← Back to blog

What the EU AI Act Means for a Small Irish Firm

Yes, the EU AI Act applies to Irish SMEs that use AI. For most firms the obligations are considerably lighter than the headlines suggest, and the heaviest ones have just moved. In May 2026 European lawmakers agreed to defer the high-risk rules from August 2026 to December 2027. What did not move is the transparency duty and the penalty regime, and both of those start on 2 August 2026.

So the date in your calendar is probably still the right date, for the wrong reason. Most Irish SMEs were never going to be caught by the high-risk rules anyway. What they are caught by is the requirement to be straight with people about when they are dealing with AI. That is a much smaller piece of work, and it is worth doing properly.

What changed in May 2026

The Act as originally written had 2 August 2026 as the day most of its substance landed. In May 2026, as part of the digital omnibus package, the Council and Parliament agreed to push the high-risk obligations back.

Standalone high-risk systems, the ones listed in Annex III covering areas like recruitment, credit scoring and insurance pricing, now apply from 2 December 2027. High-risk AI embedded in regulated products under Annex I moves to 2 August 2028. The agreement also softened the AI literacy duty, from an obligation to ensure a sufficient level of literacy to an obligation to take measures supporting it.

A lot of the commentary you will find still runs the old dates. If you have been given a compliance plan built around an August 2026 high-risk deadline, it needs a second look.

What actually starts on 2 August 2026

Three things.

Transparency. Article 50 is the broadest obligation in the whole Act and it was not deferred. If your firm runs a chatbot or any AI system that interacts with people, those people have to know they are talking to a machine. If you publish AI-generated or AI-altered content, in most cases it has to be marked as such, and synthetic media has to carry machine-readable marking. Generative systems already on the market before that date get until 2 December 2026 for the machine-readable marking element.

Penalties. The enforcement machinery becomes operative. Member State penalty powers and Commission fines on general-purpose model providers both switch on. Breaching the transparency rules carries fines up to €15 million or 3% of worldwide annual turnover, which is the number that makes this worth twenty minutes of attention rather than none.

National supervision. Ireland's authorities take up their supervisory role from that date, so there is somebody to answer to.

Note what is not on that list. Conformity assessments, technical documentation, risk management systems, post-market monitoring. All of that is high-risk machinery, and for standalone systems it is now a December 2027 problem.

Which band is your firm in?

The Act sorts AI by how much harm it could do, and the band determines the workload.

Prohibited. Social scoring, emotion inference in the workplace, a short list of practices that have been banned since February 2025. Almost no Irish SME goes near these, though the workplace emotion-inference ban is worth knowing about if anyone has been shown a clever HR product.

High risk. AI that screens CVs or ranks candidates. AI that assesses creditworthiness. AI used in risk assessment and pricing for life and health insurance. This is the band that carries real obligations, and it is also the band that just moved to December 2027. If your firm does any of these, you have eighteen months and you should use them.

Limited risk, meaning transparency obligations. Chatbots, virtual assistants, anything generating content that a person will see. This is where the ordinary Irish SME actually lands, and it is the band that bites in August.

Minimal risk. Using an assistant to draft an internal email, summarise a meeting, tidy a spreadsheet, search your own documents. The overwhelming majority of everyday business AI use sits here and carries no specific obligation under the Act at all.

Most firms we speak to assume they are in band two and discover they are in bands three and four. That is a good afternoon's work to establish, and it usually removes more worry than it creates.

Are you a provider or a deployer?

This is the distinction that decides how much of the Act lands on you, and it is the one most commentary skips.

A provider develops an AI system and places it on the market under its own name. A deployer uses one under its own authority. Buy a tool and use it, and you are a deployer, with a much shorter list of duties. Build one, or badge somebody else's as your own, or modify one substantially, and you can become a provider without ever intending to.

That last part is where firms get caught. Putting your logo and your firm's name on a white-labelled AI assistant can move you into the provider seat, with the documentation burden that comes with it.

We have carried out a formal Article 6(3) risk classification for a live AI system, including the provider versus deployer analysis. It is a documented exercise rather than an opinion. You write down what the system does, which Annex III category it might touch, why it does or does not meet the threshold, and what role you occupy. It takes a focused day for a single system. What it produces is a piece of paper you can hand to a regulator, a client, or an insurer, which is worth considerably more than a confident verbal answer.

What a regulated financial firm should check

If you are CBI-regulated, four things deserve a look beyond the general position above.

Credit and insurance uses are Annex III. Creditworthiness assessment and life and health insurance pricing are named high-risk categories. If AI touches either, you are in the December 2027 band and the preparation is real. Most advisory firms are not doing this. Some are, through tools they did not build.

The Act sits on top of GDPR, it does not replace it. Every AI use involving client data still needs a lawful basis, data minimisation, transparency and records. We have written separately on what GDPR actually asks of a regulated firm using AI. Firms that have the GDPR side in order find the AI Act asks for things they are largely already doing.

Human oversight of anything client-facing. This is a Central Bank expectation and a professional duty before it is an AI Act requirement. AI drafts, a person reviews and approves. No client-facing output goes out unreviewed.

Your vendors' status is your problem too. Ask any AI vendor where processing happens, whether they classify their system as high risk, and what role they take under the Act. A vendor who cannot answer clearly is telling you something.

The dates, plainly

  • February 2025. Prohibited practices already in force.
  • August 2025. General-purpose AI model obligations already in force.
  • 2 August 2026. Transparency obligations apply. Penalties and national supervision switch on.
  • 2 December 2026. Machine-readable marking deadline for generative systems already on the market.
  • 2 December 2027. Standalone high-risk obligations apply.
  • 2 August 2028. High-risk AI embedded in regulated products applies.

What to do this quarter

Three steps, in order, and none of them require a law firm.

Inventory what you use. Every AI tool in the business, including the ones nobody approved. The free chatbot somebody uses for client emails counts. So does the AI feature switched on inside software you already pay for. Most firms find twice what they expected.

Classify each one. Which band, and are you provider or deployer. Write down the reasoning, not just the answer. The reasoning is what a regulator asks for.

Write down who reviews what. One page. Which tools are approved, what data may go into them, who approves any output that reaches a client. If you only do one of these three, do this one, because it is also the control that keeps you right under GDPR.

We describe obligations and practical steps here. This is not legal advice, and a firm with a genuine high-risk use case should take its own.

The firms that go through this properly tend to come out with more than a compliance file. The inventory shows them where AI is already saving time, where it is being used in ways that should stop, and where the real opportunity sits that nobody had got to yet. Knowing what you run is the foundation for deploying anything else with confidence.

The next step. A dploy.ai AI Operations Assessment covers exactly this ground and maps where AI pays for your firm, for a fixed €999 within seven days. If you are a financial advisory firm, our sector page sets out how we work with firms like yours. Or book a short call to talk it through first.

Want to know where AI fits in your business?

We run a structured assessment that identifies your highest-value AI opportunities. Fixed price. Seven days. Guaranteed results.

Book a free 15-minute call