Ireland - AI Use Guidelines (2024)

Interim Guidelines for Use of AI (Public Service)

Ireland

RAI-IE-NA-IGUAPXX-2024
Effective: January 9, 2024
In Force(In Force)
GuidelineGovernance and OversightRisk Management
Export PDF

Ireland’s Department of Public Expenditure, NDP Delivery and Reform published the Interim Guidelines for Use of AI to direct public service bodies on ethical, secure and trustworthy adoption of AI, setting out seven core requirements and a risk‑based approach to adoption. The document is guidance (interim) that complements the National AI Strategy and references cybersecurity guidance from the National Cyber Security Centre. (gov.ie)

Overview

The Interim Guidelines for Use of AI (published 9 January 2024) are a cross‑departmental, interim framework created to guide Irish public service organisations in the responsible, secure and ethical adoption of Artificial Intelligence. The Guidelines implement the Government’s requirement that AI tools used in the public service meet seven requirements for ethical AI (human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non‑discrimination and fairness; societal and environmental well‑being; accountability). They are explicitly framed as practical, high‑level measures to be applied while more detailed operational guidance is finalised and while the EU AI Act and national arrangements are settled. The document further references cyber security guidance issued by the National Cyber Security Centre, which recommends restricting access to generative AI by default and using enterprise/controlled deployments for business purposes. The Guidelines are available from the Department of Public Expenditure on the government publications hub (Interim Guidelines for Use of AI (gov.ie)) and sit alongside the NCSC technical guidance (Cyber Security Guidance on Generative AI for Public Sector Bodies). ([gov.ie](https://www.gov.ie/en/department-of-public-expenditure-infrastructure-public-service-reform-and-digitalisation/publications/interim-guidelines-for-use-of-ai/))

Definitions

The Guidelines define key terms for the Public Service context: 'AI' broadly as systems that display intelligent behaviour by analysing environment and taking actions; 'Generative AI' as models able to create text, images, audio or code (e.g., large language models, multimodal systems); 'enterprise/controlled deployment' as a provider configuration that limits data exposure and supports contractual safeguards; 'risk assessment' as a documented evaluation of harms and mitigations including DPIA where personal data is involved; and 'safe space/sandbox' as a controlled environment for experimentation. The document adopts the EU/EC High‑Level Expert Group conceptual framing for trustworthy AI and ties these definitions to operational checklists for procurement, data governance and human oversight. ([gov.ie](https://www.gov.ie/en/department-of-public-expenditure-infrastructure-public-service-reform-and-digitalisation/publications/interim-guidelines-for-use-of-ai/))

Governance and Institutional Framework

The Guidelines set expectations for governance at both organisational and central levels. Public bodies must allocate clear senior ownership for AI initiatives, integrate AI risk review into existing corporate and ICT governance structures, and engage central supports such as the Office of the Government Chief Information Officer (OGCIO) and the Department of Public Expenditure, NDP Delivery and Reform. Where cyber risks arise, the National Cyber Security Centre is identified as the technical reference point for security practice. The Guidelines encourage the establishment of multi‑disciplinary review panels for higher‑risk use cases (including legal, data protection, equality and security input) and the maintenance of registers documenting AI systems, use cases, risk ratings and mitigation plans. The document also recommends that public bodies adopt an internal approval process for any AI project, combining an approved business case, risk assessment, procurement security checks and an implementation plan that preserves human oversight and traceability. These governance expectations are deliberately flexible to fit departmental structures while ensuring central visibility and coordination. ([gov.ie](https://www.gov.ie/en/department-of-public-expenditure-infrastructure-public-service-reform-and-digitalisation/publications/interim-guidelines-for-use-of-ai/))

Key Focus Areas

The Guidelines prioritise several operational focus areas. First, risk assessment: before any deployment, bodies must assess risks to fundamental rights, privacy, safety and security; where personal data is processed, a Data Protection Impact Assessment is recommended. Second, human oversight: AI must not replace human decision‑makers where outcomes materially affect citizens’ rights; a human in the loop or on the loop is required for significant decisions. Third, data governance and privacy: data minimisation, purpose limitation, secure transfer and retention policies must be applied; the Guidelines stress avoiding inputting sensitive or classified information into public LLMs. Fourth, transparency and explainability: public bodies should record system purpose, limitations and provide intelligible explanations where decisions affect individuals. Fifth, cybersecurity and supplier risk: procurement processes must evaluate provider security, data handling, model training and vulnerability management, and favour enterprise or self‑hosted solutions where possible. Sixth, fairness and non‑discrimination: datasets and models must be evaluated for bias and protected‑class disparate impact, with remediation steps documented. Seventh, environment and societal impact: public bodies should consider wider societal and environmental consequences of AI systems and avoid deployments that increase harms. Finally, accountability and documentation: maintain auditable records of design choices, data sources, model versions and human oversight arrangements to support accountability and redress. The Guidelines encourage controlled experimentation in 'safe spaces' to advance learning while managing risk. ([gov.ie](https://www.gov.ie/en/department-of-public-expenditure-infrastructure-public-service-reform-and-digitalisation/publications/interim-guidelines-for-use-of-ai/))

Implementation Framework

Implementation is presented as a stepwise, proportionate approach: identify use case and business need; classify risk and determine whether the use is low, medium or high risk; conduct DPIA and AI risk assessment where required; develop procurement and contracting terms that address data, IP and security; deploy in a controlled manner with monitoring and human oversight; and maintain documentation for audit and review. The Guidelines advise that public bodies should not use public/free consumer GenAI models for business purposes and should restrict account creation using corporate emails unless an enterprise offering with contractual assurances is in place. Procurement checks should require providers to disclose training data provenance, capability statements, and security certifications. Training and change management for staff are treated as essential, including clear 'Do and Don't' guidance aligned with the NCSC's cyber guidance (e.g., 'Do not input sensitive or secret data into public GenAI models'). ([gov.ie](https://www.gov.ie/en/department-of-public-expenditure-infrastructure-public-service-reform-and-digitalisation/publications/interim-guidelines-for-use-of-ai/))

Monitoring and Evaluation

Public bodies are required to monitor deployed AI systems continuously for performance drift, bias, security incidents and unintended outcomes. The Guidelines recommend periodic reviews aligned with risk levels, incident logging, and escalation procedures to senior governance. Monitoring includes technical checks (accuracy, robustness, adversarial resilience), human oversight effectiveness, and privacy controls. The Department encourages the creation of central registers to track AI use cases and outcomes to permit aggregate learning across the Public Service and to feed into national reporting and regulatory alignment exercises. Lessons learned from pilots and sandboxes should be shared across departments to accelerate learning while preserving confidentiality and security. ([gov.ie](https://www.gov.ie/en/department-of-public-expenditure-infrastructure-public-service-reform-and-digitalisation/publications/interim-guidelines-for-use-of-ai/))

Penalties, Liability, and Appeals

As interim guidance, the document itself does not create new criminal sanctions; enforcement rests with departmental governance, contractual remedies and existing regulatory regimes. Non‑compliance can trigger internal disciplinary measures, procurement contract sanctions, and exposure under data protection law. The Guidelines explicitly reference GDPR obligations and the Data Protection Commission as the regulator for personal data matters; consequently, significant data protection breaches could lead to statutory fines or corrective orders under existing law. The EU AI Act (as it becomes applicable) will introduce additional compliance obligations and potential sanctions for certain high‑risk systems; the Interim Guidelines are intended to help public bodies prepare for those requirements. The document also emphasises the need for clear complaint and redress pathways for affected individuals. ([gov.ie](https://www.gov.ie/en/department-of-public-expenditure-infrastructure-public-service-reform-and-digitalisation/publications/interim-guidelines-for-use-of-ai/))

Relationship to Other Instruments

The Guidelines are explicitly cross‑referenced with several instruments: Ireland's National AI Strategy (“AI – Here for Good”), the National Cyber Security Centre's guidance on Generative AI (June 2023), central procurement rules and the Cyber Security Baseline Standards, and EU instruments such as the European Commission’s Ethics Guidelines for Trustworthy AI and the EU AI Act. They are positioned as interim operational guidance to complement these instruments, helping public bodies bridge between high‑level principles and forthcoming practice‑orientated government guidance and legal obligations. The document also aligns with GDPR obligations and national procurement law, and it points to forthcoming sectoral guidance where required (e.g., health, social protection). ([gov.ie](https://www.gov.ie/en/department-of-public-expenditure-infrastructure-public-service-reform-and-digitalisation/publications/interim-guidelines-for-use-of-ai/))

International Alignment

The Guidelines draw on EU high‑level ethics principles and are designed to align with the EU AI Act's risk‑based approach. They reference international technical and security best practice (via the NCSC) and encourage procurement and contractual requirements consistent with international standards for cybersecurity and privacy. The document supports interoperability of public sector approaches across EU Member States by adopting the seven requirements for trustworthy AI from EC‑level guidance and by preparing public bodies to meet the EU AI Act’s obligations for high‑risk systems, including potential registration or conformity assessment steps required of some providers. The Guidelines also reflect an intent to coordinate with international cybersecurity and standards communities on AI‑specific security measures. ([gov.ie](https://www.gov.ie/en/department-of-public-expenditure-infrastructure-public-service-reform-and-digitalisation/publications/interim-guidelines-for-use-of-ai/))

Implementation Timeline

MilestoneTarget DateNotes
Government approval of interim guidance2024-01-09Published by Department of Public Expenditure; cross‑department working group outputs. View
NCSC generative AI guidance2023-06-01Technical and cyber recommendations published for Public Sector Bodies. View
Rollout of departmental policies & sandboxes2024–2025 (ongoing)Departments to adopt internal policies, DPIAs, and safe space pilots; central coordination to continue.
Preparation for EU AI Act2024–2026Guidelines help bodies prepare for staged obligations under the EU AI Act and national implementation measures.

Compliance Checklist

CheckYes/NoNotes
Is there a clear business case?Yes/NoDocumented business need and approval required.
Has a risk assessment and DPIA been completed (if personal data)?Yes/NoInclude mitigation plan and sign‑off.
Is human oversight defined?Yes/NoRole/responsibility matrix and decision thresholds recorded.
Has procurement checked provider security & model training data?Yes/NoPrefer enterprise/self‑hosted options; contractual clauses required.
Are monitoring and audit arrangements in place?Yes/NoLogging, performance checks, incident reporting documented.

Sources and References

SourceType
Interim Guidelines for Use of AI (Department of Public Expenditure) (gov.ie)Primary Source
Cyber Security Guidance on Generative AI for Public Sector Bodies (NCSC, 01 June 2023)Primary Source
Plain English

Ireland's new Interim Guidelines for Use of AI provide essential direction for all Irish public service bodies on how to adopt Artificial Intelligence systems in a responsible, secure, and ethical way. This guidance applies to all government departments, agencies, and other public sector entities in Ireland, aiming to prepare them for future national and European Union AI regulations.

Effective from January 9, 2024, the guidelines set out several core requirements. Public bodies must conduct thorough risk assessments before deploying any AI, evaluating potential impacts on fundamental rights, privacy, safety, and security. If personal data is involved, a Data Protection Impact Assessment is strongly recommended. Human oversight is paramount: AI systems should not replace human decision-makers in matters materially affecting citizens' rights, requiring a "human in the loop" for significant decisions. Strict data governance is also required, including data minimisation and secure handling. A key prohibition is to - never input sensitive or classified information into public, free-to-use Generative AI models like consumer chatbots. Procurement processes must scrutinise AI providers for security, data handling, and model training practices, favouring enterprise-level or self-hosted solutions.

While these guidelines do not introduce new criminal penalties, non-compliance can lead to significant consequences. These include internal disciplinary actions, contractual sanctions with suppliers, and exposure to existing legal penalties. Notably, breaches related to personal data can trigger investigations and substantial fines from the Data Protection Commission under the General Data Protection Regulation (GDPR). A critical practical takeaway is the strong recommendation to restrict access to public or free consumer Generative AI tools by default for business use. Public bodies are urged to only use enterprise-grade AI solutions that come with clear contractual safeguards and data protection assurances, preventing the accidental leakage of sensitive information.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under Ireland - AI Use Guidelines (2024). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalGovernance and Institutional Framework

    Applies to: Irish public service organisations

    Public bodies must allocate clear senior ownership for AI initiatives
  2. #2CriticalKey Focus AreasBefore deployment

    Applies to: Irish public service organisations deploying AI

    before any deployment, bodies must assess risks to fundamental rights, privacy, safety and security
  3. #3CriticalKey Focus AreasBefore deployment

    Applies to: Irish public service organisations processing personal data with AI

    where personal data is processed, a Data Protection Impact Assessment is recommended.
  4. #4CriticalKey Focus AreasBefore deployment

    Applies to: Irish public service organisations using AI for significant decisions

    AI must not replace human decision‑makers where outcomes materially affect citizens’ rights
  5. #5CriticalKey Focus AreasBefore deployment / Ongoing

    Applies to: Irish public service organisations using AI

    data minimisation, purpose limitation, secure transfer and retention policies must be applied
  6. #6CriticalImplementation FrameworkImmediately

    Applies to: Irish public service organisations

    public bodies should not use public/free consumer GenAI models for business purposes
  7. #7ImportantKey Focus AreasBefore procurement

    Applies to: Irish public service organisations procuring AI systems

    procurement processes must evaluate provider security, data handling, model training and vulnerability management
  8. #8ImportantKey Focus AreasBefore deployment

    Applies to: Irish public service organisations deploying AI

    datasets and models must be evaluated for bias and protected‑class disparate impact, with remediation steps documented.
  9. #9ImportantGovernance and Institutional FrameworkOngoing

    Applies to: Irish public service organisations using AI

    maintenance of registers documenting AI systems, use cases, risk ratings and mitigation plans.
  10. #10ImportantMonitoring and EvaluationOngoing

    Applies to: Irish public service organisations deploying AI

    Public bodies are required to monitor deployed AI systems continuously for performance drift, bias, security incidents and unintended outcomes.
  11. #11ImportantKey Focus AreasOngoing

    Applies to: Irish public service organisations deploying AI

    maintain auditable records of design choices, data sources, model versions and human oversight arrangements
  12. #12ImportantImplementation FrameworkOngoing

    Applies to: Irish public service organisations using AI

    Training and change management for staff are treated as essential, including clear 'Do and Don't' guidance
  13. #13ImportantPenalties, Liability, and AppealsBefore deployment

    Applies to: Irish public service organisations deploying AI

    The document also emphasises the need for clear complaint and redress pathways for affected individuals.

© Regulations.AI — created on 13-Jun-2026