Artificial Intelligence in Ireland

Prohibited activities in Ireland

Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI. 

Under Article 5, these uses and technologies include:

  • Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting a person’s behaviour by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to do so).
  • Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to do so).
  • Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred, or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
  • Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
  • Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
  • Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
  • Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e., their race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
  • Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
  • As a new prohibited practice introduced by the Digital Omnibus for AI, Non-consensual intimate AI-generated content and CSAM: Placing on the market, putting into service, or using AI systems that (i) are intended to create, generate, or manipulate, or (ii) are designed or capable such that the creation, generation, or manipulation is a reasonably foreseeable outcome without adequate technical safeguards, non-consensual intimate content of natural persons (including non-consensual intimate deepfakes) or child sexual abuse material. Companies must comply with this prohibition by 2 December 2026.

Prohibited activities in Ireland

Recital 40 of the EU AI Act sets out Ireland's exemptions from certain prohibitions on AI practices in the context of police cooperation and judicial cooperation in criminal matters. Such exemptions arise from historic features of EU treaty law, namely Article 6a of Protocol No 21 and cover:

  • Article 5(1)(g) – The use of AI systems to deduce sensitive information about individuals;
  • Article 5(1)(d) – The use of AI systems to predict the risk of an individual committing a criminal offence; and
  • Article 5(1)(h), Article 5(2) to 5(6) and Article 26(10) – The use of 'real-time' remote biometric identification systems in public spaces for law enforcement.

The Irish Data Protection Commission (DPC) has been active in opening a number of consultations and investigations on certain AI systems.

  • In 2026, the DPC opened an inquiry into X Internet Unlimited Company under Section 110 of the Data Protection Act 2018 regarding the use of personal data for AI training which was not in compliance with Articles 5, 6, 25 and 35 General Data Protection Regulation (GDPR) obligations.
  • In 2025, the DPC engaged with LinkedIn regarding the training of a proprietary generative AI model using the personal data of users. As a result of this consultation, LinkedIn amended its plans.
  • In 2024, the DPC ordered X to suspend training of an AI chatbot after issuing High Court proceedings pursuant to Section 134 of the Data Protection Act 2018.
  • In 2024, the DPC launched a statutory inquiry into Google Ireland under Section 110 of the Data Protection Act 2018, regarding compliance with data protection obligations pursuant to Article 35 of the GDPR for its Pathways Language Model 2 (PaLM 2).
  • In 2023/24, the DPC engaged with Meta in relation to the training of its large language model (LLM) using public content shared across the EU, which led to the DPC seeking a formal GDPR opinion on the matter from the European Data Protection Board (EDPB). Engagement with Meta and oversight of its implemented measures and improvements is ongoing.

In February 2025, the DPC also became one of five signatory data protection authorities on the Paris declaration to reaffirm their commitment to implementing data governance that promotes innovative and privacy-protecting AI. At the 47th Global Privacy Assembly in Seoul in September 2025, this declaration was subsequently expanded, and the number of signatories grew from five to 20.

Continue reading

  • no results

Previous topic
Back to top