The EU AI Act in 2026

The Law Society Technology Committee outlines where things stand now, what comes next, and what Irish law firms should be doing.

Published:
shoppingmode
  • Technology

EU flags outside the European Commission building

The EU Artificial Intelligence Act (the EU AI Act) entered into force in August 2024 with a phased implementation timetable. Previous Law Society articles addressed the first elements to take effect, namely AI literacy and prohibited AI.

Since then, however, the regulatory landscape has developed significantly. Key obligations are already live, governance structures are operational, and new amendments introduced by the EU’s “Digital Omnibus on AI” (the “AI Omnibus) were approved in June 2026, postponing some of the most demanding obligations and clarifying requirements . For Irish solicitors, the EU AI Act has moved firmly from future regulation to live compliance.

This update explains the current legal status of the EU AI Act, how the AI Omnibus proposals may affect future obligations, and what organisations should be focusing on now.

The EU AI Act Explained

The EU AI Act is a directly applicable EU regulation that takes a risk-based approach, imposing obligations according to how much risk an AI system poses to health, safety, and fundamental rights. It bans a limited category of practices considered "unacceptable risk", imposes extensive requirements on certain "high-risk" AI systems, and introduces transparency and governance obligations for general-purpose AI (GPAI) models, including many large language models like ChatGPT, Claude or Microsoft Copilot.

Crucially, it applies to organisations that use or deploy AI, not only those that develop it. Most law firms will not be AI developers, but many use AI for legal research, drafting, document review, transcription, translation or business development. The EU AI Act applies to AI systems placed on the EU market or used in the EU, including where providers or deployers are established outside the EU but the output is used within it.

What already applies: February 2025 onwards

The first obligations took effect on 2 February 2025. From that date, certain prohibited AI practices became unlawful across the EU, including, among others, systems that manipulate behaviour to cause significant harm, exploit vulnerabilities linked to age, disability or socio-economic circumstances, conduct certain biometric categorisation, or infer emotions in workplace or educational settings.

These prohibitions apply to both placing AI systems on the market and using them. An organisation can be exposed even if it did not build the system itself. Breaches attract the EU AI Act's most severe administrative fines.

In February 2025, the EU Commission published detailed guidance to assist companies in complying with their obligations in relation to prohibited AI practices:

At the same time, AI literacy obligations became applicable. Organisations must ensure that staff involved in operating or relying on AI systems have an appropriate level of understanding of those systems' capabilities and limitations. Although minor changes to the AI literacy obligations have now been introduced via the AI Omnibus as further detailed below. For Irish solicitors, these obligations sit alongside existing duties around confidentiality and professional standards.

The next phase: general-purpose AI and governance

A further milestone followed on 2 August 2025, when rules on GPAI models and core governance arrangements became applicable.

While the most onerous obligations fall on GPAI providers, this phase marks a shift from preparation to active supervision. EU-level governance bodies, including the EU’s AI Office, are now operational, and Member States are required to designate national competent authorities.

This phase has practical implications for procurement. Firms should expect AI suppliers to explain how their tools comply with the Act, particularly where those tools rely on large language models. Data use, auditability and human oversight are increasingly part of reasonable professional due diligence. The EU Commission's GPAI Code of Practice[1], published in July 2025, is voluntary but offers a presumption of conformity for providers that adhere to it.

The standards committees, CEN and CENELEC, through their Joint Technical Committee 21[2], are also in the process of developing harmonised European technical standards to support the practical implementation of the EU AI Act. These standards will address core areas such as trustworthy AI, risk and quality management, and the procedures for assessing compliance. Once these standards are officially published in the EU’s Official Journal, organisations that apply them will be presumed to comply with key EU AI Act obligations such as risk management, transparency, human oversight, cybersecurity and quality assurance.

The AI Omnibus: what has changed

Under the EU AI Act as originally adopted August 2026 was to mark the start of the core high-risk compliance regime for stand‑alone high‑risk AI systems, with 2 August 2027 for high-risk AI system embedded in regulated products. These milestones would also have triggered wide‑ranging transparency obligations and large‑scale enforcement.

However, in November 2025 the European Commission published its AI Omnibus,[3] proposing targeted amendments to simplify implementation and address delays in guidance, standards and national enforcement readiness.

In June 2026, the European Parliament and the Council formally adopted amendments to the EU AI Act based on the Digital Omnibus package, introducing a number of amendments including, but not limited to, a new prohibition on AI-generated non-consensual intimate imagery, safety-component clarifications and a stricter transitional period for watermarking obligations. The key changes are set out below.

Postponement of the High-Risk Obligations

The AI Omnibus replaces the original application dates with 2 December 2027 for standalone high-risk AI systems specified in Annex III (covering, among others, biometrics, employment, education, law enforcement, critical infrastructure and border management) and 2 August 2028 for AI systems embedded in products covered by EU sectoral safety legislation (Annex I).  

On 19 May 2026, the EU Commission published draft guidelines[4] on the classification of high-risk AI systems. The draft was open for consultation until 23 June 2026, with no confirmed timeline for finalisation yet. Although not legally binding, it signals how the Commission and national authorities are likely to assess cases, making it a practical basis for organisations to plan against.

A new prohibition: AI systems generating harmful content

The AI Omnibus introduces a new prohibited practice under Article 5, banning AI systems capable of generating child sexual abuse material or non-consensual intimate imagery, including images, video or audio, which depict an identifiable person. This new prohibition arose out of the growing concern surrounding the increase of deepfakes and deepfake technology globally.

The prohibition applies where (1) a system is placed on the EU market with the specific purpose of generating that content; (2) it is placed on the market without reasonable technical safeguards to prevent such use; and (3) where a deployer actively uses it for that purpose. The new compliance deadline for this is 2 December 2026.

Law firms should ensure that any AI tools they use cannot be misused in ways that would fall within this category.

Watermarking: a tighter transitional deadline

Importantly, the Article 50(2) watermarking obligation under Article 50(2) which requires generative AI providers to mark synthetic content (audio, images, video or text) in a machine-readable way, will still apply from 2 August 2026. The AI Omnibus allows for a transitional window for systems already on the market before that date to be brought into compliance by 2 December 2026.

On 20 July 2026, the EU Commission published guidelines[5] on transparency obligations for certain AI systems to assist providers and deployers in meeting the EU AI Act’s transparency obligations.

Overlapping compliance obligations between EU AI Act and sectoral legislation

A recurring concern in the negotiation of the amendments was overlapping compliance obligations across various pieces of EU legislation.

To tackle these concerns, machinery has now been taken out of direct EU AI Act scope: instead, the Commission will introduce health and safety requirements for high-risk AI through delegated acts under the Machinery Regulation. For other sectoral safety regimes already containing AI-specific requirements equivalent to those in the EU AI Act, the Commission can limit how the EU AI Act applies through implementing acts.

Other elements of the deal

The AI Omnibus also introduced a number of significant other changes:

  • The definition of "safety component" is narrowed so that AI that merely assists users or improves efficiency will not automatically attract high-risk status if any AI failure would not create a health or safety risk.
  • Although providers and deployers of AI system must take measures to support the development of AI literacy of their staff, they are no longer obligated to guarantee any specific level of AI literacy of any individual. The Commission and EU Member States must support and facilitate providers and deployers in their AI literacy efforts.
  • The legal basis for processing special category personal data for bias detection and correction is extended to providers and deployers of non-high-risk AI systems and models, subject to a strict necessity test.
  • The AI Office’s supervisory and enforcement competence is expanded to include AI systems built by the same provider as the underlying GPAI model, with limited carve-outs, and AI systems integrated into very large online platforms or very large online search engines as designated under the Digital Services Act.
  • SME exemptions are extended to small mid-cap enterprises, supporting smaller companies that fall just outside traditional SME thresholds.
  • The deadline for national competent authorities to establish AI regulatory sandboxes is pushed back to 2 August 2027.

Irish implementation and enforcement

Ireland has confirmed that it will operate a distributed enforcement model, allocating regulatory responsibility across existing sectoral regulators. The Department of Enterprise, Trade and Employment (DETE[6] has led Ireland’s preparatory work and has published domestic implementation guidance. An AI Office of Ireland is envisaged as a central coordination function.

DETE has designated 15 national competent authorities and 9 fundamental rights authorities, including the Data Protection Commission and Coimisiún na Meán, which will receive additional powers in cases involving AI systems.[7]  

In June 2026, the Government published the proposed Regulation of Artificial Intelligence Bill to give full domestic effect to the EU AI Act’s enforcement framework. As of 20 July 2026, the Bill has been passed by both houses of the Oireachtas and is awaiting signature into law by Uachtarán na hÉireann, Catherine Connolly.[8] For law firms, EU AI Act compliance is likely to intersect with familiar Irish regulators rather than operate as a stand‑alone regime.

What Irish firms should focus on now

For most small and medium‑sized practices, compliance does not require an enterprise‑level programme, but it does require structure and awareness. Firms should:

  • know which AI tools they use and how those tools are classified;
  • ensure no tools in use fall within (or could be misused to fall within) a prohibited category;
  • treat AI literacy as practical staff training, not theoretical policy;
  • give renewed attention to vendor management, contractual protections and date protection safeguards; and
  • review the new AI Omnibus clarifications as well as dates and use them as basis to properly assess and recalibrate compliance planning.

Firms that take proportionate steps now will be well placed as the remaining phases of the EU AI Act take effect.

References

[1] The General-Purpose AI Code of Practice | Shaping Europe’s digital future

[2] Artificial Intelligence - CEN-CENELEC

[3] Digital Omnibus Regulation Proposal | Shaping Europe’s digital future

[4] Draft Commission guidelines on the classification of high-risk AI systems

[5] Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems

[6] EU Artificial Intelligence (AI) Act

[7] These include, among others, the Central Bank of Ireland, the Commission for Communications Regulation, the Competition and Consumer Protection Commission and the Health and Safety Authority.

[8] Regulation of Artificial Intelligence Bill 2026 – No. 69 of 2026 – Houses of the Oireachtas