The EU AI Act is the world’s first comprehensive law on artificial intelligence, and it applies to Irish businesses. The good news: for most SMEs using AI for everyday automation, the obligations are manageable — as long as you build with them in mind from the start.
This article is general information, not legal advice. For your specific situation, talk to a qualified advisor. Updated 5 July 2026 with the key application dates.
The dates that matter
The Act is phasing in, and two dates matter most for SMEs:
- Since 2 February 2025 — the ban on prohibited AI practices and the AI literacy duty (Article 4) already apply. If your business uses AI, you’re expected to make sure the people operating it understand what it can and can’t do. A short written policy and a training note go a long way.
- From 2 August 2026 — the transparency obligations (Article 50) apply to AI systems in use, and national authorities gain their penalty powers. If you deploy a chatbot or AI-generated content, this is your deadline.
It’s risk-based, not one-size-fits-all
The Act sorts AI systems by risk. Most everyday SME use cases — a support chatbot, a document drafter, an internal knowledge assistant — fall into the limited-risk category, where the headline obligation is transparency.
But “most” is not “all”, and the exceptions matter: Annex III lists high-risk uses that carry a far heavier regime — and some of them look like ordinary business tools. The clearest trap for SMEs is recruitment: AI that screens, scores, or ranks job candidates is high-risk under the Act. So is AI that decides who gets credit, insurance, or essential services. If a tool influences decisions about people’s access to work or services, treat it as a different category entirely — that’s why we build CV intake and admin automation for recruiters, and deliberately don’t build candidate-scoring systems.
Transparency is the big one for most SMEs (Article 50)
If people are interacting with an AI system, they should know. From 2 August 2026 that means, in practice:
- Telling customers when they’re chatting with an AI assistant, not a person.
- Being clear about where AI is used in your service.
- Marking AI-generated content appropriately when you publish it.
Human oversight is a separate duty — don’t confuse the two
“Keep a human in the loop” is often mentioned alongside transparency, but it’s a distinct obligation (Article 14) that formally attaches to high-risk systems. For limited-risk tools it’s not a legal requirement — it’s simply good practice, and we design review points into builds anyway: AI drafts, your people decide.
Data protection still applies
The AI Act sits alongside GDPR, it doesn’t replace it. You still need a lawful basis to process personal data, and you still owe people their data rights.
Build with the Act in mind from day one
Retrofitting compliance is painful. Designing for it from the start is not. Every solution we build is designed to support your EU AI Act obligations: AI usage is disclosed, review points are built in, documentation is part of the handover, data stays in Ireland, and your business data never trains third-party models. We’ll also tell you plainly which duties remain yours as the deployer — no vague promises.