The AI studio of SIGOO GmbH Since 2012 EU AI Act Art. 26 aligned Made in Germany
All insights
AI Governance

What the EU AI Act Means If You Use AI Agents

Jun 8, 2026 · 9 min read · DreamSoft AI

This post is informational only and does not constitute legal advice. Requirements vary by jurisdiction and organizational context. Consult qualified legal counsel for your specific situation.

If your team runs AI agents — anything that autonomously sends emails, updates records, screens applicants, or triggers approvals — the EU AI Act is already law and parts of it are already in force today.

This isn't a "prepare for 2027" story. Several obligations are active now, a significant deadline lands in weeks, and the gap between "we deploy agents" and "we can prove we're governing them" is wider than most teams realize.

Here's what you actually need to know.

What the EU AI Act Is (and Why It Reaches You)

The EU AI Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024. It's a risk-based framework: the heavier the consequences of an AI system's decisions, the more it has to demonstrate about oversight, documentation, and accountability.

The Act has explicit extraterritorial reach. Article 2 applies it to any company whose AI system's output affects people in the EU — regardless of where the company is headquartered, where its servers are, or whether it has a European entity. A US company with EU customers: in scope. A startup in any country running AI-driven hiring processes for EU-based employees: almost certainly in scope.

The Timeline: What's in Force, What's Coming

Here's where things stand right now:

  • August 1, 2024 — Act entered into force.
  • February 2, 2025 — Prohibited practices (Art. 5) and the AI literacy obligation (Art. 4): enforceable now.
  • August 2, 2025 — GPAI obligations (Art. 51–56) in force. Foundation model providers must document, publish training-data summaries, and respect copyright.
  • August 2, 2026 — Transparency requirements (Art. 50), ~8 weeks away. Chatbots must disclose they're AI; AI-generated content must be labeled. Fines become enforceable.
  • December 2, 2027 — Annex III high-risk AI obligations (see the note below).
  • August 2, 2028 — Annex I high-risk AI embedded in regulated products.

The Digital Omnibus Nuance — Read This Carefully

In May 2026, EU legislators reached a provisional political agreement that would push Annex III high-risk obligations from August 2026 to December 2, 2027. For teams running agents in hiring, credit, or infrastructure, that's meaningful relief.

The catch: as of this writing, the agreement has not been formally published in the EU's Official Journal. Until that happens, current law still lists August 2, 2026 as the Annex III deadline. Legal advisors broadly recommend planning toward December 2027 — but the IAPP makes the point directly: treating an unratified proposal as binding law is a poor compliance posture.

The August 2026 transparency deadline is unaffected by the Omnibus. It stands.

The Penalties: Bigger Than GDPR

Article 99 sets a three-tier fine structure:

  • Tier 1 — Prohibited AI practices (manipulative systems, real-time biometrics in public): up to €35M or 7% of global annual turnover, whichever is higher.
  • Tier 2 — High-risk non-compliance (oversight, logging, documentation): up to €15M or 3% of global turnover.
  • Tier 3 — Incorrect information to authorities: up to €7.5M or 1.5% of turnover.

For context, GDPR's ceiling is 4% of global turnover. The AI Act's Tier 1 is 7% — calculated on worldwide revenue across the entire corporate group, not just the EU subsidiary.

There is an SME carve-out: Article 99(6) specifies that for small and medium enterprises, the lower of the two amounts applies rather than the higher. A startup with €2M in revenue faces a maximum Tier 1 fine of around €140,000, not €35M. It still hurts — but it doesn't end the company.

What It Requires from Teams Running AI Agents

Risk classification matters here. The Act divides AI systems into four categories: prohibited, high-risk (Annex III), limited risk, and minimal risk. Agents in hiring, credit scoring, insurance eligibility, education access, and critical infrastructure fall squarely into Annex III high-risk territory. General-purpose agents doing email drafting or data summarization are typically lower-risk — until they're making decisions that affect individual rights or access to services.

What follows covers the five obligations that hit deployers running high-risk agents. Even if your agents don't reach that classification today, these are the practices regulators will look for.

1. An AI Inventory — Not a Spreadsheet, a System (Art. 9)

The Act requires a documented, continuous risk-management process — not a one-time assessment at deployment. That starts with knowing what you have: a register of every AI agent in use, what it does, who it affects, and what the failure modes are.

The most consistent gap in practice: teams can't enumerate their own agents. They know roughly what tools are running, but not which agents touch which data, which have access to which external systems, or who is accountable for each one.

2. Tamper-Proof Logs Kept for Six Months (Art. 12, Art. 19, Art. 26(6))

Article 26(6) states this clearly: deployers of high-risk AI systems must retain automatically-generated logs for a minimum of six months, in a form that can be provided to regulators.

The requirement has two parts most teams miss. The logs must be automatically generated — not manually assembled after an incident. And they must be demonstrably unmodified, meaning standard application logs won't do.

There's a meaningful difference between logging what an agent said and being able to explain why it made a decision — with proof that the record hasn't been touched. Regulators aren't asking for output records. They're asking for decision logic, with an audit trail that shows who approved what, when, and in what context.

3. A Named Person Responsible for Oversight — Not a Team (Art. 14, Art. 26(2))

Article 26(2) requires deployers to assign human oversight to a specific natural person — one with the competence, authority, and tools to do the job. Not the ops team. Not IT. A person.

Article 14 specifies what that person must be able to do:

  • Understand the agent's capabilities and limitations.
  • Recognize and resist automation bias — the tendency to trust AI outputs uncritically.
  • Override or ignore the agent's output when warranted.
  • Stop the system entirely, without involving IT or filing a support ticket.

That last point is a design requirement, not an HR policy. If halting an agent requires escalation to engineering, the system doesn't meet Article 14(4)(e).

4. Your Vendor's Compliance Isn't Yours (Art. 26)

This is the most common misreading of the Act.

When you use Zapier Agents, n8n, Lindy, CrewAI, or any other tool to run workflows, those platforms carry their own provider-level obligations. But you are the deployer, and Article 26 creates a distinct, independent set of obligations for you.

OpenAI's GPAI compliance doesn't satisfy your logging requirements. Your agent platform's data handling doesn't substitute for your oversight documentation. If a regulator comes asking about your AI agents, Article 26 puts the burden on your organization to demonstrate what you've done — regardless of what your vendors have done.

5. Active Monitoring and a Defined Incident Process (Art. 9, Art. 26(5))

Risk management under the Act isn't an event — it's ongoing. Deployers are expected to monitor AI systems in production for anomalous behavior and to have a defined process for when something goes wrong. Who gets notified? Who makes the call to halt? How is the incident documented? These need to be answered before the incident happens.

The Governance Gap in Practice

Here's where the data lands: according to a 2025 survey, 93% of enterprise organizations are deploying agentic AI. In the same research, 80% report observing risky behavior from their agents, and only 21% have governance models they'd describe as mature.

Perhaps the sharpest number: 42% of companies have abandoned AI initiatives specifically due to governance failures — up from 17% the year before.

The compliance cost to retrofit governance after the fact is estimated at €50,000–€500,000 for SMEs. The cost of building it in during deployment is substantially lower. The Act effectively creates a financial argument for doing this work now rather than after a regulator inquiry.

How a Control Layer Over Your Agents Addresses the Requirements

A governance layer — software that sits above your existing agents, across platforms, without requiring you to switch builders — maps directly to the requirements above:

  • For Art. 14 and Art. 26(2): Named approver assigned per agent. Approval gates configured for high-stakes actions — before the agent sends the email, modifies the record, or makes the call. One-click halt that any designated person can trigger without IT.
  • For Art. 12, Art. 19, Art. 26(6): Centralized, tamper-evident audit trail covering every tool call, every decision, every human approval event. Six-month retention built in, configurable to longer for regulated industries. Structured enough to hand to a regulator without ad-hoc extraction.
  • For Art. 9: A central agent registry. What's running, who owns it, what integrations it has — updated automatically as agents are added or modified.
  • For cross-platform accountability (Art. 25): When you have agents across Zapier, n8n, and a custom stack, one governance layer creates one audit trail and one defined responsible person — regardless of where the underlying agent lives.

This isn't a shortcut around legal counsel. It's the operational foundation that makes compliance something you can demonstrate.

VINCHY - MAAM is a governance and human-approval layer that sits above your existing agents — without requiring you to change your agent builder. Named ownership, approval gates, tamper-evident audit trails, anomaly alerts.

This post is informational only. It does not constitute legal advice and should not be relied on as such. The EU AI Act is a complex regulation with jurisdiction-specific nuances. Consult a qualified legal professional for guidance applicable to your organization.

Where this maps to a product

VINCHY - MAAM — Multi-Agent AI Manager

A governance and human-approval layer that sits above the AI agents you've already deployed — named ownership, approval gates, a tamper-evident audit trail, and EU AI Act Art. 26 oversight. No code required.

See how it works