The EU AI Act: Employer actions you should take now

The Regulation of Artificial Intelligence Act 2026 will be Ireland’s primary dedicated AI legislation

First published on Thursday, October 8, 2026

Last updated on Thursday, October 8, 2026

2 min read

“It’s easy to imagine that the EU AI Act is only for companies that develop AI. But there’s work to do for all small businesses. You’ll need to get your policies and procedures in check.”

Gemma O’Connor, Head of HR Advisory and Technical Services at BrightHR 

Check out BrightAdvice for expert advice on what your AI policy should include, and how you can protect your business. 

Background to the EU AI Act 

In June 2026, the Irish Government approved the publication of the Regulation of Artificial Intelligence Act 2026. It is intended to implement and support the EU AI Act in Ireland.  

The EU AI Act entered into force in August 2024, with implementation between 2024 and 2027. It adopts a risk-based approach to AI regulation, and penalties for infringements are less for SMEs than other companies. 

The Government has established an AI Office of Ireland to be a single point of contact for the AI Act. Within its role, the AI Office will ensure consistent implementation, and drive innovation, adoption and deployment. 

Actions for employers 

Although the EU AI Act is being applied in a phased manner, there are rules around transparency that you should comply with now. Companies that use artificial intelligence should: 

  • Declare at the outset whether a customer is dealing with a chatbot rather than a human.  

  • Financial consumers will have the right to request to speak to a human when shopping over the phone.  

  • Clearly label AI-generated or manipulated images that look like people, objects, places or events (AKA ‘deepfakes’). 

  • Clearly label AI-generated content that informs the public on general interest issues and has not been reviewed by a person. 

How to prepare for the next phase of the EU AI Act roll out: 

  • Audit the AI systems your company develops, imports, distributes or deploys, and where they fit in to the risk tiers 

  • Review your contracts with technology providers and check their (and your) governance measures 

  • Work out which of the Market Surveillance Authorities holds oversight for your sector 

  • Check you're not using any prohibited tools (e.g. AI that uses subliminal techniques, exploits vulnerabilities, or scrapes facial images from the internet or CCTV . You can find a full list on the DETE website here.) 

  • Implement user disclosures and labelling for AI content 

  • Get your processes in check: record internal decisions, incident reporting, and train your HR team and managers in human oversight procedures 

  • Review your privacy notices and workplace policies 


Share this article