EU AI Act for Irish SMEs: what the DPC actually enforces
A client based near Dublin's Grand Canal Dock — perhaps a professional services firm that supports one of the Big Tech EU headquarters clustered in that few square miles — sends over its annual vendor questionnaire, and for the first time it asks whether your company's AI tools comply with the EU AI Act. Or maybe nothing arrived from outside at all: someone on your team just switched on an AI assistant inside a CRM or HR platform you already pay for, and nobody has checked what that switches on legally. Both situations land on Irish SMEs constantly, and the honest answer is rarely a flat yes or no.
Why Ireland's position on the AI Act is unusual
Ireland hosts the EU or EMEA headquarters of most major US technology companies — Google, Meta, Microsoft, LinkedIn, TikTok, and others are all based here. That concentration is why the Data Protection Commission (DPC) became the lead supervisory authority under the GDPR's one-stop-shop mechanism (Article 56) for a large share of cross-border cases involving those companies. Irish SMEs have absorbed some of that reputation by association: a country known internationally as Big Tech's EU base, with a data protection regulator that foreign press and foreign counsel watch closely.
It's worth being precise about what that reputation does and doesn't mean for the AI Act, formally Regulation (EU) 2024/1689. The DPC's GDPR one-stop-shop role and any role it holds under the AI Act are two separate mandates, created years apart, and they do not automatically overlap. The AI Act requires each EU member state to designate a national competent authority, or authorities, for market surveillance and conformity assessment by 2 August 2025. Ireland's exact allocation of that role — whether it sits solely with the DPC, is shared across several sectoral regulators, or routes primarily through a body such as the National Standards Authority of Ireland (NSAI) for conformity assessment work — is not something we can state with full certainty in a general guide like this one, and we would treat any single-authority framing you read elsewhere with some caution until it is checked against the current official designation.
What it costs to get wrong
The AI Act's penalty structure is tiered by severity. Prohibited practices — the short list of banned uses, such as certain social-scoring or manipulative systems — can draw fines of up to €35 million or 7% of global annual turnover, whichever is higher. Most other breaches, including failures tied to high-risk systems, top out at €15 million or 3% of global turnover.
That SME carve-out is genuinely reassuring, but it isn't a reason to skip the underlying assessment. It changes the ceiling you might face, not whether an obligation applies to your specific use case in the first place.
Where Irish SMEs actually sit in the regulation
Very few Irish SMEs are providers in the Act's sense of the word — building a model and placing it on the market under their own name. Far more are deployers: using a hiring tool, a customer chatbot, or an AI feature bundled into SaaS you already run day to day. That distinction matters a great deal for the size of your obligations. Two groups of Irish SMEs are worth a closer look regardless of that general pattern: fintech and SaaS scale-ups clustered around Dublin who build AI-adjacent products themselves, and professional services or consulting firms whose clients are the very Big Tech entities headquartered here, who are increasingly being asked to demonstrate their own AI governance as a condition of keeping the contract.
What to check in your own business
Before treating any of this as a legal project, it's worth walking through a short set of concrete questions about how your business actually uses AI today:
- Does any AI tool you use touch hiring, performance management, credit decisions, or another Annex III high-risk area?
- Has a client or partner — especially one connected to a Big Tech EU entity — sent a vendor questionnaire asking about AI Act compliance?
- Do you know whether your business is a provider or a deployer for each AI system you use, rather than just in general?
- If a regulator contacted you tomorrow, could you say with confidence who in Ireland you'd expect to hear from — the DPC, a sectoral body, or neither?
- Are any of your existing SaaS subscriptions running new AI features you haven't reviewed since they were switched on?
General information, not legal advice
Everything above is general information meant to help you get oriented, not legal advice for your specific situation — and, as flagged above, some of the institutional detail around exactly how Ireland allocates AI Act market surveillance duties is not something we can state with full precision here. The Act itself, and Ireland's implementation of it, will keep developing over the coming years. Where Komplya publishes guidance like this, we are clear about which layers have been legally reviewed and which remain draft material, so you can weigh it accordingly rather than treat it all as equally authoritative.
Where to go from here
Rather than trying to read the full regulation cold, the more useful next step is to walk through your actual AI use, tool by tool, and see where each one lands. Answer a short questionnaire about how your business uses AI and get a plain-language read on where you likely stand — including whether the DPC, another authority, or no one in particular is likely to take an interest.