The EU AI Act is already partly in force, and the rest becomes fully enforceable on 2 August 2026. The fine ceiling is €35 million or 7% of global annual turnover. By the time you finish reading, you will be able to turn the Act into an operational plan: classify the use case, position the three frameworks, scope your governance tooling, and brief the board and CEO — the regulatory slice of the control framework gap.
What does the EU AI Act require of organisations deploying agentic AI?
Under the EU AI Act, AI agents are caught by the existing definitions of an AI system and a general-purpose AI model. Scope and obligations flow from the use case. High-risk classification follows Annex III use cases such as employment, credit and education, or a safety-component role under Annex I, and profiling pushes an agent into high-risk regardless of domain. That makes the use case the first thing to pin down.
Full enforcement lands on 2 August 2026, with fines up to €35 million or 7% of global annual turnover. Your obligations are Article 50 transparency, which means disclosing AI interaction and labelling synthetic content; Article 14 human oversight, which means a competent person who can monitor, override and shut the agent down; Article 12 logging, which means tamper-evident reconstruction of what the agent did; and an AI impact assessment, with the heaviest obligations reserved for high-risk systems.
The obligations live in Regulation (EU) 2024/1689: Article 5 on prohibited practices, Articles 9 to 15 and 26 to 27 on obligations, and Article 73 on serious incident reporting. Article 12 requires logs kept for at least six months, and Article 27 makes a fundamental rights impact assessment mandatory for some deployers. The European Commission AI Office FAQ fills in the enforcement detail.
Mayer Brown’s agentic AI governance framework centres on six components: a governance team, data governance, legal compliance evaluation, risk assessment, mitigation measures and documented accountability. That structure shows what the deployer obligations above demand of an organisation in practice.
One early case pointed the same way. In Moffatt v. Air Canada, the airline was held responsible for its chatbot’s misrepresentation, and the “separate legal entity” defence failed. The Act codifies the direction that case signalled.
Most organisations are not ready for this: 78% have not taken meaningful steps toward compliance, and 74% lack a designated internal owner. The governance maturity data behind agent pilots shows the same gap between experimentation and production readiness — the gap regulation within the governance picture is meant to close.
EU AI Act vs NIST AI RMF vs ISO/IEC 42001: how do they compare for agentic AI?
The EU AI Act is binding, risk-tiered law with penalties. NIST AI RMF is voluntary, flexible risk-management guidance with no penalty. ISO/IEC 42001 is a certifiable AI management system with Annex A controls. For agentic AI, assign each framework a distinct role.
The Act sets the legal floor. NIST AI RMF is built around Govern, Map, Measure and Manage and avoids a fixed control set. ISO/IEC 42001:2023 structures 38 Annex A controls across nine objectives into an auditable system. Only the Act can fine you.
All three converge on continuous red-teaming of prompt injection, malicious tool invocation and behavioural drift, plus real-time incident detection. The gap is operational: 60% of organisations cannot terminate AI agents quickly, 63% have no limits on what agents are authorised to do, and 33% lack evidence-quality audit trails.
The voluntary alternatives are under-delivering. Washington State’s AI Task Force, one US state, turned 11 recommendations into only four laws. A Cornell study in PNAS found weak AI regulation can make AI products less safe than none at all. The binding EU regime arrives while those voluntary efforts fall short.
Jurisdiction sharpens it. The EU runs a binding regime, the US a voluntary patchwork, and Australia sits between with no dedicated AI law, yet serving EU users pulls you into scope.
Agentic AI widens the control framework gap that these three frameworks are trying to close, and the pillar overview maps the wider governance picture.
How do I decide whether to build or buy AI governance tooling on a limited budget?
When budgets are constrained, buy the tooling that must run at runtime: logging, oversight, kill switches and incident detection. Build only the lightweight glue your stack uniquely needs. The vendor test is whether the tool governs at runtime.
Treat tooling spend as a trade against the €35 million ceiling. Run the AI impact assessment before agents go live, because it forces the scope conversation early: which agents, which risk tier, which obligations.
The AI governance program lifecycle (inventory, assess, control, monitor, review) maps onto the decision. Discovery and inventory justify purchase because they are broad and repetitive. The impact assessment can stay manual because it is a scoping exercise you run once per use case. Runtime policy enforcement, logging and observability justify purchase because they must operate continuously inside live systems. Reporting and review can stay lightweight because they only summarise what the other layers already record.
A custom-built governance tool can carry roughly $1.2 million in total cost of ownership, which is why purpose-built runtime controls usually win. Ask vendors for specifics on retention, logging visibility, incident response and tenant isolation, and reject vendors that only document at promotion time.
Whatever you buy must support the operating model and oversight you run, and the runtime governance definition is the line you are testing against.
How do I prepare the board and CEO for EU AI Act enforcement and agent liability exposure?
Board and CEO preparation is a communication exercise. Condense the Act into three numbers: the 2 August 2026 enforcement date, the €35 million or 7% fine ceiling, and your governance maturity score. Then ask for two decisions: risk tier and build-vs-buy.
Be direct about liability. Your organisation is responsible for what its agents do, and the Act’s deployer obligations leave no “the vendor is responsible” escape. The regulator’s first question is likely to be who was responsible, and what the governance framework was.
Readiness makes the maturity score concrete. Only 14% of organisations qualify as AI Pacesetters, and Pacesetters lead on governance by a 51-point gap (79% versus 28%). That gap, drawn from the governance maturity data behind agent pilots, is the number your board needs.
Frame governance as a growth lever. Companies with governance tools move more than 12 times more AI projects into production, so governance converts agent experiments into production systems. The oversight model is what makes that accountability demonstrable to the board. Present it that way, and the conversation becomes one about scaling.
Run the Act in order and it becomes a decision sequence: classify the use case, assign each framework a role, buy the runtime controls and build only the glue, then brief the board in three numbers and two decisions. The question that stays with you is the useful one: what risk tier is this use case, what does runtime governance demand, and what do you need the board to approve? Liability for what your agents do is yours to own, and owning it is what makes governance a scaling lever — the thread that runs through the full governance cluster.
Frequently Asked Questions
Does the EU AI Act apply to organisations outside the EU?
Yes. The Act applies extraterritorially: any organisation whose AI system output is used in the EU is in scope, even without an EU office or subsidiary. Australian and US deployers face the same obligations when their agents serve EU users. If your Sydney-based agent handles European customers, classify that use case exactly as you would for a Berlin office.
Is the EU AI Act already in force?
Partly. The Act entered into force on 1 August 2024, and its Article 5 prohibitions and Article 4 AI literacy duties have applied since February 2025. Most remaining obligations become fully enforceable on 2 August 2026. For deployers that means the wait-and-see option is gone: some obligations are already binding, and the deadline is now months away.
Who is liable when an AI agent goes wrong?
The deployer, not just the vendor. Under the Act, the organisation operating an agent carries deployer obligations and cannot hide behind a vendor contract. Courts were already heading the same way: in Moffatt v. Air Canada, the airline was held responsible for its chatbot’s misrepresentation. For an operating deployment, accountability for what the agent does sits with you.
Do I need ISO/IEC 42001 certification to comply with the EU AI Act?
No. ISO/IEC 42001 certification is voluntary and is not a legal requirement of the EU AI Act. It is best treated as an auditable management system that gives your controls structure and evidence, while the Act sets the binding floor. Certification can strengthen your compliance story, but it does not replace risk-tiered classification, transparency, oversight or impact assessment obligations.
Will following NIST AI RMF protect my organisation from EU AI Act fines?
No. NIST AI RMF is voluntary guidance with no penalty regime, so aligning with it does not shield you from EU fines. The frameworks do converge on red-teaming, incident response and continuous risk management, but only the Act can fine you. Treat NIST as the flexible risk posture layered on top of the Act’s binding obligations, not as a substitute.
What does Article 50 transparency require in practice for a customer-facing agent?
You must disclose that customers are interacting with an AI system and label synthetic content, from 2 August 2026. In practice a customer-facing agent should identify itself as AI at the point of interaction and avoid misleading users into believing they are speaking with a human. This duty applies to most agent deployments, regardless of risk tier.
What is Article 4 AI literacy, and who has to comply?
Article 4 requires that staff and others operating or using AI on your behalf have a sufficient level of AI literacy. It applies to virtually every professional AI use, not just high-risk systems. For agent deployments this means training the people who configure, monitor and override agents, and documenting that competence before go-live.
Does the EU AI Act apply to internal-only AI agents?
Yes, if the use case is caught. Internal-only status does not create a safe harbour: an agent used for HR screening, credit decisions or employee monitoring can still be high-risk under Annex III, and Article 4 AI literacy applies broadly. Scope follows the use case and its effect on individuals, not whether the agent faces customers or staff.
When is a fundamental rights impact assessment mandatory?
It is mandatory for certain deployers of high-risk systems, including bodies governed by public law and private providers of essential public services such as credit or insurance. As leading practice most organisations should run one anyway for high-risk agent use cases, because it forces the scope conversation early: which agents, which risk tier, which obligations.
Do SMEs get exemptions under the EU AI Act?
Not a blanket one. Small and medium enterprises get lighter treatment in places, including support through AI regulatory sandboxes and some proportionality in obligations, but high-risk use cases still apply and Article 5 prohibitions bind everyone. The practical rule is to assume no exemption and classify the use case first; size affects proportionality, not scope.
What should we do first to prepare for the 2 August 2026 deadline?
Classify the use case first. Run an AI impact assessment to identify which agents are in scope, which risk tier they fall into and which obligations attach, then map those obligations across inventory, assess, control, monitor and review. That sequence turns the Act from a rulebook into a scoped plan before you spend on tooling or brief the board.