EU AI Act

The Act applies from August 2026. Your agents are already running.

Most of the EU AI Act's obligations arrive in August 2026, and three of them land directly on agent activity: keeping a record of what happened, letting a person intervene, and being able to trace how an outcome was reached. This page explains what that means in practice for an estate of AI agents.

The dates

A staged rollout, with the big one in August 2026.

The Act did not arrive all at once. Knowing which deadline is which matters, because the one that reaches most enterprise agent estates is the 2026 date rather than anything earlier.

August 2024

The Act entered into force

The text became law across the EU, starting a staged set of deadlines rather than a single switch.

February 2025

Prohibitions applied

The banned categories of AI practice took effect, along with duties around AI literacy inside organisations.

August 2025

General purpose model duties

Obligations landed on providers of general purpose AI models, including transparency and documentation.

August 2026

The bulk of the Act applies

This is the date most enterprises have been planning towards, and the one that reaches agent estates already in production.

What it asks of you

Four obligations that land on agent activity.

The Act covers a great deal more than this. These are the duties that change how an agent estate has to be built and operated, rather than how it is documented.

01

Automatic record keeping

High risk systems are expected to log events over their lifetime, so that activity can be traced back after the fact. For an agent estate this means a record of what each agent did, not a sample and not a summary. Retention periods apply, so the record has to survive.

02

Human oversight

People need to be able to understand, intervene in and stop a system's operation. For agents acting at machine speed, oversight after the fact is not oversight. It has to be possible to interrupt an action while it is happening.

03

Traceability

Regulators expect to reconstruct how an outcome was reached. When one agent invokes another, which invokes a third, the chain itself becomes part of the answer, and most estates cannot produce it.

04

Deployers carry duties of their own

Organisations that use a high risk system carry obligations of their own, including keeping logs and assigning human oversight. Buying an agent platform from a vendor does not move those duties off your side of the line.

Where estates fall short

The controls usually exist on paper and not in the call path.

Logs exist, but not as evidence

Most teams have application logs. Few have a record that spans every agent in the business, ties an action to the person or policy that authorised it, and can be shown to be unaltered.

Oversight is a review meeting

Sign off at design time is common. Being able to hold a specific high risk action until a named person approves it, on the call, is rare.

Nobody has the full inventory

You cannot evidence oversight of agents you do not know about. Estates that grew through separate teams and low code tools usually have more agents running than anyone has written down.

What KPATH AMP gives you

Evidence and controls, in the call path.

KPATH Agent Management Platform (AMP) sits between your agents and the services they reach. Because every call goes through it, the record and the intervention point are properties of the architecture rather than something each team has to remember to build.

A record of every agent action

Each call is recorded with the agent that made it, the authority it acted under, and the time. The record is tamper evident, so an alteration is detectable rather than invisible, and it is built for long retention.

Human approval at the moment of action

Actions carrying higher risk can be held until a person decides. The approval and the decision both land in the same record, rather than being reconstructed from memory later.

The chain, end to end

When agents invoke other agents, KPATH AMP tracks which one called which. That is what lets you answer how an outcome was actually reached, and stop everything a single agent set in motion.

An inventory you did not have to compile

Monitor mode watches without blocking anything and builds a picture of the agents and services already running, including the ones nobody registered.

Where to start

Four things worth doing before the deadline.

None of these require a purchase, and the first two do not require a vendor at all. They are in this order because each one depends on the one above it.

01

Find out what you are running

Every other step depends on this one. An inventory of the agents making calls, and of the systems they reach, tells you which of them plausibly sit in a high risk use and which do not. Organisations routinely discover the scope question is bigger than they assumed.

02

Work out which agents touch a high risk use

This is a legal and risk judgement rather than a technical one, and it needs the inventory in front of it. Agents involved in creditworthiness, employment decisions, or access to essential services are the usual candidates.

03

Check whether you could evidence an action today

Pick one agent action from last month and try to produce who authorised it, what it reached, and proof the record has not changed. The gap between what you can produce and what is being asked for is the actual size of the work.

04

Put a person in the path of the risky actions

Oversight has to be exercisable. That means a named human able to hold a specific action, not a committee reviewing a dashboard next quarter.

This page is not legal advice. Whether a particular system of yours is high risk under the Act, and what that requires, is a question for your legal and risk teams.

Common questions

Questions we get asked about the Act.

Does the EU AI Act apply to AI agents specifically?

The Act regulates AI systems by risk and by use, rather than by whether something is called an agent. An agent doing something the Act treats as high risk, in credit decisioning or employment or access to essential services, falls under those obligations like any other system. The practical difference is that agents act quickly, chain together, and are often built by several teams, which makes the logging and oversight duties harder to satisfy.

We buy our agent platform from a vendor. Isn't compliance their problem?

Partly. Providers carry obligations, and so do the organisations deploying the system. Deployer duties include keeping logs and making sure human oversight is assigned to people who can act. Those stay with you regardless of who built the agent.

What is the fastest way to see where we stand?

Start with the inventory, because the rest depends on it. Monitor mode blocks nothing and shows you which agents are running and what they reach. Most organisations find agents they had not accounted for, which is usually the thing that changes the timeline.

Related: finding the agents nobody registered, or the KPATH AMP platform.

Start with what you can actually evidence today.

A free 30 minute conversation about your agent estate and the records it produces.