If your business has an EU AI Act question, do you contact the AI Office of Ireland?
Perhaps.
But it may not be the regulator responsible for your particular AI system.
Ireland has chosen a distributed model for enforcing the EU AI Act. Instead of creating one regulator responsible for every use of AI, existing sectoral regulators retain responsibility in areas where they already have expertise.
The AI Office of Ireland sits at the centre of that structure.
Understanding this matters because the regulator relevant to an AI recruitment tool may be different from the regulator responsible for AI used in banking, medical devices or industrial machinery.
What does the AI Office of Ireland do?
The AI Office of Ireland is now operational as an independent statutory body established under the Regulation of Artificial Intelligence Act 2026.
It acts as Ireland's central coordinating authority and single point of contact for the EU AI Act.
Its role includes:
- coordinating Ireland's competent authorities
- supporting consistent implementation and supervision
- facilitating cooperation and information sharing between regulators
- providing access to technical expertise
- supporting responsible AI adoption and innovation
This makes the AI Office an important focal point.
But it is not Ireland's only AI regulator.
Ireland currently has 15 competent authorities
Ireland has designated 15 national competent authorities for different areas of AI Act oversight and enforcement.
Which authority matters depends on the AI system, the sector and how the technology is being used.
For example:
Financial services
The Central Bank of Ireland is responsible for certain prohibited AI practices and specified high-risk AI systems where they are used by regulated financial service providers.
This includes particular AI uses connected with areas such as creditworthiness and life or health insurance.
Employment and workplace AI
The Workplace Relations Commission supervises the deployment and use of AI systems in the Irish labour market.
Businesses using AI for recruitment, employee management or workplace decisions should therefore not assume AI compliance is purely a technology or data-protection issue.
Personal data and fundamental rights
The Data Protection Commission is designated as a market surveillance authority for certain prohibited AI practices and certain Annex III high-risk AI systems.
Separately, the DPC continues to enforce the GDPR where AI involves personal data.
An AI deployment can therefore create both AI Act and data-protection questions.
Products and safety
Other authorities cover AI embedded in particular products or safety systems.
The CCPC has responsibilities for certain AI systems associated with products such as toys, domestic gas products and leisure personal protective equipment.
The Health and Safety Authority has responsibilities covering AI safety systems associated with workplace machinery, lifts, pressure equipment and other regulated equipment.
Medical-device AI also sits within Ireland's established health-product regulatory structure.
Could more than one regulator matter?
Yes.
The distributed model means businesses should think about the activity, not simply the software.
Consider an AI system used to assess employees.
The employment context may be relevant to the WRC.
If employee personal data is processed, GDPR and the DPC may also matter.
If the system falls within the EU AI Act's high-risk rules, additional AI Act requirements may eventually apply.
This does not mean every AI system will automatically be supervised by several regulators.
It means businesses should identify the relevant legal and sectoral context rather than assuming there is one universal "AI regulator".
What applies now?
The EU AI Act is already partially applicable and Ireland's national enforcement architecture is now in place.
However, the Act remains phased.
Certain prohibited practices, AI literacy requirements and transparency obligations already apply.
The rules for Annex III high-risk AI systems, including certain uses in employment, education, essential services and biometrics, are scheduled to apply from 2 December 2027.
High-risk rules for AI associated with regulated products are scheduled to apply from 2 August 2028.
Those future dates should not be presented as obligations already generally enforceable today.
Four things businesses should do
1. Build an AI inventory
Identify where AI is actually being used across the organisation.
2. Record the business purpose
Recruitment, customer service, credit assessment and machinery safety can lead to very different regulatory questions.
3. Map the likely regulator
Record which sectoral regulator may be relevant alongside the applicable AI Act requirements.
4. Check overlapping rules
AI governance should also consider GDPR, employment law, consumer protection, product safety and other sector-specific requirements where relevant.
Blanche perspective
The question is not simply:
"Are we regulated by the AI Act?"
A more useful question is:
"What AI are we using, what is it doing, who can it affect and which regulator already understands that activity?"
Ireland's distributed enforcement model makes an accurate AI inventory even more important.
You cannot map the regulator until you understand the system.
Sources
Primary and authoritative sources used for this Insight.
- AI Office of Ireland: National Competent Authorities (official implementation information)
- AI Office of Ireland: What we do (official implementation information)
- DETE: AI Office established and CEO appointed, 30 July 2026 (official government information)
- Irish Statute Book: S.I. No. 366/2025, Designation Regulations (binding Irish legislation)
- AI Office of Ireland: EU AI Act, designated authorities and timeline (official implementation information)
- EUR-Lex: Regulation (EU) 2024/1689, consolidated 27 July 2026 (binding EU law)
- AI Office of Ireland: Central Bank of Ireland (official designation information)
- AI Office of Ireland: Data Protection Commission (official designation information)
- AI Office of Ireland: Competition and Consumer Protection Commission (official designation information)