Authority guide · updated 12 June 2026

The EU AI Act in Ireland: what it actually requires of your business

If your Irish business uses any AI, from ChatGPT to a CV-screening tool, the EU AI Act already applies to you. Parts of it have been in force since February 2025; the rest arrives on a published timetable through 2028. This guide explains what is required and when, in plain English, with the legal basis cited so you can verify everything.

Who the Act applies to: providers and deployers

The Act assigns obligations by role. A provider develops an AI system, substantially modifies one, or places one on the market under its own name. A deployer uses AI under its own authority, which is what almost every Irish SME is. Buying Copilot licences, embedding a chatbot, or subscribing to a recruitment platform makes you a deployer, not a provider.

The distinction matters because provider obligations (conformity assessment, technical documentation, CE marking for high-risk systems) are far heavier than deployer obligations. Most of this guide addresses the deployer position. One caution: building your own product on top of an AI model and selling it under your brand can tip you into provider territory, so take advice before you ship.

The risk pyramid, in one minute

The Act sorts AI uses into four tiers:

  • Prohibited (Article 5). Banned outright since 2 February 2025: social scoring, emotion recognition in the workplace, untargeted facial-image scraping, manipulative techniques causing harm, and similar. Penalties here are the Act’s highest.
  • High-risk (Annex III and Annex I). AI in employment decisions, credit, insurance pricing, education, biometrics, critical infrastructure, plus AI safety components in regulated products. Structured obligations apply, including human oversight, logging and monitoring.
  • Transparency (Article 50). Chatbots must disclose they are AI; AI-generated content destined for the public must be labelled.
  • Minimal risk. Everything else, most productivity tooling. Good governance still applies, and Article 4 literacy applies regardless of tier.

A single system can sit in more than one tier at once: a customer chatbot built on a high-risk use would carry both sets of duties. The full legal text is on EUR-Lex (Regulation (EU) 2024/1689).

The employment trap: CV screening is high-risk

The single most common way an Irish SME walks into high-risk territory is recruitment software. Any tool that ranks, filters or scores job applicants counts as high-risk under Annex III, even if a human makes the final decision. The same applies to AI that allocates work, monitors performance or informs promotion and termination. If your ATS sorts candidates, classify it now and start the deployer duties under Article 26: named human oversight, input-data checks, log retention and informing affected workers.

The full timetable

Deadlines as they stand in June 2026, including the effect of the 7 May 2026 Omnibus political agreement:

Obligation setStatus / deadline
Article 5 prohibitionsIn force since 2 Feb 2025
Article 4 AI literacy (all organisations using AI)In force since 2 Feb 2025
GPAI provider obligationsIn force since 2 Aug 2025
Article 50 chatbot/interaction transparency2 Aug 2026
Synthetic content labelling2 Dec 2026 (Omnibus-reduced deferral)
Annex III high-risk obligations (Arts 9–17 provider, Art 26 deployer)2 Dec 2027 per the 7 May 2026 Omnibus political agreement; fallback 2 Aug 2026 if not adopted in timesubject to formal adoption
Annex I product high-risk2 Aug 2028
Irish Regulation of AI Bill 2026 / AI Office of IrelandGeneral Scheme published 4 Feb 2026; priority legislation in drafting during 2026horizon item

What Ireland is adding: the AI Bill and the AI Office

The EU AI Act applies directly, but member states must designate national authorities and penalties. Ireland’s Regulation of Artificial Intelligence Bill 2026 does that work: it establishes the AI Office of Ireland as the national coordinating authority and assigns enforcement to sectoral regulators. The General Scheme was published on 4 February 2026 and the Bill is being treated as priority legislation through 2026. The practical effect for SMEs: enforcement becomes local, and any registration duties the Bill adds will land on top of the EU baseline. Official updates are published by the Department of Enterprise, Tourism and Employment.

Penalties: context, not scaremongering

The ceilings are €35 million or 7% of global turnover for prohibited practices, and €15 million or 3% for high-risk non-compliance, with proportionate caps for SMEs. The realistic near-term exposure for an Irish SME is not a headline fine. It is failing a customer’s vendor assessment, an insurer’s questionnaire, or a tender requirement because you cannot evidence basic AI governance.

The five steps for an Irish SME

  1. Inventory. List every AI tool in use, including the unofficial ones.
  2. Classify. Put each system through the Act’s risk taxonomy and record the outcome with its rationale.
  3. Assign and train. Name an owner per system and start the Article 4 literacy record; the duty is already in force.
  4. Fix the customer-facing gaps. Chatbot disclosure and content labelling have 2026 deadlines; handle them this year.
  5. Keep evidence. Vendor due diligence, training records, decisions, timestamped, in one place a third party can trust.

That sequence is exactly what AI Register Ireland operationalises: a signup-to-classified-register path you can complete in an afternoon, with the evidence trail building itself as you go.

Frequently asked questions

Yes, in stages. The prohibited-practices ban (Article 5) and the AI literacy duty (Article 4) have applied since 2 February 2025. General-purpose AI provider obligations followed on 2 August 2025. Chatbot transparency arrives on 2 August 2026, AI-content labelling on 2 December 2026, and the main high-risk obligations on 2 December 2027 under the May 2026 Omnibus agreement (subject to formal adoption).

It is Ireland's national implementing legislation for the EU AI Act. The General Scheme was published on 4 February 2026 and the Bill is priority legislation during 2026. It establishes the AI Office of Ireland as the national coordinating authority and designates sectoral regulators for enforcement.

Yes. Using AI built by others makes you a deployer under the Act. Deployers must ensure staff AI literacy (in force since February 2025), disclose AI to customers where it interacts with them (from August 2026), label AI-generated public content (from December 2026), and carry heavier duties if a tool is high-risk. CV screening is the common example.

The most common trigger is employment: any tool that ranks, filters or scores job applicants or employees, including CV-screening software, is high-risk under Annex III, even when a human makes the final decision. Credit scoring, insurance pricing, education assessment and biometric tools also qualify.

Up to €35 million or 7% of global turnover for prohibited practices, and up to €15 million or 3% for high-risk non-compliance. The Act provides proportionate caps for SMEs. The point is not the headline number but that enforcement infrastructure is being stood up in Ireland now.

Three things, in order: build an inventory of every AI tool in use; classify each against the Act's risk categories; and start an evidence trail, covering staff AI literacy records, vendor due diligence, and transparency disclosures where AI faces customers. That is precisely what an AI register is for.

Sources

Be first to put your register in place

The classification wizard encodes everything on this page. Join the waitlist and you will be among the first to add your tools, answer plain-English questions, and walk away with a classified register.

Join the waitlist