General Scheme of the Regulation of Artificial Intelligence Bill 2026
proposedpolicy · Effective Jan 1, 2026
IE regulates AI through General Scheme of the Regulation of Artificial Intelligence Bill 2026.
General Scheme of the Regulation of Artificial Intelligence Bill 2026 · effective 2026
Updated 60 days ago · 1 sources · confidence: medium
Overview
Ireland's approach to Artificial Intelligence (AI) regulation is characterized by a forward-looking, human-centred philosophy, deeply integrated with the broader European Union framework. The nation is actively positioning itself as a leader in 'trustworthy AI,' aiming to balance the promotion of innovation with the robust protection of fundamental rights and societal well-being. This commitment is articulated in its foundational policy document, "AI – Here for Good: National Artificial Intelligence Strategy for Ireland," which outlines a whole-of-government strategic framework for the responsible development and use of AI across its economy and public services.The country's regulatory maturity is rapidly advancing, with significant legislative and policy developments underway to domestically implement the landmark EU AI Act. Rather than creating a single, monolithic AI regulator, Ireland has opted for a 'distributed model' of governance, leveraging the specialized expertise of existing sectoral bodies. This pragmatic approach ensures that AI applications are overseen by regulators already familiar with the specific risks and operational realities of their respective domains, providing a nuanced and comprehensive oversight mechanism.
Regulatory approach
Ireland's regulatory approach to AI is primarily horizontal, driven by the direct applicability of the EU AI Act, but implemented through a distributed national model that incorporates sectoral expertise. The core legislative instrument, the General Scheme of the Regulation of Artificial Intelligence Bill 2026, establishes a framework for national enforcement and coordination, designating 15 sectoral regulators as Market Surveillance Authorities (MSAs). This distributed model empowers bodies like the Central Bank of Ireland for financial services AI and the Data Protection Commission for AI systems processing personal data, ensuring comprehensive oversight tailored to specific industry contexts.Complementing this binding legislative framework, Ireland also heavily relies on soft law instruments, particularly for the public sector. Guidelines such as the "Guidelines for the Responsible Use of AI in the Public Service" and the "Interim Guidelines for Use of AI" provide non-binding but comprehensive frameworks for ethical, lawful, and safe AI adoption within government bodies. These guidelines emphasize a risk-based and proportionate approach, aligning with the EU AI Act's classification of high-risk systems and promoting principles like human agency, transparency, and data governance. The National Cyber Security Centre also contributes with specific guidance on the cybersecurity risks of generative AI, advocating for a default posture of restriction for public sector use. Ireland's AI governance framework is designed as a sophisticated, federated structure, with the Department of Enterprise, Trade and Employment (DETE) leading national implementation and coordination. A central pillar of this framework is the forthcoming National AI Office (Oifig Intleachta Shaorga na hÉireann), which will serve as the 'Single Point of Contact' for the European Commission and other Member States. This office, expected to be established by August 2026, will be responsible for coordinating the activities of various Market Surveillance Authorities (MSAs), providing centralized technical expertise, and driving national AI literacy. It will be led by a Chief Executive Officer and overseen by a statutory board, ensuring both independence and alignment with national enterprise policy.Under the distributed model, a significant number of existing sectoral regulators are designated as MSAs, leveraging their deep institutional knowledge to oversee AI applications within their specific domains. For instance, the Central Bank of Ireland is the competent authority for AI systems in financial services, while Coimisiún na Meán oversees AI in media and online platforms. The Data Protection Commission (DPC) plays a critical role in monitoring AI systems that process personal data, ensuring compliance with GDPR. This network of 15 designated MSAs, alongside a National AI Implementation Committee, aims to facilitate regular communication, resolve jurisdictional overlaps, and ensure uniform enforcement of the AI Act across all sectors of the Irish economy.
Enforcement & penalties
Ireland's framework for penalties and enforcement mechanisms for AI regulation is being established in direct alignment with the requirements of the EU AI Act. The General Scheme of the Regulation of Artificial Intelligence Bill 2026 provides the legal basis for the domestic implementation of these provisions, including the enforcement of prohibitions on certain AI practices deemed to pose an 'unacceptable risk.' These prohibited practices include AI systems that deploy subliminal techniques, exploit vulnerabilities, or provide social scoring by public authorities, as well as the use of real-time remote biometric identification systems in public spaces, subject to strict exceptions.The EU AI Act mandates significant administrative fines for infringements, with penalties for prohibited practices reaching up to EUR 35,000,000 or 7% of global turnover, and scaled fines for other breaches. Ireland is committed to laying down national rules on these penalties and notifying the European Commission by the date of the Act's application. The designated Market Surveillance Authorities (MSAs) will be granted extensive powers to conduct investigations, request information, carry out on-site inspections, and ensure conformity assessments. The implementation framework also provides for 'Regulatory Sandboxes' to support businesses, particularly SMEs, in navigating compliance without immediate punitive measures, fostering a proactive approach to 'trustworthy AI' development.
Data protection
Ireland's data protection framework is robustly anchored in the General Data Protection Regulation (GDPR), which is directly applicable across the European Union. The Data Protection Commission (DPC) serves as the primary supervisory authority for data protection matters in Ireland, including those related to AI systems. The DPC has issued specific guidance, "AI, Large Language Models and Data Protection," to clarify how GDPR obligations apply throughout the AI lifecycle, from data training to deployment.This guidance emphasizes critical data protection principles such as lawfulness, transparency, purpose limitation, data minimization, and data quality. It mandates the identification and documentation of legal bases for processing personal data, particularly when large datasets, including publicly accessible personal data, are used for AI model training. Organizations are strongly advised to conduct Data Protection Impact Assessments (DPIAs) for processing activities likely to result in high risks, implement robust security measures against model extraction or prompt-injection attacks, and ensure mechanisms are in place to uphold data subject rights, including access, rectification, and erasure. The DPC's role is particularly significant given that many large multinational technology companies with EU headquarters are located in Ireland, placing the DPC at the forefront of AI-related data protection supervision.
Sector-specific rules
Ireland's distributed model of AI regulation inherently incorporates sector-specific rules by leveraging the expertise of existing regulators. The Statutory Instrument No. 366/2025 formally designates a range of sectoral bodies as Market Surveillance Authorities (MSAs) responsible for overseeing AI systems within their specific domains, as outlined by the EU AI Act. For instance, the Central Bank of Ireland is designated as the competent authority for AI systems used in the financial services sector, ensuring that AI applications comply with financial regulations and prudential standards.Similarly, the Data Protection Commission (DPC) is a key MSA, specifically tasked with monitoring AI systems that process personal data, thereby providing sector-specific oversight for privacy-sensitive applications across all industries. Coimisiún na Meán (the Media Commission) oversees AI in media and online platforms, addressing issues pertinent to content moderation, disinformation, and media plurality. Other designated authorities include the Health and Safety Authority, the Health Products Regulatory Authority, the Competition and Consumer Protection Commission, and the Commission for Communications Regulation (ComReg), each applying their sectoral expertise to the unique risks and challenges posed by AI in their respective fields, such as critical infrastructure, education, employment, and law enforcement, which are often classified as 'high-risk' under the EU AI Act.
International alignment
Ireland's AI regulatory framework is profoundly shaped by its strong alignment with the European Union's legislative agenda, particularly the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). As an EU Member State, Ireland is directly bound by the provisions of the AI Act, which possesses direct effect across the Union. The General Scheme of the Regulation of Artificial Intelligence Bill 2026 serves as Ireland's primary domestic vehicle for implementing this Act, ensuring full harmonization of definitions, prohibitions, and compliance obligations.The national implementation roadmap and related statutory instruments explicitly reference and are driven by key EU dates and requirements, such as the designation of national competent authorities, the notification of penalty rules, and the establishment of AI regulatory sandboxes. Ireland's commitment to becoming a global leader in 'trustworthy AI' is intrinsically linked to its active participation in the ongoing development of European AI standards and its coordination with the European AI Office. This robust international alignment ensures that Ireland's regulatory environment is consistent with the broader European Digital Single Market, providing legal certainty for technology companies operating across the EU.
What's next
Ireland's AI regulatory landscape is set for significant developments as the country moves towards the full operationalization of the EU AI Act. The General Scheme of the Regulation of Artificial Intelligence Bill 2026, currently in draft form, is the cornerstone of these future changes. Its enactment will provide the comprehensive national enforcement powers necessary to fully implement the EU AI Act, establishing the National AI Office and formalizing the roles of the 15 designated Market Surveillance Authorities.A key milestone is the target date of August 2, 2026, for the full application of the AI Act in Ireland, which will coincide with the establishment of the National AI Office and the operationalization of AI regulatory sandboxes. These sandboxes are designed to provide controlled environments for businesses, especially Small and Medium Enterprises (SMEs), to test innovative AI systems under supervision, fostering innovation while ensuring compliance. Further amendments or statutory instruments may expand or update the list of competent authorities and refine national penalty rules, as Ireland continues to adapt its framework to the dynamic nature of AI technology and evolving EU-level guidance. The ongoing monitoring and evaluation requirements, including biennial reporting to the European Commission on the resources of national competent authorities, will also drive continuous refinement of the Irish AI regulatory approach.
policy · Effective Jan 1, 2026
guideline · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
guideline · Effective Jan 1, 2024
central_coordinator
Central coordination, technical expertise, and single point of contact for EU AI Act implementation. Coordinates Market Surveillance Authorities.
advisory
Lead department for national AI policy and implementation of the EU AI Act.
central_coordinator
Market Surveillance Authority for AI systems in the financial services sector.
data_protection
Market Surveillance Authority for AI systems processing personal data; primary supervisory authority for GDPR.
No tracked timeline events yet
Last checked May 26, 2026
No tracked international memberships yet
Last checked May 26, 2026
guideline · Effective Jan 1, 2024
guideline · Effective Jan 1, 2023
policy · Effective Jan 1, 2021
sectoral
Market Surveillance Authority for AI systems in media and online platforms.
advisory
Provides cyber security guidance and expertise for AI technologies, particularly for public sector bodies.
enforcement
Market Surveillance Authority for AI systems impacting competition and consumer protection.
enforcement
Market Surveillance Authority for AI systems impacting workplace health and safety.
enforcement
Market Surveillance Authority for AI systems used in health products.
sectoral
Market Surveillance Authority for AI systems in the communications sector.
enforcement
Market Surveillance Authority for AI systems in the railway sector.
enforcement
Market Surveillance Authority for AI systems in the marine sector.