See every AI agent. Govern every action.
← Back to Blog
eu-ai-actcomplianceregulation

EU AI Act Compliance for AI Agents: What You Need to Know

Henrique Veiga Curi2026-03-1810 min read

The EU AI Act is the world's first comprehensive regulation for artificial intelligence. For organizations deploying AI agents, it creates specific obligations around risk classification, human oversight, documentation, and incident reporting.

Here's what you need to know (practically, not legally).

Who Does This Apply To?

If your organization deploys AI agents that affect EU citizens, regardless of where your company is based, the EU AI Act applies to you. This includes:

- Customer support chatbots serving EU customers

- AI agents making financial decisions for EU markets

- Automated hiring tools screening EU candidates

- Any AI system that processes EU personal data

The Four Risk Levels

The EU AI Act classifies AI systems into four risk categories:

Unacceptable Risk

Banned outright. Social scoring systems, real-time biometric surveillance in public spaces, manipulation of vulnerable groups. Most enterprise AI agents don't fall here.

High Risk

Subject to the most stringent requirements. This includes AI systems used in:

- Employment and worker management

- Access to essential services (credit, insurance, housing)

- Law enforcement and justice

- Critical infrastructure management

If your AI agent makes decisions that significantly affect people's lives, it's probably high-risk.

Limited Risk

Transparency obligations only. Chatbots must disclose they're AI. Deepfakes must be labeled.

Minimal Risk

No specific requirements. Most internal productivity agents fall here.

What High-Risk Classification Requires

For high-risk AI agents, the EU AI Act mandates:

Risk Management System (Article 9)

A documented process for identifying, analyzing, and mitigating risks throughout the AI system's lifecycle.

Data Governance (Article 10)

Training data must be relevant, representative, and free of errors. Data bias must be addressed.

Technical Documentation (Article 11)

Complete documentation of the AI system: its purpose, architecture, training process, performance metrics, and known limitations.

Record-Keeping (Article 12)

Automatic logging of all agent actions with enough detail to trace the agent's decision-making process. Logs must be retained for a minimum of 6 months.

Human Oversight (Article 14)

Human-in-the-loop (HITL) mechanisms that allow humans to:

- Understand the AI system's capabilities and limitations

- Monitor its operation in real time

- Intervene or override when necessary

- Decide to shut it down ("kill switch")

Accuracy, Robustness, Cybersecurity (Article 15)

The AI system must achieve appropriate levels of accuracy and be resilient to adversarial attacks.

Practical Steps to Prepare

Step 1: Inventory Your Agents

You can't classify what you don't know exists. Build a complete registry of every AI agent in your organization, including shadow agents deployed by individual teams.

Step 2: Classify Each Agent's Risk Level

For each agent, determine whether it's minimal, limited, or high-risk based on its use case and the decisions it makes.

Step 3: Implement Audit Trails

Start logging agent actions now. High-risk obligations were postponed to December 2, 2027 under the 2026 Digital Omnibus agreement, but audit-ready evidence takes 12+ months of production history to build, so the postponement is the window to start, not a reason to wait.

Step 4: Build HITL Workflows

For high-risk agents, implement approval workflows that require human sign-off before critical actions.

Step 5: Prepare Fundamental Rights Impact Assessments

Article 27 requires deployers of high-risk AI to conduct FRIAs before deployment.

The Timeline

  • August 2, 2026 (postponed to December 2, 2027 under the 2026 Digital Omnibus agreement): Obligations for high-risk AI systems take effect
  • February 2, 2027: Codes of practice for general-purpose AI
  • August 2, 2027: Full enforcement of all provisions
  • If you haven't started preparing, start now. Building the infrastructure for compliance takes months, and you need 6 months of audit trail data to be compliant on day one.

    That 6-month figure comes from Article 26(6). For what those logs have to contain and how they differ from ordinary observability data, see EU AI Act log retention and record-keeping under Article 12.


    MeshAI provides automated EU AI Act compliance scoring (0-100), risk classification, audit trails, FRIA templates, and HITL approval workflows. See our compliance features or apply for the pilot partner program.

    Frequently asked questions

    What are the four risk levels in the EU AI Act?
    The Act sorts AI systems into unacceptable risk (prohibited practices such as social scoring and certain biometric categorisation), high risk (Annex I embedded products and Annex III standalone use cases, carrying the full obligation set), limited risk (transparency duties, for example disclosing that a user is interacting with an AI system), and minimal risk (no specific obligations). Classification drives which obligations attach, so it is the first step, not a formality.
    How do you classify an AI agent's risk level?
    Work in order. First check whether the agent performs a prohibited practice, which ends the analysis. Then check whether its use case appears in Annex III or whether it is a safety component of an Annex I regulated product, which makes it high risk. If neither applies, check whether transparency obligations attach because users interact with it or it generates synthetic content. Record the reasoning: the classification itself is an artifact an auditor will ask to see.
    When is a Fundamental Rights Impact Assessment (FRIA) required?
    Article 27 requires a FRIA from deployers that are bodies governed by public law or private entities providing public services, and from deployers of the high-risk systems covered by Annex III points 5(b) and 5(c), which concern creditworthiness assessment and risk assessment or pricing for life and health insurance. It is a deployer obligation, distinct from the provider's Article 9 risk management system.
    Does the EU AI Act apply to a company based outside the EU?
    Yes, if the output of the AI system is used in the EU. Establishment is not the test, so a US-based company running agents that serve EU customers or make decisions affecting people in the EU falls in scope. This extraterritorial reach is why domestic deregulation elsewhere does not reduce the obligation.