The European Union Artificial Intelligence Act represents one of the most comprehensive regulations directed toward the development and implementation of AI in the world. While its intended audience is mostly providers of AI models and systems, companies (even multinational ones) deploying AI within the bounds of the EU must comply with the relevant portions. For example, companies anywhere on the planet who create public-facing applications that incorporate AI models are within the scope of the EU AI Act if those applications reach EU citizens.
In many cases, the public interacts with these applications through agents. You’d think that a reasonable starting place to determine your responsibilities under the law might be to search the text of the Act for helpful guidance about how agentic interactions should properly comply, right? Well, here is the number of times the word “agent” appears in the Act: zero. “Aha,” begins the thought forming in your mind. “We’re off the hook, the Act doesn’t apply to us.”
Before the belief of totally unregulated AI agents colonizes your brain, recall that the Act was ratified in 2024, before AI agents emerged into our consciousness. In this post I’ll explore the explicit and implicit requirements for compliance of agentic systems under the EU AI Act. At the end, I’ll provide a diagram that helps sort what applies to your company. Buckle up!
The minimum requirements
Let’s begin by acknowledging who even should read this blog post. Article 50 applies to companies (“deployers,” in the Act’s vernacular) who implement AI systems that EU citizens can reach. The compliance deadline was August 2, 2026, so there’s no time to delay. Paragraph 3.1.1(31) of the exhaustingly-titled Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (the ‘AI Act’) tells us:
“AI agents are covered by Article 50(1) AI Act if they are capable of interacting with the persons instructing them or with other natural persons in the execution of the tasks (e.g. making bookings, managing correspondence, negotiating or concluding contracts, executing purchases, etc).”
The same paragraph offers useful examples of such AI systems that are covered by the Act:
- AI-enabled voice assistants, chatbots/conversational agents in various contexts (e.g. public service, customer support, complaints management, e-commerce, finance, healthcare, education etc.)
- AI hotline for incidents, fraud or other reporting, (humanoid) robots/cobots, AI companions; robotic companion pets; AI avatars (e.g. in virtual reality environments)
- AI bots on social networks and media, coding agents and other AI agents capable of directly interacting with natural persons (including in complex multi-agent architectures)
Simply put: companies deploying agents that interact with humans must inform those humans that they’re interacting with agents, germane to the style of the interaction. Paragraph 3.1.2(36) of the Guidelines provides examples:
“…notifications in writing (e.g., a chatbot that starts a conversation by mentioning that it is based on AI technology), visual means (e.g. an email generated by an AI agent sent to a natural person that features an AI label at the top), auditory means (e.g. a voice assistant that says at the beginning of a session that it is powered by AI), disclosure of AI identifiers, and credentials (e.g. AI agents that disclose their AI identity to the extent feasible in a verifiable manner).”
Furthermore, Article 50(2) of the Act applies to agents that generate or manipulate synthetic content in any form (text, image, audio, video), and companies must mark that content as AI-generated if it’s perceptible by humans. The Code of Practice on Transparency of AI-Generated Content explains the necessary rules.
Now for the naming of parts: A confusion around terminology
The European Commission’s position on whether agents are AI systems was ambiguous for a while, which has caused some confusion about whether other portions of the Act (that are described for AI systems) apply for AI agents too. The EC has stated “To the extent that AI agents are AI systems, the AI Act’s risk-based rules apply” (conveniently, the statement avoids certainty).
One lawmaker quibbled by drawing a distinction between the roles of AI systems and agents: “AI agents are specifically designed to perform actions…whereas the AI Act definition appears to focus on systems that produce outputs…” Several months later at a hearing this lawmaker was told “Yes, they are, they are covered. Mainly they have elements of the general-purpose AI systems. Agents are [covered] under this” (brackets in original). Observe that the EC still sidestepped the direct question of whether AI agents are AI systems because it didn’t issue an opinion about whether agent actions constitute outputs.
Contemporary analysis, plus several recent EC documents, however, concludes that agents are, in fact, AI systems as defined in Article 3(1). An FAQ published by the AI Act Service Desk states:
“…while AI agents are not a separate category of AI under the AI Act, the definitions of an AI system in Article 3(1) AI Act and of a GPAI model in Article 3(63) AI Act are sufficient to cover AI agents. This means that the rules applicable to AI systems and GPAI models under the AI Act also apply to AI agents.”
Every time the Act references AI systems, the scope also includes AI agents, which explains why Article 50 constitutes the minimum requirements for companies who deploy them.
When does an agent become a model?
Further confusion exists around whether agents are also models as defined in Article 3(63). Does building an agent constitute the creation of a modified model?
The EC published a set of guidelines that carry legal and operational relevance here. Companies who modify models in which “…the training compute used for the modification is greater than a third of the training compute of the original model…” [paragraph 3.2(60); see also (61)] are considered providers and are bound by additional regulations. The EC estimates that “few modifications may meet [this] criterion.”
Chapter V of The Act assigns compliance duties for mitigating model-level risks to model providers, not to deployers of AI systems that incorporate agents; simply attaching an agent to a model isn’t a modification. However, if deployers modify models and attach agents to them, then deployers become providers and must comply with portions that apply to providers, namely Articles 53, 54, and 55. The General-Purpose Code of AI Practice provides helpful guidance for transparency, copyright, and safety/security aspects. Even though the Code possesses no regulatory power, the EC has “confirmed that the Code is an adequate voluntary tool for providers of GPAI models to demonstrate compliance with the AI Act” [emphasis added].
One remaining but substantial complication: If an AI system is used as a safety component covered by legislation listed in Annex I, or performs activities described in Annex III (with certain exceptions), Chapter III of the Act automatically classifies it as a high risk system (regardless of whether it uses a modified model) and it must comply with a fairly massive and ponderous thicket of system-level requirements, obligations, notifications, assessments, and registrations (deadlines: December 2, 2027 for Annex III, 2 August 2028 for Annex I). Because (as we established above) agents are AI systems, any agents that create or manipulate sensitive or personal information will trigger Chapter III compliance to mitigate system-level risks (and, to be clear, GDPR compliance, too).
Where to focus
As promised, follow this handy flowchart to understand your company’s obligations under the EU AI Act as a creator of agents that rely on general purpose AI models. The shaded boxes indicate which obligations apply.
Chapter V describes two kinds of models: those with systemic risk and those without. The principal difference is the amount of compute required for training: if greater than 1025 floating point operations, the model carries systemic risk. Because contemporary models now exceed the threshold, this stance should be every company’s default.
If flowcharts aren’t your thing, here it is in words, with braces to show grouping.
- If your agent relies on an unmodified model and doesn’t { have a safety component or process sensitive/personal information }, you are a deployer: follow Article 50.
- If your agent relies on a modified model and doesn’t { have a safety component or process sensitive/personal information }, you are a provider and deployer:
- GPAI: follow Articles 50 through 54.
- GPAISR: follow Articles 50 through 55.
- If your agent does { have a safety component or process sensitive/personal information }, follow all of the Articles in Chapter III (6 through 49) plus:
- unmodified: follow Article 50.
- modified GPAI: follow Article 50 through 54.
- modified GPAISR: follow Article 50 through 55.
This post is, of necessity, only a starting point to help you begin organizing your thoughts and forming a plan. It does not constitute legal advice. The working paper AI Agents Under EU Law: A Compliance Architecture for AI Providers (arxiv:2604.04604v1 [cs.CY]) offers thorough guidance for companies whose agents are reachable by EU citizens. It deserves your full attention.
Find out more about how Netskope helps secure AI, and the data that feeds it.