Skip to content
Blog

The EU AI Act After 2 August 2026: A 60-Minute Check for Irish SMEs

The EU AI Act is now being enforced. Here is a plain-English check for Irish SMEs using chatbots, AI assistants, and AI-generated content.

SMB-AI Team

The main rules of the EU AI Act now apply. The change happened on 2 August 2026, when the European Commission and national authorities began enforcing the Act. The Commission explains the change here.

That does not mean every Irish business using ChatGPT, Copilot, Claude, or another AI tool suddenly needs an expensive compliance project.

It does mean that businesses should know what AI they use, what information goes into it, who is responsible for the result, and when customers should be told that they are dealing with a machine.

This is a practical starting point for small and medium-sized businesses. It is not legal advice.

What changed on 2 August?

Two things matter most to ordinary businesses.

First, the European Commission and national authorities can now enforce the AI Act.

Second, new transparency rules apply to certain AI systems and content. These rules are explained in the Commission’s Article 50 guidance.

For example, people should be told when they are speaking to a customer-facing chatbot, unless the use of AI is already obvious. Some AI-generated images, videos, and audio also need a clear label when they are deepfakes. The Commission’s Article 50 FAQ explains these duties in more detail.

The rules do not say that every email helped by AI needs a label. They do not say that every AI-written advert needs a label either. The rules are about specific types of content and use, not every piece of work that received help from an AI tool.

The exact rule depends on the type of content, where it is used, and whether a person has properly reviewed it.

What has not changed?

The high-risk rules did not all start on 2 August 2026. The Commission’s current AI Act timeline sets out the different dates.

Some high-risk rules for areas such as recruitment, worker management, and certain regulated products have been delayed. The main dates are:

  • 2 December 2027 for certain high-risk uses, including many employment-related systems
  • 2 August 2028 for high-risk systems built into regulated products

That does not mean businesses can ignore these uses. GDPR, equality law, employment law, consumer law, and confidentiality rules still apply now. The AI Office of Ireland also points businesses towards the Irish authorities responsible for different parts of the Act.

Using a person to click “approve” does not automatically make a risky system safe or lawful.

What does this mean for a small business?

Most small businesses will be using AI in one of five ways:

  1. Staff use a general AI tool to draft, translate, summarise, or research.
  2. A private assistant answers questions from company documents.
  3. A chatbot answers customer questions or collects enquiries.
  4. AI helps create marketing text, images, audio, or video.
  5. AI helps sort job applications or assess candidates.

These uses do not all have the same risk.

Staff using ChatGPT or Copilot

Your business is usually the deployer. In simple terms, that means your business is using a system provided by someone else.

Your main jobs are to give staff sensible guidance and to control what information they enter.

Staff should know:

  • Which tools the business has approved
  • What customer, employee, or confidential information must not be pasted into a tool
  • How to check an answer before using it
  • When a person must review the result
  • Who to ask when something looks wrong

The AI Act calls this AI literacy. The Commission says there is no single required course or certificate. The guidance should match the tools and work your team actually uses. Read the Commission’s AI literacy questions and answers.

A private company assistant

A private assistant that searches approved company documents can be useful for policies, proposals, onboarding, and repeat process questions.

It should still have clear limits:

  • Use approved sources only
  • Start with read-only access
  • Link back to the source where possible
  • Do not allow silent changes to business records
  • Require a person to approve anything sent outside the business

These controls help reduce mistakes and protect company information. They do not automatically make the system compliant with every law.

A customer-facing chatbot

Customers should be told when they are dealing with AI, unless that is already obvious. If you use a third-party chatbot, ask the provider how this notice is handled. If you built or launched the system under your own name, your responsibilities may be different.

The chatbot should also have a clear route to a person. It should not pretend to be a member of staff or give confident answers outside its approved information.

Questions about complaints, payments, legal matters, sensitive information, and final quotes should normally go to a person.

AI-generated marketing content

Not every piece of AI-assisted marketing needs a label.

The rules are more specific. Deepfake images, videos, and audio need a clear disclosure. Text published to inform the public about matters of public interest may also need disclosure, unless there has been meaningful human review and a person or business takes editorial responsibility for it. The Commission’s transparency FAQ gives examples of what is covered.

The safe habit is simple: keep a person responsible for anything published in the company name. Check names, figures, claims, images, and quotes before publishing.

Recruitment and employee decisions

AI used to target job adverts, filter applications, score candidates, monitor workers, or influence employment decisions needs more care.

Some of these uses fall into the high-risk category. Workplace emotion recognition is already prohibited in most cases under the Act. See the Commission’s list of prohibited practices.

Do not assume that a human review makes the system low risk. If AI is deciding who gets attention or who is rejected, get specialist advice before relying on it.

The 60-minute AI check

You do not need a large project to make a useful start.

Minutes 0 to 10: List your tools

Write down every AI tool used by the business. Include tools built into software you already pay for.

For each tool, record:

  • The name of the tool
  • Who uses it
  • What it is used for
  • Who owns the account
  • Whether it faces customers, staff, candidates, or only internal users

Ask staff directly. The tools nobody has listed are often the ones that need the most attention.

Minutes 10 to 20: List the information involved

For each tool, write down what goes in and what comes out.

Look for:

  • Customer details
  • Employee information
  • Financial information
  • Health information
  • Contracts and legal documents
  • Passwords and access details
  • Confidential business information

If you do not know how a provider stores or uses the information, pause before sending more of it. Check the provider’s terms, privacy information, retention settings, and model training settings first.

Minutes 20 to 30: Check public-facing AI

Visit your website and test any chatbot or assistant as a customer would.

Check that:

  • It says when it is AI
  • It gives accurate information
  • It knows when to hand over to a person
  • It does not invent prices, promises, or policies
  • It does not ask for information it does not need

Also check recent AI-generated images, videos, and audio used in public marketing.

Minutes 30 to 40: Check permissions

For each assistant or automation, ask what it can access and what it can change.

Start with the smallest useful permission. An assistant that can read approved documents and draft a reply does not need permission to send emails, delete files, or change a customer record.

Keep approval with a named person when a mistake could cost money, damage trust, or affect someone’s rights.

Minutes 40 to 50: Give staff simple rules

Write a one-page guide covering:

  • Approved tools
  • Information that must not be entered
  • When outputs need checking
  • Which tasks always need human approval
  • How to report a bad or unexpected result

Keep a record of who received the guidance. Review it when your tools or workflows change.

Minutes 50 to 60: Choose an owner

Give one person responsibility for keeping the list up to date.

They do not need to become an AI specialist. They do need to know:

  • What tools are in use
  • Which workflows matter
  • Who approves external output
  • When supplier terms need checking
  • When to ask a solicitor, data protection specialist, or employment adviser

Review the list at least when you add a new tool or connect a new source of company data.

When should you get specialist advice?

Get advice before using AI for:

  • Hiring, firing, promotion, or worker monitoring
  • Candidate ranking or rejection
  • Credit, insurance, health, or other important decisions about people
  • Biometric identification or emotion analysis
  • Children’s information
  • Special-category personal data
  • Public-facing synthetic media that could mislead people
  • Any system where it is unclear whether your business is the provider or the deployer

The AI Act is only one part of the picture. GDPR, equality law, sector rules, contracts, and basic good judgement still matter. For personal data, the Data Protection Commission’s guidance is a useful starting point.

The sensible way to use AI

Most small businesses do not need another vague AI strategy.

They need a short list of approved tools, sensible access rules, staff who know the limits, and a person who checks important work before it leaves the business.

That is also why we start with workflows rather than agent brands. A useful managed workspace should use approved company sources, begin with limited permissions, draft rather than act, and keep a human responsible for the final decision.

The goal is not to remove people from the process. It is to remove the repetitive work while keeping the business in control.

If you are not sure what AI your business is already using, a short workflow audit can give you a clear list of tools, data risks, approval points, and practical next steps. Book a workflow audit with SMB-AI.

Sources

This article gives general information, not legal advice. Rules and guidance can change. Get advice on your specific situation where needed.