vista infosec white

Eu Ai Act Compliance

EU AI Act Compliance Ireland: Turn the Regulation Into a Working Programme

By now most leadership teams know what the AI Act is. The harder questions are the specific ones. Which of our tools actually count as AI systems? Are we the provider or the deployer? Is anything we run high-risk, and what would we show a regulator or an enterprise customer if they asked tomorrow?

That's where we start. We help organisations operating in Ireland map their AI, pin down their role under the Act, work out which obligations genuinely apply, and build the governance and evidence to back it up.

  • A complete AI inventory, including AI hidden inside SaaS and vendor tools
  • Your role per system: provider, deployer, importer or distributor
  • Risk classification and an obligation map tied to the actual articles
  • A prioritised roadmap and the evidence file to go with it
Since 2004 in audit and compliance 500+ clients assessed CREST accredited ISO 27001 certified ourselves

Talk to a Compliance Expert

    Why the EU AI Act Matters If You Operate in Ireland

    The AI Act is an EU Regulation, so it has applied directly in Ireland since it entered into force on 1 August 2024. What changed this summer is the machinery around it.

    The Regulation of Artificial Intelligence Act 2026 was signed into law on 21 July 2026, and the AI Office of Ireland (Oifig IS na hÉireann) was established on 30 July as the central coordinating authority and single point of contact for the AI Act. The Government has been clear that the Irish Act is a technical implementing measure. It doesn't add obligations on top of the EU Regulation. It gives Irish regulators the powers to supervise and enforce it, from compliance notices through to administrative sanctions.

    Ireland chose a distributed model. Fifteen competent authorities were designated in September 2025, and in practice many organisations will deal with a regulator they already know, such as the Central Bank of Ireland for regulated financial services, the Competition and Consumer Protection Commission, or Coimisiún na Meán. The AI Office of Ireland coordinates across them.

    There's also an EU layer that matters more here than almost anywhere else. Ireland hosts the European headquarters of a lot of technology companies, including general-purpose AI model providers, and the European Commission's AI Office supervises general-purpose AI models directly. If your group sits in that picture, your supervisory map may involve both Brussels and Dublin.

    None of this means every organisation carries the same obligations. What applies to you depends on your role, the AI systems involved and what they're used for. Working that out properly is the first job.

    Key dates, as they stand after the Digital Omnibus

    Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the high-risk dates. Plenty of material online still shows 2 August 2026 as the high-risk deadline. It isn't any more.

    1. 2 February 2025, already appliesProhibited AI practices (Article 5) and AI literacy (Article 4).
    2. 2 August 2025, already appliesObligations for providers of general-purpose AI models; governance and penalty frameworks.
    3. 2 August 2026, already appliesGeneral date of application. Article 50 transparency obligations apply and the Commission's enforcement powers over GPAI model providers begin. AI literacy now reads as a duty to take measures supporting staff AI literacy, following the Omnibus.
    4. 2 December 2026New prohibitions on AI generating non-consensual intimate imagery and child sexual abuse material. End of the transition for generative AI systems already on the market before 2 August 2026 to meet the Article 50(2) content-marking duty.
    5. 2 August 2027GPAI models placed on the market before 2 August 2025 must comply. Each Member State must have at least one national AI regulatory sandbox operational.
    6. 2 December 2027High-risk requirements apply to stand-alone systems in the Annex III use cases (employment, credit, education, essential services and others).
    7. 2 August 2028High-risk requirements apply to AI in products covered by Annex I EU product legislation, such as medical devices.

    Last reviewed 21 September 2026 against EUR-Lex and the Commission's AI Act Service Desk. We update this page when dates or guidance change.

    Does the EU AI Act Apply to Your Organisation?

    Your obligations follow your role, and your role is decided system by system. The same company can be a provider for the AI feature it ships and a deployer for the HR tool it licenses. Here's how the Act draws the lines.

    Provider

    You develop an AI system or GPAI model, or have one developed, and place it on the market or put it into service under your own name or trademark, whether you charge for it or not.

    Typical case: an Irish SaaS company that builds AI-driven candidate ranking into its platform and sells it across the EU.

    This sounds like us

    Deployer

    You use an AI system under your authority in a professional capacity. Most organisations are deployers of something, often many things.

    Typical case: a lender using a third-party model to assess creditworthiness, or an HR team using an AI screening tool.

    This sounds like us

    Importer

    You're located or established in the EU and place on the EU market an AI system carrying the name or trademark of a provider established outside the EU.

    Typical case: an Irish entity bringing a US vendor's AI product to EU customers under the vendor's brand.

    This sounds like us

    Distributor

    You're in the supply chain, but not the provider or importer, and you make an AI system available on the EU market.

    Typical case: a reseller or systems integrator supplying a third-party AI product to Irish and EU clients.

    This sounds like us

    Authorised representative

    You're established in the EU and hold a written mandate from a non-EU provider to carry out specified obligations on its behalf.

    Worth checking: if you're the EU entity of a non-EU group, confirm whether you are acting as representative, importer, distributor, or in fact the provider.

    Roles can change

    Under Article 25, a deployer, importer or distributor can become the provider of a high-risk system by putting its own name on it, making a substantial modification, or changing its intended purpose so it becomes high-risk.

    Not sure which applies? Start here

    Start With Your AI Inventory

    You can't classify what you haven't found. And in most organisations the AI that matters isn't the model the data science team built. It's the scoring feature switched on in a SaaS platform two years ago.

    We build the inventory with your system owners, procurement and IT rather than from a questionnaire nobody fills in. The aim is one register that legal, risk, security and product can all work from, and that stays current after we leave.

    Where unlisted AI usually turns up

    • HR and applicant tracking systems (screening, ranking, scheduling)
    • Customer service chat, email triage and call analytics
    • Fraud, AML and credit decisioning tools
    • CRM and marketing platforms that score or segment people
    • Coding assistants and productivity suites with built-in AI
    • Staff using AI tools nobody approved. Our agentic and shadow AI risk assessment is built for exactly this.
    What we record for each AI system
    FieldWhy it matters
    System, owner, vendorAccountability, and who you'll need information from
    Built, bought, embedded or GPAI-basedDrives your likely role and what the vendor owes you
    Intended purpose and business useClassification turns on purpose, not on the technology
    Who it affectsEmployees, customers, applicants or the public change the risk picture
    Data usedPersonal and special category data links you to GDPR and DPIAs
    Deployment contextInternal or customer-facing, which EU markets, decision or support
    Role and initial classificationThe starting point for the obligation map
    Evidence already heldSo you don't rebuild what already exists

    Understand Your AI Risk Classification

    People often picture the AI Act as a pyramid with four neat boxes. In practice we treat classification as a set of questions asked in order, because one system can trigger more than one set of rules. A high-risk system can also carry transparency duties.

    Question 1Prohibited?

    Article 5, applying since 2 February 2025. Practices such as social scoring, manipulative or exploitative techniques that cause significant harm, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). From 2 December 2026 this extends to AI generating non-consensual intimate imagery or child sexual abuse material.

    If yes: the practice stops. There is no compliance route.

    Question 2High-risk?

    Article 6 with Annexes I and III. Either a safety component of, or itself, a product under listed EU product legislation that needs third-party conformity assessment, or a use case listed in Annex III. An Annex III system may fall outside high-risk under Article 6(3) if it doesn't pose a significant risk of harm, but the provider must document that assessment, and systems that profile individuals stay high-risk.

    If yes: the Chapter III requirements apply from 2 December 2027 or 2 August 2028.

    Question 3Transparency duty?

    Article 50, applying since 2 August 2026. Systems that interact directly with people, generate synthetic audio, image, video or text, create deepfakes, or perform emotion recognition or biometric categorisation. Duties fall on providers, deployers or both.

    Applies on its own or alongside high-risk requirements.

    OtherwiseMinimal risk

    Most business AI lands here. No specific AI Act requirements beyond the AI literacy duty that applies to all providers and deployers, plus any voluntary codes you choose to adopt.

    GDPR, consumer law and sector rules still apply as normal.

    A caution on examples. "Recruitment AI is high-risk" is a useful rule of thumb, not a classification. The answer depends on the intended purpose, what the system actually does, and how it's used. Annex III even carves out AI used to detect financial fraud from the creditworthiness category. That's why we classify from your inventory data and record the reasoning, rather than tagging systems from a generic list.

    EU AI Act Readiness Ireland: What the Assessment Covers

    Our readiness assessment tells you where you stand today against the obligations that actually apply to you, and what to do about the gaps in what order.

    It's a structured review, not a desk exercise. We interview system owners, look at the documentation and controls you already run (ISO 27001, GDPR records, vendor due diligence, model documentation), test a sample of systems end to end, and map it all back to specific articles of the Act and, where relevant, to Irish supervisory expectations.

    The timeline depends on how many systems you have and how mature your records are. We agree scope and duration in writing before we start.

    Request an EU AI Act Assessment

    What you receive

    • Role map. Your role for each system, with the reasoning written down.
    • AI inventory review. Gaps and unowned systems flagged.
    • Classification findings. Prohibited, high-risk, transparency or minimal, with rationale.
    • Obligation map. The articles that apply, per system and per role, with dates.
    • Documentation and governance gaps. What's missing, what's partly there, what's fine.
    • Prioritised remediation roadmap. Sequenced against the real deadlines, with owners.

    AI Risk Assessment in Ireland: Beyond the Classification Label

    Classification tells you which rules apply. A risk assessment tells you what could actually go wrong with a given system and whether your controls are enough. They're different exercises and you need both.

    For providers of high-risk systems

    Article 9 requires a risk management system that runs across the whole lifecycle: identifying known and foreseeable risks to health, safety and fundamental rights, estimating them, adopting measures and testing. We help you design it so it produces evidence as a by-product, not as an afterthought.

    For certain deployers

    Public bodies, private entities providing public services, and deployers using AI for creditworthiness or life and health insurance pricing must complete a fundamental rights impact assessment (Article 27) before first use. Since the Omnibus it can cross-reference your GDPR DPIA rather than duplicate it.

    For everyone else

    Even where the Act doesn't mandate one, a proportionate AI risk assessment is how you decide what's acceptable. It's also the backbone of ISO/IEC 42001's AI risk and impact assessment, if you're heading that way.

    AI risk isn't only regulatory. Prompt injection, data leakage through retrieval, and over-permissioned agents are security problems first. Where it makes sense, we pair the governance work with AI and LLM penetration testing so the risk register reflects how your systems behave under attack, not just on paper.

    AI Governance in Ireland: Building Something That Lasts

    Obligations stick when there's a working structure behind them: named owners, a real approval step, and records produced as part of normal work. Here's what we help you put in place, and where the Act itself speaks to it.

    AreaWhat good looks likeLink to the AI Act
    Ownership and accountabilityA named owner per system, a governance forum with decision rights, and escalation pathsNot prescribed as such; underpins every obligation. Central to ISO/IEC 42001
    Policies and approvalAn AI policy, acceptable-use rules, and a gate before new AI goes live or gets repurposedGood practice; a change of intended purpose can alter your role under Article 25
    AI literacyRole-based training, tracked, matched to what people actually do with AIArticle 4, for all providers and deployers
    Human oversightNamed, trained people with the authority to intervene or overrideArticles 14 and 26(2), for high-risk systems
    Vendor governanceAI questions in due diligence, contractual access to documentation and logsArticle 25(4) written agreements for high-risk suppliers; Article 26 relies on provider instructions
    Record keepingLogs retained, documentation versioned, decisions traceableArticles 12, 18, 19 and 26(6), for high-risk systems
    Monitoring and incidentsPerformance and drift monitoring, a route for staff to report issues, defined incident handlingArticles 72 and 73 for providers; Article 26(5) for deployers of high-risk systems
    TransparencyDisclosure wording, content labelling, and notices to people affectedArticle 50; Article 26(11) for Annex III decisions about people

    Our EU AI Act Compliance Approach

    Eight stages, run in sequence the first time and on a cycle after that. New systems, vendor changes and new guidance all loop back to the start.

    1. 1

      Discover AI systems

      Build the inventory across products, business units and vendors.

    2. 2

      Determine your role

      Provider, deployer, importer, distributor or representative, per system.

    3. 3

      Classify each system

      Prohibited, high-risk, transparency or minimal, with the reasoning recorded.

    4. 4

      Map requirements

      The articles that apply, with application dates attached.

    5. 5

      Identify gaps

      Against what you already run, so nothing is rebuilt needlessly.

    6. 6

      Implement governance and controls

      Policies, oversight, vendor terms, logging, training.

    7. 7

      Build the evidence

      A file you can hand to a regulator, auditor or customer.

    8. 8

      Monitor continuously

      Re-assess on change and track new guidance and standards.

    EU AI Act Requirements by Role

    A working summary. The first two rows can apply to any AI system; the rest apply where a system is high-risk. Read it alongside the articles cited, because the detail matters.

    RequirementProviderDeployerImporterDistributor
    AI literacy (Art. 4)Take measures to support staff AI literacySame dutyNot as importer*Not as distributor*
    Transparency (Art. 50)Design for AI-interaction disclosure; machine-readable marking of synthetic contentDisclose deepfakes and certain AI-generated text; inform people exposed to emotion recognition or biometric categorisation
    High-risk AI systems only
    Risk management and data governance (Arts. 9, 10)Establish and maintain across lifecycleEnsure input data under its control is relevant and representative
    Technical documentation (Arts. 11, 18)Draw up before market; keep 10 yearsVerify it exists; keep declaration, certificate and instructions 10 years
    Logging and record keeping (Arts. 12, 19, 26)Build in automatic logging; keep logs under its control at least 6 monthsKeep logs under its control at least 6 months
    Instructions and human oversight (Arts. 13, 14, 26)Provide instructions; design for effective oversightUse per instructions; assign competent people with authority to overseeVerify instructions accompany the systemVerify instructions accompany the system
    Accuracy, robustness, cybersecurity (Art. 15)Design and declare appropriate levels
    Quality management system (Art. 17)Required, proportionate to size
    Conformity assessment, declaration, CE marking (Arts. 43, 47, 48)Complete before placing on the marketVerify assessment done and CE marking presentVerify CE marking and EU declaration
    EU database registration (Art. 49)Register (also for Annex III systems self-assessed as not high-risk)Public authorities register their use
    Fundamental rights impact assessment (Art. 27)Public bodies, public-service providers, credit and life/health insurance use cases
    Monitoring and serious incidents (Arts. 26, 72, 73)Post-market monitoring; report serious incidents to authoritiesMonitor use; inform provider and authorities of serious incidentsInform provider and authorities where a system presents a riskInform provider or importer and authorities where a system presents a risk
    Informing people (Art. 26)Tell workers' representatives before workplace use; tell people subject to Annex III decisions

    * Importers and distributors are frequently deployers or providers of other systems too, in which case those duties apply. Authorised representatives (Art. 22) verify documentation, keep it available for 10 years and cooperate with authorities under their mandate. SMEs and small mid-caps can use simplified technical documentation under the Omnibus changes.

    High-Risk AI Systems

    "High-risk" is a legal category, not a judgement about how advanced or sensitive your AI feels. A system gets there by one of two routes.

    Route 1: regulated products (Annex I)

    The AI is a safety component of a product, or is itself a product, covered by listed EU harmonisation legislation such as medical devices, and that product needs third-party conformity assessment. Applies from 2 August 2028.

    Route 2: listed use cases (Annex III)

    Biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services, including credit scoring and life and health insurance pricing; law enforcement; migration and border control; and the administration of justice and democratic processes. Applies from 2 December 2027.

    Classification matters because it's the difference between a transparency notice and a full compliance programme. Getting it wrong in either direction costs money: overclassify and you build controls you didn't need, underclassify and you're exposed when the dates arrive.

    What high-risk providers must have in place

    • Risk management across the lifecycle (Art. 9)
    • Data governance for training, validation and testing data, including bias checks (Art. 10)
    • Technical documentation covering at least Annex IV (Art. 11)
    • Automatic logging for traceability (Art. 12)
    • Transparency and instructions for deployers (Art. 13)
    • Human oversight by design (Art. 14)
    • Accuracy, robustness and cybersecurity (Art. 15)
    • A quality management system (Art. 17)
    • Post-market monitoring and incident reporting (Arts. 72, 73)

    Systems already on the market before the relevant date are treated differently under Article 111 unless their design changes significantly. Worth checking before you plan remediation.

    General-Purpose AI: Are You a User, a Builder or a Model Provider?

    This is where we see the most confusion. Using a general-purpose AI tool doesn't make you a GPAI model provider. Those obligations sit with whoever develops the model and places it on the market.

    You use GPAI tools at work

    You're a deployer of an AI system. AI literacy applies, and Article 50 deployer duties apply if you publish deepfakes or certain AI-generated text. GPAI model obligations don't.

    You build a product on someone else's model

    You're typically the provider of your AI system, and its classification depends on its purpose. The model provider must give downstream providers information to help them comply (Art. 53), so get that into your contracts.

    You train or substantially modify a model

    You may be a GPAI model provider: technical documentation, downstream information, a copyright policy and a public training-content summary, plus more for models with systemic risk (Art. 55). The Commission's guidelines explain when modifying a model makes you its provider.

    GPAI obligations have applied since 2 August 2025, the Commission has been able to enforce them since 2 August 2026, and the General-Purpose AI Code of Practice, published in July 2025, is the main voluntary route to demonstrating compliance. For groups with EU headquarters in Ireland, note that the Omnibus widened the Commission AI Office's supervision to AI systems built on a GPAI model by the same undertaking.

    ISO 42001 and the EU AI Act: How They Fit Together

    One is law. The other is a management system standard you can certify against. They reinforce each other, but one doesn't stand in for the other.

    EU AI ActISO/IEC 42001
    What it isEU Regulation (EU) 2024/1689, amended by (EU) 2026/1744International AI management system (AIMS) standard
    StatusLegally binding where in scopeVoluntary; certifiable by accredited bodies
    FocusObligations tied to roles and to specific AI systems and modelsHow the organisation governs AI: policy, risk, roles, controls, improvement
    What "done" looks likeObligations met, and for some high-risk systems a conformity assessment, CE marking and registrationA certificate for your management system scope

    Where ISO 42001 genuinely helps

    It gives you the organisational spine the Act assumes but doesn't spell out: leadership accountability, an AI policy, a repeatable AI risk and impact assessment, supplier controls, internal audit and management review. Many of the governance rows above map neatly onto it.

    Where it won't carry you on its own

    It doesn't produce system-level technical documentation, conformity assessments, CE marking, EU database registration, Article 50 disclosures or specific log retention periods. A presumption of conformity only attaches to harmonised standards cited in the Official Journal, and ISO/IEC 42001 isn't one of them.

    If certification is on your roadmap, we can design the AIMS so it produces AI Act evidence as it runs. See our ISO 42001 certification services in Ireland, or our longer comparison of the EU AI Act vs ISO 42001.

    EU AI Act Services Across Ireland

    We support organisations across Ireland, whether your AI sits with a product team in Dublin, a medtech or pharma operation around Cork or Galway, or engineering and shared-services teams in Limerick and Waterford. The work is delivered remotely by default, with workshops scheduled around your teams; if on-site sessions matter to you, raise it when we scope.

    EU engagements are contracted through our EU entity, Zulon Audits OÜ in Tallinn, and EU-region data processing is available if your evidence needs to stay within the EU. We're not a law firm. Where you need a formal legal opinion, we work alongside your solicitors or in-house counsel.

    Who We Support

    The sector doesn't decide your obligations; your role and use cases do. But some patterns come up again and again.

    SaaS and AI technology companies
    Often the provider. The key questions are whether customers use your features for Annex III purposes and what your GPAI suppliers owe you.
    Financial services and fintech
    Credit scoring and life and health insurance pricing are Annex III use cases; fraud detection is carved out of the credit category. The Central Bank of Ireland is a designated authority for regulated firms.
    Health technology and life sciences
    AI in medical devices typically follows the Annex I route, with the AI Act layered onto MDR or IVDR conformity from 2 August 2028.
    Professional services
    Mostly deployers: AI literacy, transparency for client-facing content, and sensible controls over confidential data.
    Technology and platform companies
    EU headquarters here may bring both Irish authorities and the Commission's AI Office into view, plus overlap with the DSA for very large platforms.
    Any organisation deploying third-party AI
    HR screening, customer service and decisioning tools bought in. Buying the system doesn't transfer your deployer obligations to the vendor.

    Building an AI product? Our page on ISO 42001 for SaaS and AI companies covers the certification side.

    What You May Need to Prepare

    Not every item applies to every organisation. The tags show who each one typically matters for. Part of the assessment is telling you which you can safely skip.

    AI system inventory

    Everyone

    Role mapping

    Everyone

    Classification records

    EveryoneArt. 6(3) providers

    AI literacy training records

    ProvidersDeployers

    AI policy and governance records

    Good practiceISO 42001

    Risk assessments

    High-risk providersGood practice

    Technical documentation

    High-risk providersGPAI providers

    Human oversight records

    High-risk

    Vendor information and contracts

    DeployersDownstream providers

    Logs and monitoring records

    High-risk

    Incident procedures

    High-riskGood practice

    Transparency notices and labels

    Art. 50 systems

    Why VISTA Infosec

    We've been an audit and compliance firm since 2004. That shapes how we approach the AI Act: we think in terms of what an assessor will ask to see.

    So the work is evidence-first. Every classification has written reasoning. Every obligation has an owner and a date. And we're straightforward about limits. No one can hand you a general "EU AI Act certificate". Where the Act requires third-party conformity assessment, notified bodies do it for specific high-risk systems. What we give you is a defensible, documented position.

    Because we also test AI systems for security weaknesses, the governance work doesn't stay theoretical.

    2004Delivering audit and compliance since
    500+Clients assessed
    ISO Lead AuditorsIn-house, for ISO 42001 and ISO 27001 work
    CREST accreditedAnd ISO 27001 certified ourselves
    EU entityZulon Audits OÜ, with EU-region data processing
    AI security testingLLM, agentic and shadow AI assessments

    What Does EU AI Act Readiness Cost?

    There's no honest fixed price, because two organisations with the same headcount can have very different AI footprints. We scope first, then give you a written proposal with a clear fee.

    Request an EU AI Act Assessment

    What drives the scope

    Number of AI systems in scope

    Your role, and how many roles you hold

    Whether any systems are likely high-risk

    Technical complexity of the systems

    Number of business units involved

    Existing governance (ISO 27001, ISO 42001, GDPR)

    Documentation maturity

    Jurisdictions and EU markets served

    Reliance on third-party and GPAI-based AI

    How much remediation support you want from us

    EU AI Act in Ireland: Frequently Asked Questions

    What is the EU AI Act?

    The EU AI Act, Regulation (EU) 2024/1689, is the EU's law on artificial intelligence. It takes a risk-based approach: it bans certain practices, sets detailed requirements for high-risk AI systems, imposes transparency duties on some systems, and regulates general-purpose AI models. It entered into force on 1 August 2024 and applies in phases, and it was amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in July 2026.

    Does the EU AI Act apply in Ireland?

    Yes. As an EU Regulation it applies directly in Ireland. The Regulation of Artificial Intelligence Act 2026, signed into law on 21 July 2026, sets up the Irish enforcement structure, including the AI Office of Ireland and the powers of the designated competent authorities. It doesn't add obligations beyond the EU Regulation.

    Does the EU AI Act apply to every Irish company using AI?

    It can touch most organisations that use AI professionally, but obligations vary a lot. A company using general AI tools may mainly need AI literacy measures and awareness of the prohibited practices, while a provider of a high-risk system faces a full set of requirements. Some uses fall outside scope altogether, such as purely personal non-professional use and AI developed solely for scientific research.

    How do we determine whether we are a provider or deployer?

    Ask who develops the system and puts it on the market or into service under their own name. That's the provider. If you use a system under your authority in a professional capacity, you're a deployer. Roles are assessed per system, and a deployer can become a provider under Article 25, for example by rebranding a high-risk system or changing its intended purpose so that it becomes high-risk.

    How do we know whether our AI system is high-risk?

    Check two routes. Is it a safety component of, or itself, a product under the EU legislation in Annex I that requires third-party conformity assessment? Or is it used for a purpose listed in Annex III, such as recruitment, credit scoring or access to education? An Annex III system can fall outside high-risk under Article 6(3) if it doesn't pose a significant risk of harm, but that assessment must be documented, and systems that profile people remain high-risk.

    What is an EU AI Act readiness assessment?

    It's a structured review of where you stand against the obligations that apply to you. Ours covers your AI inventory, your role for each system, risk classification, a mapping of applicable articles, documentation and governance gaps, and a prioritised remediation roadmap tied to the actual application dates.

    What documentation should we prepare?

    Start with an AI system inventory, your role mapping and classification records, plus evidence of AI literacy measures. What else you need depends on your position: high-risk providers need technical documentation, risk management records, logs and a quality management system, while some deployers need a fundamental rights impact assessment and human oversight records. Not every item applies to every organisation.

    Does ISO 42001 certification make us EU AI Act compliant?

    No. ISO/IEC 42001 certifies your AI management system, which is valuable groundwork for governance, risk and accountability. It doesn't by itself meet system-level obligations such as technical documentation, conformity assessment, registration or Article 50 transparency, and it isn't a harmonised standard that gives a presumption of conformity under the Act.

    What are the EU AI Act deadlines?

    Prohibited practices and AI literacy have applied since 2 February 2025; GPAI model obligations since 2 August 2025; Article 50 transparency and the general date of application since 2 August 2026. New prohibitions apply from 2 December 2026. High-risk requirements apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products, following the Digital Omnibus on AI. Dates were last checked on 21 September 2026.

    Can VISTA support organisations across Dublin, Cork, Galway, Limerick and Waterford?

    Yes. We support organisations across Ireland, with delivery remote by default and workshops scheduled around your teams. EU engagements are contracted through our EU entity, Zulon Audits OÜ, and EU-region data processing is available.

    Expert Auditors. Faster Certification.

     

    European Operations
    European engagements are delivered through Zulon Audits OÜ, the European practice of VISTA InfoSec.
    Visit Zulon Audits →