Artificial intelligence is moving rapidly into Irish workplaces, businesses and public services. But the data used to train and operate AI systems is increasingly becoming a regulatory issue.
The Central Statistics Office reported that 20.2% of enterprises in Ireland used artificial intelligence in 2025, up from 15.2% in 2024 and 8.1% in 2023. Large companies were considerably more likely to use AI, with adoption reaching 57.7%.
At the same time, Ireland’s AI regulatory framework has changed significantly. The EU AI Act became broadly applicable on 2 August 2026, while Ireland’s Regulation of Artificial Intelligence Act 2026 established the national architecture for implementing and enforcing the EU rules.
For businesses and citizens, one regulator remains particularly important: the Data Protection Commission.
The DPC regulates the use of personal data in AI primarily through the GDPR and Data Protection Act 2018. It also now has specific functions under the EU AI Act, including market-surveillance responsibilities for certain prohibited AI practices and certain high-risk systems.
Key facts
| Issue | What it means in Ireland |
|---|---|
| AI adoption | 20.2% of enterprises used AI in 2025 |
| Main data regulator | Data Protection Commission |
| Core privacy law | GDPR + Data Protection Act 2018 |
| AI legislation | EU AI Act + Regulation of Artificial Intelligence Act 2026 |
| Central AI authority | AI Office of Ireland |
| DPC AI role | GDPR supervision plus specific AI Act responsibilities |
| Major current concern | Personal data used to train, operate or inform AI |
| Important principle | Publicly available personal data can still be protected by GDPR |
Table of contents
- What does the DPC regulate?
- Why GDPR applies to AI
- Can AI be trained on personal data?
- Does publicly available data have GDPR protection?
- What legal basis does an AI company need?
- When is a DPIA needed?
- How does the DPC approach automated decision-making?
- What does the EU AI Act change?
- What Irish businesses need to do
- What the DPC’s AI investigations tell us
- What happens next in Ireland
What does the DPC regulate?
The DPC is Ireland’s independent data protection supervisory authority. It investigates complaints, conducts inquiries, takes enforcement action and works with other European data protection authorities.
When AI involves personal data, the DPC can therefore become involved even if the organisation does not describe itself as an “AI company”.
That distinction matters.
A retailer using an AI system to analyse customer behaviour may be processing personal data.
An employer using an AI recruitment tool may be processing applicants’ information.
A hospital using AI may process health information.
A financial institution using automated profiling may process highly sensitive information.
The question is not simply whether the organisation has bought an AI product. The question is what personal data is being processed, why it is being processed and how the processing affects individuals.
Why does GDPR apply to AI?
AI is not outside the GDPR.
The DPC has specifically warned organisations that personal data can be involved both when an AI model is developed and when the resulting AI system is used.
The GDPR’s basic principles continue to apply.
Personal data must be processed lawfully, fairly and transparently. It must be collected for specified purposes, limited to what is necessary, kept accurate and protected appropriately.
That creates several questions for an Irish organisation deploying AI:
- What data is being entered?
- Why is it being processed?
- What is the legal basis?
- Where does the data go?
- Is another company processing it?
- How long is it retained?
- Is it reused to train another model?
- Can the organisation respond to access or deletion requests?
- Could the AI output affect someone’s rights?
Can AI be trained on personal data?
Yes, but not simply because the data exists.
An organisation must assess whether the proposed processing is lawful under GDPR.
The DPC has warned that organisations developing AI models need to consider the purpose of processing, the lawful basis, necessity and proportionality, security, data-subject rights and the potential risks associated with AI models.
This becomes particularly complicated when datasets contain information originally collected for a different purpose.
For example, a company may have collected customer information to provide a service. That does not automatically mean the same information can be repurposed for AI training.
Purpose limitation and transparency remain relevant.
Does publicly available data have GDPR protection?
Yes.
This is one of the most important points for Irish businesses and AI developers.
The DPC explicitly states that publicly accessible personal data remains within the scope of GDPR.
That means information appearing on a public website or social-media platform cannot automatically be treated as unrestricted AI training material.
The organisation must consider:
- why the information was originally published;
- the context in which it was collected;
- the reasonable expectations of the person;
- the proposed new use;
- the legal basis;
- necessity and proportionality;
- potential impact on the individual.
The EDPB’s Opinion 28/2024 reinforces this approach, stating that whether an AI model is anonymous must be assessed case by case and identifying reasonable expectations as an important factor when assessing legitimate interests.
The X/Grok investigation
The DPC’s inquiry into X provides a clear example.
In April 2025, the DPC announced an inquiry into X Internet Unlimited Company concerning personal data contained in publicly accessible posts from EU/EEA users and its use for training generative AI models, including Grok.
The inquiry is examining GDPR issues including lawfulness and transparency.
The case demonstrates why “public” and “unprotected” are not equivalent concepts under European data protection law.
What legal basis does an AI company need?
There is no special GDPR legal basis called “AI”.
Instead, an organisation must identify the appropriate legal basis for the particular processing.
Depending on the circumstances, this can include consent, contractual necessity, legal obligations, vital interests, public task or legitimate interests.
Legitimate interests are particularly important in AI because many organisations may seek to use existing data to develop or improve systems.
The EDPB’s AI opinion says legitimate interest requires a structured assessment. The controller must identify a legitimate interest, establish that the processing is necessary and then balance that interest against the rights and interests of the affected individuals.
For AI developers, the practical message is straightforward:
“We want better AI” is not, by itself, a sufficient legal justification for processing personal data.
What about sensitive personal data?
AI systems can process or infer information that is particularly sensitive.
This includes health information, biometric information, political opinions, religious beliefs, trade-union membership and information concerning a person’s sex life or sexual orientation.
Special-category personal data receives additional protection under GDPR.
That makes AI applications in areas such as healthcare, recruitment, biometrics and employee monitoring particularly sensitive.
When is a Data Protection Impact Assessment needed?
A Data Protection Impact Assessment, or DPIA, is a formal process for assessing privacy risks associated with processing.
The DPC recommends considering DPIAs in AI-related situations where processing could create significant risks, particularly where organisations are using new technology, combining datasets or processing information relating to minors or vulnerable people.
The DPC’s inquiry into Google’s PaLM 2 model illustrates the importance of this issue.
In September 2024, the DPC launched a cross-border inquiry into Google Ireland concerning whether it had met its GDPR obligations regarding an Article 35 DPIA before processing personal data associated with the development of PaLM 2.
For Irish businesses, the lesson is that an AI deployment should not necessarily begin with the question:
“Which AI tool should we buy?”
It should begin with:
“What data will this system process, and what risks does that create?”
How does the DPC approach automated decision-making?
AI can move from providing assistance to making or influencing decisions about individuals.
That creates additional GDPR concerns.
Article 22 gives individuals a right not to be subject to certain decisions based solely on automated processing where those decisions produce legal effects or similarly significant effects. There are exceptions, but safeguards may include human intervention, the ability to express a point of view and the ability to contest the decision.
This can be important in:
- recruitment;
- credit assessment;
- insurance;
- employee management;
- education;
- access to services.
Human involvement also needs to be meaningful rather than merely nominal.
What does the EU AI Act change?
The EU AI Act adds another layer of regulation.
It uses a risk-based framework that includes prohibited AI practices, high-risk AI systems and other categories of AI systems.
The Act’s Article 5 prohibits certain AI practices, while Article 6 identifies categories of high-risk systems.
The AI Act became broadly applicable on 2 August 2026, although several provisions have different transition periods. The European Commission says certain high-risk rules now apply on extended dates, with Annex III high-risk use cases applying no later than 2 December 2027 and high-risk AI embedded in regulated products applying from 2 August 2028.
This means Irish businesses should not assume every AI obligation arrives on the same date.
Who regulates AI in Ireland?
Ireland has adopted a distributed model.
The AI Office of Ireland is the central coordinating authority for implementation of the EU AI Act.
The DPC has specific responsibilities where data protection and certain AI Act provisions intersect.
The DPC says it is a market-surveillance authority for certain prohibited AI practices and certain Annex III high-risk systems. It is also one of Ireland’s fundamental-rights authorities under the AI Act.
Other regulators have responsibilities relevant to their sectors.
The Central Bank, for example, has a role where AI is used in regulated financial services, while the CCPC has consumer and competition responsibilities.
The result is not a single “AI regulator” handling everything.
It is a regulatory network.
Why Ireland’s 2026 AI legislation matters
Ireland’s Regulation of Artificial Intelligence Act 2026 establishes the domestic architecture needed to implement the EU AI Act.
The Government approved publication of the legislation in June 2026, describing the AI Office as the central coordinating authority and providing designated market-surveillance authorities with enforcement powers.
The AI Office was subsequently established under the 2026 legislation, with Paul Byrne appointed its first CEO in July.
For businesses, this means AI compliance is becoming more institutionalised in Ireland.
What Irish businesses should do now
For an Irish organisation adopting AI, a practical starting checklist is:
1. Map the AI systems being used
Create an inventory of:
- AI chatbots;
- productivity assistants;
- CRM AI;
- recruitment AI;
- marketing AI;
- analytics tools;
- transcription services;
- customer-service systems;
- internally developed models.
2. Identify personal data
Determine whether systems process:
- customer information;
- employee data;
- applicant data;
- health information;
- financial information;
- behavioural information;
- biometric data.
3. Establish the legal basis
Do not assume the AI supplier’s terms answer this question.
The organisation needs to establish its own GDPR position.
4. Check the supplier
Understand:
- processing arrangements;
- retention;
- training use;
- sub-processors;
- international transfers;
- security;
- deletion;
- access mechanisms.
5. Consider a DPIA
A DPIA may be appropriate or required where processing presents a high risk.
6. Protect sensitive data
Use stricter controls where special-category information is involved.
7. Review automated decisions
If AI influences decisions about individuals, determine whether Article 22 or other GDPR requirements apply.
8. Train employees
Employees need clear rules about what information they can enter into AI systems.
9. Document decisions
AI governance should be auditable.
10. Monitor the law
The regulatory environment is changing quickly, particularly as the EU AI Act moves into application.
Ireland’s AI adoption makes the issue more urgent
The CSO’s figures show why this is not only a problem for large technology companies.
In 2025, 17.2% of small Irish enterprises used AI, compared with 28.6% of medium enterprises and 57.7% of large enterprises.
The most common uses included data mining, natural-language generation and workflow automation or decision assistance.
In other words, AI is increasingly being integrated into ordinary business processes.
That means GDPR compliance must increasingly become part of everyday AI procurement and deployment.
What the DPC’s 2025 report tells us
The DPC’s 2025 workload demonstrates how quickly the regulatory environment is expanding.
The Commission received 16,160 new cases in 2025, a 45% increase on the previous year. It also concluded 11,734 cases and imposed €530.773 million in administrative fines.
The DPC also announced an inquiry into X’s use of EU/EEA personal data for AI model training.
The Commission has therefore moved beyond theoretical discussion of AI risks.
It is using existing GDPR powers while Ireland builds its wider AI enforcement architecture.
What happens next?
Ireland’s challenge is to balance two competing objectives.
The country wants to remain an attractive location for AI investment, research and enterprise.
At the same time, organisations need to demonstrate that AI development does not undermine privacy or fundamental rights.
The Government’s 2026 Digital and AI Strategy explicitly links AI adoption with competitiveness while also emphasising responsible adoption and protection of privacy and fundamental rights.
That tension will become increasingly important in Dublin’s technology sector, Irish SMEs, financial services, healthcare, higher education and public services.
For businesses, the practical conclusion is clear.
AI does not create a GDPR-free zone.
If an AI system processes personal data, the organisation needs to understand the data, the purpose, the legal basis, the risks, the supplier arrangements and the rights of the people affected.
And as Ireland’s AI regulatory architecture matures, the DPC is likely to remain one of the most important institutions shaping how personal data can be used in the country’s AI economy.
KEY TAKEAWAYS
- GDPR already applies to AI processing involving personal data.
- The DPC is Ireland’s principal data protection regulator.
- Publicly available personal data can still fall under GDPR.
- AI training does not automatically justify processing personal data.
- Legal basis, purpose limitation and transparency remain essential.
- DPIAs can be particularly important for high-risk AI processing.
- Automated decisions can trigger additional GDPR safeguards.
- Ireland’s AI Act framework now gives the DPC specific AI Act responsibilities.
- The AI Office of Ireland coordinates the wider national AI Act framework.
- Irish business AI adoption reached 20.2% in 2025.
- DPC AI investigations have already involved Google, Meta and X.
- AI governance is becoming a normal business compliance function in Ireland.
FAQ
1. Does GDPR apply to AI in Ireland?
Yes. Where AI involves personal data, GDPR obligations can apply to the organisation processing that data.
2. Does the DPC regulate artificial intelligence?
Yes, but its role is specific. The DPC regulates personal-data processing under GDPR and has additional responsibilities under Ireland’s implementation of the EU AI Act.
3. Can AI companies train models using publicly available personal data?
Not automatically. Publicly accessible personal data can remain subject to GDPR, and organisations must assess lawful basis, purpose, necessity, proportionality and individual rights.
4. Can an Irish business put customer information into ChatGPT?
It depends on the data, purpose, legal basis, contractual arrangements, security, retention and the AI provider’s processing arrangements. Businesses should assess the specific processing before entering personal data.
5. Does AI require a DPIA?
Not every AI deployment automatically requires one. A DPIA is required where GDPR Article 35 conditions are met, and the DPC recommends considering DPIAs carefully where new AI technology or high-risk processing is involved.
6. Can an employer use AI to screen Irish job applicants?
Potentially, but employment-related AI can involve significant data-protection and AI Act considerations. Automated decision-making, profiling, transparency and fairness must be assessed.
7. Who is Ireland’s AI regulator?
Ireland uses a distributed regulatory model. The AI Office of Ireland coordinates the national implementation of the EU AI Act, while bodies such as the DPC and sectoral regulators have specific responsibilities.
8. Does the DPC regulate AI under the EU AI Act?
Yes. The DPC is designated as a market-surveillance authority for certain prohibited AI practices and certain Annex III high-risk systems, as well as having fundamental-rights responsibilities concerning data protection.
9. What happens if an AI system makes a significant decision about me?
GDPR Article 22 can provide protection against certain decisions based solely on automated processing, with safeguards and exceptions defined by the GDPR.
10. Is the EU AI Act the same as GDPR?
No. They are separate legal frameworks that increasingly interact. GDPR governs personal-data processing, while the AI Act establishes a broader risk-based framework for artificial intelligence.
