Regulation of AI stopped being a forecast in 2025. The first parts of the EU's Artificial Intelligence Act have applied since February, the obligations on the model providers since August, Ireland has named the regulators who will enforce it, and the copyright questions that hung over every model have begun to produce judgments and settlements. This briefing sets out where the rules stood in the week of 24 November, when the Commission proposed changing the timetable, and ends with the short list of things an Irish business is actually obliged to do. We are not lawyers; the list is a map to the obligations rather than advice on them.
The Act, as applied so far
| Date | What applies | Status |
|---|---|---|
| 1 Aug 2024 | Act enters into force | In force |
| 2 Feb 2025 | Prohibited practices banned; AI-literacy duty on providers and deployers of any size | In force |
| 10 Jul 2025 | General-purpose AI Code of Practice published | Published |
| 2 Aug 2025 | Obligations on providers of general-purpose models; governance provisions and penalties | In force |
| 2 Aug 2026 | Commission enforcement powers over general-purpose models; Article 50 transparency duties | Scheduled |
| 2 Aug 2026 | High-risk system obligations (Annex III: hiring, credit, education and others) | Proposed to move to 2 Dec 2027 on 19 Nov 2025 |
| 2 Aug 2027 | High-risk obligations for AI embedded in regulated products | Proposed to move to Aug 2028 |
The Act is tiered by risk. Most of what a business does with AI, drafting, summarising, extracting, searching, sits in the minimal-risk tier with no obligation beyond the literacy duty. The heavy obligations attach to a defined list of high-risk uses: screening job applicants, scoring credit, proctoring exams and similar decisions about people. Those were due on 2 August 2026. On 19 November the Commission proposed a Digital Omnibus that would move them to 2 December 2027, move the product-embedded set to 2028, and loosen some data rules for training; it had been lobbied for by Alphabet and Meta and by European companies including Mistral and ASML, and the Commission rejected the description of it as a general pause.[3][4] It needs the Parliament and the Council to agree, and until they do the original dates stand.
The obligations on the labs themselves are settled. The Code of Practice that operationalises them was published on 10 July, and by the time the obligations applied on 2 August its signatories included OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, Mistral and Aleph Alpha; xAI signed only the safety and security chapter; Meta refused, with its head of global affairs saying Europe was heading down the wrong path.[5][6] From 2 August 2026 the Commission can demand information, require access to a model and order one withdrawn.
Ireland's regulators
Ireland chose a distributed model. On 29 July it designated its first eight national competent authorities, including the Central Bank, the Data Protection Commission, the Health and Safety Authority, the HPRA, the CCPC and ComReg, and on 16 September five more, including Coimisiún na Meán, the CRU and the HSE, with a central contact point in the Department of Enterprise; that made it one of the first six member states to complete the step.[7] A National AI Office is to be established by primary legislation by 2 August 2026.[8] The AI Advisory Council's February report to government set the direction, recommending a central office and a push on adoption.[9]
What an Irish business actually has to do
- Do not use a prohibited practice. Manipulative or subliminal techniques, social scoring, scraping faces from the internet and certain biometric categorisation have been banned since February, with penalties up to €35m or 7% of global turnover.[2]
- Ensure staff have adequate AI literacy. Article 4 applies to every provider and deployer regardless of size and has applied since February, with no SME carve-out. A documented training programme is the evidence.[2]
- Check the models behind your tools. If you build on ChatGPT, Claude, Gemini or Copilot, the August obligations sit with the provider, not you; confirm the provider is a Code signatory or otherwise compliant.[5]
- From 2 August 2026, tell people when they are talking to a machine and label AI-generated content. That is Article 50, and the Omnibus does not propose to move it.[1]
- If you use AI for hiring, credit, education or another Annex III purpose, prepare for the high-risk regime on the original timetable until the delay is actually adopted.[3]
- Know your regulator. In Ireland that depends on sector: the Central Bank for financial services, the Data Protection Commission for personal data, the HSA and HPRA for safety and health, the CCPC for consumers, with the Department of Enterprise as the contact point until the National AI Office exists.[7]
Safety, by the labs and by California
Ahead of the law, the laboratories regulate themselves with published frameworks that name capability thresholds and the safeguards each triggers; Anthropic activated its ASL-3 safeguards for the first time in May, which is its own briefing.[10] The incidents that make the frameworks matter accumulated through the year: Anthropic's June study in which sixteen frontier models chose blackmail in a simulated shutdown, a coding agent that deleted a production database in July, and a state-sponsored espionage campaign run largely by a coding agent, disclosed in November.[11][12][13] California made the practice law with SB 53, signed on 29 September and in force from 1 January 2026, which requires the largest developers to publish a safety framework, report critical incidents and protect whistleblowers.[14]
Copyright: the first judgments
| Case | Court | Where it stood |
|---|---|---|
| Bartz v Anthropic | N.D. California | Training on lawfully bought books ruled fair use in June; $1.5bn settlement for the pirated copies announced 5 September, about $3,000 a book across some 500,000 works |
| New York Times v OpenAI and Microsoft | S.D. New York | Most copyright claims allowed to proceed on 26 March; in discovery |
| Getty Images v Stability AI | High Court, London | Getty dropped its main training claims for want of UK evidence; secondary claim rejected; limited trademark finding, 4 November |
| GEMA v OpenAI | Regional Court, Munich | Training on and reproducing song lyrics infringed; text-and-data-mining exception did not apply; damages ordered 11 November, not final |
The pattern is that training on pirated copies is expensive, training on lawfully obtained copies is contested and depends on the court, and licensing is becoming the default. The Anthropic settlement was about the source of the books, not the act of training, which the same judge had found to be fair use in June; the judge then withheld preliminary approval for a fortnight while the terms were tightened, and granted it on 25 September; the Munich ruling went the other way on memorised lyrics; the London ruling turned on where the training happened.[15][29][17][18] The labs have responded with contracts: News Corp, Axel Springer, Condé Nast, the Associated Press, the Financial Times and others now license content to one or more of them.[19] For a business the practical point is narrower: the provider's terms should say what it trains on and whether your data is included, and a well-drafted enterprise agreement says it is not.
What the public thinks
Pew's survey of 28,000 adults in 25 countries, published in October, found people on balance more concerned than excited about AI, and a median of 53% trusting the EU to regulate it against 37% for the United States and 27% for China.[20] The Commission's own survey on AI at work found more than 60% of Europeans positive about AI in the workplace and 84% wanting privacy and transparency carefully managed.[21] In Ireland the Department of Education published its first guidance on AI in schools in October, requiring that AI use in assessment be declared.[22] The public wants the rules, which is a reason to expect more of them.


