AI in Irish Schools: Guidance, GDPR and the EU AI Act
A practical guide to Ireland's AI guidance for schools, GDPR checks and the EU AI Act timeline, including what school leaders should review now.
Updated on 5 August 2026
Irish schools are already using AI to draft, summarise and create classroom materials. The practical question is not whether every AI tool is "compliant" in the abstract. It is whether a particular tool and use are appropriate, transparent and supported by the right safeguards.
The Department of Education's Guidance on Artificial Intelligence in Schools, GDPR and the EU AI Act each address a different part of that decision. This guide separates the legal requirements from Department guidance and sensible vendor checks.
Note
No single August 2026 deadline for every school AI tool
The EU AI Act became generally applicable on 2 August 2026, with some provisions applying on different dates. Transparency rules apply from August 2026, while the Act's Annex III high-risk rules for specified education uses apply from 2 December 2027 following the AI Omnibus changes that took effect on 27 July 2026. Not every AI tool used in a school is a high-risk system.
What Official Guidance and Law Say
Department guidance: review existing policies and practice
The Department's guidance uses a 4P Framework: Purpose, Planning, Policies and Practice. It asks schools to keep teaching and learning human-led, verify AI-generated material and consider matters such as equality, privacy, intellectual property and digital wellbeing.
It does not require every school to create a standalone AI policy. Instead, schools should review the policies already affected by AI use. Depending on the school's context, these may include:
- the Acceptable Use Policy
- privacy and data-protection policies
- the code of behaviour
- Bí Cineálta policies and procedures
- assessment, teaching and learning policies
The Department describes the guidance as a living document. Schools should therefore use the current version linked from the Digital Strategy for Schools to 2027, rather than treating a one-off policy update as finished work.
EU AI Act: the use determines the risk category
The European Commission's AI Act overview sets out a risk-based framework. In education, Annex III identifies particular high-risk uses, including AI used to:
- determine access or admission to educational institutions
- evaluate learning outcomes where that evaluation steers the learning process
- assess the appropriate educational level a person will receive or access
- monitor and detect prohibited behaviour during tests
A general writing assistant is not automatically high-risk merely because a teacher uses it in school. Classification depends on the system's intended purpose and how it is used. Obligations also differ between providers and organisations deploying a system.
AI literacy duties have applied since February 2025. The Act's general application and transparency rules are now relevant, while the Annex III high-risk education-system obligations apply from 2 December 2027.
Ireland's enforcement framework is now law
Ireland's Regulation of Artificial Intelligence Bill completed the legislative process and was signed on 21 July 2026 as Act 31 of 2026. The Oireachtas record is the authoritative source for its legislative status.
That national framework does not make every classroom AI use high-risk. Schools still need to assess the actual purpose, data and decisions involved.
Key Point
The useful distinction
The AI Act is law. The Department's 4P framework is national guidance for schools. Contract, retention, security and data-transfer questions are practical checks that help a school assess a vendor and meet its existing responsibilities.
A Six-Point AI Review for Irish Schools
Use this review before approving a new tool or allowing personal student information to be entered into it.
1. Define the purpose and risk
Record what the tool will do, who will use it and whether its output could affect admission, assessment, educational level or test monitoring. A low-stakes drafting aid and a system that evaluates a child do not carry the same risk.
2. Keep meaningful human oversight
Teachers should review and verify AI-generated material before it is relied on. AI should support professional judgement, not make decisions about a child or replace the teacher's responsibility for the final record.
3. Check data-protection risk
A Data Protection Impact Assessment is required under GDPR where processing is likely to result in a high risk to people's rights and freedoms. It is not automatically required for every AI tool. Use the DPC Data Protection Toolkit for Schools to assess the proposed use, and involve the school's data protection contact or DPO where appropriate.
4. Minimise personal data and be transparent
Use only the information needed for the stated purpose. Avoid entering names or other identifiers when anonymised or non-personal information will do. Identify an appropriate lawful basis and ensure that staff, families and pupils receive clear information where their personal data is processed. Consent is one possible lawful basis, not the default answer for every school activity.
5. Verify location, transfers and security
EU data residency is not a blanket legal requirement. Ask where data is processed and stored, whether it leaves the EEA, and what GDPR transfer mechanism and technical safeguards apply. Also check access controls, incident handling and the vendor's role under the data-processing agreement.
6. Check retention, deletion and model-training terms
Confirm how long prompts and files are kept, how deletion works and whether school content is used to train or improve models. These terms can vary by product, account type and contract, so verify the terms that apply to the school's actual service rather than relying on a general product description.
Tip
Three useful vendor questions
Where is our data processed? How long is it retained? Is our content used to train or improve any model? If an answer is unclear, do not enter personal student information until it is resolved.
What School Leaders Should Do Now
- Map current AI use. Ask staff which tools they use and for what purpose, including free personal accounts.
- Review affected policies. Update existing AUP, privacy, behaviour, Bí Cineálta and teaching-and-learning policies where needed. A separate AI policy is optional, not a Department requirement.
- Set simple boundaries. State which tools are approved, what information must not be entered and when human review is required.
- Assess higher-risk processing. Consider a DPIA where the proposed personal-data processing is likely to create high risk, and identify whether the use falls within an AI Act high-risk category.
- Keep evidence. Retain the vendor answers, relevant contract terms, decision record and review date.
For SEN documentation, SENScribe's browser privacy check looks for recognised likely names and common direct identifiers before each official AI request. Saved Student Support Files are encrypted on the device, AI processing uses Azure OpenAI within the EU data zone, and under SENScribe's Azure setup prompts are not used to train foundation models. Generated content remains a draft for teacher review and editing. See how SENScribe protects student information.
See How SENScribe Handles Your Data
Browser privacy checks, encrypted saved files, EU data-zone AI processing, and prompts kept out of foundation-model training.
Frequently Asked Questions
Does every Irish school need a separate AI policy?
No. The Department guidance says a specific AI policy is not required. Schools should review the existing policies affected by their use of AI, which may include the AUP, privacy and data-protection policies, the code of behaviour and Bí Cineálta.
Is every AI system used in education high-risk?
No. The EU AI Act identifies specified education uses as high-risk, including systems used for access or admission, certain evaluation of learning outcomes, educational-level assessment and monitoring prohibited behaviour during tests. The intended purpose and actual use matter.
Does a school need a DPIA for every AI tool?
No. Under GDPR, a DPIA is required where processing is likely to result in a high risk to individuals' rights and freedoms. Schools should screen each use and complete a DPIA where that threshold is met. The DPC toolkit provides a school-focused starting point.
Must school data stay in the EU?
Not in every case. If personal data is transferred outside the EEA, the school needs to understand the destination and verify that an appropriate GDPR transfer mechanism and safeguards are in place. Keeping processing within the EEA may simplify that assessment, but it is not a universal statutory requirement.
What dates should schools know under the EU AI Act?
AI literacy duties have applied since February 2025. The Act became generally applicable on 2 August 2026, including its transparency regime, subject to its staged timetable. Following the AI Omnibus changes, Annex III high-risk rules for specified education systems apply from 2 December 2027. Schools should check the European Commission's current timeline when planning a high-risk use.
Official sources: Department Guidance on Artificial Intelligence in Schools · Digital Strategy for Schools to 2027 · European Commission AI Act overview · Regulation of Artificial Intelligence Act 2026, Oireachtas record · DPC Data Protection Toolkit for Schools