There is no single AI regulator in Ireland, and there was never going to be. The Regulation of Artificial Intelligence Act 2026 settled the question by distributing it: your existing regulator supervises your AI, in your sector.
That answer disappoints people who wanted one phone number. It is also, on reflection, the sensible design - the body that already understands medical devices is better placed to judge an AI medical device than a new agency would be.
The structure, as enacted
Ireland's implementing legislation is the Regulation of Artificial Intelligence Act 2026, which came into force at the end of July 2026. It sits on top of the earlier European Union (Artificial Intelligence) (Designation) Regulations 2025, S.I. No. 366 of 2025, which is the instrument that actually names the authorities.
The model is a distributed, sector-based one. Market surveillance authorities supervise and enforce the AI Act within their own sectors, using the powers they already have.
The AI Office of Ireland - and what it is not
The AI Office is Ireland's single point of contact with the European Commission and the EU AI Office. It coordinates between the national authorities, maintains the national AI register, oversees regulatory sandboxes and real-world testing, and is charged with promoting AI literacy.
It is not a market surveillance authority. This is worth saying plainly, because it changed during the legislative process: the original General Scheme would have given the AI Office a supervisory role, and the published Bill removed it. If you read commentary written before June 2026, it may tell you otherwise.
So the AI Office is not who investigates you. It is who the Commission talks to.
Who supervises whom
The authorities named under the designation regulations include:
The Data Protection Commission - protection of fundamental rights in relation to personal data, including in high-risk AI systems. Given how much AI touches personal data, this is the authority most Irish companies will encounter first.
The Central Bank of Ireland - regulated entities providing financial services. If you are supervised by the Central Bank today, you are supervised by the Central Bank for AI.
Coimisiun na Mean - AI in audiovisual media services.
The Competition and Consumer Protection Commission - among the sectoral regulators receiving AI Act procedures.
The full designation covers further sectoral regulators. The principle is consistent: find the regulator that already governs your activity, and that is the one.
What they can do
Market surveillance authorities may appoint authorised officers with powers of inspection, issue contravention notices and prohibition notices, and administer fines.
The penalty ceilings are set by the Act itself: up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for most other operator breaches, and up to EUR 7.5 million or 1% for supplying incorrect or incomplete information. Public bodies face a separate, lower ceiling.
Whichever is higher applies, which is the detail that makes these numbers real for large firms and survivable for small ones.
Who enforces AI rules in the UK, the United States and Australia
United Kingdom - nobody has a dedicated AI mandate. Enforcement sits with the existing regulators under existing law. The ICO for data protection, and since 12 May 2026 under a statutory duty to produce a code of practice on AI and automated decision-making, which is not yet drafted. The FCA and PRA in financial services, still technology-neutral and principles-based. Ofcom under the Online Safety Act, and only where the service is user-to-user, search, or publishes pornography. The CMA for competition and the digital markets regime. The MHRA for AI as a medical device. The EHRC under the Equality Act and the public sector equality duty. The Digital Regulation Cooperation Forum coordinates four of them and holds no powers of its own. The AI Security Institute, despite the name, is a research body inside DSIT: it cannot require a model to be submitted for evaluation, block a release, or take enforcement action.
United States - no federal AI regulator. The FTC acts against deceptive AI claims under its existing consumer protection powers, in a programme it has run since September 2024, and the SEC against AI-washing in securities disclosure. Employment claims run through Title VII and the ADA, although the EEOC withdrew its AI-specific guidance in January 2025. At state level the attorney general is usually the enforcer: Texas gives its AG exclusive enforcement of its 2026 Act, with a 60-day cure period and no private right of action; Illinois and California route claims through their civil rights agencies. The one place with a genuine standing audit mandate is New York City, where an automated employment decision tool must have an independent bias audit every year before it may be used.
Australia - no AI regulator. The OAIC for privacy, ASIC for licensees and directors, APRA for banks and insurers, the ACCC for consumer law, eSafety for online harms. The Australian AI Safety Institute announced in December 2025 is a capability body, not an enforcement one. A Joint Select Committee on AI was appointed in August 2026 and is due to report on 30 November 2026, and the mandatory standards announced in July 2026 are expected to be legislated in early 2027.
The pattern is the same in all three: the enforcer is the regulator who already had you. That is why the question worth asking is not who the AI regulator is, but which of your existing regulators now has an AI file open on your sector. Huceptron has representation in the United Kingdom, the United States and Australia, and we answer that question jurisdiction by jurisdiction.
What this means practically
You do not need to work out who your AI regulator is. You already know who your regulator is - and now they also do AI.
The practical consequence is that your AI governance should live where your existing compliance function lives, speak the language your regulator already uses, and produce the kind of evidence they already ask for. Firms that build a separate AI compliance silo tend to end up explaining it twice.