Almost every company we speak to asks this in the same slightly defensive way, and almost every one of them is asking the wrong question. The Act does not ask what sector you are in. It asks what you do with an AI system, and there are only a few answers.
Here is the short version. If you build or brand an AI system, you are a provider. If you use one in the course of your business, you are a deployer. The great majority of Irish companies are deployers and have never thought of themselves as having anything to do with AI regulation at all.
The test, in four questions
1. Do you place an AI system on the EU market under your own name or trade mark? Then you are a provider, and you carry the heaviest set of duties. This includes rebranding somebody else's model as your own product.
2. Do you use an AI system in a professional capacity? Then you are a deployer. A recruitment screening tool, a customer chatbot, a document triage system, a fraud model bought from a vendor - all deployment.
3. Are you outside the EU but your system's output is used inside it? The Act reaches you. Territorial scope follows the output, not the office.
4. Are you using AI purely personally and non-professionally? Then it does not apply to you. That exemption is narrower than people hope, and it disappears the moment the use is commercial.
What actually attaches to a deployer
This is where the relief usually arrives. A deployer of a system that is not high-risk carries a short list, not a long one.
AI literacy. You must take measures to ensure the people operating your AI systems have sufficient understanding to do so sensibly. This applies to everybody, regardless of risk tier, and it is the most widely ignored obligation in the Act.
Transparency, where it bites. If people interact with your AI, they must be able to know it. If you publish synthetic content, it must be marked. Those duties have applied since 2 August 2026.
Human oversight and monitoring, if the system is high-risk - and most are not.
What makes a system high-risk
High-risk is a defined list, not a feeling. It covers AI used as a safety component of a regulated product, and a specific set of uses in Annex III: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential public and private services, law enforcement, migration and border control, and the administration of justice.
Recruitment is the one that catches ordinary companies. If you use AI to filter CVs or rank candidates, you are in Annex III territory - and those obligations apply from 2 December 2027.
Three things that are prohibited outright
Whatever else applies to you, these have been banned since 2 February 2025: social scoring by public authorities, exploiting vulnerabilities of specific groups, and emotion inference in the workplace or in education, outside narrow safety and medical exceptions.
That last one surprises people. Software that claims to read employee sentiment from calls or cameras is not a grey area.
If you are in the UK, the United States or Australia
The Act follows the output, not the postcode. Article 2 catches providers who place an AI system or a general-purpose model on the EU market wherever they are established, and it catches providers and deployers outside the Union where the output of the system is used in the Union. A London recruiter screening candidates for a Dublin office is in scope. A Sydney software vendor whose product is resold to a Belgian customer is in scope. A Texas company whose model powers a feature shipped to EU users is in scope. A non-EU provider of a high-risk system must also appoint an authorised representative established in the Union before the system is placed on the market.
Then there is what applies at home, which is a separate question with a separate answer.
United Kingdom. There is no UK AI Act, and the King’s Speech in May 2026 contained no AI bill. AI is policed by the regulators that were already there, under the powers they already had: the ICO for data protection, the FCA and PRA in financial services, Ofcom under the Online Safety Act, the MHRA for AI as a medical device. The material change for most firms was the Data (Use and Access) Act 2025, which on 5 February 2026 replaced UK GDPR Article 22 with Articles 22A to 22D. The blanket prohibition on solely automated significant decisions is gone. In its place sits a duty to tell the person, let them make representations, obtain human intervention and contest the outcome.
United States. There is no federal AI statute. The duties are in state law, and they commenced: Texas on 1 January 2026, California’s transparency and frontier-model rules on the same date, Illinois on employment on the same date, Colorado’s replacement statute on 1 January 2027. Federal policy since December 2025 has been to push back on state laws rather than replace them, so the patchwork is what you comply with, not a placeholder for something tidier.
Australia. No AI Act either. The National AI Plan of December 2025 said existing law would carry the load; in July 2026 the government changed course and announced mandatory Australian Standards for AI, expected to reach Parliament in early 2027. What binds today is the Privacy Act, which from 10 December 2026 requires privacy policies to disclose automated decisions that could reasonably be expected to significantly affect a person’s rights or interests, together with the Australian Consumer Law, directors’ duties, and for banks and insurers APRA CPS 230.
So a company outside the EU has two answers to keep straight: what the EU Act makes you do because of where your output lands, and what your own regulator makes you do at home. We assess both, and we have representation in the United Kingdom, the United States and Australia.
The honest answer
For most Irish SMEs the Act applies, and lightly. You are a deployer of systems that are not high-risk, and your real obligations are literacy, transparency, and knowing what you are actually running.
The companies that get into difficulty are not the ones with complicated AI. They are the ones who cannot produce a list of what they use, because nobody ever wrote it down.