KomplyaBack to blog

Who Enforces the AI Act in Ireland?

Published 2026-08-09· 6 min readRegulatory pulse

You saw the headline: the DPC has opened another inquiry into a large tech platform, or issued another significant fine. Your instinct, if your company uses AI tools anywhere in the business, is to wonder whether the same body is coming for you next, and over what exactly. Or maybe a client's procurement team has asked, ahead of an audit, which regulator you'd need to satisfy if your AI-assisted onboarding or scoring tool were ever questioned. Both are the same underlying question: who actually enforces the AI Act in Ireland, and is it the same authority you already know from GDPR?

Why this feels murkier than it should

For GDPR, the answer to "who enforces this" has been settled since 2018: the Data Protection Commission. For the AI Act, formally Regulation (EU) 2024/1689, the answer is a genuine work in progress across the EU, not just in Ireland. The Act requires each member state to designate national market surveillance authorities under its general framework (the mechanism is often referenced back to Article 70), but leaves the choice of which body, or bodies, covers which categories of AI system largely to national implementing law. Some member states have finished that process; others, Ireland included, are still finalising the detail as of this writing. That gap between "the obligations are already in force" and "the enforcement map is still being drawn" is the actual source of the confusion, and it's worth naming plainly rather than glossing over.

The DPC's two distinct jobs, and why Ireland's role here is unusual

Start with what is genuinely settled. Under GDPR, the DPC is Ireland's lead supervisory authority, and because Ireland hosts the European headquarters of a large share of the world's major technology companies, the DPC frequently acts as the lead authority under the GDPR one-stop-shop mechanism for cross-border cases involving those firms. A decision the DPC makes about a platform headquartered in Dublin can set the practical standard for how that platform treats users across the entire EU. That is not a small-country regulator's job; it is one of the more consequential enforcement seats in European data protection, and it has given the DPC nearly a decade of hands-on experience scrutinising exactly the kind of data processing, profiling, and automated decision-making that AI systems typically involve.

The DPC is now also taking on a second, distinct role connected to the AI Act: a market surveillance function for at least some categories of AI system, building on that existing data-protection expertise. Where this gets genuinely uncertain is the exact scope: which AI Act articles and which categories of AI system fall to the DPC specifically, and whether sector regulators share jurisdiction for AI used in regulated activities. Financial services is the clearest example. The Central Bank of Ireland already supervises banks, insurers, and payment firms on a sectoral basis, and AI systems used for credit scoring, fraud detection, or insurance pricing plausibly sit at the intersection of the DPC's general market surveillance role and the Central Bank's existing sectoral mandate. We have not seen a fully finalised, publicly confirmed allocation of which body handles which AI Act obligations for financial-services AI specifically, and we are flagging that as a genuine open question rather than asserting a clean division that may not exist yet. Treat any confident-sounding claim about the precise split, including this one if it turns out to be incomplete, with appropriate caution until Ireland's implementing legislation and official DPC guidance settle the point.

What it costs to get this wrong

Uncertainty about which body enforces a given rule does not reduce the size of the penalties attached to breaking it. The AI Act's own fine structure, under Article 99, sets fines of up to €35 million or 7% of a company's total worldwide annual turnover, whichever is higher, for engaging in prohibited AI practices. Most other breaches, including failures around high-risk system obligations, carry fines of up to €15 million or 3% of global turnover. Article 99(6) does provide for proportionately lower caps for SMEs and startups, which matters for most Irish businesses reading this, but a reduced cap on a multi-million-euro exposure is still a serious number for a small company, and it does not remove the obligation itself. Whichever authority ultimately confirms jurisdiction over your specific AI use case, the substantive rules and the exposure they carry are already in force now, not waiting on the institutional question to be resolved.

A DIY checklist: what to verify about your own exposure

You do not need Ireland's enforcement map to be finished before you can get your own house in order. These are the questions worth answering about your business today:

  • Do you know every AI system your company uses that processes personal data, and could you list them in five minutes if a client or auditor asked?
  • Have you checked, for each of those systems, whether it falls under the AI Act's high-risk categories in Annex III, such as employment screening, credit assessment, or insurance risk scoring?
  • If your business operates in financial services, do you know whether the Central Bank of Ireland has published, or is expected to publish, its own guidance on AI systems used in regulated activities?
  • Do you have basic documentation on file for your higher-stakes AI use cases, covering purpose, data used, and human oversight, rather than waiting for a regulator to ask first?
  • Have you assigned clear internal ownership for tracking DPC and Central Bank announcements on AI Act enforcement, so this isn't left to whoever happens to see the news?
  • Would your existing GDPR documentation actually hold up if reused as a starting point for an AI Act inquiry, or does it stop short of the AI-specific detail a regulator would want?

General information, not legal advice: this article is meant to orient you, particularly on a point, the precise institutional split of AI Act enforcement in Ireland, that is genuinely still settling and where we have been explicit about what is not yet confirmed. It is not a substitute for legal advice on your specific situation. Where Komplya publishes material like this, we distinguish content that has been formally reviewed against primary sources from material that remains in draft, so you can weigh it accordingly.

The institutional question will keep resolving itself over the coming months as Ireland's implementing rules and DPC guidance firm up, and that is genuinely out of your hands. What is in your hands is knowing, today, which of your own AI systems would draw attention if either the DPC or a sector regulator came asking. A short questionnaire on your actual AI use cases is the fastest way to get a plain-language read on where your exposure likely sits, so you are not starting that work from a standing start when the enforcement picture is finally settled.