Search every annex of the EU AI Act for an agent and you will find nothing. Teams read that silence as headroom, and it is the reverse. An agent inherits duties from the interface it speaks through, the decision it influences, the model it plans with and the action it finally takes, all at once, from instruments drafted before anything like it existed. Then comes the awkward part. Assemble a planner you did not train, three suppliers' tools and your own memory store, and no single party obviously holds the conformity file for the thing you just shipped.
None of these is an obscure provision, and each is a duty most teams believe they already satisfy. They fail on an agent for reasons particular to a system that plans, calls tools and acts in the gap between the question and the answer.
Article 50 wants a person told clearly, at the point of first interaction. The notice goes on the web widget where the pilot launched, then the same agent starts answering email, posting into shared channels and handing off to a colleague who never announces the switch back. Each of those is a first interaction, and provenance marking that is stripped on export satisfies nobody.
Record-keeping assumes the record explains the behaviour, and for an agent the output explains almost nothing. What matters sits upstream: the goal it was given, the goal it derived, the calls it made with which arguments, what came back, and which step changed its mind. Goal hijack and memory poisoning, ASI01 and ASI06, are invisible in an output log by construction.
Article 14 expects a person who can intervene, interrupt or halt, and most oversight designs approve a plan at the start and inspect a result at the end. That supervises nothing in the middle, which is where an agent does all of its work. A real stop is a revoked token, a drained queue, in-flight calls cancelled and partial side effects reconciled.
The interface it speaks through, the decision it influences, the model underneath and the action it takes. Dated, signed, and re-run whenever a goal or a tool catalogue changes.
Map every model, tool and connector to a named legal counterparty and a named internal owner. Then decide which role you hold for the assembled system, since no supplier clause reassigns a statutory one.
Goal given, goal derived, every tool call with its arguments and its result, every memory write. It is the only record that shows why an agent acted, and it has to be running before anyone asks.
Agents act through service accounts and API keys that rotate, breaking the chain from a logged action back to an accountable actor. Attribute to the agent, version it, keep the mapping.
No. No annex contains one, nothing in force regulates autonomy as such, and no threshold turns a planning loop into a regulated object. Duties reach an agent through routes that already existed: the interface it speaks through, the decision it influences, the model it plans with, and the action it takes.
The decision does. Annex III asks what the system is for, not how freely it acts, so an agent scheduling meeting rooms carries little while one screening job applicants carries the full high-risk set from 2 December 2027. Run the same test on each tool, since a wider catalogue can change the answer without any code changing.
Whoever put it on the market under their own name, which in practice is usually the integrator. Your model provider carries Articles 51 to 56 for the model and disowns your prompt, your tools and your goal. Modify intended purpose or performance far enough and you become a provider in turn, and building an agent is exactly that kind of modification.
They allocate liability between commercial parties and nothing more. A statutory role is not reassignable by clause, and no term makes a regulator or a data subject your model vendor's problem. Agentic supply chain exposure sits at ASI04 on the OWASP list for the same reason. Name a counterparty and an internal owner for every model, tool and connector.
Plan-level tracing and a stable agent identity, ahead of everything else, because both are retrospective and cover only the period they have been running. Add Article 50 disclosure on every channel the agent reaches. Then screen each goal and each tool against the Article 5 prohibitions, keeping the dated result, since a derived goal counts as much as a written one.
This paper is the obligation side: which route reaches an agent, what fires it, and the artefact that closes it. Agentic Systems: An Engineering Reference sets out the control families underneath and the artefact each one produces. Use this to work out what you owe, and that one to work out what to construct.
Whoever signs off an agent going live: heads of AI, general counsel and the CISO. It is written for people who have to say which rules reach a deployed agent, who is accountable for it, and what could be produced if an authority or a customer's assurance team asked this quarter. It skips the introduction to the technology.
Drop your details and we'll send Agentic Systems Under Regulation straight to your inbox - no spam, unsubscribe anytime.
Bring one deployed agent and we will map the routes that already reach it, name who holds which legal role, and rank the duties you could not evidence today. Two hours with the people who would build it. SECTION 7 - FAQ - 5 to 8 questions
Book an agent review