EU AI Act & AI Agents: What Applies From Today
TL;DR: As of today, 2 August 2026, the EU AI Act is enforceable. The rules that bite now are transparency (Article 50), AI literacy (Article 4), and penalties for everything already in force. The heavy high-risk conformity regime that everyone was dreading today was postponed to 2 December 2027 by the Digital Omnibus. If you run AI agents in an EU business, the practical work is small and unglamorous: know what you're running, tell people when they're talking to an AI, log what the agent did, and train the humans around it.
What changed today
Three separate things landed, and the press coverage keeps merging them.
| Item | Status from 2 Aug 2026 |
|---|---|
| Article 50 transparency | Applies. Disclose AI interaction, mark synthetic content, disclose emotion recognition and deepfakes. |
| Article 4 AI literacy | Applies, in softened form: providers and deployers must support AI literacy among staff. |
| Enforcement + penalties | Live for everything already applicable: the Feb 2025 prohibitions, Aug 2025 GPAI duties, and the above. |
| Annex III high-risk obligations | Postponed to 2 Dec 2027. |
| Annex I embedded high-risk | Postponed to 2 Aug 2028. |
| Art. 50(2) machine-readable marking | Grace period to 2 Dec 2026 for systems already on the market. |
| Non-consensual intimate imagery / CSAM prohibitions | Transitional period to 2 Dec 2026. |
| National regulatory sandboxes | Member States now have until 2 Aug 2027. |
The postponement came through the Digital Omnibus on AI, agreed and signed 8 July 2026, in force 27 July. It is a delay, not a repeal. The conformity assessments, risk management systems, technical documentation and post-market monitoring for high-risk systems are all still coming — you simply got sixteen more months.
The thing worth internalising: the delay applies to the expensive regime, not to the enforceable one. Article 50 is short, cheap to comply with, and now carries a tier-2 fine of up to €15M or 3% of worldwide turnover.
Where your agents actually sit
Most people running AI agents in a business assume the Act is aimed at them. Usually it isn't, or not in the way they fear. Four buckets, in descending severity:
Prohibited (Article 5). Social scoring, untargeted facial scraping, emotion inference in the workplace or in education, exploiting vulnerability. Applicable since February 2025, now enforceable at up to €35M or 7%. Note the workplace emotion-recognition ban — if a vendor is selling you sentiment scoring of your own employees' calls or messages, that is the one line in this Act you cannot buy your way past.
High-risk (Annex III). Recruitment and worker management, creditworthiness, insurance underwriting, access to essential services, education, biometrics, critical infrastructure. An AI recruitment screening agent is squarely in here. You now have until 2 December 2027, and you should use it, because the obligations are real: risk management, data governance, logging, human oversight, accuracy and robustness, conformity assessment, registration.
Transparency-only (Article 50). Customer-facing chatbots, voice agents, anything generating synthetic text, image, audio or video. This is where most commercial agent deployments land, and the whole obligation is essentially: say so.
Minimal risk. An agent that reads your inbox, codes invoices and posts to your ERP, with no external human on the other end. The majority of back-office automation is here. No specific AI Act obligation beyond literacy and whatever GDPR already required of you.
If you deploy agents for customer support, you're in bucket three today. If you deploy them for invoice processing or month-end close, you're in bucket four. Same platform, different obligations, because the Act regulates the use case rather than the technology.
The provider/deployer split, in plain terms
Article 50 assigns duties to both roles, and the boundary is where most confusion lives.
- Provider — you built or you place the AI system on the market under your name. Duty: design the system so people are told they are interacting with an AI (50(1)), and mark synthetic output in a machine-readable way (50(2)).
- Deployer — you use the system under your own authority. Duty: inform people exposed to emotion recognition or biometric categorisation (50(3)), and disclose deepfakes and AI-generated public-interest text (50(4)).
The trap: white-labelling makes you a provider. Put your own brand on a chatbot built on someone else's platform and you have, in most readings, placed an AI system on the market under your own name. Your vendor's compliance does not automatically transfer to your logo. Ask them for a written statement of which Article 50 duties they discharge and which they leave with you — and if they can't answer in a sentence, that tells you something.
What compliance looks like operationally
Four controls. All of them are things a well-run agent platform should already do, which is the point.
1. Disclosure at the interaction boundary
Every point where an agent talks to a human outside your company gets a plain statement that it's an AI. Not buried in a privacy policy — at the start of the conversation, in the channel it happens in. Email signature, first chat message, voice greeting.
Two failure modes we see. First, teams disclose on the web widget and forget the WhatsApp, Slack and email channels the same agent also runs on. Second, teams disclose on the happy path and lose it on handoff — bot to human is fine, but human back to bot silently is not. The obligation follows the interaction, not the surface you happened to build first.
The exception in the Act is for cases where AI involvement is "obvious from the circumstances" to a reasonably informed person. Don't build your compliance on that exception. It costs one sentence to be certain.
2. A record of what the agent did
The Act does not impose logging on transparency-only systems. Do it anyway, for the reason that matters when the regulator or the customer asks: an unlogged agent action is indistinguishable from an accusation.
What's worth keeping per run: the trigger, the model and version, the tools called, the data touched, the output, and the human who approved anything consequential. This is exactly the audit trail that high-risk logging in 2027 will require, so building it now converts a December 2027 project into a configuration change. In OIDO every agent run is recorded with its full tool-call trace by default — not as a compliance feature, but because you cannot debug a non-deterministic system without one.
3. Human approval on consequential actions
Human-in-the-loop is a high-risk requirement (Article 14 human oversight) that you should treat as a general operating principle. The dividing line we use: an agent may read anything it's scoped to, and may write freely to low-consequence surfaces, but anything that moves money, sends externally under your name, or changes a record of record stops and asks a named person.
This is the same architecture as agent guardrails generally — the control lives in what the agent is unable to do, not in instructions asking it to behave. Regulation just gave that architecture a second reason to exist.
4. AI literacy that isn't a slide deck
Article 4 was softened by the Omnibus from guaranteeing a literacy level to supporting its development among staff. That is a low bar and it is still a bar. The version that survives an inspection and is actually useful: a short session per team touching AI, covering what the tool does, where it fails, what it must never be used for, and who to tell when it does something odd. Written down, dated, attendance recorded. An hour.
The uncomfortable part: your obligations don't stop at the Act
Two things regularly bite European mid-market companies harder than the AI Act itself.
GDPR was already the binding constraint. An agent reading customer emails processes personal data. Lawful basis, purpose limitation, retention, data subject rights and international transfers all applied before today and still do. Nothing in the AI Act relaxes them. If you're choosing a platform, where the inference runs and where the logs sit matters more for GDPR than for the AI Act — see our note on cloud versus self-hosted.
Sector rules run in parallel. Finance, health and public procurement layers sit on top. If you're already navigating the EU e-invoicing mandates, you've seen how this goes: the EU-level framework sets direction, the national implementation sets your actual deadline. AI Act enforcement is delegated to national market surveillance authorities, so your practical exposure depends on which member state you're established in — Spanish SMEs, for instance, face AESIA, one of the more organised national regulators. We covered the local picture in AI automation for Spanish SMEs.
A checklist you can finish this week
- Inventory. Every AI system in use, including the ones a team bought on a card. Name, vendor, use case, who owns it.
- Classify. Prohibited / high-risk / transparency-only / minimal. Most rows will be the last two. Write the reason next to each — that sentence is your documentation.
- Kill the prohibited row if you have one. Workplace emotion recognition is the common one, usually smuggled in as "call sentiment analysis."
- Add disclosure to every external-facing agent, in every channel it runs in.
- Turn on logging and confirm you can answer "what did this agent do on 12 June and who approved it" in under a minute.
- Set the approval boundary for money, external sends and records of record.
- Run the literacy session. Date it, record it.
- Diary 2 December 2026 (marking, NCII/CSAM prohibitions) and 2 December 2027 (Annex III high-risk). If anything in step 2 landed in high-risk, that second date is a project, not a reminder.
What this means for buying decisions
The delay to December 2027 will be read by some vendors as permission to stop talking about governance. Read it the other way. The obligations arriving in 2027 — logging, human oversight, data governance, technical documentation — are properties of a platform's architecture, not features you bolt on eighteen months from now. A platform that can't tell you today what an agent did last Tuesday will not be able to tell a market surveillance authority in 2028 either.
The questions worth asking a vendor now:
- Which Article 50 duties do you discharge, and which stay with me?
- Is every agent run logged with its tool calls, retained for how long, exportable how?
- Can I require human approval on specific actions, enforced server-side rather than by prompt?
- Where does inference run, and where do logs and data reside?
- If I white-label this, am I the provider?
That's the same list you'd want for choosing an agent platform on purely operational grounds. Which is the honest summary of today: the AI Act didn't ask European businesses to do anything they shouldn't already be doing to run agents they can trust. It just attached a number to not doing it.
OIDO runs AI agents for European businesses with full run-level audit trails, server-side approval gates, and EU data residency. See how the platform handles governance or talk to us about your use case.
Sources
Frequently asked questions
What applies under the EU AI Act from 2 August 2026?
Three things. Article 50 transparency: anyone interacting with your AI system must be told it is an AI, and synthetic content must be disclosed. Article 4 AI literacy: providers and deployers must support AI literacy among staff. And enforcement itself, meaning penalties now bite for everything already in force, including the February 2025 prohibitions, the GPAI obligations from August 2025, and the transparency rules.
Were the high-risk AI rules delayed?
Yes. The Digital Omnibus on AI, signed 8 July 2026 and in force from 27 July 2026, moved Annex III standalone high-risk systems from 2 August 2026 to 2 December 2027, and Annex I product-embedded systems to 2 August 2028. The machine-readable marking duty in Article 50(2) got a grace period to 2 December 2026 for systems already on the market. Nothing else moved.
Is my AI agent a high-risk system?
Most business automation agents are not. High-risk under Annex III means a defined use case: recruitment and worker management, creditworthiness, essential public and private services, education, biometrics, critical infrastructure, law enforcement. An agent that codes invoices, drafts replies or updates a CRM sits outside that list. An agent that screens job applicants sits inside it, and you now have until 2 December 2027.
Do the transparency rules apply to me if I only use AI, not build it?
Yes, in part. Article 50 splits duties between providers and deployers. As a deployer you must disclose emotion recognition and biometric categorisation to the people exposed to it, and label deepfakes and AI-generated text published on matters of public interest. The chatbot disclosure in Article 50(1) is a provider duty, but if you deploy a customer-facing bot under your own brand you are the one the customer will blame, and in many configurations you are also the provider.
What are the fines?
Article 99 sets three tiers. Prohibited practices: up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher. Most other breaches, including Article 50 transparency: up to 15 million euros or 3 percent. Supplying incorrect or misleading information to authorities: up to 7.5 million euros or 1 percent.
What should a mid-sized company actually do this month?
Inventory every AI system you run, classify each as prohibited, high-risk, transparency-only or minimal, add the AI disclosure to anything customer-facing, record what your agents did and who approved it, and get one short AI literacy session done for the teams touching these tools. That is a week of work, not a programme.