EU AI Act in Ireland
Ireland adopted a distributed 15-authority enforcement model, the most fragmented allocation in the EU. For providers headquartered in Ireland (including many US tech multinationals with EU HQs in Dublin), identifying the correct competent authority is the first non-trivial compliance step.
Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.
Ireland announced its EU AI Act enforcement architecture in 2025 with an unusual design choice: distributed jurisdiction across 15 sector-specific competent authorities rather than a single lead body. The Competition and Consumer Protection Commission (CCPC) is designated as the coordinating market surveillance authority, but the substantive enforcement is split across bodies including the Data Protection Commission (DPC), the Central Bank of Ireland, the Medical Devices Agency (HPRA), ComReg, An Garda Síochána, and others.
The design is defensible in terms of sector expertise, but it creates a practical complexity multiplier for any AI system that touches more than one regulated domain. An AI-enabled medical device used for HR decisions at an insurance company could, in theory, answer to four separate authorities. Irish government guidance on cross-authority coordination is still in development as of April 2026.
Who Regulates What
A non-exhaustive allocation (the 15-authority list is subject to ongoing refinement):
- CCPC (Competition and Consumer Protection Commission), coordinating market surveillance authority; consumer-facing AI.
- Data Protection Commission (DPC), law-enforcement AI (Annex III Point 6), biometric systems (Point 1), AI involving personal data processing generally.
- Central Bank of Ireland, AI in financial services (credit, insurance, capital markets) under Points 5(b), 5(c).
- HPRA (Health Products Regulatory Authority), AI-enabled medical devices under MDR/IVDR integration.
- Department of Justice / An Garda Síochána, law enforcement deployments.
- Department of Education, Annex III Point 3 education AI.
- WRC (Workplace Relations Commission), Annex III Point 4 employment AI.
- ComReg, telecoms and digital infrastructure (Point 2 overlap).
- NTA, CRU, transport and energy infrastructure.
- Additional sectoral authorities, filling remaining Annex III domains and sectoral overlaps.
Why This Matters for Big Tech
Dublin is the EU headquarters for Meta, Google, Microsoft, Apple, LinkedIn, X, TikTok and others. Ireland's DPC is already the primary data-protection supervisor for many of these entities under GDPR's one-stop-shop principle. Under the AI Act's distributed Irish model, the DPC retains that role for data-related aspects, but coordination with CCPC and sectoral bodies is required for full-system oversight.
For a US-headquartered AI provider placing systems on the EU market with Dublin as its EU establishment, the practical consequence is: single AI system, multiple Irish regulators, one coordinating body. Compliance programmes built around a single-authority engagement model will need to adapt.
The Phased-Compliance Playbook for Irish Providers
A provider or deployer in Ireland has the following compliance path:
- Identify the primary competent authority per system. Map each AI system against the 15-authority allocation. The CCPC is a coordination point but not a substitute for identifying the substantive regulator.
- Engage early with the primary authority. Several Irish authorities (DPC, Central Bank, HPRA) have pre-enforcement engagement programmes, early dialogue reduces enforcement risk.
- Work-council analogue. Ireland does not have statutory works councils of the German kind, but the Workplace Relations Commission and ICTU engagement is relevant for Annex III Point 4 deployments.
- One-stop-shop coordination. Where a system touches multiple authorities, request a CCPC-coordinated single-point-of-contact engagement. Guidance is evolving.
- Document for cross-border reach. Irish-based providers serving other Member States will face parallel queries from other national authorities. Documentation must be multi-jurisdictionally defensible.
Multi-Member-State Compliance
If you deploy across Germany, France, Ireland and the UK, the Full Readiness Bundle gives you a single source of truth for the AI Act obligations that apply regardless of Member State, with country-specific appendices for major jurisdictions.
one-time · instant download
Get the Full Bundle →Also available: Checklist Pack $149 · White-Label $999/yr
Member State Tracker
Countdown Plan
Week-by-week compliance work plan across the EU AI Act's phased timeline.
Week-by-Week →