EU AI Act

Do I need an AI policy under the EU AI Act?

The short answer

If anyone in your business uses an AI tool for work, you are a deployer under the EU AI Act, and Article 4 expects you to show that those staff have sufficient AI literacy. A short written policy plus a dated training record is the proportionate answer for most Irish SMEs. You do not need a compliance programme; you do need something written down and evidence that people were told.

You are probably a deployer already

A deployer is any organisation using an AI system under its own authority in the course of work. If someone in accounts drafts supplier emails with an assistant, or a manager summarises meeting notes with one, that is you. Nobody had to sign a project off for it to be true.

This is why "we have not started with AI yet" is usually inaccurate. The tools arrived through individuals, not through procurement.

What proportionate looks like for a 10 to 250 person business

Three artefacts, and none of them are long:

  • A two-page policy. Approved tools, forbidden inputs, where human approval is mandatory, disclosure, and who to tell when something goes wrong.
  • A training record. Dated, named, role-based, tied to a policy version.
  • A tool register. One line per system: what it does, what data it sees, who owns it.

That is enough for most Irish SMEs to answer a client questionnaire honestly, which in practice is the test you will face first.

The forbidden-inputs list is the part that matters

Most real incidents are not exotic. Someone pastes a customer list, an unreleased set of accounts or a colleague's medical note into a public assistant. Naming those categories explicitly, and naming the two approved tools where work data may go, prevents more harm than any governance framework.

Build the approvals into the tool, not just the document

A policy that relies on people remembering it will drift. Where a workflow is automated, the approval step should be in the software: the tool drafts, a named person releases, and the log records both. Then the policy describes what the system already enforces, which is a much easier thing to evidence.

Common questions

Does the EU AI Act apply to a small Irish business?
Yes, if you use AI systems at work. Most obligations fall on providers who build systems, but deployers who use them have duties too, including the Article 4 AI literacy expectation. Size does not exempt you; it shapes what proportionate looks like.
What is Article 4 in plain English?
Providers and deployers must take measures to ensure the people operating AI systems on their behalf have a sufficient level of AI literacy, considering their role, the context and who is affected. In practice: role-appropriate training, and a record of it.
What should an SME AI policy actually contain?
Which tools are approved, what may never be pasted into them, when a human must approve output, how AI involvement is disclosed to customers, who to tell when something goes wrong, and who owns the policy. Two pages is usually enough.
Do I have to tell customers they are talking to AI?
Where people interact with an AI system, they should be told, unless it is obvious from the context. A one-line disclosure on a chat or voice assistant covers it, and it costs nothing in trust when it is done plainly.
Is banning AI tools a safer option?
Rarely, and it seldom works. Staff use assistants on personal accounts instead, which is exactly the situation a policy exists to prevent. Approving two tools and saying clearly what may not go into them is safer than a ban nobody follows.
How do I prove AI literacy if we are audited or asked by a client?
A dated attendance log naming who was trained, on what, at what depth, alongside the policy version they were trained on. Large clients increasingly ask for this in procurement well before any regulator does.

Next step

A 20-minute call is enough to tell you whether there is a workflow here worth building, and to say so plainly if there is not.