The EU AI Act for Irish small businesses
Most Irish small businesses that simply use AI tools like ChatGPT, Claude or Make are "deployers" under the EU AI Act, not "providers", and deployers of ordinary low-risk AI carry only two real duties: make sure staff have a reasonable level of AI literacy, and tell people when they are talking to a bot or looking at AI-generated content. The heavy paperwork in the Act lands on high-risk systems and on the companies that build the models, not on a five-person firm using a chat assistant to draft emails.
This guide is written for owners of small Irish businesses, not for lawyers. It sets out the real dates, what the words "provider" and "deployer" mean in practice, a checklist you can run in ten minutes, who enforces the Act in Ireland, and the short list of things worth doing this month. It is general information, not legal advice. If you are near a high-risk use case, get a solicitor.
What is the EU AI Act, in one paragraph?
The AI Act is a single EU-wide product safety law for artificial intelligence. It sorts AI by risk rather than by technology. A small number of uses are banned outright, such as social scoring and untargeted scraping of faces to build a recognition database. A defined list of uses is "high risk", such as AI that screens job applicants or decides on credit, and those carry real engineering, documentation and human oversight duties. A third group carries transparency duties only, such as chatbots and synthetic media. Everything else, which is where nearly all small business use sits, has no specific obligations under the Act at all.
Two more things are worth knowing. The Act applies to you if your AI output is used in the EU, wherever the vendor sits. And it sits on top of GDPR rather than replacing it. If your AI use touches personal data, the Data Protection Commission's rules still apply exactly as before.
What are the real dates?
The timeline moved in 2026, so any article written before July 2026 is likely out of date on the high-risk dates. Here is where it stands as of 19 August 2026.
| Date | What starts | Relevant to a typical SME? |
|---|---|---|
| 1 Aug 2024 | Regulation enters into force | No action |
| 2 Feb 2025 | Banned AI practices, plus the AI literacy duty (Article 4) | Yes. The literacy duty applies to every organisation using AI |
| 2 Aug 2025 | Rules for general-purpose AI models, governance structures, penalties | Falls on model makers such as OpenAI and Anthropic, not on you |
| 2 Aug 2026 | Transparency duties (Article 50): tell people they are dealing with AI; mark AI-generated content | Yes, if you run a chatbot or publish synthetic media |
| 2 Dec 2026 | End of the grace period for machine-readable marking on systems already on the market before August 2026 | Vendor side, mostly |
| 2 Dec 2027 | High-risk obligations for stand-alone Annex III systems, deferred from Aug 2026 | Only if you use AI for hiring, credit, worker monitoring, education or similar |
| 2 Aug 2028 | High-risk AI embedded in regulated products under Annex I | Manufacturers |
The deferral came through the Digital Omnibus on AI, which entered into force on 27 July 2026. It moved the deadline because the harmonised technical standards were not ready. It did not water down the substance of the high-risk rules, and there is no further extension built in.
Provider or deployer: which one are you?
This single distinction decides most of your obligations, and it is simpler than it sounds.
A provider develops an AI system, or has one developed, and puts it on the market under its own name or trademark. Anthropic is a provider of Claude. OpenAI is a provider of ChatGPT.
A deployer uses an AI system under its own authority in the course of business. A Waterford accountancy firm with five Claude seats is a deployer. A salon using an AI booking assistant is a deployer. Deployer duties are far lighter than provider duties.
There is one trap. If you take a general-purpose system, put your own brand on it and sell it on, or if you substantially modify a high-risk system or change what it is used for, you can become a provider yourself and inherit the provider duties. Buying a white-label chatbot and selling it to your own clients under your logo is the usual way a small firm walks into this. If that is your plan, take advice first.
Does the AI Act apply to me? A ten-minute checklist
Work down the list. Answer honestly rather than optimistically.
- Do you use any AI tool in the business at all? Chat assistants, AI note takers, AI in your CRM, AI features inside Canva, Microsoft 365 or your accounts package all count. If yes, the AI literacy duty in Article 4 applies to you. If no, nothing else on this list applies.
- Does a customer ever interact directly with an AI system of yours? A website chatbot, an AI phone answerer, an automated email responder that writes its own replies. If yes, from 2 August 2026 you must make clear that the person is dealing with AI, unless it is obvious to a reasonable person.
- Do you publish AI-generated or AI-edited images, audio or video that could pass for real? If yes, deepfake and synthetic media labelling duties apply. AI-assisted text on matters of public interest also needs disclosure where it is published without human review.
- Do you use AI to screen CVs, rank candidates, allocate tasks, monitor or evaluate staff, or decide on credit, insurance pricing or access to essential services? If yes, you are near the high-risk list in Annex III. Duties here are real: human oversight, informing affected workers, logging, and using the system per the provider's instructions. Get advice, and note the 2 December 2027 date.
- Do you brand and resell an AI system as your own? If yes, you may be a provider, not a deployer. Get advice.
- Does the AI touch personal data? Almost always yes. That is GDPR, and it is the part most Irish SMEs actually get caught by. See our guide on whether Claude is GDPR compliant in Ireland.
If you answered yes only to items 1 and 6, which is the common case, your AI Act exposure is genuinely small. Two duties, both cheap to satisfy.
Duty one: AI literacy (Article 4)
Since 2 February 2025, providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and anyone else operating AI on their behalf. The Digital Omnibus softened the wording from guaranteeing a level of literacy to supporting its development, but the duty is still there and it applies regardless of company size. Read the text at Article 4.
What "sufficient" means is proportionate to your context: what the tools do, who uses them, and what could go wrong. There is no certificate to buy and no register to join. For a small Irish firm, a defensible position looks like this:
- A short written AI use policy: which tools are approved, what may and may not be pasted into them, who to ask.
- One training session for staff covering hallucinations, confidentiality, checking output, and never pasting client data into a personal free account.
- A dated note of who attended and what was covered. That note is your evidence.
- A refresh when you add a new tool or a new person.
An afternoon of work, once. That is the whole of it for most firms. Our Claude for Business setup includes the policy and the training session for this reason.
Duty two: transparency (Article 50), from 2 August 2026
From 2 August 2026, three things matter to a small business.
Chatbots. If people interact with an AI system directly, they must be told, unless it is obvious to a reasonably well-informed person. A line of text such as "You are chatting with an AI assistant. Ask for a human at any time" on your website widget satisfies this. It is a one-line change, and it also reduces complaints.
Synthetic media. AI-generated or manipulated image, audio and video content that resembles real people, places or events must be disclosed as artificially generated. This is aimed at deepfakes. If you use an AI-generated stock-style image in a blog post, say so in the caption and move on.
AI-generated text on public interest matters. Text published to inform the public on matters of public interest must be disclosed as AI-generated, unless it went through human review with someone holding editorial responsibility. In practice, if a human edits and signs off your blog posts, you are outside this.
The full text is at Chapter IV of the Act.
What you do not have to do
Plenty of scare-marketing is circulating. For an ordinary SME using ordinary AI tools, none of the following is required by the AI Act:
- Register your business or your AI use on any EU database. Registration duties attach to providers of high-risk systems.
- Appoint an "AI officer". The Act does not create that role.
- Carry out a fundamental rights impact assessment. That falls on deployers of certain high-risk systems, mainly public bodies and providers of essential private services.
- Get a conformity assessment or CE marking for the tools you buy. That is the vendor's job.
- Buy a certification. There is no AI Act certificate for buyers.
- Stop using a US-based AI tool. Vendor location is not the test; the GDPR transfer position is a separate question, and it is handled by the vendor's data processing agreement.
Who enforces the AI Act in Ireland?
Ireland chose a distributed model rather than one AI super-regulator. Under the European Union (Artificial Intelligence) (Designation) Regulations 2025, S.I. No. 366 of 2025, and a follow-up announcement in September 2025, fifteen existing bodies act as national competent authorities in their own sectors. They include the Data Protection Commission, the Competition and Consumer Protection Commission, the Central Bank of Ireland, ComReg, Coimisún na Meán, the Health and Safety Authority, the HPRA and the Workplace Relations Commission.
A national AI Office coordinates them, acts as the single point of contact for the EU, and runs the regulatory sandbox. It must be operational by 1 August 2026. The Department of Enterprise, Tourism and Employment holds the policy lead, and its AI pages are the place to watch for Irish guidance. Your Local Enterprise Office and Enterprise Ireland are the practical route to funded digital and AI adoption support.
For a small business, the sensible reading is this: the regulator you are most likely to hear from about AI is the Data Protection Commission, about personal data, not about the AI Act itself.
What are the penalties?
Fines are tiered. Banned practices attract up to 35 million euro or 7 per cent of worldwide annual turnover. Most other breaches attract up to 15 million euro or 3 per cent. Supplying incorrect information to authorities attracts up to 7.5 million euro or 1 per cent. For SMEs and start-ups, the Act applies the lower of the fixed amount and the percentage, rather than the higher. These ceilings are aimed at systemic abuse, not at a plumber whose chatbot lacks a disclosure line.
What to actually do this month
- List your AI tools. One page. Tool, who uses it, what data goes in, who pays for it. Shadow AI on personal accounts is the real risk, and this is how you find it.
- Write a one-page AI use policy. Approved tools, banned inputs, the human review rule, who to ask.
- Run one training session and date the record. That is Article 4 handled.
- Add the disclosure line to any chatbot or AI phone answerer before 2 August 2026. If you have already passed that date, do it now.
- Move business use onto business accounts. Personal free plans usually have no data processing agreement and weaker training controls. See how Claude handles business data.
- Check whether any use case sits near Annex III. If you use AI in hiring or credit decisions, put a real human decision-maker in the loop now and diary the December 2027 date.
Not sure where your AI use sits?
The FMOps Claude readiness check maps what your team already uses, what data it touches, and what needs a policy. If you want the whole thing set up properly, including the written policy and staff training, that is Claude for Business.
Frequently asked questions
Does the EU AI Act apply to small businesses in Ireland?
Yes, but lightly for most. If your business uses AI tools such as ChatGPT, Claude or AI features inside your CRM, you are a deployer of low-risk AI. Your duties are to support a reasonable level of AI literacy among staff, which has applied since 2 February 2025, and, from 2 August 2026, to tell people when they are interacting with AI or looking at AI-generated content. There is no registration, no AI officer and no certification for ordinary business use.
What is the difference between a provider and a deployer under the AI Act?
A provider develops an AI system and places it on the market under its own name, as Anthropic does with Claude. A deployer uses an AI system under its own authority in the course of business, which is what nearly every Irish SME does. Deployer duties are much lighter. You can become a provider if you rebrand and resell an AI system as your own, or substantially modify a high-risk system.
What are the EU AI Act deadlines for 2026 and 2027?
Banned practices and the AI literacy duty applied from 2 February 2025. Rules for general-purpose AI models applied from 2 August 2025. Transparency duties for chatbots and AI-generated content apply from 2 August 2026. The main high-risk obligations were deferred by the Digital Omnibus on AI to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products.
Do I have to tell customers my chatbot is AI?
Yes, from 2 August 2026, unless it is obvious to a reasonably well-informed person. A short line on the chat widget saying the visitor is chatting with an AI assistant and can ask for a human at any time satisfies the requirement. The same principle covers AI phone answerers and AI-generated images, audio or video that could pass for real.
Who regulates the EU AI Act in Ireland?
Ireland uses a distributed model. Under S.I. No. 366 of 2025 and a September 2025 follow-up, fifteen existing regulators act as national competent authorities in their own sectors, including the Data Protection Commission, the CCPC, the Central Bank of Ireland, ComReg, Coimisiun na Mean, the Health and Safety Authority and the Workplace Relations Commission. A national AI Office coordinates them and must be operational by 1 August 2026.
