Skip to content

Regulatory reference

AI agent regulation

There is no AI agent regulation, and as of September 2026 none is scheduled. That is not a gap — it is a deliberate position. The European Commission's own guidance states that AI agents are not a separate legal category; they are regulated as AI systems under rules that already exist. Which means some obligations already apply to your agents today.

The Commission's position

Asked directly whether AI agents fall under the AI Act, the Commission's AI Act Service Desk gives a structural answer: an AI agent typically consists of at least one general-purpose AI model plus interface and scaffolding components, and therefore constitutes an AI system within the meaning of the Act.

No new category. No separate instrument. The existing definitions are held to reach agents already, and the Commission notes that developments are recent and fast-evolving and that it continues to monitor them.

Why this is the right thing to know rather than a disappointment. "Not yet regulated" invites people to wait. The actual position is that several obligations apply to agents now, and the rest apply on the same schedule as every other AI system. There is nothing to wait for.

What already applies to agents today

In force sinceWhatRelevance to agents
2 Feb 2025Article 5 prohibitionsApply to any AI system, agents included — manipulation and the other prohibited practices
2 Feb 2025Article 4 AI literacyBoth providers and deployers must take measures supporting AI literacy among staff operating AI on their behalf
2 Aug 2025General-purpose AI model obligationsReach the model inside the agent
2 Aug 2026Article 50 transparencyThis is the one that bites agents directly. Systems interacting with people must disclose that they are AI

Article 50 is the live obligation

If you operate an agent that talks to customers, candidates, suppliers or the public, the transparency obligation is not a 2027 problem. It has applied since August 2026.

The practical question is not whether you disclose in the product brief. It is whether an agent that reaches a person through a channel nobody catalogued — an email thread, a ticket queue, a chat integration stood up by one team — discloses. That is an inventory problem before it is a compliance one.

On AI literacy, one nuance

Article 4 was softened by the July 2026 omnibus. It now requires providers and deployers to "take measures to support the development of" AI literacy rather than to ensure a sufficient level of it, and explicitly does not require any guaranteed standard. It remains in force, and it is not contingent on a system being high-risk.

When an agent becomes high-risk

Agents are not high-risk because they are autonomous. They are high-risk if their deployment context falls in Annex III — which several common agent use cases do.

Agent doing thisLikely position
Screening or ranking job candidatesAnnex III — employment
Assessing creditworthinessAnnex III — essential private services
Pricing life or health insurance riskAnnex III
Marking assessments or deciding progressionAnnex III — education
Triaging support ticketsGenerally not Annex III, but Article 50 transparency applies
Writing code, summarising documents internallyGenerally not Annex III

Where an agent is in Annex III, the full high-risk regime applies from 2 December 2027, including Article 26 deployer obligations.

The awkward case worth naming: an agent built for a benign purpose that acquires a high-risk one because someone points it at a new task. Classification is a property of use, not of the software, and agents are unusually easy to repoint.

What is genuinely coming, and what is not

Not coming, as far as anyone can currently see: an EU regulation specific to AI agents. We searched for a scheduled instrument in the EU and US and found none. The Commission's stated approach is to handle agents under existing categories.

Actually developing: NIST is building Control Overlays for Securing AI Systems, of which two are agent-specific — single-agent and multi-agent. These are voluntary, and no publication date has been announced. Worth tracking, not worth planning around.

Worth watching for a different reason: US state law is where the near-term movement is. California's automated decision-making technology rules apply from 1 January 2027, and Colorado's replacement AI statute applies to consequential decisions from the same date. Neither is agent-specific, both reach automated decisions, and both arrive before the EU's December 2027 date.

So the honest summary: the regulation that will govern your agents already exists. The work is not waiting for a new instrument — it is knowing which of your agents sit in a context that makes an existing obligation apply.

Common questions about AI agent regulation

Is there a specific EU regulation for AI agents?

No, and none is scheduled. The Commission's position is that agents are AI systems under the existing AI Act definitions — typically a general-purpose AI model plus interface and scaffolding — and are regulated through rules that already apply rather than through a new instrument.

Do our AI agents have to tell people they are AI?

Where they interact with people, Article 50 transparency has applied since 2 August 2026. The compliance difficulty is usually not the disclosure itself but knowing every channel through which an agent reaches a person — agents get connected to inboxes and ticket queues without anyone recording it.

Does autonomy make an agent high-risk?

No. High-risk status comes from the deployment context falling within Annex III — employment, credit, insurance, education, biometrics and the rest — not from how autonomously the system operates. A highly autonomous agent summarising internal documents is generally not high-risk; a simple one ranking job applicants generally is.

What if an agent changes what it does?

Then its classification may change with it, because classification follows use. This is a real operational risk with agents specifically, since repointing one at a new task is trivial and rarely triggers any review. It is an argument for recording what each agent is permitted to do rather than what it was built to do.

Are US rules coming sooner than the EU's?

For automated decisions, in some states yes. California's ADMT rules and Colorado's AI statute both apply from 1 January 2027, ahead of the EU's 2 December 2027 high-risk date. Neither targets agents specifically. Note that Colorado's applicability is tied to the Attorney General completing rulemaking, so confirm its status before relying on the date.

Dates on this page were verified on 23 September 2026 against the Council of the EU's press release of 29 June 2026 and the European Commission's regulatory framework page. Article-level detail is drawn from published compilations of the amended text and is described rather than quoted, because the consolidated text was not retrievable in full at the time of writing. This is a reference, not legal advice.

Last reviewed 2026-09-23. Published by Agent Trust Cloud, a Globixera company — globixera.com.