Skip to main content
Clearlead AI Consulting

Last updated: 21 July 2026. This page is maintained as the law and Irish implementation evolve.

The EU AI Act in Ireland

The EU AI Act (Regulation (EU) 2024/1689) is the EU's legal framework for artificial intelligence. It applies in phases between 2025 and 2028. Obligations depend on how AI is used. Organisations outside the EU are in scope where their AI systems or outputs are used in the EU.

This page is a maintained reference for businesses in Ireland: which obligations apply from when, who enforces the Act here, and what your use of AI requires. It reflects the amendments made by the Digital Omnibus on AI (June 2026) and Ireland's national implementation, including the Regulation of Artificial Intelligence Bill 2026.

The timeline below shows the current deadlines, and the checker further down maps your use of AI to the obligations and Irish regulators involved.

Talk to us about where you stand

Application timeline

The Act applies in phases. The Digital Omnibus on AI (June 2026) deferred the high-risk obligations to December 2027 and August 2028. All other obligations apply from their original dates, including the transparency rules, the prohibitions and the penalty framework.

Status note: the Omnibus was adopted in June 2026 and signed on 8 July. It takes legal effect three days after publication in the Official Journal, expected before the end of July 2026. Until then, the deferred dates are agreed but not yet law.

  1. 2 Feb 2025In force

    Prohibited practices and AI literacy

    The bans on unacceptable-risk AI (Article 5) apply, with no grace period. The AI literacy duty (Article 4) also begins to apply.

  2. 2 Aug 2025In force

    General-purpose AI obligations and penalties

    Obligations for providers of general-purpose AI models apply, and the penalty framework is in place.

  3. 2 Aug 2026Next deadline12 days away

    Transparency rules and Irish enforcement

    Article 50 applies: chatbot disclosure, machine-readable marking of AI-generated content, and deepfake labelling. The Commission's enforcement powers over general-purpose AI providers activate, and Ireland's AI Office opens.

  4. 2 Dec 2026Coming

    Marking grace period ends; new prohibitions

    Generative AI systems already on the market before 2 August 2026 must have machine-readable marking in place. New prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material apply.

  5. 2 Dec 2027Coming

    Standalone high-risk systems (Annex III)

    The full high-risk regime applies to standalone systems: hiring and CV screening, credit scoring, education, access to essential services and similar uses.

    Moved from 2 Aug 2026 by the Digital Omnibus.

  6. 2 Aug 2028Coming

    High-risk AI in regulated products (Annex I)

    The high-risk regime applies to AI embedded in products already covered by EU safety legislation, such as medical devices and machinery.

    Moved from 2 Aug 2027 by the Digital Omnibus.

Obligations

What applies now, and what is next

Obligations grouped by status. This section updates automatically: when a deadline passes, its obligations move into the "already in force" group.

Already in force

Applies now

Since 2 Feb 2025

Prohibited practices (Article 5)

Certain uses of AI are banned outright, including:

  • Social scoring by public authorities
  • Manipulative techniques targeting vulnerabilities
  • Untargeted scraping for facial recognition databases
  • Real-time remote biometric identification in public spaces, with narrow law-enforcement exceptions

Fines up to €35 million or 7% of worldwide turnover.

AI literacy (Article 4)

Organisations must take measures on the AI literacy of staff who operate or use AI systems:

  • The Digital Omnibus (June 2026) softened this duty: organisations must support the development of AI literacy, and do not have to guarantee a level for any individual
  • No direct fine is attached to Article 4
  • Documented, role-appropriate training is the evidence regulators ask for

Since 2 Aug 2025

General-purpose AI model obligations

Providers of general-purpose AI models must:

  • Maintain technical documentation and information for downstream providers
  • Comply with EU copyright law and publish training-content summaries
  • Meet additional obligations where a model poses systemic risk

The penalty framework for the Act as a whole is also in place from this date.

Next deadline: 2 Aug 2026

12 days away

Transparency (Article 50)

Duties for AI systems that interact with people or generate content:

  • Chatbots and AI assistants must disclose that they are AI
  • AI-generated content must carry machine-readable marking
  • Deepfakes must be labelled
  • AI-generated text published to inform the public on matters of public interest must be labelled, unless a human has taken editorial responsibility

Fines up to €15 million or 3% of worldwide turnover.

National enforcement begins

The enforcement structures the Act requires come into operation:

  • Ireland's AI Office opens as the national coordinator
  • The sectoral regulators designated in 2025 take on their AI Act remit
  • Regulators can request evidence of measures taken, including AI literacy measures under Article 4

General-purpose AI enforcement

The European Commission's enforcement powers over providers of general-purpose AI models activate:

  • The model obligations themselves have applied since August 2025
  • Businesses building products directly on these models should establish where the provider's obligations end and their own begin

Later deadlines

  • 2 Dec 2026Generative AI systems already on the market before 2 August 2026 must have machine-readable marking in place. New prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material apply.
  • 2 Dec 2027The full high-risk regime applies to standalone systems: hiring and CV screening, credit scoring, education, access to essential services and similar uses. (moved from 2 Aug 2026 by the Digital Omnibus)
  • 2 Aug 2028The high-risk regime applies to AI embedded in products already covered by EU safety legislation, such as medical devices and machinery. (moved from 2 Aug 2027 by the Digital Omnibus)

Regulators

Who enforces this in Ireland

There is no single national AI regulator in Ireland. Coordination and enforcement are handled by different bodies.

Ireland's AI Office (Oifig IS na hÉireann) opens on 2 August 2026 as an independent statutory body under the Department of Enterprise, Tourism and Employment. Its role is coordination: it is Ireland's single point of contact with the European Commission, maintains a pool of technical experts, will run a national AI regulatory sandbox, and publishes guidance. Under the Regulation of Artificial Intelligence Bill 2026 (published 17 June 2026, currently before the Oireachtas) the Office is not a market surveillance authority, so it does not investigate or fine directly. This could change before the Bill is enacted.

Enforcement sits with existing sectoral regulators, designated in July 2025 (S.I. No. 366/2025). Most businesses are likely to deal with one of these three:

Data Protection Commission

AI in law enforcement, migration, administration of justice and democratic processes, and biometric systems in those areas.

Central Bank of Ireland

AI in regulated financial services, such as credit scoring and insurance pricing.

Workplace Relations Commission

AI in employment: hiring, screening and monitoring.

Diagram showing Ireland's AI Office as coordinator and the sectoral regulators as enforcers under the EU AI Act
Coordination and enforcement are different jobs.

Others among the fifteen designated authorities include the HSE (health services), ComReg and the CRU (infrastructure), the NTA (road traffic), Coimisiún na Meán (platforms and media), the CCPC, and the Health and Safety Authority. These bodies draw on the EU Market Surveillance Regulation, which allows unannounced inspections (including remote ones), covert testing of AI systems, and orders to correct, withdraw or prohibit systems.

Interactive checker

What applies to you

Obligations under the Act depend on how AI is used, on your role (provider or deployer), and on the sector. Select how your organisation uses AI to see the obligations, deadlines and Irish regulators most likely to apply.

Where does your organisation use AI? Select all that apply.

Select at least one option above to see which obligations, deadlines and Irish regulators are likely to apply.

Not sure where you stand?

A short, focused review is usually enough.

We can establish which obligations apply to your organisation and what to do first. Get in touch and we can talk it through.

Non-compliance

Penalties

The penalty framework has been in place since August 2025 and was not deferred by the Digital Omnibus. Proportionality for SMEs applies to the size of fines, not to the obligations themselves.

Up to €35m or 7% of worldwide turnover

Prohibited practices

Up to €15m or 3% of worldwide turnover

Most other non-compliance, including the transparency rules

Up to €7.5m or 1% of worldwide turnover

Supplying misleading information to regulators

Conformity assessment for high-risk systems

For most Annex III high-risk systems, conformity assessment is an internal self-assessment: the provider assembles technical documentation, data governance evidence, human oversight design, a quality management system and post-market monitoring, then declares conformity itself. Third-party (Notified Body) assessment is mandatory only for specific categories such as biometric identification.

In practice this is a documentation obligation, and much of the required documentation is engineering evidence: how the system was evaluated, against which metrics, on which data, and with what results.

Selling into the EU from outside

Like GDPR, the AI Act is extraterritorial. If your AI system is placed on the EU market, or its output is used by people in the EU, you are in scope regardless of where you are established. This includes UK businesses serving Irish or EU customers.

Practical steps

What to do, in order

  1. Inventory your AI. List everything customer-facing and internal, including tools adopted without formal sign-off.

  2. Fix the transparency items. Chatbot disclosures, content marking, deepfake labels (required from 2 August 2026). These are typically small, contained changes.

  3. Document AI literacy measures. Role-based training, recorded, with materials and attendance retained. No certification exists or is required.

  4. Classify anything potentially high-risk. Check against Annex III and determine your role (provider or deployer; the obligations differ substantially). The documentation involved is substantial, so use the time before December 2027.

  5. Check vendor contracts. Where a supplier's AI sits in your customer journey, establish who carries the marking and disclosure duties.

For background on the Act itself and its risk categories, see our guide to understanding the EU AI Act.

Every project is different

Not sure where to begin?

A free introductory call is all it takes. No commitment, no preparation needed. Just a straightforward conversation about your situation and whether we can help.