// news · agents · policy2026-08-06source: EU AI Act enforcement analysis

EU high-risk provisions land on agent deployments: risk management, human oversight, conformity assessment

The AI Act's high-risk obligations became enforceable on 2 August alongside the Article 50 transparency duties. For anyone running agents in Europe, risk management, human oversight and conformity assessment are now compliance artefacts with deadlines rather than architecture preferences.

Human oversight is the requirement that will bite hardest, because it is the one agent architectures are specifically designed to reduce. The commercial case for an agent is that it acts without waiting for a person; a regime requiring meaningful human oversight of high-risk systems is asking for the opposite property, and reconciling the two is a design problem, not a paperwork one.

Conformity assessment is the second-order problem. Assessing a fixed system against fixed criteria is well-understood practice. Assessing something whose behaviour depends on a model version, a tool set, a prompt and a runtime effort setting is not, and the assessment regime was not written with reconfigurable systems in mind.

The practical first task for most organisations is smaller and duller than either: work out which of the tools already deployed became agents in a product update. Vendors are shipping agency into existing seats, and an inventory is a prerequisite for any of this.

See our analysis →

Wilson Sonsini — EU AI Act enforcement phase begins → · EU Artificial Intelligence Act — Enforcement of Chapter V under the EU AI Act → · Outsource Accelerator — EU AI Act enforcement begins for AI model makers →