GDPR, NIS2, the EU AI Act and DORA — answered for your organisation in plain English: which apply, which obligations matter most, and the first steps, each linked to the text of the law. A compliance support tool, not legal advice.
Find out in 5 minutes — free. No credit card, no consultant fees, no jargon.
No credit card required • Results in 5 minutes • EU data residency • Assessments free
Multiple regulations converging in 2026. Irish businesses face unprecedented compliance burden.
Penalties are set per regulation and per breach, and most organisations are nowhere near the maximums. What matters is which obligations apply to you — that is what the assessment answers.
Start free in 5 minutes. Know exactly where you stand.
For Irish businesses & tech companies
For banks, credit unions & insurers
Why most Irish SMEs can't afford the traditional approach.
| Feature | GuardAI | Compliance Consultant |
|---|---|---|
| Initial gap assessment | About 10 minutes | Scoped per engagement |
| Cost | Free (paid plans from €29/mo at launch) | Quoted per engagement |
| GDPR + NIS2 + AI Act + DORA | ✅ All covered | Typically one specialism |
| Available 24/7 | ✅ Always on | ❌ Business hours only |
| Instant action plan | ✅ Immediate | Weeks of consulting |
| No extra charge for new regulations | ✅ Included | ❌ New engagement required |
| Irish-specific guidance | ✅ DPC, CBI aligned | Depends on firm |
| Re-run as you close gaps | ✅ Unlimited, free | New engagement each time |
No credit card · Results in 5 minutes · EU data residency
Built on the regulation texts — not marketing claims.
The free assessment maps your answers against the actual regulation texts — NIS2's 10 risk-management measures, DORA's five pillars, GDPR's core articles — and shows every gap with the article it comes from.
The assessment is free and takes about 10 minutes. It tells you which frameworks apply, the obligations that matter most for you, and the first steps — each linked to the regulation text.
No fake reviews here — we don't publish testimonials we can't verify. Run the free assessment on your own business and judge the output yourself.
No legal expertise required. Plain-English questions mapped directly to the regulation texts.
Answer plain-English questions mapped to GDPR, NIS2, AI Act or DORA requirements.
Get your compliance score (0–100%) with gap analysis. See exactly where you are vulnerable.
Every gap ranked by severity with the requirement it comes from — re-run free as you close them.
Last reviewed 25 September 2026. GuardAI is a compliance support tool, not legal advice — check the source, and take advice for decisions that carry legal risk.
Applies: 25 May 2018 · Maximum: Up to €20m or 4% of worldwide annual turnover, whichever is higher
Applies: Transposition deadline 17 October 2024 · Maximum: Essential entities: at least €10m or 2% of turnover; important entities: at least €7m or 1.4% (maximums set by national law)
Applies: Prohibitions 2 February 2025; GPAI 2 August 2025; high-risk 2 December 2027 / 2 August 2028 · Maximum: Prohibited practices: up to €35m or 7% of worldwide turnover
Applies: 17 January 2025 · Maximum: Set nationally. In Ireland the Central Bank can impose up to €10m or 10% of annual turnover
NIS2 applies to Irish businesses in 18 essential and important sectors with 50+ employees or €10M+ turnover — including IT services, healthcare, energy, transport, and digital infrastructure. The NCSC estimates around 3,500 Irish entities will be in scope, up from roughly 120 under the original NIS Directive.
The EU transposition deadline was 17 October 2024. Ireland has not yet enacted its law (the National Cyber Security Bill), and on 8 July 2026 the European Commission referred Ireland to the EU Court of Justice for incomplete transposition. Once in force, fines for essential entities reach at least €10 million or 2% of worldwide turnover (€7 million or 1.4% for important entities), and management bodies must approve and oversee cybersecurity measures. In-scope organisations are already being asked for NIS2-level controls by customers and insurers.
Approximately 5 minutes. You answer plain-English questions about your business and instantly get your compliance score with a prioritised action plan.
Yes. All GuardAI data is processed and stored within the EU, fully compliant with GDPR data transfer restrictions.
GDPR focuses on personal data protection and applies to almost all businesses. NIS2 is a cybersecurity directive requiring risk management, incident reporting, and resilience measures in critical sectors. Most Irish businesses will need to comply with both.
DORA has applied since 17 January 2025. NIS2 is EU law already; Ireland's transposing Act is overdue.
Free to start • No credit card required • EU data residency
Free Resource
The 10 NIS2 risk-management measures explained in plain English. Plus GDPR quick-wins for Irish SMEs. No spam.
Unsubscribe anytime. EU data residency. GDPR compliant.
Picked for what you just worked out — not a list of everything we make.