Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
whitepaper

Agentic Systems Under Regulation.

Search every annex of the EU AI Act for an agent and you will find nothing. Teams read that silence as headroom, and it is the reverse. An agent inherits duties from the interface it speaks through, the decision it influences, the model it plans with and the action it finally takes, all at once, from instruments drafted before anything like it existed. Then comes the awkward part. Assemble a planner you did not train, three suppliers' tools and your own memory store, and no single party obviously holds the conformity file for the thing you just shipped.

In depth

No Rulebook Named Your Agent, And Four Regimes Reached It Anyway.

01

Silence in the annexes is an absence of tailored rules, not an exemption.

Article 5 prohibitions have bound conduct since February 2025, general-purpose model duties since August 2025, Article 50 transparency since August 2026, and GDPR and sector law never stopped applying to anything an agent touches. A programme waiting for an agentic rulebook is not ahead of the market, it is running live and unassessed under four instruments that already apply.

In shortA programme waiting for an agentic rulebook is not a…
02

Autonomy classifies nothing, and the annex test never asks about it.

Annex III follows the decision the agent influences, so a wholly autonomous agent booking meeting rooms carries light duties while a single-step assistant that ranks job applicants sits inside the high-risk set from 2 December 2027. Widen a tool catalogue after launch and an agent can move into a regulated class without a line of the planner changing. Run the test on the decision, then again on every tool, and record the result per agent with a date and a name against it.

In shortRun the test on the decision, then again on every to…
03

The provider role is where the drafting genuinely breaks.

The Act allocates duties to roles that assume one system with one maker, and an agent is a supply chain wearing a single name. Ask who provides a system whose planner runs on a frontier model you did not train, whose tools come from three suppliers and whose actions land in your customers' accounts, and four defensible answers come back. Change intended purpose or performance far enough and you become the provider, and the system prompt, the tool catalogue and the memory are precisely the work that changes what the model underneath does. In practice, whoever integrates is whoever ends up holding the file.

In shortwhoever integrates is whoever ends up holding the file
The detail

Three Duties That Agents Fail For Reasons No Other System Has.

None of these is an obscure provision, and each is a duty most teams believe they already satisfy. They fail on an agent for reasons particular to a system that plans, calls tools and acts in the gap between the question and the answer.

Zone · 01

Disclosure on every channel

Article 50 wants a person told clearly, at the point of first interaction. The notice goes on the web widget where the pilot launched, then the same agent starts answering email, posting into shared channels and handing off to a colleague who never announces the switch back. Each of those is a first interaction, and provenance marking that is stripped on export satisfies nobody.

Zone · 02

Logs of the plan

Record-keeping assumes the record explains the behaviour, and for an agent the output explains almost nothing. What matters sits upstream: the goal it was given, the goal it derived, the calls it made with which arguments, what came back, and which step changed its mind. Goal hijack and memory poisoning, ASI01 and ASI06, are invisible in an output log by construction.

Zone · 03

A stop that holds

Article 14 expects a person who can intervene, interrupt or halt, and most oversight designs approve a plan at the start and inspect a result at the end. That supervises nothing in the middle, which is where an agent does all of its work. A real stop is a revoked token, a drained queue, in-flight calls cancelled and partial side effects reconciled.

By the numbers

The figures that make it a board-level conversation.

0
agentic categories in any annex of the EU AI Act, and no autonomy threshold anywhere in it
2 Aug 2026
Article 50 transparency became applicable to agents that talk to people, and was not delayed
<50%
of organisations actively secure the non-human identities an agent acts through
Inside the report

What you'll take away.

01

Step 1 - Write down which routes reach each agent

The interface it speaks through, the decision it influences, the model underneath and the action it takes. Dated, signed, and re-run whenever a goal or a tool catalogue changes.

02

Step 2 - Settle the provider question in writing

Map every model, tool and connector to a named legal counterparty and a named internal owner. Then decide which role you hold for the assembled system, since no supplier clause reassigns a statutory one.

03

Step 3 - Trace the plan, not just the final message

Goal given, goal derived, every tool call with its arguments and its result, every memory write. It is the only record that shows why an agent acted, and it has to be running before anyone asks.

04

Step 4 - Give each agent a stable versioned identity

Agents act through service accounts and API keys that rotate, breaking the chain from a logged action back to an accountable actor. Attribute to the agent, version it, keep the mapping.

Questions

Frequently asked.

Is there an agentic category in the EU AI Act?

No. No annex contains one, nothing in force regulates autonomy as such, and no threshold turns a planning loop into a regulated object. Duties reach an agent through routes that already existed: the interface it speaks through, the decision it influences, the model it plans with, and the action it takes.

If autonomy does not classify a system, what does?

The decision does. Annex III asks what the system is for, not how freely it acts, so an agent scheduling meeting rooms carries little while one screening job applicants carries the full high-risk set from 2 December 2027. Run the same test on each tool, since a wider catalogue can change the answer without any code changing.

Who is the provider when an agent is assembled from four suppliers?

Whoever put it on the market under their own name, which in practice is usually the integrator. Your model provider carries Articles 51 to 56 for the model and disowns your prompt, your tools and your goal. Modify intended purpose or performance far enough and you become a provider in turn, and building an agent is exactly that kind of modification.

Do our supplier contracts move these duties to the vendor?

They allocate liability between commercial parties and nothing more. A statutory role is not reassignable by clause, and no term makes a regulator or a data subject your model vendor's problem. Agentic supply chain exposure sits at ASI04 on the OWASP list for the same reason. Name a counterparty and an internal owner for every model, tool and connector.

What should we switch on first?

Plan-level tracing and a stable agent identity, ahead of everything else, because both are retrospective and cover only the period they have been running. Add Article 50 disclosure on every channel the agent reaches. Then screen each goal and each tool against the Article 5 prohibitions, keeping the dated result, since a derived goal counts as much as a written one.

How does this differ from your engineering reference for agents?

This paper is the obligation side: which route reaches an agent, what fires it, and the artefact that closes it. Agentic Systems: An Engineering Reference sets out the control families underneath and the artefact each one produces. Use this to work out what you owe, and that one to work out what to construct.

Who should read this report?

Whoever signs off an agent going live: heads of AI, general counsel and the CISO. It is written for people who have to say which rules reach a deployed agent, who is accountable for it, and what could be produced if an authority or a customer's assurance team asked this quarter. It skips the introduction to the technology.

Get the whitepaper

Have it emailed to you.

Drop your details and we'll send Agentic Systems Under Regulation straight to your inbox - no spam, unsubscribe anytime.

Download whitepaper
Next step

Nobody wrote a rule for your agent, and somebody still carries the file.

Bring one deployed agent and we will map the routes that already reach it, name who holds which legal role, and rank the duties you could not evidence today. Two hours with the people who would build it. SECTION 7 - FAQ - 5 to 8 questions

Book an agent review