By Joseline Valdez Rojas (ADAPT Intern)
Dataset.
The EU AI Act provides a common regulatory framework for artificial intelligence across Europe. Much of what implementation looks like in practice, however, will be shaped at national level. Member States have to decide who supervises the rules, how responsibilities are divided between regulators, how those authorities work together and how legal obligations are translated into procedures that organisations can actually follow. These choices may sound administrative, but they can have a significant impact on how consistent and accessible the AI Act becomes in practice.
In 2025, the ADAPT Centre responded to a public consultation on Ireland’s national implementation of the EU AI Act. Its submission put forward 15 recommendations covering not only institutional design, but also questions around fundamental rights, regulatory learning, incident reporting, data sharing, guidance and coordination across the AI value chain.
The publication of the General Scheme of the Regulation of Artificial Intelligence Bill 2026 in February 2026 provided an opportunity to look at those recommendations again, this time against Ireland’s emerging implementation framework. The question was relatively simple: could the mechanisms proposed by ADAPT Centre actually be identified in the Irish framework?
The analysis:
The scope of the analysis was deliberately narrow. It was not a full assessment of whether Ireland was legally compliant with the EU AI Act, nor was it an attempt to establish whether ADAPT Centre’s submission had directly influenced the legislative process. Instead, the comparison focused on function. For each of the 15 recommendations, four elements were considered: who was expected to act, what action was being requested, what practical mechanism was proposed and what outcome that mechanism was intended to achieve. The closest provisions in the General Scheme were then compared against those elements.
That distinction mattered. Two provisions can look similar because they use related terminology while performing quite different regulatory functions. A national contact point for communication with European institutions, for example, does not necessarily provide organisations with guidance on which European or national laws protect fundamental rights. Similarly, an AI register and a searchable guidance portal may both organise information, but they are designed to solve different problems.
Each recommendation was therefore classified as reflected, partially reflected, or not clearly identifiable. The final category was intentionally cautious. “Not clearly identifiable” means that no clear functional equivalent was found in the documents reviewed. It does not mean that such a mechanism could not exist elsewhere in Irish law, regulatory guidance or future administrative practice.
What did the General Scheme actually reflect?:
The first comparison produced a striking result. None of the 15 recommendations was fully reflected in the General Scheme. Six were partially reflected and nine were not clearly identifiable.
Figure 1. Functional assessment of the 15 ADAPT Centre recommendations against Ireland’s General Scheme: 0 reflected, 6 partially reflected and 9 not clearly identifiable.
The numbers, however, tell only part of the story. Ireland was clearly building an implementation architecture. The General Scheme proposed a national AI Office, mechanisms for coordination between authorities, regulatory sandboxes and procedures for dealing with serious incidents. The stronger correspondence generally appeared where ADAPT Centre had recommended broad institutional structures. The gaps became more visible when the recommendations moved from establishing institutions to defining the practical tools those institutions would need.
These included clearer mapping of fundamental rights protections, alignment between Fundamental Rights Impact Assessments and Data Protection Impact Assessments, centralised implementation guidance, common tools for incident reporting and practical contractual guidance for actors across the AI value chain. The General Scheme was therefore relatively developed when it came to creating the institutional architecture. It was less specific about some of the processes needed to make that architecture operate consistently. Then the legislative context changed.
The framework moved forward:
While the analysis was being carried out, the formal Regulation of Artificial Intelligence Bill 2026 was published in June. It was considerably more detailed than the General Scheme and gave statutory form to many arrangements that had previously appeared only as proposed structures. That meant the initial findings had to be tested again. The 15 recommendations were reassessed against the new legislative text. Interestingly, the overall classification did not change: 0 fully reflected, 6 partially reflected and 9 not clearly identifiable. But something had changed underneath those headline figures. The comparison showed that the later framework strengthened the correspondence for six recommendations, left eight largely unchanged and weakened one.
This is an important distinction, because a recommendation can become more clearly addressed without moving into a different overall category. The later legislation strengthened areas such as regulatory coordination, sandboxes and real world testing, serious incident reporting and data protection safeguards. At the same time, several of the areas that had shown weaker correspondence in the General Scheme remained unresolved or only partly addressed. These included detailed fundamental rights guidance, better alignment between impact assessment processes, centralised implementation guidance and practical tools for actors across the AI value chain.
Regulatory sandboxes are a useful example, the later framework provided a clearer legal basis for multiple sandboxes and real world testing. That was a meaningful development. ADAPT Centre’s recommendation, however, described something broader: a model of regulatory learning in which different mechanisms could be created, adapted and retired depending on sectoral, technological and value chain needs. Serious incident reporting followed a similar pattern. Reporting and centralisation became clearer, while elements such as a shared incident taxonomy, common templates and a systematic way of learning from incidents across authorities were not clearly identifiable.
The legislation subsequently completed the parliamentary process and was signed by the President on 21 July 2026, becoming the Regulation of Artificial Intelligence Act 2026 (No 31 of 2026).
Final thoughts:
Ireland has now established much of the legal architecture required for national implementation of the EU AI Act. The harder question is how consistently that architecture will work across different sectors and authorities.
How will organisations receive clear guidance when several regulators may be involved? How can Fundamental Rights Impact Assessments and Data Protection Impact Assessments work together without creating unnecessary duplication? What common tools will authorities use to learn from serious incidents? And how can providers, deployers, public bodies and affected stakeholders contribute to regulatory learning?
Not every answer necessarily requires another piece of primary legislation. Some of these issues may be better addressed through regulatory guidance, cooperation agreements, sector specific procedures, common templates or shared implementation tools. This is where the difference between legal capacity and operational capacity becomes important. Giving an authority the legal power to act does not automatically explain how regulators should coordinate, how organisations should navigate their obligations or how stakeholders should participate.
A useful next step would therefore be to translate the remaining issues into an implementation roadmap: identifying which questions require guidance, which depend primarily on institutional coordination and which may require further policy or legislative development. Ireland has built much of the legal structure for implementing the EU AI Act. The next test is whether that structure can operate coherently across institutions, sectors and stakeholders.
References: