The EU AI Act After 2 August 2026: A 60-Minute Check for Irish SMEs
The EU AI Act is now being enforced. Here is a plain-English check for Irish SMEs using chatbots, AI assistants, and AI-generated content.
The EU AI Act is now being enforced. Here is a plain-English check for Irish SMEs using chatbots, AI assistants, and AI-generated content.
The main rules of the EU AI Act now apply. The change happened on 2 August 2026, when the European Commission and national authorities began enforcing the Act. The Commission explains the change here.
That does not mean every Irish business using ChatGPT, Copilot, Claude, or another AI tool suddenly needs an expensive compliance project.
It does mean that businesses should know what AI they use, what information goes into it, who is responsible for the result, and when customers should be told that they are dealing with a machine.
This is a practical starting point for small and medium-sized businesses. It is not legal advice.
Two things matter most to ordinary businesses.
First, the European Commission and national authorities can now enforce the AI Act.
Second, new transparency rules apply to certain AI systems and content. These rules are explained in the Commission’s Article 50 guidance.
For example, people should be told when they are speaking to a customer-facing chatbot, unless the use of AI is already obvious. Some AI-generated images, videos, and audio also need a clear label when they are deepfakes. The Commission’s Article 50 FAQ explains these duties in more detail.
The rules do not say that every email helped by AI needs a label. They do not say that every AI-written advert needs a label either. The rules are about specific types of content and use, not every piece of work that received help from an AI tool.
The exact rule depends on the type of content, where it is used, and whether a person has properly reviewed it.
The high-risk rules did not all start on 2 August 2026. The Commission’s current AI Act timeline sets out the different dates.
Some high-risk rules for areas such as recruitment, worker management, and certain regulated products have been delayed. The main dates are:
That does not mean businesses can ignore these uses. GDPR, equality law, employment law, consumer law, and confidentiality rules still apply now. The AI Office of Ireland also points businesses towards the Irish authorities responsible for different parts of the Act.
Using a person to click “approve” does not automatically make a risky system safe or lawful.
Most small businesses will be using AI in one of five ways:
These uses do not all have the same risk.
Your business is usually the deployer. In simple terms, that means your business is using a system provided by someone else.
Your main jobs are to give staff sensible guidance and to control what information they enter.
Staff should know:
The AI Act calls this AI literacy. The Commission says there is no single required course or certificate. The guidance should match the tools and work your team actually uses. Read the Commission’s AI literacy questions and answers.
A private assistant that searches approved company documents can be useful for policies, proposals, onboarding, and repeat process questions.
It should still have clear limits:
These controls help reduce mistakes and protect company information. They do not automatically make the system compliant with every law.
Customers should be told when they are dealing with AI, unless that is already obvious. If you use a third-party chatbot, ask the provider how this notice is handled. If you built or launched the system under your own name, your responsibilities may be different.
The chatbot should also have a clear route to a person. It should not pretend to be a member of staff or give confident answers outside its approved information.
Questions about complaints, payments, legal matters, sensitive information, and final quotes should normally go to a person.
Not every piece of AI-assisted marketing needs a label.
The rules are more specific. Deepfake images, videos, and audio need a clear disclosure. Text published to inform the public about matters of public interest may also need disclosure, unless there has been meaningful human review and a person or business takes editorial responsibility for it. The Commission’s transparency FAQ gives examples of what is covered.
The safe habit is simple: keep a person responsible for anything published in the company name. Check names, figures, claims, images, and quotes before publishing.
AI used to target job adverts, filter applications, score candidates, monitor workers, or influence employment decisions needs more care.
Some of these uses fall into the high-risk category. Workplace emotion recognition is already prohibited in most cases under the Act. See the Commission’s list of prohibited practices.
Do not assume that a human review makes the system low risk. If AI is deciding who gets attention or who is rejected, get specialist advice before relying on it.
You do not need a large project to make a useful start.
Write down every AI tool used by the business. Include tools built into software you already pay for.
For each tool, record:
Ask staff directly. The tools nobody has listed are often the ones that need the most attention.
For each tool, write down what goes in and what comes out.
Look for:
If you do not know how a provider stores or uses the information, pause before sending more of it. Check the provider’s terms, privacy information, retention settings, and model training settings first.
Visit your website and test any chatbot or assistant as a customer would.
Check that:
Also check recent AI-generated images, videos, and audio used in public marketing.
For each assistant or automation, ask what it can access and what it can change.
Start with the smallest useful permission. An assistant that can read approved documents and draft a reply does not need permission to send emails, delete files, or change a customer record.
Keep approval with a named person when a mistake could cost money, damage trust, or affect someone’s rights.
Write a one-page guide covering:
Keep a record of who received the guidance. Review it when your tools or workflows change.
Give one person responsibility for keeping the list up to date.
They do not need to become an AI specialist. They do need to know:
Review the list at least when you add a new tool or connect a new source of company data.
Get advice before using AI for:
The AI Act is only one part of the picture. GDPR, equality law, sector rules, contracts, and basic good judgement still matter. For personal data, the Data Protection Commission’s guidance is a useful starting point.
Most small businesses do not need another vague AI strategy.
They need a short list of approved tools, sensible access rules, staff who know the limits, and a person who checks important work before it leaves the business.
That is also why we start with workflows rather than agent brands. A useful managed workspace should use approved company sources, begin with limited permissions, draft rather than act, and keep a human responsible for the final decision.
The goal is not to remove people from the process. It is to remove the repetitive work while keeping the business in control.
If you are not sure what AI your business is already using, a short workflow audit can give you a clear list of tools, data risks, approval points, and practical next steps. Book a workflow audit with SMB-AI.
This article gives general information, not legal advice. Rules and guidance can change. Get advice on your specific situation where needed.