// blog · analysis · agents2026-08-06source: EU AI Act analysis and enterprise coverage

High-risk is now a deployment question

The AI Act's high-risk obligations ask for meaningful human oversight. The commercial case for an agent is that it acts without waiting for a person. Those two facts have to be reconciled by December, and most organisations cannot yet list which of their tools became agents.

Risk management, human oversight and conformity assessment became enforceable on 2 August. For anyone running agents in Europe these are now compliance artefacts with deadlines, not architecture preferences.

Human oversight is the one that bites

Because it is the property agent architectures exist to reduce. The entire commercial argument for an agent is that it acts without waiting for a person to approve each step. A regime requiring meaningful human oversight of high-risk systems is asking for the opposite, and reconciling the two is a design problem rather than a documentation exercise.

Conformity assessment is the harder second-order problem. Assessing a fixed system against fixed criteria is well-understood. Assessing something whose behaviour depends on model version, tool set, prompt and a runtime effort setting is not — and the assessment regime was not drafted with reconfigurable systems in view.

The prerequisite nobody has done

An inventory. Most organisations cannot currently list which of their deployed tools acquired agency in a product update, because nobody procured those capabilities — they arrived inside software already licensed, already deployed, already holding permissions across the corpus.

And that is the direction of travel, not an aberration. Microsoft is explicitly betting that the next battle is deployment rather than models, which means more agency shipped into more existing seats, faster.

Governance as a product, which is an admission

The interesting detail in that bet is governance being sold as a deliverable rather than assigned as the customer's obligation. Historically a vendor tells you to handle governance yourself. Selling it is a concession that customers cannot supply it — and the surveys agree, with integrated cross-agent governance reported in single-digit percentages while roughly 40% of enterprise applications are expected to carry agents by year end.

Those two numbers describe a gap, not a maturity curve. Capability is shipping faster than the ability to supervise it, the shipping is done by vendors, and the supervising is done by customers.

What to do first

Not policy. Inventory. Work out what became an agent, what permissions it inherited, and who would notice if it acted wrongly. Everything in the AI Act's high-risk chapter presupposes you can answer those three questions, and most organisations currently cannot.

EU Artificial Intelligence Act — Enforcement of Chapter V under the EU AI Act → · Pure AI — Microsoft bets enterprise AI's next battle is deployment, not models → · Gartner — Gartner predicts 40% of enterprise apps will feature task-specific AI agents by 2026 →