owner or approver
Engagement partner
What enforces it
Approval on the exact file version.
09
Client-facing messages and commitments: change orders, status reports, email in a person's name
Owner or approver
Project manager; partner for fees
What enforces it
Approval on the exact message and fee.
13
Expert and litigation work: every source verified by the testifying expert; AI use recorded
Owner or approver
Testifying expert
What enforces it
Expert approves each source list; the log records AI use.

Price and billing

05
Pricing: rates below the card, discounts and fixed fees under the margin floor
Owner or approver
Partner or pricing desk
What enforces it
Rules on floors; approval shows the exact price and margin.
10
Time and billing: people approve their own time; invoices and write-offs approved; the firm's policy on AI-assisted work applied
Owner or approver
Consultant, billing lead, partner
What enforces it
Approval per time entry and invoice; the billing policy is a rule.

Knowledge and people

11
Reuse of past work: only work marked cleared for reuse, checked for other client names and figures
Owner or approver
Knowledge lead
What enforces it
Rules limit retrieval to cleared work; memory quarantine.
14
Decisions about people: staffing, ratings and promotions proposed by agents, decided by people, inputs recorded
Owner or approver
Resource manager and HR
What enforces it
Human queue; compensation hidden; inputs logged.

Records and agent changes

15
Records: engagement files, prompts and outputs kept under the retention schedule and legal holds
Owner or approver
Records lead or general counsel
What enforces it
The log, per engagement. File retention stays in the document store.
16
Changes to agents (playbooks, prompts, tools, templates) reviewed before they go live; a stop per agent, practice and firm
Owner or approver
Engagement AI lead
What enforces it
Approval on agent changes; kill switches.
17
Evidence: what each agent did, for whom, on which engagement, in a record that cannot be quietly edited
Owner or approver
Risk
What enforces it
The tamper-evident log, exportable per engagement.

What belongs elsewhere

The PSA stays the system of record
Projects, time and billing stay in the PSA, pipeline in the CRM, files in the document store.
Conflicts searches
The conflicts system decides who is conflicted. OrchKernel enforces what it decides.
Whether a claim is true
OrchKernel can require the check and record who did it. It cannot tell a real source from a plausible one.
Document permissions
SharePoint, Drive and Teams permissions are fixed in those systems.
Office suite security
Patching the office suite, as with EchoLeak, is the vendor's and IT's job.
Contracts, insurance and pricing strategy
MSAs, DPAs, BAAs, professional liability cover and what to charge are outside any software.

Licensing for a consulting firm

OrchKernel is source-available under the Business Source License 1.1 and runs on your own servers, so you can read the code that enforces these controls. Running it for your own firm is one deployment for one organization, which the license allows, and so is a separate deployment for each client. One deployment serving several organizations as a hosted service needs a commercial license (see the license page). Whether one firm deployment whose agents work inside many client environments fits the standard license is to be confirmed with us.

15

Scorecard by stage

Record the baseline before Stage 1 and track the same numbers at each stage. For most consulting operating metrics, such as realization, write-offs, win rate and proposal cost, there is no public benchmark: the standard professional services benchmark is paywalled, and we have not quoted any figure we could not source.

Engagements on the recordStage 0
How to count it
Active engagements with SOW, budget and team in the PSA, sites limited to that team, and the client's AI terms recorded
Public benchmark
No public benchmark
Hours per proposalStage 1
How to count it
Partner and staff hours from RFP to submission, against your own baseline
Public benchmark
No independent benchmark. Vendor claims of 70% to 80% faster drafting[30,31]
Win rateStage 1
How to count it
Bids won over bids submitted, against your own history
Public benchmark
No public benchmark
Time-entry lagStage 1
How to count it
Days between work done and time entered
Public benchmark
No independent benchmark. Laurel claims up to 30 minutes a day recovered (vendor claim)[29]
UtilizationStage 1
How to count it
Your own trend, with your own definition, held constant
Public benchmark
Filings only: CRA 77%, Huron 75.7% to 78.2%, FTI 57% to 60% in 2025, each defined differently[5,6,7]
Reference defectsStage 2
How to count it
Defects caught before release, and any found after
Public benchmark
No public benchmark. Target none after release
Speed and quality on suitable tasksStage 2
How to count it
Sample deliverables by task type, with and without AI
Public benchmark
Independent experiment only: 25.1% faster and 40% higher quality inside the frontier, worse outside it[23]
Revenue not billed hourlyStage 3
How to count it
Fixed-fee, per-deliverable, subscription and managed service revenue as a share of the total
Public benchmark
No public benchmark
RealizationStage 3
How to count it
Fees billed and collected over hours worked at standard rates, by practice and by pricing model
Public benchmark
No public benchmark
Fixed-fee margin varianceStage 3
How to count it
Actual margin against the estimate at signature; change orders raised against requests absorbed; write-offs
Public benchmark
No public benchmark. The main professional services benchmark is paid
Days sales outstandingStage 4
How to count it
Receivables and unbilled work over daily revenue
Public benchmark
Accenture reports days services outstanding of 50 in fiscal 2026, the only large public reference[3]
Margin per professionalStage 5
How to count it
Revenue and gross margin per professional, quarter by quarter
Public benchmark
Filings: gross margin about 32% at Accenture (fourth quarter of fiscal 2026) and FTI (2025); operating margin 10.3% to 15.4% at FTI, Huron, CRA and Accenture[3,8]
16

Sources and further reading

Sources were read in October 2026; dates are publication or data dates. Last reviewed October 2026.

Primary sources

Government agencies, regulators, courts and SEC filings. Some EU texts are read in unofficial copies, marked as such.

  1. 1
    Employment Situation, Table B-1: employees on nonfarm payrolls by industry. US Bureau of Labor Statistics, September 2026 data, preliminary.
  2. 2
    Occupational Outlook Handbook: Management analysts. US Bureau of Labor Statistics, 2025 data.
  3. 3
    Accenture fourth-quarter and full-year fiscal 2026 results (Form 8-K exhibit). Accenture plc, filed with the SEC, 1 October 2026.
  4. 4
    Accenture annual report on Form 10-K for fiscal 2025. Accenture plc, filed with the SEC, 10 October 2025.
  5. 5
    FTI Consulting annual report on Form 10-K for 2025. FTI Consulting, filed with the SEC, 26 February 2026.
  6. 6
    CRA International annual report on Form 10-K for fiscal 2025. CRA International, filed with the SEC, 26 February 2026.
  7. 7
    Huron Consulting Group annual report on Form 10-K for 2025. Huron Consulting Group, filed with the SEC, 24 February 2026.
  8. 8
    Company facts (XBRL) for FTI Consulting, Huron, CRA International, Booz Allen Hamilton and ICF International. US Securities and Exchange Commission, annual reports filed February to May 2026.
    Margins computed from reported revenue, direct cost and operating income. Other firms: CIK 1289848, 1053706, 1443646, 1362004
  9. 9
    Procurement Policy Note 017: Improving transparency of AI use in procurement. UK Cabinet Office, 17 February 2025.
    Replaces PPN 02/24 for procurements under the Procurement Act 2023
  10. 10
  11. 11
    GDPR Article 28: Processor. Regulation (EU) 2016/679, unofficial consolidated copy at gdpr-info.eu.
    Unofficial copy
  12. 12
    EU AI Act, Article 4: AI literacy. Regulation (EU) 2024/1689, unofficial copy at artificialintelligenceact.eu.
    Unofficial copy
  13. 13
    EU AI Act, Article 26: Obligations of deployers of high-risk AI systems. Regulation (EU) 2024/1689, unofficial copy at artificialintelligenceact.eu.
    Unofficial copy
  14. 14
    EU AI Act, Article 50: Transparency obligations. Regulation (EU) 2024/1689, unofficial copy at artificialintelligenceact.eu.
    Unofficial copy
  15. 15
    EU AI Act, Annex III: High-risk AI systems referred to in Article 6(2). Regulation (EU) 2024/1689, unofficial copy at artificialintelligenceact.eu.
    Unofficial copy
  16. 16
    EU AI Act implementation timeline. Future of Life Institute, artificialintelligenceact.eu, updated 31 August 2026.
    Tracker, not the Official Journal. Dates after the Digital Omnibus to be confirmed
  17. 17
  18. 18
    Thaler v. Perlmutter, No. 25-449: docket. Supreme Court of the United States, certiorari denied 2 March 2026.
    Court of appeals opinion: 130 F.4th 1039 (D.C. Cir. 18 March 2025), as cited in the government's brief in opposition
  19. 19
    Proposed amendments published for public comment. United States Courts, comment period 14 August 2026 to 15 February 2027.
  20. 20
    CVE-2025-32711: Microsoft 365 Copilot information disclosure. National Vulnerability Database, NIST, 11 June 2025.
  21. 21
    45 CFR 160.103: Definitions (business associate). Electronic Code of Federal Regulations.
  22. 22
    Formal Opinion 512: Generative artificial intelligence tools. American Bar Association Standing Committee on Ethics and Professional Responsibility, 29 July 2024.
    Could not be opened for this review; wording to be confirmed

Industry bodies and independent research

Working papers and field experiments by researchers with no product to sell.

  1. 23
    Navigating the Jagged Technological Frontier (Dell'Acqua, McFowland, Mollick and others), summarized by a co-author. Harvard Business School Working Paper 24-013; summary at One Useful Thing, September 2023.
  2. 24
    The Rapid Adoption of Generative AI (Bick, Blandin and Deming), working paper w32966. National Bureau of Economic Research, September 2024, revised February 2025.

Vendor sources

Published by companies that sell software or AI services to consulting and professional services firms. Directional, not an industry benchmark.

  1. 25
    Future of Professionals report 2026. Thomson Reuters, 2026.
    Vendor sourceSurvey of legal, tax, accounting and risk professionals and their corporate clients
  2. 26
    Data, privacy and security for Microsoft 365 Copilot. Microsoft Learn, updated 30 September 2026.
    Vendor source
  3. 27
  4. 28
  5. 29
    Laurel: AI time capture. Laurel.
    Vendor source
  6. 30
    Responsive: AI for RFPs and proposals. Responsive.
    Vendor source
  7. 31
  8. 32
    Distyl AI. Distyl.
    Vendor source

Company and press

News coverage and encyclopedia summaries of cases, deals and company statements. Used where no primary source could be opened.

  1. 33
  2. 34
  3. 35
  4. 36
    Major N.L. healthcare report contains errors likely generated by A.I.. The Independent (Newfoundland and Labrador), 22 November 2025.
  5. 37
    Hallucination (artificial intelligence). Wikipedia, citing the Australian Financial Review of 5 and 6 October 2025.
    Secondary source. The AFR articles could not be opened for this review
  6. 38
    Jeff Hancock (Kohls v. Ellison). Wikipedia.
    Secondary source
  7. 39
    Mata v. Avianca, Inc.. Wikipedia.
    Secondary source
  8. 40
  9. 41
    Accenture (acquisition of Faculty). Wikipedia.
    Secondary source
  10. 42

Become a design partner

Run Stage 0 and two Stage 1 workflows on your own PSA and proposal data with us, then the reference check in one practice. You get early access, help with setup, and a say in what we build next.

Or email support@prefero.ai