[nonimo]
EN
Download

AI in Irish local authorities: what council staff can use

· Updated · Written and maintained by Joaquín Trapero, Nonimo

There are 31 local authorities in Ireland, they deliver more than 1,100 services between them, and the question their staff are actually asking has moved on from whether AI is coming: it is whether the thing on their screen is allowed, and what happens if they paste a resident’s details into it. This guide answers both, with the Irish documents that decide it.

In several councils the answer is already a written no: free, publicly available chat tools are prohibited for council work, and only ones that are enterprise approved may be used. The Government’s own public service guidelines say much the same. And the data a council holds is the kind that makes the question serious, because a resident cannot choose a different housing authority the way they can choose a different shop.

What follows is what staff already use AI for, what the law asks, what the guidance asks, and how to answer a complaint without letting a resident’s details out of the building.

What Irish council staff already use AI for

The most detailed public account of this comes from Dublin City Council. In February 2025 its Gen AI Lab, set up with Trinity Business School and the ADAPT Research Ireland Centre, ran an ideation workshop across departments with representatives from 14 different sections. The findings were published on 9 June 2026 by researchers at ADAPT and Trinity.

The use cases it produced are worth reading because they are not the ones a vendor would pitch.

areathe idea that came out of the workshop
Customer servicetranscribing, translating and analysing customer service interactions
Housing and financerent assessment assisted by AI
Communicationssynthesising information for press releases
Internal supporta chatbot for staff
Public safetyrisk management for Dublin Fire Brigade
Procurementintelligent automation of procurement

Source: Ji, Biyabani and Jha, Gen AI for Local Governments: Findings from Dublin City Council Case Study, 9 June 2026.

The one on that list that is legally different from the others

Rent assessment assisted by AI. Transcription and press releases are ordinary office automation. A system that helps decide what a tenant pays, or whether they qualify for a support, is a decision about access to an essential public service, and that is the category the EU AI Act treats as high-risk under Annex III point 5(a).

Nothing about that makes it forbidden. It makes it a different kind of project, with a different set of documents attached to it, and it is the reason an inventory that lumps all AI together is worse than no inventory at all.

What the staff themselves worried about

The same study grouped the anticipated outcomes and the potential obstacles into five headings: compliance, staff upskilling, public satisfaction, resources, and data and output. Three of those five are about the organisation rather than the technology, which is the finding most vendor material leaves out.

It is also the finding that predicts how these projects fail. A council that buys licences without answering the compliance and upskilling questions has only dealt with the easy part of the problem. The policy and training side has to be in place first, and it is not something a council can buy in.

What is running now, rather than what was imagined

Alongside the lab work there is a live procurement story. Dún Laoghaire Rathdown County Council told the Dublin Inquirer in March 2026 that it was taking part in a 90 day pilot of Copilot led by the Local Government Management Agency, alongside eight other local authorities. Dublin City Council and South Dublin County Council have both bought Copilot licences.

31local authorities in Ireland
1,100services they deliver between them
9in the Copilot pilot led by the LGMA
LGMA Corporate Plan 2026 to 2030, and Dublin Inquirer, 4 March 2026

The LGMA itself has put this in writing. Its Corporate Plan 2026 to 2030 lists, as one of ten objectives, harnessing artificial intelligence and other innovative technologies to improve efficiency and service delivery. So the direction is set at sector level, and the individual authority is left to work out the controls.

The data a local authority holds, and why it is the difficult kind

A council is not a business with customers. It is a body people cannot avoid dealing with, holding records they did not choose to hand over, about circumstances they would usually rather nobody knew. Some of those circumstances are health or ethnic origin, which the GDPR puts on a short, specially protected list.

the recordwhy it is harder than it looks
Housing and tenancy filesarrears, anti-social behaviour reports, medical priority, family composition
Social and community serviceshomeless services, Traveller accommodation, disability adaptations
Planningobjections carry the objector’s name and address on a public file
Enforcement and sanctionsderelict sites, litter fines, waste prosecutions, dog control
Complaints and representationsrouted through a councillor, so a third party is already involved

Housing, planning and social service records will usually include special category data within the meaning of Article 9 of the GDPR.

The third party who is already in the room

A council complaint often arrives through an elected member, which means the file already involves somebody who is neither the council nor the resident. That matters for AI use in a way it does not in a private office: the text a staff member is tempted to paste contains a named resident, a named councillor and a political context.

It also means the resident has not necessarily consented to anything, and would not be the only person identifiable in the output. The same problem shows up in any professional setting where a file names people who never chose to be there, which is why the real test is whether the disclosure itself is the event rather than whether anything went wrong afterwards.

The asymmetry that makes this different from a shop

If a retailer mishandles your email address you can shop elsewhere. If a housing authority mishandles the file that says why you were given medical priority, there is no elsewhere. That asymmetry is why the Government’s own guidance is more cautious for the public service than the market is for everyone else, and why the ceiling on fines is not the interesting part of the risk.

What the public already thinks about this

The Central Statistics Office ran the OECD Trust Survey in Ireland in 2025 and asked people how confident they were that government agencies could use AI while protecting personal information from unauthorised access or misuse. Almost three quarters were not confident. Only 15% said they were.

15%
of people in Ireland were confident government agencies can use AI while protecting their personal information. OECD Trust Survey 2025, run by the CSO

On the broader question of using AI to deliver more personalised services or cost reductions, around half gave a confidence rating below 5 on a scale of 0 to 10, and a third gave 6 or more. So the scepticism is specifically about data, not about AI in general, which is a useful thing to know before writing the part of any policy the public will see.

Not confident, below 5 out of 10about half
Confident, 6 or more out of 10a third
Confident on protecting personal data15%
Confidence in government agencies' use of AI. OECD Trust Survey 2025, run by the CSO

Read the two together and the public position is coherent rather than hostile. People are open to a council using AI to work faster. They do not believe the council can keep their file safe while doing it. A policy that answers only the first half is answering the question nobody asked.

What one council’s own rules say, and who they leave out

Dublin City Council’s guidelines for staff say that the use of free and publicly accessible generative AI tools “present a significant risk for organisations”, because of the absence of effective safeguards for data privacy and safety. The rule that follows is blunt: public generative AI models are not to be used for business purposes, and any tool implemented must be enterprise approved.

South Dublin County Council has an AI policy for staff that also prohibits free or public generative AI tools. Dún Laoghaire Rathdown has a corporate AI policy approved in 2025 that includes which tools staff may use and prohibits entering sensitive or confidential information into public AI systems, plus an internal awareness programme.

The gap that is not an oversight

None of these policies applies to councillors. Dublin City Council’s generative AI guidelines cover staff, and elected members have their own ethical guidelines, which deal with behaviour and donations rather than work practices. South Dublin County Council put it plainly to the Dublin Inquirer: it does not dictate to councillors which AI they may use, and has no role in doing so.

That is constitutionally tidy and operationally awkward, because councillors handle exactly the material the staff policy exists to protect. A representation about a rent arrears case contains a named tenant, an address and a reason.

What the councillor training actually said

In February 2026 Dublin City Council circulated a training webinar run by the Association of Irish Local Government on using the free version of ChatGPT for press releases, social media and speaking points. The Association’s head of operations and member services said councillors were explicitly advised not to use such tools for personal data, confidential information or any material relating to internal local authority systems or decision making.

That advice is correct, and it is the whole policy in one sentence. The difficulty is that it arrives as advice to individuals rather than as a rule with a tool behind it, which is the same difficulty every organisation has with staff putting client information into a chatbot.

The law: the GDPR, the Data Protection Act 2018 and the DPC

Start here rather than with the AI Act, because this is the law that applies to a council’s AI use today and will decide most of the arguments. It is also the law that settles which assistants a council may use, and the criteria it applies to each one are the same for a council as for a practice.

A local authority is a controller. When a staff member types a resident’s details into a chat tool run by another company, the council is disclosing personal data to a processor or to another controller, depending on the terms, and it needs a lawful basis, a record, and an answer to what happens next.

The Data Protection Commission’s own note on AI puts the test in a single question: if someone asks for access to their personal data, or asks you to delete it, and it is inside the AI system, can you do it?

The assessment that comes before any of this

Article 35 of the GDPR requires a data protection impact assessment where processing is likely to result in a high risk to people’s rights and freedoms. For a council, two of the triggers named in Article 35(3) itself are close to routine: processing special category data on a large scale, and systematic and extensive evaluation of personal aspects by automated means where decisions follow from it.

That assessment is work most councils already know how to do rather than something the AI Act invented, and Article 27(4) of the AI Act lets the later fundamental rights assessment refer back to it. Doing the data protection assessment properly in 2026 makes the 2027 obligation substantially cheaper.

The order matters more than the paperwork. Decide the lawful basis, then the assessment, then the tool. Doing it the other way round produces a procurement that has to be justified backwards, which is the position several organisations found themselves in after staff had already started using a consumer chat tool on real files.

Two ceilings of the same size, from two different laws

lawwho decidesceiling for a public body
GDPR, via the Data Protection Act 2018Data Protection Commission€1,000,000, section 141(4)
EU AI Act, via the 2026 Actan adjudicator, confirmed by the High Court€1,000,000, section 105(5)(a)

Section 105(5)(a) borrows its definition of public body from section 10 of the Data Sharing and Governance Act 2019, which names a local authority at subsection (1)(i).

€1,000,000
the ceiling on an administrative fine against an Irish public body, under both the Data Protection Act 2018 and the Regulation of Artificial Intelligence Act 2026

The cap is worth putting in perspective rather than in a business case. A fine running to seven figures against a council is a headline, a Local Government Audit Service question and a council meeting, and none of those are priced in euro. The reputational cost of a badly handled resident file arrives long before any regulator does.

Why the DPC is the regulator to plan around

Under S.I. No. 405 of 2026 the Data Protection Commission is the market surveillance authority for Annex III points 1, 6, 7 and 8 of the AI Act, and for most points of Article 5. It is also, separately, the supervisory authority for data protection. For a council, that means one office can look at the same deployment through two statutes.

The public service guidelines add two triggers worth remembering. Where processing entails legislative change there is a mandatory consultation with the Data Protection Commission and a legislative consultation form to complete. And where a proposal involves special categories of data, the guidance advises contacting the DPC before starting.

What the AI Act asks of local authorities, and when

Most of what the EU AI Act asks of a council is the same as what it asks of a business, and we have set that out in the guide to what the EU AI Act means for an Irish organisation. Three things are different for a public body.

Article 27, and the phrase that names you

Article 27 requires a fundamental rights impact assessment before deploying an Annex III high-risk AI system. It names, as the deployers who must do it, bodies governed by public law and private entities providing public services. A local authority is the first of those, and a contractor running a service for one is the second.

The assessment has six prescribed contents: a description of your processes, the period and frequency of use, the categories of people likely to be affected, the specific risks of harm to them, how human oversight will actually be implemented, and what you will do if the risks materialise.

Two practical details soften it. Article 27(4) lets you refer back to a data protection impact assessment done under Article 35 of the GDPR rather than writing everything twice. And Article 27(3) requires you to notify the market surveillance authority of the results, on a template the AI Office is to develop.

the council useAnnex III pointthe Irish authority named for it
Recruitment and staff decisionspoint 4Workplace Relations Commission
Housing supports and eligibilitypoint 5(a)none named, so the general designation applies
Emergency call triage and dispatchpoint 5(d)Health Service Executive, but only for public emergency healthcare
Access to essential healthcarepoint 5(a), in partHealth Service Executive

Source: S.I. No. 405 of 2026, Schedule 2, read against Annex III of Regulation (EU) 2024/1689.

The date, which moved

Article 27 applies from 2 December 2027, along with the rest of the Annex III high-risk regime, after Regulation (EU) 2026/1744 deferred it. That is not a reason to stop, because a system procured in 2026 will still be running then and the assessment covers first use.

2 February 2025the Article 5 bans, already in force
2 August 2026Article 50 transparency, already in force
2 December 2027Article 27 and the high-risk duties
The three dates that matter to a council. Article 113 of Regulation (EU) 2024/1689 as amended

Two of those three dates have already passed, which is the part that gets lost when the conversation turns to 2027. The bans and the transparency duty are live now. The high-risk paperwork is the only piece still in the future, and it is the piece that needs the longest lead time.

The corner with no named regulator

S.I. No. 405 of 2026 names a market surveillance authority for each area of Annex III, but Schedule 2 covers point 5(a) only insofar as it relates to access to essential public healthcare services and benefits, where the authority is the Health Service Executive.

A local authority using AI in a decision about housing supports is in point 5(a) and outside that exception. No sectoral body is named for it. What covers it is the general designation in Regulation 4(4), which makes Oifig IS na hÉireann a market surveillance authority for the purposes of Article 70(1). The practical reading is that the AI Office is where a housing AI question lands, and that the Department has said further legislation follows in the autumn.

Ireland’s official guidance for the public service

The document to read is the Guidelines for the Responsible Use of AI in the Public Service, published by the Department of Public Expenditure, Infrastructure, Public Service Reform and Digitalisation on 7 May 2025 and last updated on 31 October 2025. It runs to 84 pages and it is written for public servants rather than for lawyers.

It sets out seven principles, a decision framework for working out whether AI is the right answer at all, a Responsible AI Canvas for the planning stage, and lifecycle guidance.

the seven principles
human agency and oversighttransparency
technical robustness and safetydiversity, non discrimination and fairness
privacy and data governancesocietal and environmental well being
accountability

Guidelines for the Responsible Use of AI in the Public Service, section 4.

The three sentences that decide most real cases are these.

AI tools can assist human capabilities, but they should never replace them.

Where AI is used as a tool in a decision making process in a high risk context, a human must make the final decision.

Guidelines for the Responsible Use of AI in the Public Service

The worked example that is exactly a council chatbot

The guidelines take a public service body implementing a chatbot powered by AI to answer queries from the public, classify it as limited risk under the EU AI Act, and conclude that the body must ensure people are notified they are interacting with an AI system. The reason given is that the public has a right to know so they can judge the interaction appropriately.

That is Article 50(1) arriving through the front door, and it has been legally binding since 2 August 2026 rather than merely advisable. If your authority has a chatbot on its website, this is the one duty to check today.

The question the framework asks first

Before any of the risk classification, the decision framework asks whether AI is the best solution at all. It then asks what type of AI solution fits, and it has a separate section on using free, enterprise or licensed offerings, which is the question every council is actually deciding.

That ordering is deliberate and it is worth copying. A surprising share of council AI projects are automation projects with a chat interface bolted on, and they would be cheaper, more auditable and more explainable as ordinary software. The framework gives a public servant permission to say so, which is the most useful thing in the document.

The counterpart to that question is what the vendors do with the text once you have decided, and that is an answer for each product rather than a general one. Our guide to what Microsoft Copilot does with your data covers the product most Irish councils have licensed.

Where the guidance is stricter than the law

On legal basis, the guidelines are notably cautious. They say consent could be used where the risk is low, such as for a chatbot, and that processing with a high risk, involving profiling of individuals on a large scale for a task carried out in the public interest, may require a specific legislative mandate under primary legislation or regulations.

That is a higher bar than most private sector advice, and it is the right one for a council, because the lawful basis a local authority relies on is usually a public task rather than consent, and a public task has to come from somewhere.

The NCSC, and the document that was deprecated in July

This is the trap in the current paperwork, and it is easy to walk into. The public service guidelines quote the National Cyber Security Centre’s recommendation that access to generative AI tools be restricted by default and allowed only as an exception on an approved business case, with no staff use until risk assessments, usage policies and awareness programmes are in place.

That recommendation comes from the NCSC’s Cyber Security Guidance on Generative AI for Public Sector Bodies of 1 June 2023. That document was marked deprecated on 30 July 2026. The guidelines that cite it were last updated on 31 October 2025, so the footnote still points at it.

30 July 2026
the date the NCSC's 2023 generative AI guidance was marked deprecated, while the guidelines that cite it still point at it

The substance of the recommendation has not been reversed, so a council that restricted access on the strength of it was not misled. What has changed is the document you should be citing in a policy written today, and the fact that the old one now carries a deprecation notice on its first page.

What replaced it

documentwhat it is for
2026 NCSC AI Cyber Security Risk Assessment: Public Sector Deploymentthe threat picture and the risks, to be read first
Securing AI Adoption in the Public Sectorseven principles across five lifecycle phases, the operational companion

Both published by NCSC-IE in 2026 and available at ncsc.gov.ie.

None of this removes the underlying problem, which is that guidance ages faster than the documents that cite it. That is an argument for linking to primary sources and dating every claim, and it matters just as much when working out what the EU AI Act asks of an Irish organisation.

The guidelines document is aimed at chief information officers and senior managers, and says explicitly that it is designed to be flexible and accessible to smaller public sector bodies without specialist AI security capability. That description fits most of the 31 local authorities better than it fits a government department.

The survey finding, and the caveat nobody quotes

The risk assessment includes a survey. It is worth knowing its size before quoting it: the link went to 77 individuals, the response rate was 16%, and the 12 respondents represented eight government departments and four agencies.

77invited to the NCSC survey
12responded
0local authorities named among them
NCSC-IE, 2026 AI Cyber Security Risk Assessment, Annex II

No local authority is named among them. So the one Irish public sector survey of AI security maturity does not describe local government, and anyone who tells you it does has not read Annex II. Its findings are still the best available: three quarters of respondents had policies and some basic security controls, data quality and data protection were the top two challenges, and access to staff with the necessary skills was third.

The finding that does transfer

The assessment found that in half of responding organisations, large language models hosted in the cloud are available only to a subset of users, and described this as a gap between sanctioned and unsanctioned use that increases shadow AI exposure. A council that has bought a limited number of Copilot licences for a workforce of hundreds has created exactly that gap on purpose, which is defensible only if it is paired with a rule about what everyone else may do.

Which tools, which accounts, and why a licence is not a control

A licence is only one control, and it works on exactly one axis: what the vendor may do with the text after it arrives. Everything else is still yours.

The four products most councils will be choosing between behave differently, and the differences are in their own documentation rather than in anyone’s marketing. We have gone through them one at a time for ChatGPT, Claude, Gemini and Copilot.

what a licence changeswhat it does not change
whether your text trains the vendor’s modelwhether you had a lawful basis to disclose it
retention periods and deletion commitmentswhether you can answer an access request about it
where processing happens, and under what termswhether a human made the final decision
who you can hold to a contractwhether the resident was told

The left column is the vendor’s. The right column stays with the council whichever product it buys.

The account, not the product

The single most common configuration error is signing in with the wrong account. The same brand name can be a consumer service with consumer terms or an enterprise service with organisational commitments, depending on which credentials were used, and a staff member who signs in with a personal account is outside every protection the council paid for.

The NCSC guidelines address this directly, recommending discovery across the tenant for unsanctioned AI tool use, reviewed monthly, and a verified monthly check that the setting that opts out of model training has not been reset.

The staff policy: what it has to say to be worth writing

Most council AI policies fail in the same way. They say what staff must not do, and stop. A policy that names no approved route is a policy that guarantees the unapproved one.

  1. Which tools are approved, by name and by account type. Not a category. A list.
  2. What may never go in, by example. A resident’s name, address, Eircode, PPS number, case or tenancy reference, arrears figures, social work notes, medical priority, planning objections.
  3. Who may decide an exception, and how it is recorded. One named role, one line of reasoning per decision.
  4. What to do when it goes wrong. Who to tell, in what hour, and the fact that telling is not a disciplinary matter.
  5. The training record. Dates, names, tools covered, and the version of the policy people saw.
what most council policies saywhat a usable one says instead
do not enter confidential informationdo not enter a name, an address, an Eircode or a rent account number
use approved toolsCopilot, signed in with your work account, and nothing else
be careful with AI outputscheck every figure and date against the file before it goes out
report any incidenttell the data protection officer the same day, and you will not be disciplined for telling

Nothing in the left column is wrong, but none of it is actionable at 4pm on a Friday.

Why the list of examples earns its place

Because abstraction fails. A staff member who has read that confidential information must not be entered will still paste a complaint email, because the email does not feel confidential. A list that names arrears figures and social work notes does not have that problem. The free AI use policy template we publish is a starting point you can adapt rather than a document to adopt unchanged.

The training obligation is already live

Article 4 of the EU AI Act, in force since 2 February 2025 and amended in July 2026, requires providers and deployers to take measures to support AI literacy among staff and others operating AI systems on their behalf. It does not require certifying anyone. The NCSC guidelines go further for the public sector and ask whether AI literacy training is required before access is granted.

What to ask a supplier in a public procurement

Public procurement is slow, which for once is an advantage: it means the questions get asked before the contract, which is the only time the answers are cheap.

  1. Are you the provider, and are we the deployer? In writing, with the Article numbers.
  2. Is any part of this in Annex III, and which point? A supplier who cannot classify its own product has not read the Regulation.
  3. What will you hand us for Article 27? Deployers need the provider’s information under Article 13 to do the assessment at all.
  4. Where is the processing, who are the subprocessors, and what is the model provider? The chain is where the surprises live.
  5. Can you support a deletion request that reaches into the system? This is the DPC’s question, and it is the one that fails.
  6. What happens at the end? Export, deletion, and what happens to anything derived from our data.

The two questions that are specific to a council

The first is what happens to the system if the service is brought back in house or moved to a different provider, because a council’s obligations to its residents outlive its contracts. The second is whether the supplier will accept being named in a fundamental rights impact assessment that goes to a regulator.

Both are cheap to ask before signature and impossible to add afterwards. They also tell you something the technical answers do not, which is whether the supplier has read the public sector half of the Regulation or only the commercial half.

A third question is worth asking even though it is not about AI at all: whether the arrangement is covered by the authority’s cyber insurance, and on what terms. We have set out what Irish cyber policies actually say in the guide to cyber cover and how to compare it.

The answer that should worry you

It is not a refusal that should worry you. A supplier who says a system is not high-risk and explains why is more useful than one who claims to be fully AI Act compliant, because there is no such thing as a compliant product in the abstract. Compliance attaches to a deployment, and at least half of it belongs to the council.

The NCSC guidelines ask the procurement question in the same spirit: whether the evaluation considers the vendor’s own supply chain, including the underlying model provider and any subprocessor.

When a resident asks: transparency, access and the file

At some point somebody will ask whether a machine was involved in a decision about them. The answer has to be ready before the question, because three separate regimes point at it.

what they can askunder what
Was I dealing with an AI system?Article 50(1) of the EU AI Act, since 2 August 2026
What personal data do you hold about me?Article 15 of the GDPR
What records exist about this decision?the Freedom of Information Act 2014

Local authorities are FOI bodies: section 6(1)(b) of the 2014 Act covers entities established by or under an enactment, and a local authority is established under the Local Government Act 2001.

The one that catches councils out

The freedom of information route, because it reaches records the access request does not. A prompt is a record. So is the output that a staff member pasted into a case note, and so is the email thread in which two officers discussed whether to trust it.

If AI was used in the handling of a case and nothing in the file says so, the file is incomplete, and that is a records problem before it is an AI problem. It is also the point at which a council discovers whether it can actually answer the access and deletion question the DPC asks.

The cleanest fix is a one line convention: when AI assisted with a document, the file says which tool, on what date, and who checked the output.

Human oversight is not a formality here

The public service guidelines require that all AI tools used in the public service be part of a process with human oversight built in, and that where AI is used in a high-risk decision, a human makes the final decision. For a council, that is the difference between a decision a person can appeal and a decision nobody can explain, not a governance nicety.

A worked example: answering a complaint without letting the resident out of the building

Take an ordinary Tuesday. A complaint arrives about repeated missed bin collections at a named address, copied to a councillor, with a tone that needs a careful reply.

What people actually do

They paste the whole email into a chat tool and ask for a polite response. In one action, the resident’s name, their address, their Eircode, the councillor’s name and the substance of their complaint have left the building. The output is usually good. The disclosure already happened.

What the same job looks like done properly

  1. Strip the identifiers before the text leaves the machine. Name, address, Eircode, account reference, and the councillor’s name.
  2. Ask for the shape, not the answer. A structure for a reply about a missed collection, an apology, a remedy and a timeline.
  3. Write the specifics yourself. The dates, the route, the remedy and the commitment come from your systems, not from a model.
  4. Check it against the file. The guidelines’ own point about generative models drawing on sources that are unreliable or no longer current applies to your own service information too.
  5. Record it. Which tool, what date, who checked it.
what the file should recordexample
which toolCopilot, work account
what it was asked forstructure for a reply about a missed collection
what it was not giventhe resident’s name, address and Eircode
who checked the outputthe officer who signed the reply

A convention of this kind costs one line per document and answers both an access request and a freedom of information request.

Getting the first row right depends on knowing what the tool does with what it receives, which is a per product question rather than a general one. Our guides to ChatGPT and Claude go through the vendors’ own documents.

A shorter version of the same rule

If you would not read the sentence aloud in the lift, it should not be in the prompt. That heuristic gets staff most of the way there, and it survives the arrival of the next tool, which is more than most policies manage.

What a tool solves, and what no tool solves

Nonimo is a Mac and Windows app that sits between the person and the chat window. It finds names, addresses, emails, phone numbers, dates of birth, company names, card numbers and IBANs in the text you are about to send, and replaces them with markers such as [PERSON_1] and [ADDRESS_1] before the text leaves the machine. On Irish paperwork it lifts out PPS numbers, Eircodes and Revenue references, and leaves placeholders behind.

It pseudonymises and does not anonymise: the mapping stays encrypted on the user’s machine, so the reply can be put back into real names, and the text stays personal data for the council. What the app keeps is on our security page.

What no tool solves is the lawful basis, the human oversight and the decision about whether AI belongs in that process at all. A tool changes what is in the payload; in a local authority the decision always rests with a person with a name.

If your authority is working through the Act rather than the data, our guide to the EU AI Act in Ireland covers it. If the question arrived from your insurer or your broker rather than from a regulator, cyber cover in Ireland and the AI questions on a cyber questionnaire cover that side. The version of the tool for a whole organisation is on the organisations page.

Sources

Common questions

Can council staff in Ireland use ChatGPT at work?

It depends on your authority, and in Dublin the answer is no. Dublin City Council's staff guidelines prohibit free, publicly available generative AI for council work and require tools that are enterprise approved. South Dublin County Council has a similar policy. Check your own before assuming.

Do the Government's AI guidelines apply to local authorities?

They are written for the public service as a whole and local authorities are part of it. The Guidelines for the Responsible Use of AI in the Public Service were published on 7 May 2025 by the Department of Public Expenditure and last updated on 31 October 2025.

What is a fundamental rights impact assessment, and does my council need one?

It is the Article 27 assessment that deployers who are bodies governed by public law must carry out before using an Annex III high-risk AI system. A local authority is such a body. The obligation applies from 2 December 2027.

Can a council be fined for breaching the AI Act in Ireland?

Yes, but the ceiling is lower than for a company. Section 105(5)(a) of the Regulation of Artificial Intelligence Act 2026 caps an administrative fine on a public body at €1,000,000. Section 141(4) of the Data Protection Act 2018 sets the same ceiling for GDPR fines.

Do councillors have to follow the council's AI policy?

Generally not. Dublin City Council's generative AI guidelines apply to staff, not to elected members, and South Dublin County Council has said it has no role in dictating which AI councillors use. Councillors have separate ethical guidelines that do not cover work practices.

Does a council chatbot have to say it is AI?

Yes, since 2 August 2026 under Article 50 of the EU AI Act, unless it would be obvious to a reasonably observant person. The Government's own public service guidelines use a chatbot run by a public body as their worked example of this duty.

Which regulator supervises AI use by an Irish local authority?

It depends on the use. The Data Protection Commission covers most of Article 5 and several Annex III areas, the Workplace Relations Commission covers employment uses, and Oifig IS na hÉireann holds the general Article 70(1) designation and coordinates the rest.

What should a council never put into a public AI tool?

Anything that identifies a resident. Names, addresses, Eircodes, PPS numbers, case references, tenancy and rent account details, social work notes, planning objections and complaint correspondence. The AILG told councillors the same thing about personal and confidential material.

Is a Copilot licence enough to make AI use lawful in a council?

No. A licence changes what the vendor may do with the text, which is one control out of several. It does not carry out a data protection impact assessment, decide a lawful basis, provide human oversight or answer a resident's access request.

Does the NCSC have guidance on AI for the public sector?

Yes, and it changed in 2026. The 2023 generative AI guidance was marked deprecated on 30 July 2026 and replaced by two documents, an AI cyber security risk assessment and a set of guidelines for AI deployments, both published in 2026.