Supplying incorrect, incomplete or misleading information to a competent authority carries a penalty of up to €7.5m or 1% of global turnover. That provision has been live since 2 August 2026.
Most Irish organisations have read the EU AI Act as a build project with a deadline attached. Classify the systems, write the documentation, be ready for December 2027. That framing misses what changed six weeks ago. Since 2 August 2026 the supervisory machinery has been operational, and the first thing supervision produces is a letter asking you a question.
Who can write to you
Ireland took the distributed route. Rather than stand up a single AI regulator, the State designated fifteen competent authorities and gave market surveillance functions to thirteen of them, mapped onto the sectors those bodies already supervise — financial services, health products, consumer protection, transport, employment. If you are a regulated firm, the authority that will ask you about your AI systems is almost certainly one you already correspond with, using a case officer you already know.
The National AI Office coordinates that network and acts as the single point of contact, but it lost its own market surveillance designation before it opened. Nobody is going to send you a letter from a new AI regulator. The letter arrives from the Central Bank or the HSA, on the same headed paper as everything else they send you, and it lands with whoever normally handles their correspondence.
What they are entitled to see
The powers are broader than most compliance teams assume. Article 21 obliges a provider, on a reasoned request from a national competent authority, to hand over all the information and documentation needed to demonstrate conformity — in a language the authority can readily understand, which in Ireland means English. Technical documentation has to be retained for ten years.
Article 74 layers the market surveillance regime of Regulation (EU) 2019/1020 on top of that. Authorities get full access to documentation, and where documentation and testing prove insufficient, to the training, validation and testing datasets. Source code is reachable on a reasoned request, subject to conditions. Deployers have their own obligation under Article 26 to retain automated logs for at least six months, which is the evidence a supervisor will use to check whether the story you told matches the system's behaviour.
The penalty for a bad answer is already in force
Article 99 sets three tiers. Prohibited practices reach €35m or 7% of worldwide turnover. Most obligations sit at €15m or 3%. The third tier gets less attention and matters more right now: supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities is capped at €7.5m or 1% of global turnover, with lower ceilings for SMEs.
That provision has applied since 2 August 2026. It does not wait for the high-risk regime, which the Digital Omnibus pushed out to 2 December 2027 for Annex III systems. A firm whose AI deployments are entirely low-risk, entirely compliant and entirely benign can still be sanctioned for the quality of its reply to a regulator's question. The exposure attaches to what you say about your estate.
Most organisations cannot answer the first question
The opening question in any information request is some version of: what AI systems do you operate, in what function, and who is accountable for each one. In the diagnostics we run, that question takes weeks rather than hours, and the list IT produces rarely matches the list the business is actually using.
The gap is structural. Copilot licences get assigned centrally and used departmentally. An applicant tracking system quietly adds a candidate scoring feature in a release note. A finance team builds a forecasting workflow on a free-tier model with a personal login. A vendor renames a product with "AI" in the title and nothing else changes. Each of those is a separate answer to a supervisor's question, and each has a different owner, none of whom has been asked to write anything down.
An incomplete inventory produces an incomplete reply. An incomplete reply, under Article 99(5), is a sanctionable act in its own right — and it invites the follow-up question that a complete reply would have closed.
What to have ready before the letter
Three artefacts, none of which take long to build and all of which take longer than a statutory response window.
A current inventory of AI systems in use, with the business function, the vendor, the named owner and the intended purpose recorded in plain English. Then, for each system that touches a person — hiring, credit, pricing, access, performance — an evidence pack holding the vendor's documentation, the human oversight arrangement, and confirmation that logging is switched on and retained. Finally, a named individual who owns the response itself, with authority to say what the organisation does and does not run.
Do that and a reasoned request becomes an administrative task. Skip it and the first four weeks go on discovery, under a clock, with a penalty attached to getting it wrong.
We work with Irish boards and leadership teams on precisely this question: what is deployed, who owns it, what evidence exists, and how quickly a defensible answer can be assembled. If you would rather establish that now than under a deadline, a diagnostic conversation with Acuity AI Advisory is the place to start. Vendor-neutral, evidence first.