# Ireland’s AI Office: What It Does, Who It Works With and What It Means for Organisations

Canonical URL: https://xpertdpo.com/ai-office-of-ireland-powers-regulators-reporting/

Content type: Article

Published: 2026-08-11T13:02:28+01:00

Updated: 2026-08-11T13:02:29+01:00

Author: Philipa Jane Farley, Head of Legal and Operations

Summary: Ireland's AI Office now sits at the centre of a distributed regulatory system. We explain its role, powers, reporting lines and practical implications.

## Article

Ireland now has a national AI Office, but it does not sit above a self-contained system of AI regulation.

 Instead, it sits at the centre of a distributed regulatory model. Existing authorities retain responsibility for defined sectors and uses of AI. The Irish Office coordinates those authorities, provides a national point of contact, supports shared expertise and connects the Irish system to the wider European governance structure.

 That choice is understandable. An AI system used in recruitment does not stop being an employment matter because it includes AI. A medical device does not lose its product-safety regime. A financial-services system remains subject to financial regulation, and the processing of personal data remains subject to GDPR.

 The difficulty is that this can leave DPOs, compliance teams and accountable senior leaders with a more immediate question: when an AI issue arises, who is responsible for what?

### Ireland now has a national AI Office

 The [Regulation of Artificial Intelligence Act 2026](https://data.oireachtas.ie/ie/oireachtas/act/2026/31/eng/enacted/a3126.pdf) was signed into law on 21 July 2026. Most of the Act came into operation on 31 July under [S.I. No. 403/2026](https://www.irishstatutebook.ie/2026/en/si/0403.html), and [S.I. No. 404/2026](https://www.irishstatutebook.ie/2026/en/si/0404.html) appointed the same date as the establishment day for Oifig IS na hÉireann, the AI Office of Ireland.

 This moves the Irish position beyond proposals and interim administrative arrangements. There is now an independent statutory body with its own Board and Chief Executive Officer, defined functions and formal accountability arrangements.

 The establishment of the Irish Office does not mean that every substantive obligation under the EU AI Act became applicable on the same day. The EU framework continues to apply in phases, and organisations should use the current [EU AI Act timeline](https://xpertdpo.com/eu-ai-act-timeline-2026-practical-actions/) when planning their implementation work. The national enforcement architecture and the substantive compliance timetable are related, but they are not the same thing.

### Why Ireland chose a distributed model

 The EU AI Act requires Member States to designate national competent authorities. These include one or more market surveillance authorities, which supervise and enforce rules for AI systems, and notifying authorities, which oversee the bodies carrying out relevant conformity assessments. Each Member State must also identify a single point of contact.

 Ireland chose to build on existing sectoral regulators rather than place all AI Act supervision inside one new body. The [Government's AI Act overview](https://enterprise.gov.ie/en/what-we-do/innovation-research-development/artificial-intelligence/eu-ai-act/eu-ai-act.html) describes this as a distributed model intended to use established regulatory capacity and expertise.

 There is a sound logic to that approach. Recruitment, credit, health, public services, online platforms and regulated products raise different questions, and an authority that already understands the sector begins with an advantage. The corresponding risk is fragmentation: organisations may struggle to identify the correct route, while matters involving privacy, equality, safety and consumer protection may require several authorities. The Irish Office is intended to address that coordination problem.

> Ireland's AI Office is the coordinating centre of the system, not a replacement for every regulator already in it.

### What the Irish Office is, and what it is not

 The Act gives the Irish Office a broad coordinating and capability-building mandate. Its functions include:

- coordinating the activities of competent authorities to encourage consistent implementation and supervision
- facilitating cooperation and information sharing, including support for joint investigations and enforcement activities
- promoting AI innovation, adoption and literacy
- increasing public awareness of AI systems and AI Act rights and obligations
- facilitating access to technical, legal and regulatory expertise for competent authorities
- advising the Minister on matters connected with its functions

 It is also designated as Ireland's single point of contact under Article 70(2) of the EU AI Act. This gives Ireland, the European institutions, organisations and individuals a central route into a system that would otherwise be difficult to navigate.

 The Irish Office is independent in performing its functions, subject to the Act. The Minister may issue written directions concerning relevant Government AI policies, which must be laid before the Oireachtas. That power does not extend to the Irish Office's core coordination, regulatory-cooperation and expertise functions, or to Part 6 adjudication.

 The [final designation regulations](https://www.irishstatutebook.ie/2026/en/si/0405.html) formally designate the Irish Office as a market surveillance authority. That designation should not be read as making it the universal frontline investigator and fining body for every AI system in the State. Detailed operational remits are distributed among the listed sectoral authorities, and the Irish Office is not given a separate, all-economy sectoral remit in those schedules.

 The distinction determines where incidents and complaints go, who may request evidence and which authority can use the enforcement toolkit.

### Who does what in practice

 The correct regulator will depend on the AI system, the organisation's role, the sector, the purpose for which the system is used and the provision being supervised. The following examples are illustrative rather than exhaustive.

| Area | Likely lead | Irish Office role | Practical implication |
| --- | --- | --- | --- |
| Personal data and specified AI Act areas | Data Protection Commission | Coordination and sandbox cooperation | Keep GDPR and AI Act analyses connected but legally separate |
| Employment-related high-risk AI | Workplace Relations Commission | Coordination and shared support | Involve employment, equality and privacy teams early |
| Regulated financial services | Central Bank of Ireland | Coordination and information flow | Connect AI evidence to existing sector governance |
| Specified online and media contexts | Coimisiún na Meán | National and EU coordination | Consider platform, consumer and rights rules together |
| Regulated products and safety | Relevant product or safety authority | Expertise and possible joint work | Identify product and conformity rules as well as the AI Act |
| General-purpose AI models | European AI Office | EU coordination and complaint routing | Separate model-provider and downstream deployment duties |

 The full list is more extensive. Organisations should not select a regulator simply by industry name: one organisation may deploy systems falling within different supervisory remits.

 This is why [AI Act role mapping](https://xpertdpo.com/ai-act-role-mapping-provider-deployer-importer-and-distributor/) should include a regulatory-route field alongside the organisation's role, system use, risk classification, applicable regimes and likely authority.

### How the Irish Office connects to the European system

 The Irish Office must be distinguished from the European AI Office, which sits within the European Commission, supports EU-wide implementation and has direct supervisory and enforcement responsibilities for general-purpose AI model obligations. The [European Commission's governance overview](https://digital-strategy.ec.europa.eu/en/policies/ai-act-governance-and-enforcement) explains how it works alongside national authorities.

 The European AI Board is different again. It brings together representatives from Member States and supports consistent application of the AI Act across the Union. The European AI Office provides the Board's secretariat and supports its work, but the two bodies are not interchangeable.

 At national level, the Irish Office provides the central connection into that European structure. It may cooperate and enter agreements with equivalent bodies outside the State, and complaints concerning matters within Article 75 can be transmitted to the European AI Office.

 Cases may cross institutional boundaries. A system may use a general-purpose model supervised at EU level, be deployed in an Irish regulated sector and process personal data in several Member States. The governance file should explain each part without treating the vendor, model provider and deployed system as the same regulated object.

 Our guide to [European data protection and AI governance institutions](https://xpertdpo.com/european-data-protection-ai-governance-institutions-guide/) provides the wider institutional map.

### Complaints: one entry point, several possible routes

 Article 85 gives natural and legal persons who have grounds to consider that the EU AI Act has been infringed a complaint route. Under the Irish Act, a complaint may be made to a relevant market surveillance authority or to the Irish Office. The Irish Office conducts an initial assessment and may transmit it to the relevant Irish authority, send it to the European AI Office where Article 75 is engaged, or take other appropriate action. It must notify the complainant in writing if it transmits the complaint.

 The receiving authority also performs an initial assessment. It may dismiss a complaint on specified grounds, transmit it, act on it or take no further action. Complaints must still be considered for market-surveillance purposes. This is not a promise that every complaint will become a formal investigation or produce a full written merits decision, and GDPR complaint assumptions should not be imported into this process.

> A complaint can enter through one door and still need to travel to the authority with the right sectoral powers.

 An AI complaint should not be assigned automatically to privacy, legal or customer service. Triage must identify prohibited practices, high-risk duties, personal-data issues, equality concerns, safety incidents and sector rules. The explanation sent to an individual, the DPIA, AI risk assessment, testing, vendor material and decisions should not tell different versions of the same story.

 The Act also applies the Protected Disclosures Act 2014 to reporting AI Act infringements and the protection of reporting persons. Internal speak-up and whistleblowing arrangements should therefore be included in the process map rather than treated as unrelated channels.

### Serious incidents, FRIAs and the national AI register

 Providers of high-risk AI systems have serious-incident reporting duties under Article 73 where the relevant conditions are met. Reports go to the relevant market surveillance authority, which must take the required measures and inform relevant public bodies. The Irish reporting structure also provides for information to reach the Irish Office.

 There is a separate route for fundamental-rights impact assessments under Article 27. Where that Article applies, specified deployers must notify the relevant market surveillance authority of the assessment results. The Irish Act requires the authority to provide a copy to the Irish Office. The application dates for the associated high-risk regime should be checked against the current timeline rather than assumed from the establishment date of the Irish Office.

 The Act also requires the Irish Office to establish and maintain a national AI register. It must include incidences of prohibited AI practices in the State, serious incidents involving high-risk systems reported under Article 73, specified high-risk systems and other AI incidents or notifications required under the EU AI Act.

 The register must be secure, accessible and regularly updated. The Act does not expressly say that every part of it will be published for unrestricted public access. Until the Irish Office confirms the access and publication arrangements, it would be unsafe to describe it simply as a public register.

 The register could nevertheless give the national system a view across matters otherwise separated by regulator or sector, informing guidance, enforcement priorities and systemic-risk analysis.

### Where the investigative and sanctioning powers sit

 The Act gives relevant market surveillance authorities and their authorised officers a substantial enforcement toolkit. Depending on the legal route and safeguards, authorised officers may:

- require information, records, documentation and relevant material
- access training, validation and testing datasets and, where the EU AI Act's conditions are met, source code
- enter and inspect premises, with court warrants where required
- search records and data equipment and require access assistance
- test systems, obtain samples and preserve evidence
- issue contravention and prohibition notices
- require remediation, restriction, withdrawal, recall, disposal or destruction
- seize relevant AI products where authorised
- refer suspected infringements into the statutory adjudication process

 The regime includes representations, court supervision and appeal routes. Relevant EU fine ceilings include up to EUR35 million or 7 per cent of worldwide annual turnover for prohibited-practice infringements, EUR15 million or 3 per cent for specified other obligations, and EUR7.5 million or 1 per cent for incorrect, incomplete or misleading information. The applicable rules determine the ceiling for undertakings and smaller enterprises. The Irish Act caps fines on public bodies at EUR1 million.

 The better operational lesson lies in the information powers. An organisation may be asked for documentation, datasets, testing, decisions and technical evidence. A statement that a system is "human overseen" does not show how oversight worked, who exercised it or whether intervention was effective.

 This connects directly to our work on [bias, fairness and explainability evidence](https://xpertdpo.com/bias-fairness-explainability-evidence-ai-governance/). The organisation should know where the evidence is held, who can explain it and how it relates to the live version of the system.

> The practical question is not only whether an AI system is compliant. It is who may ask, what evidence they can require and whether the organisation can produce it coherently.

### The DPC, GDPR and fundamental-rights bodies

 The Data Protection Commission remains Ireland's GDPR supervisory authority and also has designated market-surveillance responsibilities under the AI Act in specified areas. Those roles may overlap, but the underlying legal tests do not merge.

 A DPIA can provide important evidence about purpose, necessity, proportionality, risks to individuals, transparency, automated decision-making, security and controls. It cannot by itself discharge AI Act duties concerning risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, conformity assessment or post-market monitoring. Nor does AI Act documentation replace the GDPR assessment.

 The same distinction applies to fundamental-rights bodies identified under Article 77. These bodies are not all AI Act competent authorities. They retain their existing mandates but receive additional information and cooperation rights for high-risk AI systems. They may access relevant documentation and, where documentation is insufficient to determine whether Union fundamental-rights obligations have been infringed, may make a reasoned request for testing through the relevant market surveillance authority.

 For DPOs, the useful role is not to claim ownership of every AI obligation. It is to identify privacy and rights issues early and keep the DPIA connected to the live system. Our article on [AI governance and DPIAs](https://xpertdpo.com/ai-governance-and-data-protection-impact-assessments-dpias/) explains that lifecycle connection in more detail.

### Sandboxes and the Irish Office's innovation role

 The Irish Office may establish one or more AI regulatory sandboxes in accordance with Article 57. Sandboxes are intended to support the development and testing of qualifying AI systems within a controlled framework and with regulatory involvement.

 This sits alongside the Irish Office's innovation, adoption and literacy functions. Early regulatory engagement can improve systems before decisions become expensive to reverse. Organisations will still need clarity on the status of sandbox feedback, participating authorities and required evidence. Participation is not certification or immunity from enforcement.

 Where a sandbox involves processing personal data or otherwise falls within the DPC's supervisory remit, the Act requires the Irish Office to associate the DPC with its operation and relevant supervision. This is another example of the distributed model working as intended: the sandbox creates a coordinated setting but does not displace the competent authority's legal mandate.

### How the Irish Office is accountable

 The Irish Office has a Board responsible for oversight and a Chief Executive Officer responsible for management. The CEO may be required to account to the Public Accounts Committee and other Oireachtas committees within the Act's terms.

 The Office must prepare three-year strategy statements, maintain accounts audited by the Comptroller and Auditor General and submit annual reports. These materials go before the Oireachtas, and strategy statements and annual reports must be published on the Office's website.

 Sectoral authorities must copy Article 74(2) annual reports to the Irish Office and the Competition and Consumer Protection Commission, and provide specified incident, sandbox and fundamental-rights assessment material to the Irish Office. The CCPC copy requirement is a reporting flow, not evidence that it is a default regulator.

 One accountability issue deserves measured attention. Section 139 of the Act amends the Freedom of Information Act 2014 so that the Irish Office is outside FOI in performing its substantive statutory functions, except for records concerning the general administration of those functions.

 The Office still has transparency and accountability duties, but annual reports, Oireachtas scrutiny, cooperation agreements, enforcement publications and access to the AI register will carry greater importance. The question is whether they provide enough usable information to understand the system's operation.

### The balanced view: coordination is the promise and the test

 Ireland's model has real advantages. Sector regulators retain existing expertise, while a central office can build shared technical capability, reduce duplication, support joint work and provide a route into EU governance.

 It also creates risks. Organisations and complainants may not know which authority is responsible; procedures and technical capacity may vary; and cross-regulatory matters may move slowly. The Irish Office must also balance innovation and literacy with regulatory coordination.

 The success of the model will therefore depend on how clearly those allocated roles operate in practice. Useful early indicators will include:

- clear and accessible complaint and incident routes
- published explanations of regulatory remits and handovers
- practical cooperation agreements between authorities
- consistent interpretations and evidence expectations
- visible technical capability and adequate resourcing
- transparent information about sandbox criteria and outcomes
- reporting that shows trends without compromising legitimate confidentiality

 That is the standard against which the new architecture should be assessed. The aim is not to eliminate every overlap. It is to make overlaps manageable and accountability intelligible.

### What senior teams should do now

 Organisations do not need to wait for the first investigation to prepare for this structure.

1. **Add the regulatory route to the AI inventory.** Record the organisation's AI Act role, system purpose, sector, risk classification, applicable legal regimes and likely competent authority.
2. **Connect complaint and incident processes.** Privacy, customer complaints, HR, product safety, security, whistleblowing and legal teams need a shared escalation route for AI-related matters.
3. **Build one evidence index.** Connect AI assessments, DPIAs, vendor due diligence, contracts, technical documentation, testing, logs, human-oversight records, decisions and change control without pretending they answer identical legal questions.
4. **Preserve separate legal conclusions.** GDPR, AI Act, equality, consumer, employment, product-safety and sector rules may rely on shared facts but require their own analysis.
5. **Assign regulatory engagement roles.** Decide who will contact the Irish Office, the DPC or a sectoral authority; who can provide technical evidence; and who briefs accountable senior management.
6. **Review vendor dependencies.** Contracts and operating processes should support documentation, incident notification, model or system change notification, access to evidence and regulatory cooperation.
7. **Monitor the Office's first operational outputs.** Its strategy, guidance, complaint route, sandbox arrangements, cooperation agreements and reporting will show how the statutory model works in practice.

### The XpertDPO view

 Ireland's distributed approach is defensible. AI risk does not exist in a legal vacuum, and established sector expertise matters.

 But coordination must make accountability clearer rather than simply adding another institutional layer. A DPO or compliance lead should be able to identify the likely authority, explain the relationship between legal regimes and produce an evidence position that reflects how the system actually operates.

 The DPO should not become the default owner of every AI Act obligation. The function should remain independent, advise on privacy and rights, connect the DPIA to live governance and challenge gaps between claims and reality. Wider ownership belongs across legal, risk, security, procurement, HR, product, technology and management.

 Organisations are preparing to engage with a national network that is now legally in place and can route complaints, receive incident and assessment information, request evidence and coordinate across institutional boundaries.

 The Irish Office will ultimately be judged less by the neatness of the institutional chart than by whether people, organisations and regulators can use the system when an AI issue is live.

## General Information Only

This article is provided for general information and does not constitute legal, regulatory, or professional advice. Data protection obligations depend on the specific facts, context, and jurisdiction involved. You should not rely on this content as a substitute for advice tailored to your organisation.

If you would like support with a specific issue, please contact us: https://xpertdpo.com/contact/
