Artificial Intelligence in Ireland

Regulatory guidance / voluntary codes in Ireland

In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has published various guidelines and codes of practice. These are non-binding, as only the Court of Justice of the European Union has authoritative interpretation powers. Codes of practice are voluntary compliance tools which help demonstrate compliance with binding AI Act obligations.

The Commission has published the following guidelines:

The Commission has also published the following codes of practice:

Under Article 95 of the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct in order to adopt, on a non-binding basis, technical solutions and industry best practices. Because of this, it is expected that the AI Office will issue further codes of conduct for this purpose.

To provide organisations with support identifying and implementing AI literacy initiatives, on 4 February 2025 the Commission launched a repository of AI literacy practices.

In May 2024, the Council of Europe adopted the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework Convention) (CETS No. 225). The Framework Convention was opened for signature on 5 September 2024 in Vilnius, and the European Union signed the same day pursuant to Council Decision (EU) 2024/2218. It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy, and the rule of law, whilst being conducive to technological progress and innovation.

The Irish government and certain competent authorities in Ireland have also published guidance on the use and adoption of AI, including those detailed below.

Guidelines for the Responsible Use of AI in the Public Service (2025)

On 7 May 2025, the Irish Government (specifically, the Department of Public Expenditure, Infrastructure, Public Service Reform and Digitisation) published Guidelines for the Responsible Use of AI in the Public Sector (Public Sector Guidelines), which were developed to empower public servants to use AI in the delivery of services. The Public Sector Guidelines set the overarching framework for adoption and use of AI by the public service, and are built around 'Seven Principles for Responsible AI', namely:

  • Human agency and oversight
  • Technical robustness and safety
  • Privacy and data governance
  • Transparency
  • Diversity, non-discrimination and fairness
  • Societal and environmental well-being
  • Accountability

National Cyber Security Centre (NCSC) Guidance on AI

To complement the Public Sector Guidelines, the National Cyber Security Centre (NCSC) in Ireland has published cyber security guidelines for AI deployments (Cyber Security Guidelines), which address the cyber security obligations arising from the use and adoption of AI.

The Cyber Security Guidelines are directed at public bodies, but the NCSC recognises within these guidelines that they may also be useful for management boards who will have expanded responsibilities under the Network and Information Security Directive 2 (NIS2). They are structured around seven principles spanning the phases of the AI lifecycle as follows:

  • Design – Principle 1: Build trust and security through informed design and risk awareness.
  • Development – Principle 2: Identify and secure all assets ensuring end-to-end traceability and recovery. Principle 3: Build resilience through effective security controls and supply chain assurance.
  • Deployment – Principle 4: Implement rigorous testing and validation to ensure reliability. Principle 5: Support oversight and assurance through accountable, explainable and transparent operation.
  • Maintenance – Principle 6: Maintain secure operations through continuous oversight and rapid response.
  • End-of-life – Principle 7: Safely retire artefacts and document that compliance obligations have been met.

Central Bank of Ireland Regulatory and Supervisory Outlook Report 2026

Pursuant to European Union (Artificial Intelligence) (Designation) Regulations 2025, the Central Bank of Ireland (CBI) is designated as the market surveillance authority in Ireland, responsible for the financial supervision of institutions placing on the market, putting into service, or using AI systems in direct connection with the provision of financial services.

In February 2026, the CBI published its regulatory and supervisory outlook report (Report) in which it provides guidance for the use of AI in financial services. The Report states that firms must adhere to the following standards when deploying AI:

  • Strategic alignment: Firms must ensure their use of AI is appropriate for the specific business challenge being addressed.
  • Accountability and explainability: They should establish clear accountabilities and responsibility, human oversight of decisions and their explainability.
  • Proportionate governance: Risk management practices must be commensurate with the scale, scope and sensitivity of the AI deployment.
  • Compliance: Processes should be in place to ensure all EU AI Act obligations are met, including transparency requirements.

Continue reading

  • no results

Previous topic
Back to top