error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

      Summer 2026 marks a significant step forward in the implementation of the EU AI Act. Two important developments have sharpened regulatory expectations for organisations.

      The first being that the European Commission has published draft guidelines on the classification of high-risk AI systems, providing long-awaited clarity on when the most onerous obligations apply.

      In addition, Ireland has published the Regulation of Artificial Intelligence Bill 2026, establishing the national enforcement framework and confirming how the AI Act will be supervised domestically.

      Together, these developments signal a shift from regulatory expectations to practical implementation and enforcement readiness.

      Jackie Hennessy

      Partner, Risk Consulting

      KPMG in Ireland


      EU Commission guidance: clarity on what is ‘high-risk’ AI

      The classification of “high-risk” AI is central to the EU AI Act. Many of the most demanding obligations, including risk management, documentation, testing, and oversight, are triggered only where an AI system is high-risk.

      The Commission’s draft guidelines (published 19 May 2026) provide clarification that AI systems are considered high-risk where they:

      • Are embedded in regulated products (such as medical devices, machinery); or
      • Are used in sensitive use cases such as employment, education, biometrics, or access to essential services.

      The guidance includes examples to support organisations in assessing their use cases, while recognising that classification will often require context-specific judgement.

      While the guidelines are not legally binding, they reflect the Commission’s interpretation and will guide enforcement by regulators and market surveillance authorities.


      Key takeaway


      The guidance highlights the need for robust classification processes. AI must be classified at the level of each use case, not just the AI system, and based on both intended purpose and actual use.

      AI Classification cannot be circumvented by superficial controls, such as human sign-off alone.


      Ireland’s Artificial Intelligence Bill: moving into enforcement

      On 17 June 2026, the Irish Government approved publication of the Regulation of Artificial Intelligence Bill 2026, marking a major milestone in Ireland’s AI regulatory framework.

      The Bill does not create new obligations beyond the EU AI Act. Instead, it establishes Oifig IS na hÉireann (AI Office of Ireland) as the central coordinating authority; empowers Market Surveillance Authorities (MSAs) to supervise compliance, investigate breaches, and impose sanctions, and provides a structured enforcement toolkit, ranging from compliance notices to fines and prosecution.


      What do these updates mean for organisations?

      With enforcement mechanisms being formalised at national level and regulatory interpretation becoming clearer at EU level, organisations that delay, risk facing tight timelines, increased remediation costs and heightened scrutiny, whereas those that act early will be better positioned to deploy AI in a controlled, trusted and scalable way.

      In practice, this means organisations must move now to establish structured AI governance, including inventorying AI use cases, embedding classification and risk assessment processes, and aligning controls with existing regulatory frameworks.


      Next steps

      • Identify the use cases of AI currently in operation across your organisation.
      • Assess each use case to determine whether it falls within a high-risk.
      • Define clear ownership and governance structures.
      • Design and embed AI risk management controls.
      • Align processes and documentation with anticipated supervisory requirements.

      How can KPMG help?

      Our team at KPMG has the expertise to support organisations in translating evolving regulatory expectations under the EU AI Act into practical, scalable and business-aligned solutions.

      We work with clients to assess their exposure, design fit-for-purpose governance frameworks, and implement operational controls that align with both AI Act requirements and existing regulatory obligations such as GDPR, model risk management and cybersecurity frameworks.

      Our approach combines regulatory insight with deep functional expertise, enabling organisations to move beyond theoretical compliance and embed AI governance into day-to-day operations.

      KPMG helps clients navigate complexity, reduce regulatory risk, and build trusted AI capabilities that support sustainable innovation. 

      Download this page in PDF (665KB)

      EU AI Act: From regulation to reality

      (PDF, 655KB)

      Get in touch

      Whether you are assessing readiness, strengthening governance, or implementing AI controls, KPMG can help you take the next step with confidence.

      Contact our team to explore a tailored approach for your organisation. 

      Jackie Hennessy

      Partner, Risk Consulting

      KPMG in Ireland

      Shane Garahy

      Partner, Risk Consulting

      KPMG in Ireland

      Emma Coogan

      Director, EU AI Hub

      KPMG in Ireland

      Maria McAnearney

      Manager

      KPMG in Ireland

      Read more in Consulting

      Something went wrong

      Oops!! Something went wrong, please try again

      You can with AI

      We understand the transformative opportunities provided by artificial intelligence. Contact us to drive new AI opportunities for growth in your business.
      3 people in office with neon lines overlaid