← Back to research
Briefing · Policy & infrastructure· Updated 14 September 2026· 7 min read

The rules arrive: the AI Act's first year, the copyright judgments, and what an Irish business has to do

The AI Act's bans have applied since February and its model obligations since August, Ireland has fifteen regulators lined up, the Commission has just proposed pushing the hard part back a year, and the copyright cases have produced their first judgments and a $1.5bn cheque. The rules at the end of 2025, with dates.

A stack of cream documents tied with a sage ribbon and a small brass seal

Regulation of AI stopped being a forecast in 2025. The first parts of the EU's Artificial Intelligence Act have applied since February, the obligations on the model providers since August, Ireland has named the regulators who will enforce it, and the copyright questions that hung over every model have begun to produce judgments and settlements. This briefing sets out where the rules stood in the week of 24 November, when the Commission proposed changing the timetable, and ends with the short list of things an Irish business is actually obliged to do. We are not lawyers; the list is a map to the obligations rather than advice on them.

The Act, as applied so far

DateWhat appliesStatus
1 Aug 2024Act enters into forceIn force
2 Feb 2025Prohibited practices banned; AI-literacy duty on providers and deployers of any sizeIn force
10 Jul 2025General-purpose AI Code of Practice publishedPublished
2 Aug 2025Obligations on providers of general-purpose models; governance provisions and penaltiesIn force
2 Aug 2026Commission enforcement powers over general-purpose models; Article 50 transparency dutiesScheduled
2 Aug 2026High-risk system obligations (Annex III: hiring, credit, education and others)Proposed to move to 2 Dec 2027 on 19 Nov 2025
2 Aug 2027High-risk obligations for AI embedded in regulated productsProposed to move to Aug 2028
The AI Act's timeline as it stood on 24 November 2025. Sources: [1] [2] [3]

The Act is tiered by risk. Most of what a business does with AI, drafting, summarising, extracting, searching, sits in the minimal-risk tier with no obligation beyond the literacy duty. The heavy obligations attach to a defined list of high-risk uses: screening job applicants, scoring credit, proctoring exams and similar decisions about people. Those were due on 2 August 2026. On 19 November the Commission proposed a Digital Omnibus that would move them to 2 December 2027, move the product-embedded set to 2028, and loosen some data rules for training; it had been lobbied for by Alphabet and Meta and by European companies including Mistral and ASML, and the Commission rejected the description of it as a general pause.[3][4] It needs the Parliament and the Council to agree, and until they do the original dates stand.

The obligations on the labs themselves are settled. The Code of Practice that operationalises them was published on 10 July, and by the time the obligations applied on 2 August its signatories included OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, Mistral and Aleph Alpha; xAI signed only the safety and security chapter; Meta refused, with its head of global affairs saying Europe was heading down the wrong path.[5][6] From 2 August 2026 the Commission can demand information, require access to a model and order one withdrawn.

Ireland's regulators

Ireland chose a distributed model. On 29 July it designated its first eight national competent authorities, including the Central Bank, the Data Protection Commission, the Health and Safety Authority, the HPRA, the CCPC and ComReg, and on 16 September five more, including Coimisiún na Meán, the CRU and the HSE, with a central contact point in the Department of Enterprise; that made it one of the first six member states to complete the step.[7] A National AI Office is to be established by primary legislation by 2 August 2026.[8] The AI Advisory Council's February report to government set the direction, recommending a central office and a push on adoption.[9]

What an Irish business actually has to do

  1. Do not use a prohibited practice. Manipulative or subliminal techniques, social scoring, scraping faces from the internet and certain biometric categorisation have been banned since February, with penalties up to €35m or 7% of global turnover.[2]
  2. Ensure staff have adequate AI literacy. Article 4 applies to every provider and deployer regardless of size and has applied since February, with no SME carve-out. A documented training programme is the evidence.[2]
  3. Check the models behind your tools. If you build on ChatGPT, Claude, Gemini or Copilot, the August obligations sit with the provider, not you; confirm the provider is a Code signatory or otherwise compliant.[5]
  4. From 2 August 2026, tell people when they are talking to a machine and label AI-generated content. That is Article 50, and the Omnibus does not propose to move it.[1]
  5. If you use AI for hiring, credit, education or another Annex III purpose, prepare for the high-risk regime on the original timetable until the delay is actually adopted.[3]
  6. Know your regulator. In Ireland that depends on sector: the Central Bank for financial services, the Data Protection Commission for personal data, the HSA and HPRA for safety and health, the CCPC for consumers, with the Department of Enterprise as the contact point until the National AI Office exists.[7]

Safety, by the labs and by California

Ahead of the law, the laboratories regulate themselves with published frameworks that name capability thresholds and the safeguards each triggers; Anthropic activated its ASL-3 safeguards for the first time in May, which is its own briefing.[10] The incidents that make the frameworks matter accumulated through the year: Anthropic's June study in which sixteen frontier models chose blackmail in a simulated shutdown, a coding agent that deleted a production database in July, and a state-sponsored espionage campaign run largely by a coding agent, disclosed in November.[11][12][13] California made the practice law with SB 53, signed on 29 September and in force from 1 January 2026, which requires the largest developers to publish a safety framework, report critical incidents and protect whistleblowers.[14]

Copyright: the first judgments

CaseCourtWhere it stood
Bartz v AnthropicN.D. CaliforniaTraining on lawfully bought books ruled fair use in June; $1.5bn settlement for the pirated copies announced 5 September, about $3,000 a book across some 500,000 works
New York Times v OpenAI and MicrosoftS.D. New YorkMost copyright claims allowed to proceed on 26 March; in discovery
Getty Images v Stability AIHigh Court, LondonGetty dropped its main training claims for want of UK evidence; secondary claim rejected; limited trademark finding, 4 November
GEMA v OpenAIRegional Court, MunichTraining on and reproducing song lyrics infringed; text-and-data-mining exception did not apply; damages ordered 11 November, not final
The principal copyright cases as of 24 November 2025. Sources: [15] [16] [17] [18]

The pattern is that training on pirated copies is expensive, training on lawfully obtained copies is contested and depends on the court, and licensing is becoming the default. The Anthropic settlement was about the source of the books, not the act of training, which the same judge had found to be fair use in June; the judge then withheld preliminary approval for a fortnight while the terms were tightened, and granted it on 25 September; the Munich ruling went the other way on memorised lyrics; the London ruling turned on where the training happened.[15][29][17][18] The labs have responded with contracts: News Corp, Axel Springer, Condé Nast, the Associated Press, the Financial Times and others now license content to one or more of them.[19] For a business the practical point is narrower: the provider's terms should say what it trains on and whether your data is included, and a well-drafted enterprise agreement says it is not.

What the public thinks

Pew's survey of 28,000 adults in 25 countries, published in October, found people on balance more concerned than excited about AI, and a median of 53% trusting the EU to regulate it against 37% for the United States and 27% for China.[20] The Commission's own survey on AI at work found more than 60% of Europeans positive about AI in the workplace and 84% wanting privacy and transparency carefully managed.[21] In Ireland the Department of Education published its first guidance on AI in schools in October, requiring that AI use in assessment be declared.[22] The public wants the rules, which is a reason to expect more of them.

Sources

  1. [1]Implementation timeline · EU Artificial Intelligence Act (artificialintelligenceact.eu) · Aug 2025
  2. [2]EU AI Act: ban on certain AI practices and requirements for AI literacy come into effect · Mayer Brown · Jan 2025
  3. [3]European Commission delays full implementation of AI Act to 2027 · Euronews · 19 Nov 2025
  4. [4]An uncertain journey on the Digital Omnibus · Paul, Weiss · 21 Nov 2025
  5. [5]EU AI Act: GPAI model obligations in force and final GPAI Code of Practice in place · Latham & Watkins · Aug 2025
  6. [6]The EU's general-purpose AI obligations · Skadden · Aug 2025
  7. [7]Ireland adopts distributed model for AI oversight · Matheson · Sept 2025
  8. [8]EU AI Act update: Ireland appoints its national competent authorities · Conventus Law · Sept 2025
  9. [9]Ireland's AI Advisory Council report to government: helping to shape Ireland's AI future · Department of Enterprise, Tourism and Employment · 21 Feb 2025
  10. [10]Activating AI Safety Level 3 protections · Anthropic · 22 May 2025
  11. [11]Agentic misalignment: how LLMs could be insider threats · Anthropic · 20 Jun 2025
  12. [12]Vibe coding service Replit deleted user's production database, faked data, told fibs galore · The Register · 21 Jul 2025
  13. [13]Disrupting the first reported AI-orchestrated cyber espionage campaign · Anthropic · 13 Nov 2025
  14. [14]California's SB 53: what the frontier AI law does · Carnegie Endowment for International Peace · Oct 2025
  15. [15]AI giant Anthropic to pay $1.5bn over pirated books · RTÉ News · 6 Sept 2025
  16. [16]New York Times' copyright case against OpenAI goes forward · NPR · 26 Mar 2025
  17. [17]Getty Images loses copyright infringement claim against Stability AI in the UK's first generative AI ruling · Ropes & Gray · Nov 2025
  18. [18]OpenAI chatbots cannot use song lyrics without paying, German court rules · Euronews · 11 Nov 2025
  19. [19]A timeline of the major deals between publishers and AI companies · Digiday · 2025
  20. [20]How people around the world view AI · Pew Research Center · 15 Oct 2025
  21. [21]Commission survey shows most Europeans support the use of artificial intelligence in the workplace · European Commission · 13 Feb 2025
  22. [22]Guidance on artificial intelligence in schools · Department of Education and Youth · Oct 2025
  23. [23]Oireachtas AI committee publishes interim report with 85 recommendations · RTÉ News · 16 Dec 2025
  24. [24]International AI Safety Report 2026 · International AI Safety Report · Feb 2026
  25. [25]Character.AI, Google agree to mediate settlements in wrongful teen death lawsuits · K-12 Dive · 13 Jan 2026
  26. [26]OpenAI sued over Connecticut murder-suicide · Axios · 11 Dec 2025
  27. [27]Court grants final approval of Anthropic copyright settlement · Authors Guild · 20 Jul 2026
  28. [28]The General-Purpose AI Code of Practice · European Commission · 31 Jul 2026
  29. [29]$1.5bn Anthropic settlement gets preliminary approval · Silicon Republic · 26 Sept 2025

Begin your AI transformation.

Book a call with the founders. Thirty minutes to understand your business, your team, and where AI could actually help. No deck, no pitch.

Talk to us →