Blog Post

AI Agents Were Never Outside the Definition

September 29, 2026

Table of Contents

The word agent appears nowhere in the AI Act. Some read that absence as a scope question still to be settled, and treat agentic deployments as sitting outside a regime written before they existed.

‍

On its own FAQ the Commission has answered it directly. Agents are not a separate category and the existing definitions already reach them, so nothing needs amending for the rules to apply. Being in scope and being obligated are different things, though, and most of what follows from scope was moved to 2027.

‍

What Has the Commission Said?

‍

The FAQ states that while agents are not a separate category under the Act, the definitions of an AI system and of a general-purpose AI model are sufficient to cover them, so the rules applicable to AI systems and general-purpose models also apply to agents.

‍

The same answer adds that regulatory considerations remain preliminary at this stage, that understanding of what constitutes an agent varies greatly, and that the AI Office continues to monitor developments and may develop further strategies. So the scope answer is settled and the definitional boundary is not.

‍

Which Is a Different Uncertainty Than People Assume

‍

The open question is not whether the Act reaches agents. It concerns where the edges of the term sit, which matters for guidance and standards rather than for whether obligations attach to a given deployment. Working without published standards is the position either way.

‍

Why Doesn't Autonomy Put Them Outside?

‍

Because autonomy is inside the definition rather than an exception to it, which is the cleanest answer to the loophole reading.

‍

Detection detail showing an authorized agent's actions across identity, endpoint, browser and network sources within a three-second window, with a volume figure against the agent's own baseline
An agent acting under valid authorization and inside its permission set is still a machine-based system inferring how to generate outputs, which is what the definition turns on.

Article 3(1) describes a machine-based system that operates with some autonomy and infers how to generate outputs including predictions, content, recommendations or decisions. Operating autonomously is a characteristic the definition anticipates, and there is no carve-out for a system that acts rather than only advises.

‍

Which Explains the Absence of the Word

‍

The Act defines by property rather than by product category, so it reaches technologies named after it was written. The absence of the term is a drafting choice rather than an omission, and the same choice will apply to whatever the next label turns out to be.

‍

What Applies to an Agent Today?

‍

Four things, and none of them is the high-risk file most agent governance work is aimed at.

‍

  • The prohibited practices: In force since February 2025, applying regardless of how a system is built.
  • General-purpose model obligations: Applying to the model provider since August 2025, with Commission enforcement powers for the most advanced models from August 2026.
  • Transparency: Applying from August 2026 where a person interacts with the system or where it generates synthetic content.

‍

The literacy duty completes it, applying to providers and deployers of any AI system with national supervision beginning in August 2026, and sequencing the obligations by date sets out.

‍

What Was Deferred?

‍

The part everybody is working on, which is the inversion worth acting on.

‍

Activity stream showing an agent's session paused after a tool call envelope breach, with the constituent signals from four sources each individually permitted
What an agent did and under whose identity is the record a later classification exercise rests on, and it accrues before any obligation requires it.

Regulation (EU) 2026/1744 deferred Chapter III Sections 1 to 3 to December 2027 for standalone high-risk systems and August 2028 for those embedded in regulated products. Risk management, technical documentation, logging, human oversight, conformity assessment and registration all sit inside that.

‍

An Agent Is Classifiable Now and Obligated Later

‍

An agent screening job applicants or assessing creditworthiness falls in a listed high-risk category today and the duties attaching to that classification start in December 2027. A program building the conformity file first and ignoring transparency and literacy has the sequence backwards.

‍

Does the Retrospective Framing Hold?

‍

Partly, and being precise about which part matters more than the rhetorical version.

‍

An agent deployed a year ago has been within scope for a year, so the classification was always correct rather than newly created. What has not been true for a year is the set of high-risk obligations, since those were never in force and have now moved further out. Saying agents have been regulated all along overstates it, and saying they were outside the Act understates it.

‍

What Was Genuinely Owed Retrospectively?

‍

The prohibitions, which have applied since February 2025 and are absolute. An agent whose deployment falls into a prohibited practice was never permitted, and no deferral touched that. What an agent does that the older tooling cannot see is a separate matter from whether it is in scope.

‍

What Remains Unresolved?

‍

Role allocation across a chain, which the Act did not anticipate and no deferral addresses.

‍

The provider and deployer distinction assumes roles are stable. A deployer configuring an agent with broad tool-calling rights, autonomous decision scope or the ability to spawn sub-agents may be carrying provider-level duties on the strength of that configuration, and the analysis turns on what was configured rather than on what the contract says.

‍

Which Connects to a Decision Being Made Now

‍

Architecture choices determine role, and role determines which obligations arrive in December 2027. The choices are being made today by people who will not be asked about them for eighteen months, and when a deployer becomes the provider sets out where that line sits.

‍

What Should Be Done in the Interval?

‍

Three things, and the first is cheap while the second is the one with a live deadline.

‍

Classify every agent deployment against the high-risk categories, since knowing which ones qualify determines what the later date costs and the exercise needs no standards to be published. Address transparency and literacy now, because those apply today. Then record what each agent did and under whose identity, since a conformity file assembled in 2027 will be evidenced by records that either accrued or did not. An AI Interaction Data Fabric produces the third as a byproduct rather than as a project.

‍

In Scope Since the Beginning, Obligated Later

‍

The Commission has stated on its own FAQ that agents are not a separate category and that the existing definitions of an AI system and a general-purpose model already cover them, so no amendment is needed for the rules to apply. Autonomy sits inside the definition rather than outside it, and the absence of the word agent reflects defining by property rather than by product category. What applies today is the prohibitions, the general-purpose model obligations on the model provider, transparency and literacy. What was deferred to December 2027 is the entire high-risk apparatus most agent governance work is aimed at, so an agent is classifiable now and obligated later. The genuinely unresolved question is also role allocation across a chain, which architecture choices being made today will decide. Kovrr's AI Security and Governance Platform records what each agent reached and under whose identity while the interval runs.

‍

To see which agent deployments would classify as high-risk and what each currently reaches, book a demo mapped to your own estate.

Yakir Golan

CEO

AI Agents and the AI Act FAQs

Speak to an Expert

Are AI agents covered by the EU AI Act?

Does the EU AI Act mention AI agents?

Is autonomy an exception under the EU AI Act?

Which EU AI Act obligations apply to AI agents now?

Are high-risk obligations for AI agents deferred?

Who is the provider of an AI agent?