Dublin: The Artificial Intelligence Act has now passed its initial implementation milestones, and the enforcement architecture across member states is beginning to take recognisable shape. Ireland, which hosts the European headquarters of most large general-purpose AI providers, has emerged as a node of disproportionate significance in the supervisory map. The capacity-building question facing the national authority designated under the regulation is not unique to Dublin, but the concentration of regulated entities makes it especially visible there.
The regulation distinguishes between general-purpose AI models, high-risk systems deployed in specific use cases, and prohibited practices. Each category carries its own supervisory logic. General-purpose providers above a defined compute threshold report directly to the AI Office; high-risk systems are governed primarily through national market surveillance; prohibited practices fall to enforcement chains that include data protection, consumer protection and equality bodies depending on the alleged harm. The fragmentation is partly inevitable given how AI cuts across sectors, but it complicates the predictability that companies seek and that public administrations require.
Several substantive questions remain only partly resolved. The first concerns codes of practice for general-purpose models, where the negotiation between providers, civil society organisations and rights-holder groups has been contested on training data transparency, copyright compliance and systemic risk evaluation. The provisional texts move closer to outcome-based obligations rather than prescriptive procedures, which provides flexibility but raises the question of how regulators will verify adequacy without intrusive inspection rights. The second concerns the interaction with existing legislation, particularly the General Data Protection Regulation, the Digital Services Act and sector-specific medical or financial rules. Companies operating across these regimes report substantial costs in mapping overlapping obligations, even where the underlying objectives are consistent.
The third concerns enforcement capacity. Estimates of staff and budget across national AI authorities show wide variation. Some member states have integrated AI supervision into existing data protection authorities, others into telecommunications regulators, others into newly created bodies. The risk of regulatory arbitrage between member states with different supervisory intensity is a familiar one from data protection enforcement, and the experience of one-stop-shop disputes under GDPR has informed the design of cross-border cooperation mechanisms under the AI Act. Whether those mechanisms function more smoothly than their predecessor depends substantially on early test cases.
Industry response has been ambivalent. The European AI industry has welcomed clarity but raised concerns about the pace at which standards under European harmonised norms are being produced, which directly affects compliance pathways for high-risk providers. International providers face the additional question of how to align European obligations with divergent rules emerging in the United Kingdom, the United States and parts of Asia. The Commission has consistently maintained that the AI Act sets the European baseline rather than seeking extraterritorial reach, but the practical effect of strict European obligations on global product design is recognised, including by those subject to them.
The longer-term success of the regulation will hinge less on the elegance of its categorical structure than on the credibility of its enforcement. If supervisors can demonstrate, within reasonable timeframes, that high-risk obligations are being met and that prohibited practices are detected and sanctioned, the regulatory bargain will hold. If implementation gaps accumulate, the political pressure to either tighten or loosen the regime will grow, depending on which gap proves most visible.




