The EU AI Act and AI agents
The EU AI Act (Regulation (EU) 2024/1689) sets obligations according to risk. For high-risk AI systems it requires, among other things, automatic event logging (Article 12) and effective human oversight (Article 14), and it gives the organisations deploying them duties to monitor use and keep logs (Article 26). For AI agents that act on real systems, those duties become concrete controls: enforced approval points, a complete record of what the agent did, and the ability to stop it.
Is your agent high-risk?
It depends on what it is used for, not on the technology. The Act lists high-risk areas in Annex III — among them creditworthiness assessment of individuals, risk assessment and pricing in life and health insurance, access to essential public and private services, employment decisions and critical infrastructure. Many agents will not be high-risk, although transparency and general-purpose AI obligations can still apply. Classification is a legal assessment for your organisation to make.
Human oversight (Article 14), for an agent
Article 14 asks that the people overseeing a high-risk system can understand its capabilities and limits, stay alert to over-reliance on it, decide not to use its output, and intervene or stop it.
- Approval points before consequential actions, enforced by the platform.
- The ability to cancel a run, and budgets that stop it on their own.
- The evidence the agent relied on, shown to the person deciding.
- Refusals and stop reasons that are visible, not silent.
Record-keeping (Article 12) and deployer logs (Article 26)
Article 12 requires high-risk systems to allow automatic recording of events over their lifetime, so their operation can be traced. Article 26 asks deployers to keep the logs under their control for a period appropriate to the purpose — at least six months unless other law says otherwise. For an agent that means recording each request, each proposed action, each decision and approval, and each result.
When it applies
The Act entered into force on 1 August 2024 and applies in stages: prohibited practices from 2 February 2025, general-purpose AI obligations from 2 August 2025, and most remaining obligations from 2 August 2026, with some product-related high-risk obligations later. EU proposals to adjust some high-risk dates have been under discussion, so check the current official timeline for your case.
What a platform can and cannot do
A platform can provide the controls and the evidence an assessment asks for. It cannot make an organisation compliant — that depends on the use, the classification, the organisation’s processes and its people. This guide is general information, not legal advice.
- Enforced approval chains before consequential actions, with quorum and separation of duties — oversight a person can exercise.
- Runs that can be cancelled, and iteration, time and cost budgets that stop them on their own.
- A per-company, tamper-evident record of requests, decisions, approvals and results, with retention you set.
- Exposure policy that limits what data reaches a model, and evaluation records for agent behaviour.
Asked often.
Answered plainly.
Does using A2A Matrix make us compliant with the EU AI Act?+
No platform can do that on its own. Compliance depends on your use, its classification and your organisation. A2A Matrix provides controls and evidence your assessment will ask for.
Are AI agents high-risk under the EU AI Act?+
Only if their use falls in a high-risk category, such as those listed in Annex III. The same agent technology can be high-risk in one use and not in another.
How long do logs have to be kept?+
For deployers of high-risk systems, Article 26 says at least six months, unless other EU or national law requires otherwise. Sector rules are often longer.
What does human oversight mean in practice for an agent?+
That a person can see what the agent relied on, approve or refuse consequential actions before they happen, and stop a run — enforced by the platform, not left to the model.