← All posts

The EU AI Act: Which Irish Businesses Are in Scope, and the Deadlines

Ask most Irish SME owners about the EU AI Act and you will hear one of two things: "that is a problem for OpenAI and Google," or "we do not really do AI." Both answers are usually wrong. The EU AI Act scope is deliberately broad, and it captures the ordinary business that bought an AI recruitment tool, added a chatbot to its website, or lets a vendor score its customers.

The EU AI Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024, and its obligations are landing in phases rather than all at once. That phasing is a gift if you use it to plan, and a trap if you assume nothing applies until some distant date.

Most Irish SMEs have not yet worked out whether they are a provider or a deployer of AI, which is the single question that decides how much of this regulation lands on them. This post walks through the scope, the roles, and the timeline, in plain terms.

What the EU AI Act Actually Regulates

The Act does not regulate "AI" as a blanket category. It regulates AI systems according to the risk they pose to people's safety and fundamental rights. That risk-tiered structure is the heart of the EU AI Act, and understanding your tier is the first practical step.

There are four broad tiers, plus a separate track for general-purpose AI models. The higher your risk tier, the heavier your obligations. For a typical 50 to 250 staff Irish business, the realistic questions are: are we touching anything prohibited, are any of our uses high-risk, and do we owe transparency to customers.

The Four Risk Tiers, in Plain English

Here is the structure without the legalese.

Tier What it means Typical SME example
Prohibited (unacceptable risk) Banned outright Social scoring, certain manipulative or exploitative systems
High-risk Strict obligations before and during use AI in recruitment or HR screening, credit scoring, biometrics, critical infrastructure
Limited risk Transparency obligations Customer-facing chatbots, deepfakes and AI-generated content
Minimal risk No specific obligations Spam filters, AI in inventory forecasting

The trap for SMEs is assuming you sit in "minimal risk" by default. A recruitment screening tool that ranks candidates, or a system that helps decide who gets credit, sits in the high-risk tier even if you bought it off the shelf.

Provider or Deployer: The Question That Decides Everything

The Act defines two main roles, and your obligations flow from which one you occupy.

A provider develops an AI system, or has one developed, and puts it on the market or into service under its own name. Think of the company that builds and sells the tool.

A deployer uses an AI system under its own authority in the course of business. Think of the Irish firm that buys that tool and runs it on its own candidates, customers, or staff.

Here is the point most people miss. Even an SME that only deploys a third-party AI tool has deployer obligations. If you use an AI hiring tool to sift CVs, you are a deployer of a high-risk system. You cannot simply point at the vendor. You will have duties around human oversight, using the system as intended, monitoring its operation, and informing the people affected.

Transparency: The Duty That Catches Almost Everyone

Even outside the high-risk tier, the limited-risk transparency rules catch a huge number of ordinary businesses.

If you run a customer-facing chatbot, users must be told they are interacting with an AI and not a human, unless it is obvious. If you publish AI-generated or AI-manipulated content, including deepfakes and certain synthetic images, that must be disclosed. If your marketing or support teams are quietly leaning on generative tools for customer-facing output, transparency obligations may already apply to you.

These are not onerous duties, but they are duties. A one-line disclosure on a chatbot is cheap. A complaint that you deceived customers is not.

General-Purpose AI and the Tools You Already Use

There are separate rules for general-purpose AI (GPAI) models, the large foundation models that sit behind many of the tools your teams use daily. Those obligations fall primarily on the model providers, not on you as a downstream user.

For an SME, the practical takeaway is that your obligations come from how you deploy AI, not from the underlying model. But you should still know which of your vendors rely on GPAI, because their compliance affects the assurances you can pass on to your own customers.

The Phased Timeline

The Act applies in stages. The dates below are the headline milestones. Some simplification of these timelines was under discussion during 2026, so treat the future-dated items as a planning guide rather than a fixed promise, and confirm the current position before you rely on a specific day.

  1. From 2 February 2025: the prohibitions on unacceptable-risk practices applied.
  2. From 2 August 2025: obligations for general-purpose AI models applied.
  3. From 2 August 2026: obligations for high-risk systems in the Annex III use cases (recruitment, credit, biometrics and similar) are due to apply.
  4. From 2 August 2027: rules for AI embedded in already-regulated products are due to apply.

The message from the phasing is simple. If you deploy anything in the high-risk category, the clock you care about is the 2026 milestone, and preparation of a year or more is realistic, not excessive.

Who Enforces This in Ireland

National competent authorities are being designated to supervise and enforce the Act at member-state level. In Ireland, the detail of which bodies hold which responsibilities has been taking shape, so keep an eye on official guidance rather than assuming the landscape is settled.

For your purposes, the enforcement structure matters less than the readiness structure. Regulators reward businesses that can show they identified their AI uses, classified the risk, and put oversight in place. That evidence is what you should be building now.

Common Mistakes

A handful of errors come up again and again with Irish SMEs.

The first is assuming the Act is "a big-tech problem" and that a small deployer has nothing to do. Deployer obligations are real, particularly for high-risk uses like hiring.

The second is not keeping an inventory of where AI is actually used across the business. Marketing, HR, and customer support often adopt AI tools without anyone centrally tracking it, so nobody can answer the scope question.

The third is conflating GDPR compliance with AI Act compliance. They overlap, especially where AI processes personal data, but they are distinct regimes with distinct duties. Doing one well does not discharge the other.

The fourth is ignoring transparency because it feels trivial. Undisclosed chatbots and undisclosed AI content are exactly the kind of low-effort, high-visibility failures that generate complaints.

How ShieldIQ Helps with the EU AI Act

ShieldIQ helps you answer the scope question first: it walks you through an inventory of where AI is used across the business, classifies each use against the Act's risk tiers, and flags whether you are acting as a provider or a deployer. From there it maps your obligations, tracks the phased deadlines that apply to you, and keeps the evidence a competent authority would expect to see, all in one place rather than scattered across spreadsheets and email.

Run a free EU AI Act assessment to see where you stand โ†’