A practical guide to EU AI Act compliance for Irish businesses. Learn what companies using AI should review, document and prepare in 2026.

01

What does the EU AI Act actually require you to do?

Artificial intelligence is already part of everyday business. Employees use ChatGPT to draft emails, marketing teams generate content, recruitment teams use AI-enabled software, customer service teams deploy chatbots and major workplace platforms increasingly integrate AI into products companies already use.

For an Irish business, the important question is not whether the company considers itself an 'AI company'. It is how AI is being used within the organisation. The EU AI Act applies directly across the European Union, including Ireland, and uses a risk-based structure. Different requirements can apply depending on the role of the organisation, the AI system and the purpose for which it is used.

02

Start by finding out where AI is already being used

One of the most practical first steps is creating an AI inventory. This does not need to start as a complicated technical exercise. Ask each department which AI-enabled tools are currently being used, who uses them and what they are used for.

Unofficial employee use matters too. A company may have no formal AI programme while employees are already uploading documents, drafting reports or analysing information through external AI services. This is often described as shadow AI. You cannot manage AI risk effectively if you do not know where AI is being used.

  • ChatGPT, Claude, Gemini or similar generative AI tools.
  • Microsoft Copilot, Google Gemini for Workspace or other AI-enabled productivity tools.
  • AI-enabled recruitment, HR and customer-service software.
  • Automated document analysis, marketing, fraud or risk-detection tools.
  • AI-supported decision-making software and internally developed AI applications.
03

Understand your role under the AI Act

The AI Act places different responsibilities on different actors. A business using an AI system in its operations will commonly be a deployer. A company developing an AI system and placing it on the EU market may instead be a provider, which can involve substantially greater obligations.

There are also rules for importers, distributors and other participants in the AI supply chain. The distinction matters because compliance requirements depend heavily on the organisation's role in relation to each system.

04

Classify the AI use, not simply the software

The AI Act does not treat every AI use in the same way. Some practices are prohibited, certain systems may fall within high-risk rules, some uses carry specific transparency duties, and other business applications may carry fewer AI Act-specific obligations.

It is therefore usually not enough to say 'we use ChatGPT'. Using generative AI to brainstorm marketing headlines is very different from using an AI system to evaluate employment candidates. Context matters.

  • Who uses the system and for what purpose?
  • What information goes into it?
  • What happens with the output?
  • Does the AI influence a decision about a person?
  • Is the system embedded in a product or service supplied to others?
05

AI literacy is already a compliance issue

Article 4 of the EU AI Act requires providers and deployers to take measures supporting AI literacy among staff and other people dealing with AI systems on their behalf. The obligation has applied since 2 February 2025. The European Commission's current AI literacy FAQ states that supervision and enforcement rules apply from 3 August 2026.

The appropriate measures should reflect matters such as people's knowledge and experience and the context in which AI is used. A lengthy training programme is not necessarily the answer. Training should be proportionate to the way employees actually use or oversee AI.

  • When AI may be used and which tools are approved.
  • What information must not be entered into public or unapproved AI tools.
  • Why AI outputs require verification and how hallucinations can arise.
  • Confidentiality, personal data, copyright and intellectual-property risks.
  • How to escalate an AI-related error, concern or incident.
06

Create an internal AI usage policy

Businesses increasingly need clear, usable rules around acceptable AI use. A policy should answer the questions employees actually face rather than relying on broad instructions to 'use AI responsibly'.

Useful rules include whether confidential or personal information may be entered into a given tool, whether AI may generate client-facing material, when AI-assisted research needs human verification, which tools are approved and what to do when an AI-related incident occurs. Without clear rules, employees will often create their own.

07

Review third-party AI suppliers

Most businesses will not develop their own AI systems. They will buy or subscribe to them. That does not remove governance or compliance risk. Important AI procurement should gradually become part of normal supplier due diligence.

  • Who provides the system and what its intended purpose is.
  • What data the system processes and where relevant processing occurs.
  • Whether submitted information may be retained or used for model training under the actual service terms.
  • What contractual protections, security controls and human oversight are available.
  • What AI Act or other compliance documentation the provider makes available.
08

Consider GDPR alongside the AI Act

AI compliance does not replace existing data-protection responsibilities. When an AI use involves personal data, GDPR requirements may still include lawful basis, transparency, data minimisation, security and retention. In circumstances likely to create high risks to individuals' rights and freedoms, a Data Protection Impact Assessment may also be required.

A single AI use can therefore engage several legal and governance frameworks at the same time. AI Act screening should not become a reason to overlook privacy or sector-specific rules.

09

What should an Irish business do now?

For many SMEs, the starting point can be relatively straightforward. Ireland uses a distributed regulatory model that draws on existing sectoral authorities, with the AI Office of Ireland established as the central coordinating authority for implementation of the EU AI Act in the State.

The objective should not be hundreds of pages of documentation. It should be enough governance to know where AI is being used, what risks it creates, which obligations may apply and who is responsible for managing them.

  • Identify where AI is being used and record the purpose of each material system or use case.
  • Determine whether the organisation is a provider, deployer or another regulated actor for each relevant system.
  • Screen AI uses for prohibited practices, high-risk rules and transparency-related obligations.
  • Create practical employee AI rules and introduce proportionate AI literacy measures.
  • Review important AI suppliers and document key governance decisions.
10

Blanche perspective

Start with visibility and ownership. An accurate AI inventory, clear internal rules and a proportionate review process create the foundation for every later compliance decision.

Not sure where your organisation stands? Blanche helps organisations map AI use, identify potential EU AI Act obligations and build practical governance proportionate to their business. Start with an AI compliance assessment to turn your current AI use into a clear set of next steps.

S

Sources

Primary and authoritative sources used for this Insight.

  1. Regulation (EU) 2024/1689, consolidated text
  2. European Commission: AI Act and current application timeline
  3. European Commission: AI literacy questions and answers
  4. Department of Enterprise: AI Office of Ireland and 2026 appointments
  5. Irish DPC: AI, large language models and data protection