Solutions
Article 50 disclosure duties for AI agents — in force since 2 August 2026
Compliance for AI Agents
Oversight, disclosure and logging controls for systems that act on their own — built for teams shipping agents, copilots and autonomous workflows.
Autonomous agents that use tools, take actions, and chain steps raise AI Act questions standard checklists miss. We map your agentic workflows to the Act and deliver a control set built for systems that act on their own.
Where this fits. EU AI Act Readiness tells you what the Act requires of your systems generally. AI Governance & Documentation builds the artifacts. This page is the specialized lane for one class of system — autonomous agents acting in consumer funnels — where the exposure is concentrated, live today, and enforced on both sides of the Atlantic.
Common challenges
General AI checklists don’t account for systems that take real-world actions — sending messages, moving money, changing records.
Telling when an autonomous workflow crosses into the Act’s high-risk tier — or across a prohibited-practice line.
Turning a third-party general-purpose model into an agent can quietly change your role — and your obligations.
Article 14 oversight and Article 12 logging are hard to apply to fast-chaining agents where a human can’t naturally intervene in time.
Why agents are getting their own scrutiny
The direction of travel is explicit. The Commission’s 2026 classification guidance singles out agentic AI systems for closer scrutiny — including the expectation that providers monitor what their agents actually do in production, not merely what the terms and conditions say they do. And since 2 August 2026, Article 50 requires people to be told when an AI is acting — including an agent acting on a user’s behalf. For agentic teams, ‘our policy prohibits it’ is no longer an answer if the agent’s logs show otherwise. Closing that gap between paper compliance and control is exactly what this engagement does.
Illustrative agent trace — the control set in action
Illustrative only. A composed example of the four controls, not a real system, client or product.
Our approach
Workflow mapping
For each agent or automated workflow: what it does, what tools and actions it can trigger (sending messages, moving money, changing records, calling external systems), and how much it decides without a human.
Classification handoff
Where autonomy shifts each workflow’s position under the Act — the high-risk uses an acting agent can drift into and the prohibited-practice lines it can cross. Full system classification is our EU AI Act Readiness assessment; this engagement starts where it ends and goes deeper on the agent-specific risks.
Human-oversight reviewArt. 14
The control points, approvals, and stop/override mechanisms your agents need, and where today’s design leaves a person unable to intervene in time.
Transparency & disclosureArt. 50
Where users and affected third parties must be told they’re dealing with an AI agent — a live obligation since 2 August 2026, which the Commission’s final Guidelines apply expressly to agents acting on someone’s behalf and do not allow to be buried in terms or settings.
Logging & traceabilityArt. 12
What agent actions you need to record to show what happened and why.
Role & dependency check
Whether wrapping a general-purpose model into an agent makes you a provider, and which GPAI-linked obligations follow.
The deliverable
A workflow-by-workflow control checklist plus a prioritised gap report, in plain language your engineering team can act on.
Who it’s for
Agentic SaaS, AI-native products, and any company giving an LLM the ability to take real-world actions.
Hiring, credit, healthcare, critical services — where autonomy meets the Act’s strictest expectations.
Fast-chaining workflows where oversight has to be designed in, because nobody can watch in real time.
FAQ
The Act doesn’t have a separate “agent” category — but autonomy, tool use, and the ability to act change how its existing rules apply to you. Higher autonomy tends to mean higher risk, stricter human-oversight expectations, and more to log. We assess your agents against the rules as they actually apply.
Usually yes. Deploying agents based on someone else’s model still brings obligations, and turning a general-purpose model into an agent can make you a provider in your own right. We map which role you hold and what follows from it.
Sequence and depth. The general Readiness assessment classifies any AI product and maps its obligations — it answers what you owe. This engagement is the specialized lane for agents: it builds and tests the controls autonomy demands — oversight points, stop/override mechanisms, disclosure moments, action logging — which a general assessment names but does not design. Most agentic teams run Readiness first; some come straight here when the agents are already live.
See where your agents stand
Walk us through what your agents can do and where a human sits in the loop. You get a workflow-by-workflow control checklist and a prioritised gap report your engineering team can act on.
Get the agent control reviewStart upstream: EU AI Act Readiness · AI Governance & Documentation
General information about the EU AI Act. It is not legal advice, and a control review is not a guarantee of compliance.