Ireland has its AI regulator. The AI Office is open, the national authorities are named, and the first wave of the EU AI Act has been in force for over a year. If you missed that piece, it’s here: Ireland has an AI regulator now.
This post is about what happens next. The dates still to come, what each one actually asks of a small business, and the handful of things worth doing this quarter so none of it becomes a scramble.
One thing up front. The AI Act is a large piece of law, but for most Irish SMEs the practical to-do list is short. You are almost certainly a “deployer” (a business using AI tools), not a “provider” (a business building and selling AI systems). Deployers carry far lighter obligations. Keep that in mind as you read.
Where we are today
Three parts of the Act are already live:
- Banned uses (since February 2025). Things like social scoring, emotion recognition in the workplace, and manipulative AI. Not relevant to how most businesses use ChatGPT or Claude, but worth knowing so you can rule them out.
- AI literacy (since February 2025). Every business using AI must make sure staff have enough understanding to use it responsibly. This is the one most SMEs have quietly missed. It applies to a two-person accountancy practice as much as it does to a bank.
- General-purpose AI rules (since August 2025). These sit with the model providers (OpenAI, Anthropic, Google, and so on), not with you. What it means for you is that the tools you buy come with better documentation about what they were trained on and what they can do.
And as of 2 August 2026, the Irish authorities have the power to enforce all of this. The AI literacy duty in particular has gone from “good practice” to “something a regulator can ask you about”.
The dates still to come
Here is the timeline that matters for a business in Ireland. Some of these dates moved in 2026. The Digital Omnibus package, adopted at EU level in July 2026, gave businesses more time on the high-risk rules, and the dates below are the final ones.
2 August 2026 (now in force). Transparency rules. If a customer is talking to a chatbot on your website, they need to be told it’s a chatbot. If you publish AI-generated images, audio or video that could be mistaken for real, it needs to be labelled. If you use AI to write and publish content on matters of public interest, that needs to be disclosed unless a person has reviewed and taken responsibility for it. The technical watermarking requirement for AI-generated content has a grace period to 2 December 2026 for systems already on the market, but the plain-language disclosure to customers applies now.
2 December 2027. High-risk AI systems, Annex III. This is the big one for the small number of SMEs it touches. “High-risk” covers AI used in recruitment and CV screening, HR decisions like promotions or performance monitoring, credit scoring, access to education, and insurance pricing. If you use AI in any of those areas, you have real obligations as a deployer: human oversight, monitoring, keeping logs, telling affected workers or applicants, and using the system as the provider intended. The Digital Omnibus moved this deadline from August 2026 to 2 December 2027, and that date is now settled law. Either way, if you screen CVs with AI today, start on the deployer obligations now rather than waiting for the deadline.
2 August 2028. High-risk AI built into regulated products, Annex I. Medical devices, machinery, lifts, toys, vehicles. If you manufacture products in these categories with AI inside them, this is your date. The Omnibus moved this from August 2027 to August 2028. Most service businesses can skip this line entirely.
2 August 2027. Older general-purpose models must comply. Any large AI model that was already on the market before August 2025 has to meet the provider obligations by this date. Again, this sits with the model companies, not you.
Ongoing through 2026 and 2027. Codes of practice and standards. The Commission is publishing codes of practice, including one on labelling AI-generated content, and the European standards bodies are working on the harmonised standards that will tell high-risk providers exactly what “compliant” looks like. These will make things clearer, not harder. Expect guidance from the Irish AI Office to follow each one.
What “compliant” actually looks like for a typical Irish SME
Strip it all back and here is what a regulator would expect to see if they asked a 15-person business how it manages AI:
- A tool inventory. A list of the AI tools in use, who uses them, and for what. Most businesses can write this on one page. Most haven’t.
- A risk check against the banned and high-risk lists. A short, documented pass through your inventory asking: does anything here touch recruitment, HR decisions, credit, or customer-facing bots? If no, note it and move on. If yes, that tool gets the extra attention.
- A written AI usage policy. What staff can and can’t put into AI tools (customer data, financial records, anything confidential), who signs off on AI-generated content before it goes out, and what to do if something goes wrong.
- A training record. Evidence that staff were shown how to use the tools responsibly, and when. A two-hour session with a sign-in sheet meets the AI literacy duty for most businesses.
- Transparency in the right places. A line on your chatbot, a label on AI-generated visuals, a note in your privacy policy about AI use.
That’s it. Five things. None of them require a lawyer, and all five can be done inside a month.
Three things worth doing before Christmas
If you do nothing else this quarter:
- Run the inventory. Ask every team member which AI tools they use, including the free ones on their phone. The answer is always longer than the owner expects, and that gap is the real risk.
- Get the literacy session done. It’s the one obligation that applies to every single business, it’s been enforceable since August, and it’s the cheapest one to close.
- Look hard at recruitment and HR. If any AI tool touches hiring, performance or pay, treat it as high-risk now regardless of where the final deadline lands. The obligations are heavier, but they are also well defined, and starting early turns a compliance problem into a competitive one. Candidates and staff notice when a business handles this properly.
A note on fines
The headline figures are large. Up to €35 million or 7% of turnover for banned practices, and lower tiers for other breaches. For SMEs the Act caps fines at whichever figure is lower, and every signal from the Irish AI Office so far points to a guidance-first approach in the early years. No business is getting a €35 million fine for forgetting to label a chatbot.
The real cost of ignoring this isn’t the fine. It’s losing a tender because a larger customer asked for your AI policy and you didn’t have one. That’s already happening.
Where AIVA fits
Two ways I can help:
AI Governance Starter. A fixed-price package that gets all five items above done for you: tool inventory, risk check, policies, disclosures, a staff handbook with a training guide, and a governance register, with the option of us running the training for your team. Details at aiva.ie/services/ai-governance.
The AI Act check. A free check on this site that tells you whether the Act applies to your business and which of the obligations actually matter for you. Ten questions, about 3 minutes, and nothing you answer leaves your browser. Start there if you’re not sure.
Check if the AI Act applies to your business →
The AI Act was written for the businesses building AI. For the businesses using it, it mostly asks you to know what you’re using and to be honest about it. You were probably going to do that anyway.
Sonia Madsen Founder, AIVA Consulting
References
- Regulation (EU) 2024/1689 (the EU AI Act), full text on EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- European Commission, AI Act overview and implementation timeline: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Commission, AI Act Service Desk (guidance, FAQs and the interactive compliance checker): https://ai-act-service-desk.ec.europa.eu/en
- European Commission, Questions and answers on the AI literacy obligation (Article 4): https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers
- European Commission, General-Purpose AI Code of Practice: https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai
- European Commission, Digital Omnibus package (adopted changes to AI Act deadlines): https://digital-strategy.ec.europa.eu/en/policies/digital-omnibus
- Department of Enterprise, Tourism and Employment, AI Act implementation in Ireland: https://enterprise.gov.ie/en/what-we-do/innovation-research-development/artificial-intelligence/
- Coimisiún na Meán (lead national coordinating authority): https://www.cnam.ie
- AIVA Consulting, Ireland Has an AI Regulator Now: https://www.aiva.ie/blog/ireland-has-an-ai-regulator-now
- AI Office of Ireland, guidance for business: https://aioffice.gov.ie
This post is general information, not legal advice. Deadlines reflect the position at time of writing.