The GenAI Compliance Gap: Why 88% of Irish Firms Are Flying Blind on AI Policy

Business2000 5 min read
The GenAI Compliance Gap: Why 88% of Irish Firms Are Flying Blind on AI Policy

A policy document nobody reads is not a compliance programme. It is a liability waiting to be activated.

That is the position most Irish businesses are in right now. Research from Ibec published in early 2025 found that 88% of Irish firms using generative AI have no formal governance framework in place that staff actually follow. The policies exist on SharePoint. The behaviour exists everywhere else.

The Gap Between Paper and Practice

There is a clean binary at work here. You are either governed or you are exposed. There is no middle category called "we have a draft somewhere."

The EU AI Act is not a framework businesses can grow into at their own pace. It is a regulation with hard deadlines. Systems classified as high risk, including AI tools used in hiring, credit decisions, and certain customer-facing applications, face full compliance requirements from August 2026. General-purpose AI systems with significant reach face obligations from August 2025. Fines sit at up to €35 million or 7% of global annual turnover, whichever is higher. For a company with €50 million in Irish revenue, that upper ceiling is €3.5 million, roughly the cost of seven senior hires wiped out in a single enforcement action.

The Irish picture is not an outlier. It mirrors the EU-wide pattern. But Ireland carries a specific weight here. With the European headquarters of Google, Meta, Microsoft, and dozens of other AI-adjacent companies based in Dublin, the Data Protection Commission is already the de facto regulator for much of Europe's digital economy. Enforcement that originates here travels further. The €29M Leak problem already showed what a single high-profile data failure can do to Ireland's reputation as a trusted digital jurisdiction.

Why the Policy Exists But the Practice Doesn't

Three reasons explain why Irish firms wrote the document and skipped the discipline.

Reason one: AI adoption outran legal awareness. Generative AI tools entered the workplace through individual employees, not IT procurement. A marketing manager started using ChatGPT in January 2023. By the time legal heard about it, half the team was doing the same. The policy was written after the fact, as a paper exercise, without changing the underlying workflow. The tool was already embedded. The policy was cosmetic.

Reason two: Governance was treated as a one-time task. A policy is not a programme. A programme involves training, monitoring, a named owner, and a review cycle. Most Irish firms appointed no AI officer, trained no staff on the policy, and set no review date. The document was written to satisfy a board question, not to govern actual behaviour.

Reason three: The stakes felt abstract. Regulatory risk without a visible enforcement action reads as theoretical. Irish SMEs in particular tend to manage risk reactively. The GDPR fines that made headlines were handed to the multinationals. That perception is about to become expensive.

What Actual Compliance Looks Like

There are four things that separate a functioning AI governance programme from a filed document.

Step 1: Inventory. Map every generative AI tool in use across the business. Include tools accessed through personal accounts, browser extensions, and third-party software that has quietly added AI features. This step comes first because you cannot govern what you have not found.

Step 2: Classification. Assign each tool to a risk category under the EU AI Act. Most generative tools used for content creation or internal summarisation sit in the minimal-risk category and require only transparency obligations. Tools used in performance management, recruitment filtering, or financial decisions require significantly more rigour. The classification determines your compliance burden, so getting it wrong costs you twice.

Step 3: Owner and training. Appoint a named individual responsible for AI compliance, not as an add-on to an existing role but as a documented accountability. Train every employee who touches an AI tool. Training does not mean a 45-minute video. It means staff can explain what data they may and may not input, and why.

Step 4: Review cycle. Set a quarterly review for the first year. The tools are changing fast. A policy written for GPT-4 in February may not reflect how the same platform behaves by September. The review cycle is what turns a document into a living control.

The order matters. Skipping the inventory and going straight to policy writing is exactly how you end up back at the beginning, with a document that does not reflect reality.

The Competitiveness Argument

Compliance is not just about avoiding fines. It is a commercial question.

Enterprise clients, particularly in financial services, pharma, and public procurement, are beginning to include AI governance requirements in supplier questionnaires. A firm that can demonstrate a functioning AI compliance programme wins contracts that a firm with a filed-and-forgotten policy will not. Irish companies are already losing ground in AI adoption, and the firms that treat compliance as a differentiator rather than a tax will pull ahead of those treating it as a cost.

The deeper risk is not a fine from a regulator. It is a client asking for your AI policy during a tender process, finding that the policy says one thing and your staff do another, and walking away. That loss never appears in a headline. It just quietly costs you the contract.

The Turn

The businesses that will come out of this period well are not the ones with the thickest policy documents. They are the ones where the managing director can name their highest-risk AI tool, the employee who owns AI compliance, and the last date the policy was reviewed. That is a thirty-second test. Most Irish businesses will fail it today.

Write the policy by all means. Then build the programme around it, because the regulation is not waiting for anyone to feel ready.

More in Economy