What EU AI Act requirements apply to Irish and UK-based organisations?
Irish organisations are directly subject to the EU AI Act where they provide, deploy, import, distribute or use AI systems in scope, while UK-based organisations can also fall in scope when they place AI systems on the EU market or where AI system outputs are used in the EU.

- Ireland: the Act applies directly. Eight national competent authorities were designated under S.I. No. 366/2025 - including the DPC, the Central Bank of Ireland, the CCPC, ComReg, the Health and Safety Authority and the HPRA - with five more announced in September 2025 awaiting formalisation, to be coordinated by a planned AI Office of Ireland.
- UK: there is no domestic AI Act equivalent. The UK follows a principles-based, regulator-led approach through the ICO and sectoral regulators, alongside the AI Safety/Security Institute - but the EU AI Act reaches UK firms extraterritorially under Article 2.
- Both jurisdictions: where an AI system processes personal data, GDPR duties continue in full - Article 30 records of processing and, for high-risk processing, an Article 35 DPIA - enforced by the DPC in Ireland and the ICO in the UK.
- Already applying: the Article 5 prohibitions and the Article 4 AI literacy duty since 2 February 2025, and general-purpose AI model obligations since 2 August 2025.
- System name and owner.
- Business purpose and user group.
- Whether the organisation is provider, deployer, importer, distributor or another operator.
- Whether the system is internal, vendor-supplied or customer-facing.
- Whether the system may fall into prohibited, high-risk, limited-risk or minimal-risk categories.
- Whether Article 50 transparency duties may apply.
- What evidence exists for human oversight, policies, testing, monitoring and approvals.
- When the system must be reviewed again.
- Prohibited practices (Article 5): banned outright, applying since 2 February 2025.
- High-risk systems (Article 6, with Annex I and Annex III): permitted but subject to the Act's core compliance regime - providers must complete a conformity assessment before placing the system on the EU market, and deployers carry use, oversight and, in some cases, fundamental rights impact assessment duties.
- Transparency-risk systems (Article 50): systems that interact with people, generate or manipulate content, or perform emotion recognition or biometric categorisation carry disclosure duties from 2 August 2026.
- Minimal-risk systems: no additional obligations beyond the cross-cutting Article 4 AI literacy duty, which has applied to providers and deployers across all tiers since 2 February 2025.
| Date | What starts to apply |
|---|---|
| 2 February 2025 | Article 5 prohibited practices are banned, and the Article 4 AI literacy duty applies to providers and deployers across all risk tiers. |
| 2 August 2025 | General-purpose AI (GPAI) model obligations apply to providers. Models placed on the market before 2 August 2025 have until 2 August 2027 to comply. |
| 2 August 2026 | Article 50 transparency obligations apply, and the European Commission's AI Office gains its GPAI enforcement powers. |
| 2 August 2026 (current law) | High-risk obligations for Annex III systems apply. The provisionally agreed Digital Omnibus (not yet in force) would move this to 2 December 2027. |
| 2 August 2027 (current law) | High-risk obligations for AI embedded in Annex I regulated products apply. The provisionally agreed Digital Omnibus (not yet in force) would move this to 2 August 2028. |
- Providers: must not place prohibited systems on the market; must complete a conformity assessment for high-risk systems before placing them on the EU market; providers of Annex III high-risk systems must register them in the EU database under Article 49; GPAI model providers carry the model obligations applying since 2 August 2025; and Article 50 transparency duties apply from 2 August 2026.
- Deployers: must not use prohibited systems; carry the Article 4 AI literacy duty (since 2 February 2025); meet Article 50 transparency duties for in-scope systems from 2 August 2026; carry use and oversight duties for high-risk systems when the high-risk regime applies; and certain deployers must complete an Article 27 fundamental rights impact assessment before first use of a high-risk system.
- Scope limit on registration: merely using a vendor-supplied high-risk tool does not require a deployer to register it in the EU database - only deployers that are public authorities register their use.
- Both roles, both jurisdictions: where the system processes personal data, the GDPR applies in parallel - Article 30 records and, for high-risk processing, an Article 35 DPIA.
- Must register: providers of Annex III high-risk AI systems, in the EU database.
- Must register their use: deployers that are public authorities using Annex III high-risk systems.
- Do not register: private organisations merely using a vendor-supplied high-risk tool.
- Never registered: limited-risk (Article 50) and minimal-risk systems.
- Biometrics.
- Critical infrastructure.
- Education and vocational training.
- Employment and worker management.
- Access to essential private and public services, including creditworthiness assessment and life and health insurance pricing.
- Law enforcement.
- Migration, asylum and border control.
- Administration of justice and democratic processes.
- Prohibited practices (Article 5): up to EUR 35 million or 7% of total worldwide annual turnover.
- Most other obligations, including Article 50 transparency duties and deployer duties: up to EUR 15 million or 3% of total worldwide annual turnover.
- Supplying incorrect, incomplete or misleading information to authorities: up to EUR 7.5 million or 1% of total worldwide annual turnover.
- SMEs and start-ups: each fine is capped at the lower of the two amounts.
- Article 30 RoPA: record the AI processing, its purposes, data categories, recipients, transfers and retention - in Ireland under the EU GDPR and in the UK under the UK GDPR.
- Article 35 DPIA: required where AI processing is likely to result in a high risk to individuals; AI-driven profiling and innovative technology commonly trigger it.
- Enforcement: the DPC (Ireland) and the ICO (UK) enforce the GDPR overlay in parallel with any AI Act duties.
| Ireland (EU AI Act applies directly) | United Kingdom (no domestic AI Act) |
|---|---|
| Legal status: Regulation (EU) 2024/1689 applies directly as EU law, on the staged timeline above. | Legal status: the EU AI Act does not apply domestically, and the UK has no AI Act equivalent. |
| Regulatory model: distributed enforcement by national competent authorities - eight designated under S.I. No. 366/2025, including the DPC, the Central Bank of Ireland, the CCPC, ComReg, the Health and Safety Authority and the HPRA, with five more announced in September 2025 awaiting formalisation. | Regulatory model: principles-based and regulator-led, through the ICO and sectoral regulators, alongside the AI Safety/Security Institute. |
| Coordination: an AI Office of Ireland is planned under the Regulation of Artificial Intelligence Bill 2026; the Bill is not yet enacted, with the office targeted to be operational around 1 August 2026. | Coordination: no single AI statute or coordinating AI authority; existing regulators apply cross-sector principles within their own remits. |
| Extraterritorial exposure: not applicable - the Act already applies in Ireland. | Extraterritorial exposure: UK organisations are in scope under Article 2 when they place AI systems on the EU market or when their system's output is used in the EU. |
| AI Act penalties: Article 99 tiers of up to EUR 35 million or 7% of worldwide annual turnover, applied through the designated national authorities. | AI Act penalties: none domestically, but the EU tiers reach UK firms caught by Article 2. |
| Registration: providers of Annex III high-risk systems register in the EU database; public-authority deployers register their use. | Registration: the same Article 49 duty applies to UK providers only when they place Annex III high-risk systems on the EU market. |
| GDPR overlay: Article 30 RoPA and Article 35 DPIA duties enforced by the DPC under the EU GDPR. | GDPR overlay: Article 30 RoPA and Article 35 DPIA duties enforced by the ICO under the UK GDPR. |
Where Acompli fits for EU AI Act readiness
Best for teams that need AI Act evidence connected to GDPR records: Acompli keeps an AI inventory with owners, roles, risk tiers, classification rationale and review dates linked to the relevant Article 30 entries, DPIAs, suppliers and risks. The AI System Register and Member-State conformity templates are opt-in early access, so they should be treated as available readiness capabilities rather than universal shipped guarantees; every classification and legal judgement remains human-approved.
See Acompli EU AI Act workflows
Primary sources
- Regulation (EU) 2024/1689 - the EU Artificial Intelligence Act (EUR-Lex)
- Council of the EU - Digital Omnibus on AI provisional agreement, 7 May 2026
- European Parliament - Digital Omnibus on AI legislative train
- European Commission AI Act Service Desk - implementation timeline
- Department of Enterprise, Tourism and Employment - EU Artificial Intelligence Act
- S.I. No. 366/2025 - designation of Irish national competent authorities for the EU AI Act (Irish Statute Book)
- Department of Enterprise, Tourism and Employment - General Scheme of the Regulation of Artificial Intelligence Bill 2026
- ICO - Artificial intelligence guidance hub (UK)