The EU AI Act for Irish small businesses: what actually applies to you
Most Irish SMEs are deployers of AI, not providers — which changes almost everything about what the EU AI Act asks of them. Here's what actually applies, when, and what to do about it.
What this means for you
- Almost every Irish SME is a *deployer* of AI, not a provider — the heaviest obligations don't apply to you.
- The rules that do apply are mostly transparency, staff AI literacy, and not using banned practices.
- Practical next step: list the AI tools already in use, note what data goes into them, and write a short usage policy.
Every few weeks another headline lands about the EU AI Act and fines running to seven figures, and every few weeks another Irish business owner reads it, decides the whole thing sounds like something for Google and Microsoft to worry about, and moves on. That instinct is about 80% right and 20% dangerously wrong, and the 20% is worth twenty minutes of your attention.
The single distinction that decides everything
The Act separates providers — organisations that build or substantially modify an AI system and put it on the market — from deployers, organisations that use one in the course of their business.
If your business uses ChatGPT, Copilot, an AI feature inside Xero, a chatbot on your website, or a CV-screening tool you bought from a vendor, you are a deployer. Almost every Irish SME is a deployer and nothing else. The heavy obligations in the Act — conformity assessments, technical documentation, registration in an EU database, post-market monitoring — sit with providers. They are not your problem.
Deployer obligations are real but far lighter, and they scale with risk.
The risk tiers, in plain terms
Prohibited. A short list of practices banned outright: social scoring, emotion inference in the workplace or in education, untargeted scraping of facial images, certain manipulative systems. If you're doing any of these, stop — this is the one tier where "we're only a small business" is not a defence.
High risk. This is the tier most SMEs assume doesn't touch them and occasionally are wrong about. It includes AI used in recruitment and employment decisions — CV screening, candidate ranking, promotion or termination decisions — and AI used in access to essential services like credit scoring. If you use an AI tool to filter job applicants, you're a deployer of a high-risk system, and you carry specific duties: use the system according to the provider's instructions, assign human oversight to someone competent to exercise it, keep the logs the system generates, and inform affected workers before you put it into use.
Limited risk — transparency only. Chatbots must make clear that people are talking to a machine. AI-generated or manipulated content — text published to inform the public, synthetic images, audio, video — has to be disclosed as such. Deepfakes must be labelled. This is where most SME use lands, and the obligation is genuinely just: be honest that it's AI.
Minimal risk. Spam filters, AI in your accounting reconciliation, drafting assistance for internal work. No specific obligations.
The one obligation that applies to essentially everyone
Since February 2025, AI literacy has been a live requirement. Article 4 asks providers and deployers to take measures to ensure their staff have a sufficient level of AI literacy, taking into account their technical knowledge, their training, and the context the systems are used in.
There is no certificate to buy and no register to join. What a regulator would want to see is evidence that you took it seriously: a short written record of what training your team received, when, and what your internal rules on AI use are. For a ten-person business that's a two-page document and one afternoon, not a project.
It is also, conveniently, the single highest-value thing you can do anyway — most of the risk in SME AI use comes from staff not knowing what's safe to paste where.
Dates that matter
- 2 February 2025 — prohibited practices and the AI literacy obligation applied.
- 2 August 2025 — governance rules and obligations for general-purpose AI models applied.
- 2 August 2026 — the bulk of the Act, including the transparency obligations and most high-risk rules, applies.
- 2 August 2027 — extended deadline for high-risk AI embedded in regulated products.
In Ireland, enforcement is distributed across a set of designated national authorities rather than a single AI regulator. The practical read: expect the Data Protection Commission's existing posture on personal data to be the sharp end of this for most SMEs, because AI and GDPR overlap far more than AI and the AI Act do. For the practical side of that overlap, the GDPR and AI tools guide sets out the four-rule policy we recommend.
Not sure which tier your business is in? Take the free AI Scorecard — it takes five minutes and gives you a structured read on your AI exposure and next step.
What to actually do, in order
1. Write down what you use. A list of every AI tool in the business, who uses it, and what data goes into it. Most owners are surprised by how long this list is once they ask the team rather than guessing. This inventory is the foundation of everything else and takes an hour.
2. Check the list against the tiers. Anything touching hiring, firing, promotion, or creditworthiness gets flagged for a closer look. Anything customer-facing gets a transparency check. Everything else is almost certainly minimal risk.
3. Add disclosure where it's missing. If you run a chatbot, say it's a chatbot. If you publish AI-drafted content as public information, be straight about it. This is cheap and it's the obligation most likely to be noticed by a customer rather than a regulator.
4. Do the AI literacy piece properly. A short session, a written record, and four plain rules on data handling that your team can actually remember. Our companion piece on GDPR and AI tools sets out those four rules in full.
5. Keep the paperwork light and current. A living one-page register beats a fifteen-page policy written once and never opened.
For the data-handling question specifically, the companion piece on whether you can put client data into ChatGPT walks through the same practical test.
What not to do
Don't buy an "AI Act compliance platform" as your first move — for a business at deployer level with no high-risk systems, you're purchasing a solution to a problem you probably don't have. Don't ban AI outright either: in every organisation where that's been tried, use continued on personal accounts, which converts a manageable compliance question into an invisible one.
And don't treat the Act as the only thing to comply with. For most Irish SMEs, GDPR is the more likely source of an actual problem, and the two overlap on the same practical question: do you know where your data goes when someone on your team uses AI?
If you want a structured read on where your business currently sits — including your exposure on this — the free Scorecard takes five minutes and gives you an honest answer rather than a sales call.
Not sure where your business stands?
The free AI Scorecard takes five minutes and gives you a written read on where AI would genuinely help — and where it wouldn't.
Take the free scorecard