The EU AI Act in Ireland
How Regulation (EU) 2024/1689 applies in Ireland, and the 8 AI instruments Ireland has of its own.
The EU AI Act
The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.
Key dates
- 1 Aug 2024— Entry into Force of the AI Act
- 2 Feb 2025— Prohibited AI practices and AI literacy obligations apply
- 2 Aug 2025— Governance rules and obligations for General-Purpose AI (GPAI) models apply
- 27 Jul 2026— Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- 2 Dec 2026— Watermarking obligations on AI-generated content apply
- 2 Aug 2027— Obligations for high-risk AI systems included in Annex I of the AI Act apply
Ireland’s own AI instruments
8 records tracked for Ireland, beyond the EU-level Act above.
Ireland AI Regulation Act
Ireland · 2026 · 31 Jul 2026
Ireland - AI Act Implementation (366/2025)
Ireland · 2025 · 25 Jul 2025
Ireland - AI Act Implementation Roadmap
Ireland · 2025
Ireland - Responsible AI Use Guidelines
Ireland · 2025 · 7 May 2025
Ireland - AI Data Protection Guidance
Ireland · 2024 · 18 Jul 2024
Ireland - AI Use Guidelines (2024)
Ireland · 2024 · 9 Jan 2024
Ireland - Cyber Security Guidance on Generative AI
Ireland · 2023 · 1 Jun 2023
Ireland - National AI Strategy
Ireland · 2021 · 8 Jul 2021
National authority in Ireland
Named in Ireland’s own records, not inferred.
- Department of Enterprise, Trade and Employment (DETE) - National Single Point of Contact / Coordinating Authority (Minister) — Central coordinating authority, Single Point of Contact and sponsor of National AI Office; policy lead for national implementation.
- Data Protection Commission (DPC) — National data protection authority responsible for GDPR enforcement and oversight of personal-data aspects of AI.
- Central Bank of Ireland — National competent authority and market surveillance authority for financial-sector uses of AI (where designated).
- Competition and Consumer Protection Commission (CCPC) — Market surveillance and consumer protection authority for certain consumer-facing AI products and services.
- Health Products Regulatory Authority (HPRA) — Regulatory authority for medical and health-product related AI systems (designation for health product categories).
- Commission for Communications Regulation (ComReg) — Regulatory oversight where AI intersects with communications services and relevant product categories.
- Health and Safety Authority (HSA) — Market surveillance and safety oversight for AI used in workplace machinery and safety-critical product categories.
Per Ireland - AI Act Implementation (366/2025)
- Minister for Enterprise, Trade and Employment (DETE) — Designated national competent authority and Single Point of Contact for Article 70; coordinating role pending establishment of NAIO
- Central Bank of Ireland — Designated market surveillance authority (Article 74(6) designation in S.I. No. 366/2025)
- Data Protection Commission — Designated market surveillance authority (Article 74(8) designation in S.I. No. 366/2025); supervises data protection aspects of AI systems
- Health and Safety Authority — Designated national competent authority for workplace and certain product safety Annex I points
- Health Products Regulatory Authority — Designated notifying / market surveillance authority for health products and medical device related Annex I points
- Competition and Consumer Protection Commission — Designated market surveillance authority for consumer product related Annex I points and enforcement of consumer protection obligations
- Commission for Communications Regulation — Designated notifying/market surveillance authority for communications and related Annex I points
- Commission for Railway Regulation — Designated national competent authority for rail/transport Annex I points where indicated in the Schedule
- Marine Survey Office (Department of Transport) — Designated market surveillance authority for maritime/marine Annex I points
- Health Services Executive — Designated national competent authority for health-service related responsibilities (as per Departmental announcements)
- National Transport Authority — Designated competent authority for transport/regulatory aspects related to public transport where indicated
- Workplace Relations Commission — Designated competent authority for certain workplace-related Annex I responsibilities
Per Ireland - AI Act Implementation Roadmap
- Department of Enterprise, Trade and Employment (DETE) — Lead coordinating department for national implementation; submit General Scheme and coordinate cross-departmental work.
- Data Protection Commission (DPC) — Designated as one of the national competent authorities with responsibilities linked to data protection and fundamental rights where AI impacts personal data.
- Central Bank of Ireland (CBI) — Competent authority for AI applications in financial services.
- Competition and Consumer Protection Commission (CCPC) — Competent authority for consumer-facing AI matters and market surveillance in relevant sectors.
- Commission for Communications Regulation (ComReg); Commission for Railway Regulation; Health and Safety Authority; Health Products Regulatory Authority; Marine Survey Office — Sectoral competent authorities for communications, rail, workplace safety, health products and maritime respectively.
Per Ireland - Responsible AI Use Guidelines
- Department of Public Expenditure, Infrastructure, Public Service Reform and Digitalisation — Lead author and policy lead for the Guidelines; provides publication, resources and implementation supports.
- Office of the Data Protection Commissioner (DPC) — Regulator for data protection compliance (GDPR) relevant to AI systems processing personal data.
- European Commission / EU AI governance bodies — Provides the EU Artificial Intelligence Act framework and implementation guidance which the Guidelines align with.
Per Ireland - AI Data Protection Guidance
- Data Protection Commission (DPC) — Lead supervisory authority; issuer of the guidance; responsible for GDPR enforcement in Ireland
- European Data Protection Board (EDPB) — EU-level coordinating body for DPAs; issues guidance and statements on AI/data protection interplay
Per Ireland - AI Use Guidelines (2024)
- Department of Public Expenditure, NDP Delivery and Reform — Publisher and central policy lead for public service AI guidance; coordinates cross‑department working group.
- National Cyber Security Centre (NCSC) — Technical cyber security guidance and incident reporting authority for public sector cybersecurity standards and GenAI guidance.
- Data Protection Commission (Ireland) — Regulator for data protection and enforcement of GDPR obligations related to AI processing of personal data.
Per Ireland - Cyber Security Guidance on Generative AI
- National Cyber Security Centre (NCSC) — Issuing authority for cybersecurity guidance and national incident response coordination (CSIRT-IE).
- Department of the Environment, Climate & Communications (DECC) — Parent Department referenced in the guidance; departmental oversight and policy coordination for NCSC activities.
- Department of Public Expenditure, NDP Delivery & Reform (DPENDR) — Lead on interim public service AI guidelines and whole-of-government AI policy coordination.
Per Ireland - National AI Strategy
- Department of Enterprise, Trade and Employment — Lead co-ordinating department for the National AI Strategy and publisher of the strategy and implementation materials
- Data Protection Commission (DPC) — National data protection authority responsible for oversight of compliance with GDPR and data-protection-related aspects of AI deployments
- CeADAR (Ireland’s Centre for AI) — Designated national AI Innovation Hub / Digital Innovation Hub for AI: provides test-before-invest, skills and adoption supports (not a statutory regulator but a key implementation partner)
Penalties in Ireland
As stated in Ireland’s own records.
- Administrative fines in line with the EU AI Act scale (including fines up to the levels referenced in the AI Act such as up to €35 million or a percentage of global turnover, where applicable).
- Orders for corrective action including modification, withdrawal, suspension of use or market recall of AI systems.
- Publication of non-compliance decisions and naming of offending entities (subject to procedural safeguards).
- Temporary or permanent bans on placing specific AI systems on the market or putting them into service.
- Administrative enforcement costs and fees payable to NCAs for investigations and market surveillance activities.
- Civil liability exposure under national tort and consumer law where the Bill clarifies or preserves rights to compensation.
Per Ireland - AI Act Implementation (366/2025)
- S.I. No. 366/2025 is a designation instrument and does not itself impose penalties; national penalty rules required by Article 99 of the AI Act must be laid down separately by Member States. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99?utm_source=openai))
- The AI Act (Article 99) establishes EU-level ceilings for administrative fines (e.g., up to €35,000,000 or up to 7% of worldwide turnover for prohibited practices; up to €15,000,000 or up to 3% of turnover for certain other infringements; up to €7,500,000 or up to 1% of turnover for providing incorrect or misleading information). National procedures, safeguards and exact arrangements for imposing fines are to be determined under national law. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99?utm_source=openai))
- Member States must notify the Commission of national rules on penalties by the AI Act’s date of application and must report annually on administrative fines imposed. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99?utm_source=openai))
Per Ireland - Responsible AI Use Guidelines
- The Guidelines themselves do not create new statutory penalties; non‑compliance may lead to internal sanctions (project suspension, removal of system), contractual penalties under supplier agreements, or disciplinary action for staff.
- Non‑compliance with binding laws referenced in the Guidelines (e.g. GDPR, the EU AI Act) may lead to statutory enforcement actions, administrative fines and remedial orders under those instruments.
- Reputational and operational consequences, including audit findings, Parliamentary scrutiny and potential referral to national regulators (e.g. Data Protection Commission).
Per Ireland - AI Data Protection Guidance
- Administrative fines and corrective measures under the GDPR, including penalties of up to €20 million or 4% of global annual turnover (whichever is higher).
- Orders to suspend or restrict specific processing activities, require remedy or deletion of datasets or models, or impose binding operational measures.
- Possible additional enforcement under Ireland’s <a href="https://www.irishstatutebook.ie/eli/2018/act/7/enacted/en/print">Data Protection Act 2018</a>, including audits and court action.
- Reputational and commercial consequences, contractual liabilities and private-law claims for damages in national courts.
Per Ireland - AI Use Guidelines (2024)
- The Interim Guidelines themselves are non‑binding; enforcement uses existing departmental governance, contractual sanctions and statutory regimes.
- Non‑compliance that results in data protection failures may attract enforcement by the Data Protection Commission under GDPR (e.g., corrective orders, fines).
- Procurement breaches or contractual non‑performance can result in supplier sanctions, contract termination, and financial remedies.
- Serious failures that amount to criminal misconduct or gross negligence will be handled under applicable criminal or employment law regimes.
Per Ireland - Cyber Security Guidance on Generative AI
- No specific fines or penalties are established by this advisory guidance itself; non-compliance may result in internal disciplinary measures under departmental policy.
- GDPR-related enforcement (Data Protection Commission fines and remedial orders) may apply where personal data is mishandled.
- Potential contractual liability and procurement sanctions for failure to follow procurement and security requirements.
- Enforcement under NIS/NIS2 or other sectoral regulatory regimes may apply to entities within scope of those laws.
Per Ireland - National AI Strategy
- None specified in the strategy itself — AI – Here for Good is a policy/strategy document and does not create statutory penalties. Enforcement and penalties (where applicable) remain within existing legal/regulatory regimes (e.g., Data Protection Commission enforcement under GDPR) or prospective EU statutory measures. ([gov.ie](https://www.gov.ie/en/department-of-enterprise-tourism-and-employment/publications/ai-here-for-good-national-artificial-intelligence-strategy-for-ireland/))
Ireland overview
The full picture of AI regulation in Ireland, beyond just the EU AI Act.
Ireland AI regulation overview →