[nonimo]
EN
Download

The EU AI Act in Ireland: what your business has to do

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Ireland is in the European Union, so the EU AI Act applies here in full. There is no way to opt out, no grace period for Irish firms and no size threshold that lets a small business ignore it. The more useful point, and one that rarely gets made, is this: most of the Act does not apply to you, because most of it was written for the people who build AI systems rather than for the people who use them.

If you bought your AI rather than built it, the Act calls you a deployer, and a deployer’s list is short. Three things bind you in September 2026. Stay clear of the practices banned by Article 5. Take measures to support AI literacy among the staff who use the tools, under Article 4. Meet the disclosure duties in Article 50 if you run a chatbot or publish text a machine wrote.

Everything else people worry about sits in the high-risk chapter, and that chapter now opens on 2 December 2027. Ireland then added its own layer on top. The Regulation of Artificial Intelligence Act 2026 was signed on 21 July 2026, it created a statutory AI Office, and a statutory instrument made ten days later handed the actual enforcement to fourteen bodies you have probably already dealt with.

Provider, deployer, and the one you almost certainly are

The Act classifies roles rather than companies, and the same company can hold more than one. The Department of Enterprise, Tourism and Employment sets out four of them on its own guidance page, and the distinction between the first two decides nearly everything that follows.

rolewhat it meanshow common
Providerdevelops an AI system, or places one on the EU market under its own name or brandrare outside the technology sector
Deployeruses an AI system under its own authority in the course of its workalmost every organisation
Importerbrings a system developed outside the EU into the EU marketspecialist
Distributormakes a system available in the EU without modifying it, for example a resellerspecialist

Source: Department of Enterprise, Tourism and Employment, The EU AI Act and my organisation.

Why the label decides everything else

Providers carry the heavy obligations: risk management systems, data governance, technical documentation, logging, conformity assessment, registration. Deployers carry a short list that is mostly about how you use the thing, not about how it was made.

Reading a compliance article written for providers and assuming it describes your duties is the most expensive mistake in this area. The cheapest correction is to write down, once, which role you hold for each tool you use, which is the first line of any AI use policy worth having. It is also the reason so many Irish firms have concluded the Act is unmanageable and then done nothing at all, which is the one outcome that is genuinely risky.

The one case where a deployer turns into a provider

There is a trapdoor, and the Government’s own public service guidance flags it. A deployer becomes a provider, with all of a provider’s duties, in two situations: when it puts its own name or trademark on a high-risk AI system, and when it makes a substantial modification to one.

Wrapping a bought model in your own branded product is enough to fall through. Writing prompts for it is not, and neither is buying a licence, although the licence you bought changes what the vendor may do with your text: the four main products differ, as our guide to what Microsoft Copilot does with your data sets out.

Nor is fine tuning it on your own documents, unless what comes out changes the intended purpose of the system, which is the point at which substantial modification starts to bite.

If all you do is use ChatGPT or Copilot at work

This is the position most Irish organisations are actually in, and the numbers say it is arriving fast. The Central Statistics Office reported on 20 August 2026 that the share of enterprises with ten or more people using AI went from around 8% in 2023 to 15% in 2024 and to more than 20% in 2025.

8%of Irish enterprises used AI in 2023
15%in 2024
20%in 2025
Enterprises with 10 or more people. CSO, 20 August 2026

That puts Ireland level with the EU average and behind Denmark on 42% and Finland on 38%. Among enterprises with 250 or more employees the figure went from around 36% in 2023 to almost 60% in 2025, so the larger your organisation, the more likely it already has an AI question it has not answered.

Denmark42%
Finland38%
Ireland, and the EU average20%
Enterprises using AI in 2025. CSO, 20 August 2026

Using an everyday chatbot at work does not make your organisation a provider, and it does not make the tool a high-risk system. General-purpose AI models carry their own chapter of obligations, but those sit on the company that built the model. That is why the model providers have been publishing model documentation since August 2025 and you have not.

What does land on you

The ordinary use of it. What each of the big four does with what your staff type is a separate question, answered by the vendors’ own documents rather than by the Act, and the answers are not the same. We have gone through them for ChatGPT, Claude, Gemini and Copilot.

The reason to read those before reading any more of this one is that the AI Act question and the data protection question arrive in the opposite order to the one people expect. The AI Act asks what the tool is for. Data protection asks what went into it. In an Irish office, the second is almost always the live problem.

The dates, after the omnibus moved them

The AI Act entered into force on 1 August 2024 and applies from 2 August 2026, with a list of exceptions in Article 113 that is longer than the rule itself. Then, on 8 July 2026, the Parliament and Council adopted Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026.

datewhat startswho it lands on
2 February 2025Article 4 literacy and the Article 5 banseveryone, including deployers
2 August 2025duties for general-purpose AI models, and the penalty regimemodel providers, and enforcement
27 July 2026the Digital Omnibus on AI enters into forceit moves the dates below
2 August 2026general application, including Article 50 transparencyproviders and deployers
2 December 2026the two new Article 5 prohibitionseveryone
2 December 2027duties for high-risk systems in Annex IIIproviders, and deployers of those systems
2 August 2028duties for high-risk AI inside regulated productsproduct manufacturers

Source: Article 113 of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

What the omnibus actually did

It deferred. Standalone high-risk systems under Annex III moved from 2 August 2026 to 2 December 2027, and AI embedded in products already covered by EU product safety law moved to 2 August 2028. It did not repeal the high-risk regime and it did not narrow Annex III.

It also left alone everything that was already running. Public bodies read this calendar differently, because Article 27 lands on them and not on you, and we have set out their version of it separately. Article 5 has applied since February 2025. Article 50 started on schedule on 2 August 2026. The penalties chapter has been live since August 2025. If a supplier tells you the Act has been postponed, they have read one paragraph of it.

The provision most people missed

The omnibus added a genuinely new Article 4a, in force since 27 July 2026. It lets providers and deployers process special categories of personal data where that is strictly necessary to detect and correct bias, subject to six cumulative conditions including pseudonymisation, strict access controls and deletion once the bias is corrected.

It creates no obligation to go looking for bias. What it removes is the standard excuse for not looking, which was that checking a hiring model for discrimination would itself require processing data about ethnicity or disability that nobody had a lawful basis to hold. That argument is now much harder to make.

The Irish date that is not fixed yet

There is a second calendar running alongside the European one, and it is unfinished. When the Department announced the AI Office on 30 July 2026, it noted that amendments arising from the Digital Omnibus still need domestic effect and that further legislation would be brought forward in the autumn.

So the Irish enforcement architecture described further down is the position today, not a settled one. That is also why every claim here carries a date, and dates matter just as much when you work out whether putting client data into ChatGPT is a data breach. Anything you build around it should survive one more turn of the handle. That is an argument for writing down decisions and keeping records, and against paying anyone for a compliance certificate.

The Article 5 prohibitions, and the two arriving in December 2026

These are the only rules in the Act that are absolute, and they have bound everybody since 2 February 2025. Most of the list is exotic: social scoring, untargeted scraping of facial images, predicting who will commit a crime from personality traits, real-time remote biometric identification by police in public places.

Two will not stay exotic, because the technology to do them is now sold as an ordinary feature of ordinary software. Both are worth naming explicitly in your acceptable use policy, because an employer can fall into them by buying a feature rather than by taking a decision, which is not how most compliance risk usually arrives.

banned practicethe ordinary version of itwho supervises it in Ireland
Article 5(1)(f), inferring emotions at worksentiment scoring on staff calls or interviewsWorkplace Relations Commission
Article 5(1)(g), biometric categorisation by protected traitinferring ethnicity or beliefs from a faceData Protection Commission
Article 5(1)(c), social scoringranking people across unrelated contextsData Protection Commission

Source: S.I. No. 405 of 2026, Schedule 3, which assigns each point of Article 5(1) to a named Irish body.

Emotion inference at work catches ordinary employers

Article 5(1)(f) bans AI systems used to infer emotions of a person in the workplace and in education institutions, with a narrow exception for medical or safety reasons. Contact centre software that scores agent tone, interview tools that rate candidate enthusiasm and wellbeing dashboards built on voice analysis all sit squarely inside it.

The ban is already in force: it has applied since February 2025, it sits in the €35 million band rather than the €15 million one, and in Ireland the Workplace Relations Commission is named as the market surveillance authority for it outside education institutions. That is a body Irish employers already know how to meet, in a forum where employees already know how to bring things.

The two new ones

The omnibus added prohibitions on AI systems that generate or manipulate intimate imagery of an identifiable person without their explicit consent, and on systems that generate child sexual abuse material. Both take effect on 2 December 2026.

They are drafted with unusual care. Placing such a system on the market is prohibited only where that generation is its intended purpose, or where it is a reasonably foreseeable and reproducible outcome without adequate safeguards. Using one for that purpose is prohibited outright, with no equivalent qualification.

AI literacy under Article 4, and what the rewrite changed

Article 4 has applied since 2 February 2025 and it is the obligation most Irish businesses have quietly missed, because it reads like a suggestion. The July 2026 rewrite softened the verb without removing the duty.

Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf.

Article 4(1) of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744

The amended text then adds a sentence that was not there before: the obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual. Two new paragraphs oblige the Commission to publish practical examples of compliance, and the AI Board to adopt recommendations. The direction of travel is support and evidence, not certification.

What that means you should keep

Something dated, something specific to the tools you actually use, and something that names the people it reached. A slide deck sent to the whole company is thinner evidence than a half day session with an attendance list and a copy of the policy people signed.

If you have neither, the quickest sensible starting point is an acceptable use policy that says which tools are approved and what must never be typed into them. There is a free template for that you can adapt. For the learning half, the State now runs AIReady.ie, a free set of short lessons, which is a reasonable baseline to point staff at and to record.

what to keepwhy it is the useful evidence
a dated attendance listit names the people the measure actually reached
the version of the policy they sawit ties the training to a rule, not to a topic
the list of tools it coveredArticle 4 is about the systems you use, not about AI in general

This is our reading of what supports an Article 4 measure, not a checklist published by any authority.

Why the obligation is not as silly as it sounds

The ground under this is softer than people assume. When the CSO ran the OECD Trust Survey in Ireland in 2025, some 56% of respondents said they understood the term artificial intelligence well enough to explain it to someone else, 42% had a general idea, and 2% were not familiar with it at all.

56%
of people in Ireland could explain what AI means to someone else. OECD Trust Survey 2025, run by the CSO

Third highest of the 38 countries surveyed, behind Luxembourg and Norway on around 67%, and still close to half the adult population who would struggle to describe what the tool on their desk is doing. Article 4 is asking you to close that gap for the people who use it on your behalf, not to make them engineers.

Article 50: saying it is a machine, and marking what it writes

This is the duty that started on 2 August 2026, and it is the one most Irish websites are now quietly in breach of. Article 50 sets four separate duties, and they do not all fall on the same party.

dutywho owes itthe everyday version
Tell people they are talking to an AIthe provider, by designyour website chatbot
Mark generated content as machine readablethe providerwatermarking inside the tool
Tell people an emotion or biometric system is runningthe deployerscoring applied to staff or visitors
Disclose a deepfake, or AI text on public interest mattersthe deployermarketing images, published copy

Source: Article 50(1) to (4) of Regulation (EU) 2024/1689, in application since 2 August 2026.

The exceptions are narrower than they read

Public bodies in Ireland are ahead of the private sector on this one, because their own guidance told them to do it before the Article became applicable, as we cover in the guide to AI in Irish local authorities.

The chatbot duty falls away only where the AI is obvious from the point of view of a person who is reasonably well informed, observant and circumspect. A widget in the corner of a homepage with a human first name is not obvious, and giving it a human first name is an argument against you rather than for you.

The published text duty falls away where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. That is a real exception and a useful one. It also means somebody has to actually hold that responsibility rather than skim the draft on the way out.

2 August 2026
the date Article 50 transparency started applying, with no transition period. Article 113 of Regulation (EU) 2024/1689

There is no grandfathering here either. A chatbot that went live in 2024 owes the disclosure today, and the fix is usually a line of copy rather than a project. That is the rare AI Act obligation an Irish business can close this afternoon, which is a reason to close it before anything harder.

Who polices it here

Coimisiún na Meán is the Irish market surveillance authority for Article 50 where the provider or deployer is an intermediary service, an audiovisual media service, a sound broadcasting service, a designated online service or a hosting service. That designation arrived with S.I. No. 405 of 2026 and it is new.

For everybody else, Article 50 breaches sit in the €15 million band of Article 99(4), the same band as the deployer obligations. Article 50(5) adds a timing rule that is easy to miss: the information has to reach people at the latest at the time of the first interaction or exposure, and it has to meet the applicable accessibility requirements.

High risk: what it covers, and why it now lands in December 2027

High-risk status comes from a list, not from how dangerous your use feels. Annex III names eight areas, and a system is high-risk if it is intended to be used for one of the purposes described there. Three of those areas reach ordinary Irish businesses.

Annex III areathe version that reaches an ordinary business
Point 4, employmentCV screening, ranking candidates, task allocation, promotion or termination
Point 5(b) and (c), credit and insurancecreditworthiness scoring, risk pricing for life and health cover
Point 3, educationadmissions, assessment scoring, monitoring during exams

Source: Annex III of Regulation (EU) 2024/1689. Points 1, 2 and 6 to 8 sit mostly with the State and with critical infrastructure.

Recruitment is the one that catches ordinary employers

If you use a tool that filters or ranks job applications, you are the deployer of a high-risk system. That is true today. What changes on 2 December 2027 is that the Article 26 deployer duties attach to it, and those duties are specific enough to plan for.

Use the system in line with the provider’s instructions. Assign human oversight to someone competent, trained and with the authority to override it. Make sure the input data you feed it is relevant and sufficiently representative. Keep the logs. And tell the workers and their representatives before you put it into service.

The fundamental rights assessment, and who has to do one

Article 27 adds a second document on top for a narrower group. Before deploying an Annex III high-risk system, deployers that are bodies governed by public law, or private entities providing public services, and deployers of the credit and insurance systems in points 5(b) and (c), must assess the impact on fundamental rights.

The phrase that catches Irish companies is the second one. A private firm running a public service under contract owes the same assessment as the public body that hired it, which is why anyone bidding for that work should read what the Act asks of local authorities as well as this guide.

The assessment has six prescribed contents, it can refer back to a data protection impact assessment under Article 35 of the GDPR, and under Article 27(3) its results go to the market surveillance authority.

The deadline moved, the classification did not

The most common misreading of the omnibus in Ireland this summer is that the high-risk rules went away, when all that moved is the date the obligations bite.

A recruitment screening tool bought today is a high-risk AI system today. The fact that its duties attach in December 2027 is a reason to choose a supplier who will still be able to hand you the documentation then, rather than a reason to stop asking for it now. Contracts signed this year will still be running.

Before you buy: the questions that decide this later

Almost everything in this guide is easier if the answers were pinned down before the purchase order. Several of them overlap with what an insurer will ask you at renewal, and those are covered in our guide to the AI questions on a cyber questionnaire. These are the five that matter, in the order a supplier will find hardest to dodge.

  1. Which role are you, and which am I? Ask the supplier to say in writing that it is the provider and you are the deployer. If it will not, find out why.
  2. Is any part of this in Annex III? A straight yes or no, with the point number. A supplier who cannot classify its own product has not read the Regulation.
  3. What will you give me in December 2027? Instructions for use, the technical documentation a deployer needs, and the logging the system produces. Get the list now.
  4. Where does my data go, and is it used for training? This is a data protection question rather than an AI Act one, and it is the one your staff will actually trip over.
  5. Who is your model provider, and what happens when they change terms? The subprocessor chain is where most of the surprises live.

The answer that should worry you

It is not a refusal that should worry you. A supplier who says a system is not high-risk and explains why is more useful than one who says it is fully AI Act compliant, because there is no such thing as an AI Act compliant product in the abstract. Compliance is a property of a deployment, and half of it is yours.

The NCSC makes the same point in its 2026 guidance to the public sector, which is worth reading even if you are a private business: it asks whether the procurement evaluation considers the vendor’s own supply chain, including the underlying model provider and any subprocessor.

Who enforces this in Ireland, and the Act that set it up

Ireland chose a distributed model. Rather than create a single AI regulator, the Government gave the job to the sectoral regulators who already supervise each area, and built a coordinating office on top. The architecture sits in two statutory instruments and one Act.

instrumentdatewhat it does
S.I. No. 366 of 2025made 25 July 2025first designations, product areas plus the Central Bank and the DPC
Regulation of Artificial Intelligence Act 2026signed 21 July 2026creates Oifig IS na hÉireann, powers, adjudication, fines
S.I. No. 405 of 2026made 31 July 2026designations for Annex III and Article 5, and for the Office itself

Sources: the Irish Statute Book. The 2026 Act is Number 31 of 2026.

Fourteen bodies, and how to find yours

Add up the distinct bodies named in the three Schedules of S.I. No. 366 of 2025 as substituted by S.I. No. 405 of 2026, plus the one named in Regulation 4(4), and the total comes to 14.

They are the Health and Safety Authority, the Competition and Consumer Protection Commission, the Marine Survey Office, the Commission for Communications Regulation, the Commission for Railway Regulation, the Health Products Regulatory Authority, the Data Protection Commission, the National Transport Authority, the Commission for Regulation of Utilities, the Workplace Relations Commission, the Health Service Executive, the Central Bank of Ireland, Coimisiún na Meán and Oifig IS na hÉireann.

The practical consequence is that there is no single number to ring, and that an answer for the whole organisation is more useful than one per tool, which is the case we make on the organisations page. If your AI question is about hiring, it is the Workplace Relations Commission. If it is about personal data inside an Annex III system, it is the Data Protection Commission. If it is a lending decision, it is the Central Bank.

The Office that coordinates, and the gap it was designed to fill

Oifig IS na hÉireann, the AI Office of Ireland, was established as an independent statutory body under Part 2 of the 2026 Act, with Paul Byrne appointed as its first Chief Executive on 30 July 2026. Section 9 gives it coordination, cooperation, literacy and public awareness functions, and section 42 makes it the single point of contact under Article 70(2).

14
bodies named as market surveillance authorities across S.I. No. 366 of 2025 as amended by S.I. No. 405 of 2026

There is a detail here that explains an odd sequence. The published Bill dropped the market surveillance designation the General Scheme had given the Office, which left Ireland with a single point of contact that was not itself a market surveillance authority, contrary to Article 70(2). Ten days after the Act was signed, Regulation 4(4) inserted by S.I. No. 405 of 2026 designated the Office as a market surveillance authority for the purposes of Article 70(1).

21 Julythe Act is signed into law
30 Julythe Office gets its first chief executive
31 Julythe statutory instrument closes the gap
Ten days in 2026 that built the Irish enforcement architecture

The speed is the point. An architecture assembled in ten days, with a gap closed by statutory instrument and more legislation promised for the autumn, is one that will keep moving. Build your records so that they survive a change of regulator, and avoid anything that depends on today’s allocation staying still.

The powers, and the two ways a complaint reaches you

Part 5 of the 2026 Act rarely gets quoted, but everybody should read it once. Market surveillance authorities appoint authorised officers under section 68, who have powers of inspection under section 70, and who can serve a contravention notice under section 71 or a prohibition notice under section 72.

The notices are the part worth planning for, because they arrive before any fine does and they carry their own deadlines. A contravention notice says what is wrong and what has to change. A prohibition notice stops the activity. Section 77 gives a right of appeal against certain measures, which is a reminder that the first letter is not the last word.

Two routes bring them to your door. Section 61 lets anyone complain to a market surveillance authority about an infringement. Section 62 covers the reporting of infringements and the protection of reporting persons, applying the Protected Disclosures Act 2014 to them. In plain terms, your own staff can report you, and the law protects them when they do.

There is a third route that is unusual and worth knowing. Section 53 lists nine relevant fundamental rights public bodies, among them the Irish Human Rights and Equality Commission, the Ombudsman and the Electoral Commission. Under section 59, such a body can request that a market surveillance authority organise testing of a high-risk system.

61anyone may complain to the authority
62staff may report, and are protected
59a rights body may ask for testing
Three routes into an investigation. Sections of the Regulation of Artificial Intelligence Act 2026

None of the three requires a regulator to go looking. That is the practical difference between this regime and a market surveillance regime that relies on inspections, and it is why the internal answer matters more than the external one. An organisation whose own staff would report it has already failed the test that counts.

The fines, and the Irish ceiling that is not in the Regulation

Article 99 sets three ceilings, and each is expressed as a euro figure or a percentage of worldwide annual turnover, whichever is higher. For SMEs and small mid-cap enterprises, paragraphs 6 and 6a flip that round: whichever is lower.

Banned practices, Article 5€35 million
Deployer duties and Article 50€15 million
Wrong information to a regulator€7.5 million
Ceilings in Article 99(3) to (5), or 7%, 3% and 1% of worldwide turnover if higher

The middle band is the one that matters to a deployer. It covers the Article 26 deployer obligations and the Article 50 transparency duties, at up to €15 million or 3% of worldwide annual turnover. The top band, up to €35 million or 7%, is reserved for the Article 5 prohibitions.

The bottom band, up to €7.5 million or 1%, is for supplying incorrect, incomplete or misleading information to a notified body or a national competent authority in reply to a request. Section 105(4) of the Irish Act ties that band to seven named sections of its own, including replies to a contravention notice and to a notice of suspected non-compliance.

What Ireland added on top

Article 99(8) leaves each member state to decide how far fines may be imposed on its own public authorities. Ireland answered in section 105(5)(a): a fine on a public body within the meaning of section 10 of the Data Sharing and Governance Act 2019 shall not exceed €1,000,000.

That definition includes a local authority at subsection (1)(i), so the ceiling for a county council is a fraction of the private sector one. We have written separately about what the Act asks of Irish local authorities, because the rest of their position is very different from yours.

Nobody in Ireland writes a penalty notice

Ireland also chose an unusual route to the fine itself, and it is worth knowing before a consultant tells you enforcement is imminent. Under Part 6 of the 2026 Act, the market surveillance authority does not impose the fine.

An independent adjudicator, appointed by the Minister under section 117 and drawn from a register kept under section 120, makes findings on breach and on amount. The authority then decides on the finding, and under section 114 the adjudication takes effect only when confirmed by the High Court. That is a longer road than a regulator signing a notice, with appeals built in at two levels.

The AI Act and the GDPR are different laws, and they stack

These are the two most confused things in Irish AI compliance, so it is worth saying plainly. They ask different questions, they are triggered by different facts, and a use of AI can be perfectly fine under one and a serious problem under the other. The GDPR half is the one that decides whether an assistant may see a client file at all, and the criteria behind that call repay reading on their own.

EU AI ActGDPR and Data Protection Act 2018
the questionwhat kind of system is this, and what is it forwhose personal data is processed, and on what basis
triggerthe purpose the system is intended forany personal data, however small the amount
Irish regulatorone of fourteen, by sectorthe Data Protection Commission

The Data Protection Commission wears two hats

The DPC is the data protection supervisory authority for Ireland and, under S.I. No. 405 of 2026, it is also the market surveillance authority for Annex III points 1, 6, 7 and 8 and for most points of Article 5. The same office can look at one deployment through two statutes, with different tests and different ceilings.

It is also the regulator named in the privacy documentation of the tool most of your staff are using, as our guide to what OpenAI keeps sets out.

Its guidance on the data protection half is not new. The DPC published a note on AI, large language models and data protection on 18 July 2024, and its framing there is still the one to start from: as a user of an AI product relying on personal data, your organisation could be a data controller, and a formal risk assessment should be considered.

The question in that note that decides everything

If someone asks you for access to their personal data, or to delete the personal data you hold on them within the AI system, can you do it? That one sentence in the DPC note quietly settles whether your AI use is defensible.

If the answer is no, you have a GDPR problem, and the AI Act will not help you with it. The fix is knowing what left the building, not writing a policy document, which is a question about the payload rather than about the tool.

What the AI Act does not fix: the client data an employee pastes

Here is the gap that neither the Act nor the omnibus closes, and it is the one that actually costs Irish firms money. Nothing in the Regulation stops an employee opening an everyday chatbot and typing a client’s name, address and file reference into it.

That is neither a prohibited practice nor a high-risk system, and it will not appear in any inventory, but it is a disclosure of personal data to a third party, which makes it a data protection question, and possibly a personal data breach depending on what happened next.

The Act helps at one remove. Article 4 literacy is the hook for training people not to do it, and the Article 26 duties give you a usable template for oversight even before they bind you. But the control itself has to live somewhere else, and there are only three places it can realistically live: the contract with the vendor, the configuration of the account, and what leaves the machine in the first place.

What a tool can do here, and what no tool can do

This is where we have an interest, so here is the shape of it plainly. Nonimo is a Mac and Windows app that sits between the person and the chat window. You call it, it finds names, addresses, emails, phone numbers, dates of birth, company names, card numbers and IBANs in what you are about to send, and it replaces them with markers such as [PERSON_1] and [ADDRESS_1] before the text leaves the machine.

The engine runs on the computer, the policy step is set by IT rather than by each user, and the mapping is kept encrypted on the user’s own machine so the text can be put back afterwards. There is a free plan with a limit of 200,000 words a month.

It pseudonymises, and that is not the same as anonymising

Two things it is not, and they matter more than the pitch. It pseudonymises rather than anonymises, and under Article 4(5) of the GDPR that means the data is still personal data and you are still its controller. For the provider, that depends on who holds the key. Irish identifiers have rules of their own, as Spanish and Australian ones do: an Eircode is caught on its own, and a PPS number when its name sits beside it.

And it does not make anybody compliant with anything, because compliance belongs to the controller rather than to a piece of software. What it changes is what is in the payload, which is a smaller claim than the market usually makes and an easier one to check. The controller’s side of it, from the processor contract to the statute that limits who may use a PPSN, is the part no software carries.

the claimwhat is actually true
it anonymisesit pseudonymises, and the mapping is kept, encrypted, on the user’s machine
it covers every Irish numberit covers the PPS number, the Eircode and the IHI by name, and lets unlabelled digits through by design
it blocks the pasteby default nothing is blocked, and it is not a data loss prevention product

The engine’s categories are declared in the source, and every claim above can be checked against them.

The reason to be this exact about it is that the exact version is the only one that survives a procurement questionnaire. A supplier who tells an Irish firm its product delivers anonymisation has made a statement the Data Protection Commission can test, and the test is simply whether anyone can reverse the mapping. If the answer is yes, and for a tool whose whole point is putting the names back it is always yes, the claim was wrong.

If you want the organisational version rather than the desktop one, that is on the organisations page. If an insurer or a client is already asking you about your AI use, the questions and how to answer them are covered in our guides to the cyber questionnaire and to cyber cover in Ireland.

Sources

Common questions

Does the EU AI Act apply to Irish businesses?

Yes, in full. Ireland is a member state and the Act is a regulation, so it applies directly without being transposed. There is no size threshold. Most of its weight, though, falls on the people who build AI systems rather than on those who use them.

What is a deployer under the EU AI Act?

An organisation that uses an AI system under its own authority in the course of its work. If you bought a tool rather than built it, and you have not put your own name on it, you are a deployer. It is the lightest of the four roles.

What do I have to do right now if my staff use ChatGPT at work?

Three things. Stay clear of the practices banned by Article 5, take measures to support AI literacy among the staff who use it under Article 4, and meet the Article 50 disclosures if you run a chatbot or publish text a machine wrote.

When do the high-risk rules start in Ireland?

2 December 2027 for systems listed in Annex III, and 2 August 2028 for AI built into regulated products. Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved both dates. The classification itself did not change.

Who enforces the EU AI Act in Ireland?

Existing sectoral regulators. The two designation instruments name fourteen bodies between them, including the Data Protection Commission, the Central Bank, the Workplace Relations Commission and Coimisiún na Meán. The AI Office of Ireland coordinates them and is the single point of contact.

What are the fines under the EU AI Act?

Up to €35 million or 7% of worldwide annual turnover for a banned practice, €15 million or 3% for most other breaches including Article 50, and €7.5 million or 1% for giving a regulator wrong information. For SMEs the lower figure applies.

Is AI literacy under Article 4 a training obligation?

It is an obligation to take measures, not to certify anyone. The wording amended in July 2026 says providers and deployers shall take measures to support the development of AI literacy, and adds that this does not require guaranteeing any specific level for any individual.

Does the EU AI Act replace the GDPR?

No. They are separate laws with separate triggers and they apply at the same time. The AI Act asks what kind of system you are using. The GDPR asks whose personal data went into it. A use can be fine under one and a problem under the other.

Do I have to tell people when a chatbot on my website is AI?

Yes, since 2 August 2026. Article 50 puts the duty on the provider to design the system so people are told, unless it is obvious to a reasonably observant person. Deployers carry their own version for deepfakes and for emotion recognition.

Can an employee report my company to a regulator over AI?

Yes. Section 62 of the Regulation of Artificial Intelligence Act 2026 covers the reporting of infringements and the protection of reporting persons, and applies the Protected Disclosures Act 2014 to them. Section 61 also lets anyone complain to a market surveillance authority.