On 21 July 2026, President Connolly signed the Regulation of Artificial Intelligence Act 2026 into law — No. 31 of 2026, 10 Parts, 139 sections, 4 Schedules. Nine days later, the Department of Enterprise, Tourism and Employment confirmed the appointment of Paul Byrne as the first Chief Executive Officer of Oifig IS na hÉireann, the AI Office of Ireland, and restated a point worth taking at face value: "the Act is a technical implementing measure and does not add to the obligations placed on regulated entities by the EU Regulation." The substantive rules were already fixed by Regulation (EU) 2024/1689. What Ireland has just finished building is the machinery to enforce them domestically — and for regulated financial services, that machinery runs directly through the Central Bank.
The Central Bank gets its own track
Part 8 of the Act (sections 128–133) amends the Central Bank Act 1942 rather than folding the Bank into the Act's general enforcement regime. Section 129 is explicit: "Parts 5, 6 and 7 shall not apply to the Central Bank." Instead, section 133 lets the Bank pursue AI Act infringements — including breaches of Article 5's prohibited-practice rules, Article 16 provider obligations, Article 22 authorised-representative obligations, Article 23 importer obligations, Article 24 distributor obligations, Article 26 deployer obligations, and Article 50 transparency duties — through its own existing inquiry powers under sections 33AO, 33AR and 33AV of the 1942 Act, at fine levels set by the corresponding paragraph of Article 99 of the EU Regulation. Section 131 amends the Bank's information-sharing gateway (section 33AK) to add AI Act supervision as a permitted purpose. Section 132 inserts the Act into Schedule 2 of the 1942 Act, the schedule listing enactments enforceable under the Bank's own administrative-sanctions procedure.
For firms running credit scoring, loan decisioning, underwriting, or AML/fraud detection models, this matters practically: your AI systems will be examined by the same regulator, under broadly the same inquiry powers, as everything else it already supervises. A parallel, near-identical regime was built for the Competition and Consumer Protection Commission — Part 9 (sections 134–137) inserts an entirely new Part 2A into the Competition and Consumer Protection Act 2014, an 18-section administrative-fines procedure (sections 46A–46R) run by the CCPC's own Commission rather than through the Act's independent-adjudicator route.
The distributed model
Everyone else runs through the Act's own architecture: an authorised officer with entry, seizure and record-production powers (section 70); contravention and prohibition notices (sections 71–72); referral to an independent adjudicator (sections 78–113); and, ultimately, an administrative fine that only takes legal effect once confirmed by the High Court (section 114). Section 78 names eleven bodies that use this route directly — Coimisiún na Meán, the Commission for Railway Regulation, the Commission for Communications Regulation, the Commission for Regulation of Utilities, the Data Protection Commission, the Health and Safety Authority, the Health Products Regulatory Authority, the Health Service Executive, the Marine Survey Office, the National Transport Authority, and the Workplace Relations Commission. Section 78 is the Act's own list, used for Part 6 adjudication purposes; it structurally excludes the Central Bank and the CCPC because those two run separate enforcement tracks of their own, not because they fall outside the regime. The full designation sits in a separate instrument, the European Union (Artificial Intelligence) (Designation) Regulations 2025 (S.I. No. 366 of 2025), which designates 15 sectoral competent authorities in total — confirmed directly on DETE's own legislation page. Together, that's Ireland's "distributed model" of AI supervision: fifteen sectoral authorities, coordinated by the new AI Office rather than concentrated in a single regulator.
One correction, up front
A common claim in early commentary is that AI literacy obligations only take effect this year. They do not. Article 4 of the EU Regulation — the duty on providers and deployers to ensure staff have a sufficient level of AI literacy — has applied since 2 February 2025. If your organisation has not addressed this yet, it is not early; it is overdue.
What actually starts on 2 August, and what does not
The AI Office is, in DETE's own words, "expected to be operational by 2 August 2026" — note the hedge; the Act's own commencement mechanism (section 1(2)) requires a ministerial order, and nothing in the Act fixes that date directly. What is fixed, because it comes from the EU Regulation itself rather than from Irish commencement, is Article 50: the transparency duties requiring AI systems to disclose that a person is interacting with AI, and requiring synthetic content to be marked and deepfakes disclosed, remain live from 2 August 2026 regardless of Irish domestic timing.
The picture is more complicated for Article 77 — the provision letting fundamental-rights bodies (nine are named in section 53: An Coimisiún Toghcháin, Coimisiún na Meán, the Data Protection Commission, the Environmental Protection Agency, the Financial Services and Pensions Ombudsman, the Irish Human Rights and Equality Commission, the Ombudsman, the Ombudsman for Children, and the Office of Ombudsman for the Defence Forces) escalate to a market surveillance authority when a firm's own documentation on a high-risk system is insufficient. That mechanism is tied to the substantive high-risk obligations in Annex III of the EU Regulation — and those obligations were postponed by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on 27 July 2026, from 2 August 2026 to 2 December 2027. Several firms' compliance calendars still show an August trigger for Article 77 access rights; on the current text, that trigger has moved. What has not moved is the underlying logic: once it does bite, a firm that cannot produce its own evidence quickly is the firm an Article 77 body escalates against.
The practical requirement
None of this changes what section 70 already permits, right now: an authorised officer can enter premises, compel production of records — defined broadly enough in section 70(11) to include algorithms, code, software and data in any stored form — and require them "in a form in which they can be taken and in which they are, or can be made, legible and comprehensible." Once a matter is referred for adjudication, section 84 sets out precisely what must be handed over: the facts, the evidence relied on, every prior notice served, and a summary of the firm's own submissions. That is a specific, citable checklist, not a general "be compliant" instruction — and it is achievable to build against now, independent of exactly which date each obligation lands.
Coming shortly
We are building a short, free diagnostic that maps your organisation's AI use cases to the relevant competent authority and the evidence you would need to produce on request. It is not legal advice, and it will not tell you everything — but it will tell you where you stand, and what to fix first. Details shortly.
Not sure which competent authority your AI systems fall under?
Book an EU AI Act readiness conversation →This article is provided for general information only. It is not legal advice and does not create a lawyer–client relationship. Abdulwahab Adesanya holds an LLM in IP & IT Law from University College Dublin and advises on AI governance and compliance at Adesanya AI Advisory; he does not hold an Irish solicitor's practising certificate. For the authoritative text, see the Legislation Library.