Regulatory reference
AI agent regulation
There is no AI agent regulation, and as of September 2026 none is scheduled. That is not a gap — it is a deliberate position. The European Commission's own guidance states that AI agents are not a separate legal category; they are regulated as AI systems under rules that already exist. Which means some obligations already apply to your agents today.
The Commission's position
Asked directly whether AI agents fall under the AI Act, the Commission's AI Act Service Desk gives a structural answer: an AI agent typically consists of at least one general-purpose AI model plus interface and scaffolding components, and therefore constitutes an AI system within the meaning of the Act.
No new category. No separate instrument. The existing definitions are held to reach agents already, and the Commission notes that developments are recent and fast-evolving and that it continues to monitor them.
Why this is the right thing to know rather than a disappointment. "Not yet regulated" invites people to wait. The actual position is that several obligations apply to agents now, and the rest apply on the same schedule as every other AI system. There is nothing to wait for.
What already applies to agents today
| In force since | What | Relevance to agents |
|---|---|---|
| 2 Feb 2025 | Article 5 prohibitions | Apply to any AI system, agents included — manipulation and the other prohibited practices |
| 2 Feb 2025 | Article 4 AI literacy | Both providers and deployers must take measures supporting AI literacy among staff operating AI on their behalf |
| 2 Aug 2025 | General-purpose AI model obligations | Reach the model inside the agent |
| 2 Aug 2026 | Article 50 transparency | This is the one that bites agents directly. Systems interacting with people must disclose that they are AI |
Article 50 is the live obligation
If you operate an agent that talks to customers, candidates, suppliers or the public, the transparency obligation is not a 2027 problem. It has applied since August 2026.
The practical question is not whether you disclose in the product brief. It is whether an agent that reaches a person through a channel nobody catalogued — an email thread, a ticket queue, a chat integration stood up by one team — discloses. That is an inventory problem before it is a compliance one.
On AI literacy, one nuance
Article 4 was softened by the July 2026 omnibus. It now requires providers and deployers to "take measures to support the development of" AI literacy rather than to ensure a sufficient level of it, and explicitly does not require any guaranteed standard. It remains in force, and it is not contingent on a system being high-risk.
When an agent becomes high-risk
Agents are not high-risk because they are autonomous. They are high-risk if their deployment context falls in Annex III — which several common agent use cases do.
| Agent doing this | Likely position |
|---|---|
| Screening or ranking job candidates | Annex III — employment |
| Assessing creditworthiness | Annex III — essential private services |
| Pricing life or health insurance risk | Annex III |
| Marking assessments or deciding progression | Annex III — education |
| Triaging support tickets | Generally not Annex III, but Article 50 transparency applies |
| Writing code, summarising documents internally | Generally not Annex III |
Where an agent is in Annex III, the full high-risk regime applies from 2 December 2027, including Article 26 deployer obligations.
The awkward case worth naming: an agent built for a benign purpose that acquires a high-risk one because someone points it at a new task. Classification is a property of use, not of the software, and agents are unusually easy to repoint.
What is genuinely coming, and what is not
Not coming, as far as anyone can currently see: an EU regulation specific to AI agents. We searched for a scheduled instrument in the EU and US and found none. The Commission's stated approach is to handle agents under existing categories.
Actually developing: NIST is building Control Overlays for Securing AI Systems, of which two are agent-specific — single-agent and multi-agent. These are voluntary, and no publication date has been announced. Worth tracking, not worth planning around.
Worth watching for a different reason: US state law is where the near-term movement is. California's automated decision-making technology rules apply from 1 January 2027, and Colorado's replacement AI statute applies to consequential decisions from the same date. Neither is agent-specific, both reach automated decisions, and both arrive before the EU's December 2027 date.
So the honest summary: the regulation that will govern your agents already exists. The work is not waiting for a new instrument — it is knowing which of your agents sit in a context that makes an existing obligation apply.
Common questions about AI agent regulation
Is there a specific EU regulation for AI agents?
No, and none is scheduled. The Commission's position is that agents are AI systems under the existing AI Act definitions — typically a general-purpose AI model plus interface and scaffolding — and are regulated through rules that already apply rather than through a new instrument.
Do our AI agents have to tell people they are AI?
Where they interact with people, Article 50 transparency has applied since 2 August 2026. The compliance difficulty is usually not the disclosure itself but knowing every channel through which an agent reaches a person — agents get connected to inboxes and ticket queues without anyone recording it.
Does autonomy make an agent high-risk?
No. High-risk status comes from the deployment context falling within Annex III — employment, credit, insurance, education, biometrics and the rest — not from how autonomously the system operates. A highly autonomous agent summarising internal documents is generally not high-risk; a simple one ranking job applicants generally is.
What if an agent changes what it does?
Then its classification may change with it, because classification follows use. This is a real operational risk with agents specifically, since repointing one at a new task is trivial and rarely triggers any review. It is an argument for recording what each agent is permitted to do rather than what it was built to do.
Are US rules coming sooner than the EU's?
For automated decisions, in some states yes. California's ADMT rules and Colorado's AI statute both apply from 1 January 2027, ahead of the EU's 2 December 2027 high-risk date. Neither targets agents specifically. Note that Colorado's applicability is tied to the Attorney General completing rulemaking, so confirm its status before relying on the date.