AI Regulation Tracker / Financial supervision
Central Bank of Ireland Names AI a Core Supervisory Risk for 2026
Not a new rule, but a signal boards should read carefully. In its February 2026 Regulatory and Supervisory Outlook, the Central Bank of Ireland lists data, modelling, and AI among its priority risk themes and devotes a dedicated Spotlight to supervising AI, pointing firms back to explainability, accountability, and model governance.
Supervisory outlook reports do not make headlines the way a fine or a new regulation does, and that is exactly why professionals miss them. They are the clearest signal a regulator gives about where it is going to look next. The Central Bank of Ireland published its Regulatory and Supervisory Outlook for 2026 in February, and it put artificial intelligence front and centre, both as a named priority risk theme and as one of three dedicated Spotlight chapters. When a supervisor spends that much space on a topic, it is telling you where the questions will come from.
Read what the Central Bank actually says about AI as a risk, because it is measured, not alarmist. In its own words, "widespread adoption of third-party AI tools changes the risk landscape and calls for stronger model governance, data quality, transparency and accountability." That single sentence carries the operational load. The concern is not that firms use AI. It is that they buy AI tools from third parties and bolt them into decision-making without the governance, data discipline, and transparency to stand behind them.
What does the Central Bank expect boards to do?
The through-line of the Spotlight is that the fundamentals still apply, and boards are on the hook for them. The Central Bank puts it plainly: "A focus on the core principles of explainability, accountability, good governance and strong risk management is essential." Those four words are the test. Explainability means you can describe how an AI-influenced decision is reached. Accountability means a named human, ultimately the board and senior management, owns the outcome. Good governance means AI sits inside your existing risk framework rather than in a shadow process. Strong risk management means you are actively monitoring model performance, not trusting it because it worked in a demo. The Central Bank also flags that the safeguards built into providers' models "can be brittle," and it singles out agentic AI as a frontier risk that needs close monitoring.
Is this a new binding rule?
No, and it is worth being precise. The Outlook is a statement of supervisory priorities, not a regulation. It does not create a fresh legal obligation on its own. The Central Bank is explicit that "many of the risks associated with AI are not new and are already covered by existing regulations and standards, with the AI Act representing a targeted addition to the operating framework." In other words, the supervisor is not inventing a new AI rulebook. It is telling firms that their existing duties around governance, risk, and outsourcing already reach their AI use, and that the EU AI Act layers on top. Ireland has designated the Central Bank as a financial-sector regulator under the AI Act, so this Outlook is the supervisor setting expectations ahead of that regime biting.
What should executives and boards do now?
Treat the Outlook as advance notice of the questions supervisors will ask, and get ahead of them. Inventory where AI, including third-party tools, touches decisions in credit, fraud detection, investment, pricing, or consumer interactions. For each material use, be able to show who owns it, how it is governed, how its performance is monitored, and how a decision could be explained to a customer or a supervisor. Do not leave AI in a shadow process outside your risk framework, because the Central Bank's whole point is that it belongs inside it. If you run a group with an Irish-regulated entity, assume the Central Bank's approach previews what other European supervisors are doing, and align once rather than scrambling per-jurisdiction. None of this is compelled by the Outlook alone, but the direction is unambiguous, and demonstrable governance is far cheaper to build before a supervisory review than during one.
Questions professionals are asking
Does the Central Bank's Outlook create a new AI rule?
No. The Regulatory and Supervisory Outlook 2026, published February 2026, is a statement of supervisory priorities, not a regulation. It does not create a fresh legal obligation on its own. The Central Bank says many AI risks are already covered by existing regulation, with the EU AI Act as a targeted addition. Its force comes from signalling where supervisory engagement will focus.
What is the Central Bank asking boards to demonstrate?
Ownership and control of AI risk. The report stresses explainability, accountability, good governance, and strong risk management as the core principles. In practice that means a firm can explain how AI-influenced decisions are reached, name the humans accountable, keep AI inside its existing risk framework, and actively monitor model performance rather than trusting a tool because it once worked well.
Why does the report focus on third-party and agentic AI?
Because that is where the Central Bank sees rising risk. It says widespread adoption of third-party AI tools changes the risk landscape and calls for stronger model governance, data quality, transparency, and accountability, and it warns that safeguards built into providers' models can be brittle. It singles out agentic AI as a frontier risk needing close monitoring by firms and regulators.
Does this matter for US or international groups?
Yes, if the group has an entity supervised by the Central Bank of Ireland. That entity is directly in scope, and Ireland has designated the Central Bank as a financial-sector regulator under the EU AI Act. The Outlook also previews the direction European supervisors are taking, so international groups should align AI governance once rather than treating Ireland as an isolated case.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any supervisory expectation applies to your firm with qualified financial-services counsel in the relevant jurisdiction.