The EU AI Act and Agentic AI
Learn how the EU AI Act and agentic AI intersect, including risk tiers, obligations for high-risk systems, and what deployers should consider.
The EU AI Act is the European Union's comprehensive framework for regulating artificial intelligence, and its risk-based approach has significant implications for agentic systems. Because agents operate with autonomy and can take consequential actions, many enterprise deployments are likely to engage with the Act's more demanding requirements. This article explains the general structure and how it relates to agents. It is general information, not legal advice, and organizations should seek qualified counsel for their specific circumstances.
A Risk-Based Framework
The AI Act sorts systems into tiers based on their potential for harm. At the top are prohibited practices, which are banned outright. Below that sit high-risk systems, which carry the heaviest set of obligations. Then come limited-risk systems, subject mainly to transparency duties, and minimal-risk systems, which face little additional regulation. The compliance burden scales with the tier, so determining where a given system falls is the first and most consequential question for anyone deploying it.
Where Agentic AI Tends to Fall
Commentary on the Act has noted that agentic systems exhibit many of the characteristics associated with higher risk. They operate with varying levels of autonomy, which is the defining feature of an agent. They can adapt after deployment through memory and accumulated context. And they generate outputs that influence real environments by sending messages, executing code, or invoking external services. For these reasons, many analysts expect that a substantial share of enterprise agent deployments will need to engage with the high-risk tier and its requirements, depending on the specific use and context.
Obligations for Higher-Risk Systems
For systems that fall into the high-risk category, the Act sets out a range of obligations that generally include risk management, data governance, technical documentation, record-keeping, transparency to users, human oversight, and standards for accuracy and robustness. The emphasis on human oversight is especially relevant to agents, since autonomy is precisely what the oversight requirement is meant to temper. Organizations deploying high-risk systems are expected to maintain the documentation and controls needed to demonstrate conformity.
General-Purpose AI and the Models Behind Agents
The Act also addresses general-purpose AI models, which frequently serve as the foundation for agents. Rules for these models, including transparency obligations and, for the most capable models, additional requirements around risk assessment and security, have been phasing in. A voluntary code of practice has been developed to help providers align with these expectations. Deployers building agents on top of such models should understand that obligations attach at multiple layers, from the underlying model to the agentic system built on it.
What Deployers Should Keep in Mind
The Act's requirements are being phased in over time, with different obligations taking effect on different dates, so the practical impact unfolds gradually. For organizations building or deploying agents that may serve EU users, the prudent course is to assume that meaningful obligations may apply, to build transparency, human oversight, and documentation into the design from the start, and to monitor how guidance and enforcement develop. Because the details are intricate and consequential, professional legal advice tailored to a specific deployment is strongly advisable.
Frequently Asked Questions
Does the EU AI Act specifically name agentic AI?
The Act uses a risk-based framework rather than naming every technology, but its definitions of autonomy, adaptiveness, and outputs that affect real environments map closely onto how agents work. This is general information, not legal advice.
Are all AI agents considered high-risk under the Act?
Not automatically. Classification depends on the specific use and context, but many enterprise agent deployments are expected to engage with the high-risk tier because of their autonomy and real-world impact.
What should deployers do to prepare?
Build transparency, human oversight, and thorough documentation into agents from the outset, understand that obligations may apply at both the model and system levels, and consult qualified counsel for the specifics of your deployment.
