The European Union’s Artificial Intelligence Act has entered a major implementation phase, and businesses operating in Ireland need to understand which requirements already apply, which obligations depend on their use of AI and when additional rules will take effect. The EU AI Act, Regulation (EU) 2024/1689, establishes a risk-based framework for artificial intelligence. Following the 2026 AI Omnibus amendments, the main implementation milestones extend into August 2028.
For Irish businesses, the immediate priority is to identify how AI is being used, assess the risks, ensure staff have appropriate AI literacy, check applicable transparency requirements and determine whether any systems fall into regulated high-risk categories. The fact that a business buys AI software from another company does not automatically remove its responsibilities.
Key facts
- The law: Regulation (EU) 2024/1689, the EU Artificial Intelligence Act.
- Who it affects: Providers, deployers, importers and distributors of AI systems, subject to the Act’s scope and specific exceptions.
- What changed in 2026: The AI Omnibus entered into force on 27 July 2026 and revised certain implementation deadlines.
- Rules already in application: Prohibitions on specified AI practices and AI literacy obligations, among other requirements, apply from earlier phases.
- Major milestone: Most of the Act’s rules began applying on 2 August 2026, with some exceptions and transitional arrangements.
- Upcoming dates: Certain high-risk use cases have a revised application date of 2 December 2027, while specified product-related high-risk requirements are scheduled for 2 August 2028.
- Where Irish businesses can start: The AI Office of Ireland and the European Commission’s AI Act Service Desk provide official guidance.
Table of contents
- What is the EU AI Act?
- What changed in 2026?
- Who needs to comply?
- EU AI Act implementation timeline
- The four AI risk categories
- What businesses using AI need to do
- AI literacy and transparency requirements
- What the rules mean for Irish SMEs
- How the Act affects UK businesses serving EU customers
- A practical business compliance checklist
- Where to get official guidance
1. What is the EU AI Act?
The EU AI Act is a regulation designed to establish common rules for developing, placing on the market and using artificial intelligence in the European Union. It aims to support trustworthy AI while protecting health, safety and fundamental rights.
Rather than imposing identical requirements on every AI tool, the legislation follows a risk-based approach. Obligations depend on factors including the system’s intended purpose, the role of the organisation and the specific provisions that apply.
For example, a business using a general-purpose AI assistant to help draft routine internal documents does not automatically face the same requirements as an organisation deploying a regulated AI system to assess job applicants or support decisions in another sensitive area.
However, organisations should not assume that a familiar or widely available AI product is automatically outside the law. They need to assess the actual use case and applicable requirements.
2. What changed in 2026?
The 2026 AI Omnibus amended parts of the AI Act’s implementation framework. The European Commission confirmed that the amendment entered into force on 27 July 2026.
One important consequence is a revised timetable for certain high-risk AI obligations. The legislation also includes measures intended to simplify aspects of compliance and support innovation, including provisions affecting smaller and growing companies.
The changes do not amount to a general suspension of AI regulation.
Businesses must still assess obligations that already apply, including relevant AI literacy requirements, prohibitions and transparency rules. They should also prepare for future requirements where their systems fall within the relevant categories.
The practical message is straightforward: use the amended legal timeline, rather than relying on an older compliance calendar.
3. Who needs to comply with the EU AI Act?
The Act can apply to different organisations depending on their role in the AI supply chain and the scope of their activities.
Providers
Providers develop AI systems, or have systems developed, and place them on the market or put them into service under their own name or trademark. Provider responsibilities can include technical documentation, conformity assessment and other requirements for applicable high-risk systems.
A company that modifies or commercialises an AI system may need to assess whether its activities bring it within the provider definition.
Deployers
Deployers use AI systems under their authority, other than in the course of a personal, non-professional activity.
This category is particularly relevant to ordinary businesses. An employer using AI in recruitment, a company operating a customer-facing chatbot or an organisation using an AI-enabled decision-support system may have deployer responsibilities.
Those responsibilities vary according to the system and the applicable provisions.
Importers and distributors
Importers and distributors can have responsibilities when they bring AI systems into the EU market or make them available within the supply chain.
Businesses should not assume that only the original developer has legal obligations.
Businesses outside the EU
The Act can also affect certain organisations based outside the European Union. Its territorial provisions include circumstances in which an AI system’s output is used in the EU.
A business’s location alone is therefore not always enough to determine whether the Act applies. Organisations serving European customers should assess their activities against the legislation’s actual scope.
4. EU AI Act implementation timeline
The implementation timetable has several stages. The following dates reflect the framework and amendments in force as of 9 October 2026.
| Date | Milestone | What it means for businesses |
|---|---|---|
| 1 August 2024 | Act entered into force | The legal framework was established. |
| 2 February 2025 | Initial prohibitions and AI literacy requirements began applying | Organisations need to consider prohibited practices and appropriate AI literacy measures. |
| 2 August 2025 | General-purpose AI model obligations and governance arrangements began applying | Relevant providers and organisations need to assess the requirements applicable to their roles. |
| 2 August 2026 | Most rules began applying, subject to exceptions | Applicable transparency, enforcement and other obligations require attention. |
| 2 December 2026 | Specified new prohibitions and a transitional deadline relating to certain synthetic-content systems | Relevant providers and deployers should check the exact provisions and transition conditions. |
| 2 August 2027 | Member States should have at least one AI regulatory sandbox operational | Relevant to national implementation and supervised experimentation. |
| 2 December 2027 | Revised application date for specified high-risk use cases | Relevant organisations should prepare for applicable high-risk requirements. |
| 2 August 2028 | Revised application date for specified high-risk AI systems linked to regulated products | Providers and other affected organisations should assess the relevant product legislation and transition rules. |
The dates do not mean that every obligation applies to every organisation on the same day. Existing-system provisions, transitional arrangements and the classification of a particular AI system can affect the outcome.
Businesses should consult the European Commission’s implementation timeline before making a compliance decision.
5. What are the four AI risk categories?
The EU AI Act distinguishes between different levels of risk rather than treating every AI application identically.
Prohibited AI practices
Certain AI practices that pose unacceptable risks are prohibited, subject to the precise legal definitions and exceptions.
Examples include specified forms of manipulative or exploitative AI, certain social-scoring practices and particular uses of emotion recognition in workplaces or educational institutions.
The prohibitions are not blanket bans on every technology that resembles these examples. The specific practice, purpose and statutory conditions matter.
Businesses should review how their systems operate rather than relying solely on a vendor’s general product description.
High-risk AI systems
High-risk requirements can apply to specified AI uses affecting areas such as employment, education, critical infrastructure, certain essential services and other sensitive contexts.
Depending on the system and the organisation’s role, requirements may include risk management, documentation, human oversight, monitoring and other safeguards.
Not every AI tool used in a sensitive industry is automatically high-risk. Classification depends on the relevant legal criteria, intended purpose and applicable exceptions.
AI systems subject to transparency requirements
Some AI applications must meet specific transparency obligations. Depending on the provision, this can include informing people that they are interacting with an AI system or making certain AI-generated or manipulated content identifiable.
The exact requirements differ between providers and deployers and between different types of AI use.
Minimal- or low-risk AI
Many ordinary AI applications do not fall into the Act’s prohibited or high-risk categories and may not attract additional requirements under particular AI Act provisions.
That does not exempt them from other applicable laws, such as data protection, consumer protection, employment or intellectual property rules.
A low-risk classification under the AI Act is not a general legal clearance for every use of a tool.
6. What should businesses using AI do?
A company does not need to build its own AI model to have responsibilities. It should start by understanding the systems it already uses.
Create an AI inventory
Record the AI tools and systems used across departments, including those purchased from vendors and those integrated into existing software.
Include recruitment platforms, customer service tools, document assistants, analytics systems and automated decision-support applications where relevant.
For each system, record its purpose, supplier, users, data involved and the business process it supports.
Identify the organisation’s role
Determine whether the business is acting as a provider, deployer, importer or distributor for each relevant activity.
A company may occupy different roles for different systems. Buying a software subscription does not automatically make a business a provider, but developing or placing a modified system on the market under its own name can require further analysis.
Assess the intended use and risk category
Check the provider’s documentation and assess how the business actually uses the system.
For potentially high-risk applications, consult the relevant provisions and official classification guidance. Do not classify a system solely by the product’s marketing description.
Establish appropriate staff training
Review the AI literacy needs of people who use or oversee AI systems. Training should be appropriate to their knowledge, experience, the context of use and the people affected.
A practical programme can cover approved tools, confidential information, verification of AI outputs, escalation procedures and the limits of automated decisions.
Check transparency and human oversight
Where applicable, ensure people receive required information about AI interactions or AI-generated content.
For higher-impact uses, establish appropriate human oversight, review procedures and escalation routes consistent with the relevant legal requirements.
Keep records and review suppliers
Retain the documentation required for the organisation’s role and the specific system.
Ask suppliers about intended use, system limitations, data handling, documentation, updates and support for compliance. Contractual assurances can help, but they do not automatically transfer every legal responsibility away from the organisation using the technology.
7. AI literacy and transparency requirements
What is AI literacy?
AI literacy concerns the knowledge and understanding needed to use AI appropriately. Article 4 of the AI Act requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and other people dealing with AI systems on their behalf, taking account of their knowledge, experience, education, training and context of use.
For a business, this means considering what staff need to know to use AI responsibly, rather than simply issuing a general statement that AI tools are permitted.
Practical steps may include:
- explaining which AI tools are approved for business use;
- training staff to check outputs rather than treating them as automatically accurate;
- setting rules for entering personal, confidential or commercially sensitive information;
- explaining when human review is necessary; and
- keeping training and governance arrangements under review.
The appropriate measures will differ between organisations and use cases.
When must people be told they are interacting with AI?
Article 50 contains specific transparency obligations for certain AI systems and uses. Depending on the circumstances, people may need to be informed that they are interacting with an AI system, or content generated or manipulated using AI may need to be disclosed or marked.
The requirements are not identical for every chatbot, image generator or internal tool. Businesses should identify the applicable obligation and whether any exception or transition applies.
The revised timeline also includes a 2 December 2026 milestone for certain synthetic-content systems and related transitional arrangements. Organisations developing or deploying these systems should verify their specific duties against the current legislation.
8. What does the EU AI Act mean for Irish SMEs?
Irish small and medium-sized enterprises should focus on proportional, practical compliance rather than assuming they need a large in-house legal team.
The first step is to identify which AI systems are used and how they affect customers, employees and business decisions.
A company using AI for routine drafting may face a different set of obligations from one using AI to screen job applicants or support decisions in a regulated service. The distinction depends on the particular system, role and legal provisions.
SMEs should:
- Maintain an inventory of AI tools and their purposes.
- Identify relevant provider or deployer responsibilities.
- Review prohibited-practice risks and applicable transparency duties.
- Provide appropriate AI literacy measures.
- Check whether any systems fall into high-risk categories.
- Review supplier documentation and contractual arrangements.
- Monitor upcoming deadlines and official guidance.
The AI Office of Ireland provides guidance for businesses and links to compliance resources. The European Commission’s AI Act Service Desk also offers tools to help organisations understand their obligations.
Irish businesses should also remember that AI Act compliance is only one part of responsible AI use. Data protection, employment, consumer and sector-specific rules may apply independently.
9. How does the Act affect UK businesses serving EU customers?
The United Kingdom is outside the European Union, but a UK business may still need to consider the EU AI Act when supplying AI systems or using AI in circumstances covered by the regulation.
The correct approach is to assess the business’s activities and the Act’s territorial scope, rather than assume either that every UK business is covered or that no UK business is covered.
Northern Ireland is part of the United Kingdom, not an EU Member State. Its position should not be conflated with Ireland’s membership of the EU. Businesses operating across the border should assess the relevant legal frameworks and the particular activities involved.
UK businesses that supply AI products into the EU should review their provider, importer or distributor role where applicable. UK organisations deploying AI should also determine whether the regulation’s territorial provisions apply to their circumstances.
The EU AI Act should not be described as automatically replacing UK domestic law.
10. A practical EU AI Act compliance checklist
Use this checklist as a starting point, not as a substitute for a system-specific legal assessment.
List the AI tools and systems used across the organisation.
-
Record each system’s purpose, supplier and business owner.
-
Determine the organisation’s role for each relevant system.
-
Check the prohibited-practice rules.
-
Assess whether any intended use could qualify as high-risk.
-
Review applicable AI literacy requirements and staff training.
-
Identify transparency obligations for chatbots and synthetic content.
-
Check whether human oversight or additional safeguards are required.
-
Review supplier documentation, contracts and system limitations.
-
Retain the records required for the relevant role and use case.
-
Check current transitional provisions and future deadlines.
-
Consult official Irish and EU guidance where the classification is uncertain.
Assign responsibility for these actions to an appropriate person or team and review the inventory when new tools are introduced or existing systems change.
11. Where can Irish businesses get official guidance?
Businesses should prioritise primary sources when interpreting regulatory obligations.
AI Office of Ireland: The national coordinating body provides business guidance, compliance information and links to relevant authorities. Start at aioffice.gov.ie/for-business.
European Commission AI Act Service Desk: The EU platform provides the implementation timeline, explanations of the legislation and tools to help organisations assess their obligations. Visit ai-act-service-desk.ec.europa.eu.
Irish Government: The Department of Enterprise, Tourism and Employment publishes information on the EU AI Act and Ireland’s implementation framework. See the official Irish Government guide.
Organisations with complex or high-impact use cases should obtain suitable legal or regulatory advice rather than relying on a general explainer alone.
Conclusion
The EU AI Act is not a blanket ban on business AI. It establishes obligations that vary according to the system, the organisation’s role and the risks involved.
For Irish businesses, the practical priority in October 2026 is to understand existing obligations, document AI use, provide appropriate AI literacy, assess relevant transparency and prohibited-practice rules, and identify any systems that may fall into high-risk categories.
The 2026 AI Omnibus has changed certain future deadlines, but businesses should not interpret those changes as a reason to postpone all compliance work. The safest starting point is an accurate AI inventory, followed by a review of the current legislation and official guidance.
This article is an informational overview, not legal advice. Businesses should consult the current legislation and relevant authorities when determining their obligations.
Frequently asked questions
1. What is the EU AI Act?
The EU AI Act is Regulation (EU) 2024/1689, which establishes a common legal framework for artificial intelligence in the European Union. It uses a risk-based approach, with different requirements for prohibited practices, high-risk systems and certain uses requiring transparency.
2. Does the EU AI Act apply to Irish businesses?
Yes, where the business and its activities fall within the Act’s scope. Relevant organisations can include providers and businesses deploying AI systems, although their specific responsibilities depend on their role, the system and the applicable provisions.
3. What changed under the EU AI Act in 2026?
The AI Omnibus entered into force on 27 July 2026, introducing targeted amendments and changing certain application deadlines. Businesses should use the amended implementation timeline rather than rely on older summaries of the original timetable.
4. Which EU AI Act rules already apply?
AI literacy requirements and prohibitions on specified AI practices began applying in February 2025. General-purpose AI model obligations followed in August 2025, and most of the Act’s rules began applying in August 2026, subject to exceptions and transitional provisions.
5. Does using ChatGPT make a business subject to the EU AI Act?
Using ChatGPT does not automatically make every business subject to every requirement in the Act. Businesses should assess their role, the nature and purpose of their AI use and whether the relevant provisions apply. Other laws, including data protection law, may apply independently.
6. What counts as high-risk AI?
High-risk AI includes specified systems and use cases covered by the Act’s relevant provisions, including certain applications in employment, education, critical infrastructure and other sensitive areas. Classification depends on the statutory criteria and the system’s intended purpose; it is not determined by the industry alone.
7. When do the revised high-risk AI rules apply?
Under the revised timeline, specified high-risk use cases are scheduled for 2 December 2027, while certain high-risk AI systems linked to regulated products are scheduled for 2 August 2028. Businesses should check the applicable category and transitional conditions.
8. What is the AI literacy requirement?
Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy among relevant staff and people acting on their behalf, taking account of their knowledge, experience and context of use. Appropriate measures will vary between organisations.
9. Do small businesses have to comply with the EU AI Act?
Small businesses are not automatically exempt. Their obligations depend on their role and AI use, and some provisions provide specific proportionality measures or support. SMEs should assess their systems and check the applicable rules rather than assume the entire Act does not apply.
10. Does the EU AI Act apply to UK companies?
It can apply to certain UK-based providers or other organisations where the Act’s territorial provisions are met. The outcome depends on the company’s activities and the system concerned. The EU AI Act is not automatically the domestic regulatory framework for every business operating in the UK.
11. Where can Irish businesses check their AI Act obligations?
Businesses can begin with the AI Office of Ireland’s business guidance and the European Commission’s AI Act Service Desk, including its implementation timeline and compliance resources.


1 Comment
Pingback: AI Skills Demand in Ireland: 2026 Jobs Outlook