What the AI Act is
The EU AI Act (Regulation (EU) 2024/1689) is the first broad law governing how artificial intelligence is built and used. It applies directly in every member state, including Ireland. It doesn't ban AI or require a licence to use it. It sorts uses of AI by how much harm they could do, and sets duties to match.
It applies to businesses that build AI (providers) and to businesses that use it in their work (deployers). Most SMEs are deployers: they use a chatbot, a recruitment tool or a scoring system someone else built. Deployers have fewer duties than providers, but not none.
The four levels of risk
| Level | Examples | What it means |
|---|---|---|
| Banned | Social scoring, manipulative techniques, emotion recognition at work or in education, scraping faces to build recognition databases | Not allowed since 2 February 2025 (Art. 5) |
| High-risk | CV screening and candidate ranking, decisions on promotion or dismissal, creditworthiness checks, life and health insurance pricing | Strict duties from 2 December 2027 (Annex III) |
| Transparency | Customer chatbots, AI-generated images, audio, video or text, emotion recognition | People must be told, since 2 August 2026 (Art. 50) |
| Minimal | Spam filters, AI features in spreadsheets, stock forecasting | No specific duties beyond supporting staff AI literacy |
The level depends on what you use the tool for, not which tool it is. The same language model is minimal risk when it drafts internal emails and high-risk when it ranks job applicants.
What applies now
- Banned practices have been prohibited since February 2025. A ban on AI that creates non-consensual intimate imagery was added by the Digital Omnibus, with a transition to 2 December 2026.
- Transparency duties under Article 50 have applied since 2 August 2026. If your AI talks to people or produces content they see, they generally need to know. See what Article 50 asks of you.
- AI literacy. Providers and deployers must take measures to support AI literacy among staff who use AI. The Digital Omnibus softened this from a duty to ensure a sufficient level of literacy.
What changes on 2 December 2027
The rules for high-risk AI listed in Annex III apply from 2 December 2027. They were due in August 2026, but the Digital Omnibus postponed them. They were delayed, not dropped.
If you deploy a high-risk AI system, you will need to, among other things:
- use it according to the provider's instructions
- assign people with the competence and authority to oversee it
- monitor how it performs and keep the logs it generates
- tell workers and their representatives before using it in the workplace
- tell people when it's used to make or support decisions about them
Some deployers, including those assessing creditworthiness or pricing life and health insurance, must also carry out a fundamental rights impact assessment before first use.
Fines
Up to €35 million or 7% of worldwide turnover for banned practices, and up to €15 million or 3% for most other breaches. For SMEs and start-ups each cap is the lower of the two figures (Art. 99(6)).
What to do first
- List every AI tool you use. Include AI features switched on inside software you already pay for, such as your CRM, helpdesk or applicant tracking system.
- Note what each one is used for, and whether it affects customers, staff or applicants.
- Fix the transparency gaps. These duties already apply and are usually quick to close.
- Flag anything touching hiring, credit or insurance for a proper look before December 2027.
Not sure where to start? Our two-minute checker gives you an indication, and our fixed-fee audit does the full job.
Sources: Regulation (EU) 2024/1689, Articles 4, 5, 26, 27, 50, 99 and Annex III, as amended by the Digital Omnibus on AI (political agreement 7 May 2026). This guide is general information, not legal advice.