On August 2, 2026, the EU AI Act moved from paper to enforcement. The European Commission's enforcement powers over general-purpose AI went live, fines became real, and the Article 50 transparency obligations started applying to AI systems on the EU market. If you deploy AI agents — chatbots, support copilots, coding assistants, autonomous workflows — that serve anyone in the EU, this is no longer a “someday” regulation.
The timeline, as it stands now¶
- Feb 2, 2025 — Prohibited practices (Article 5) took effect: social scoring, manipulative AI, and similar uses are banned outright.
- Aug 2, 2025 — Obligations for general-purpose AI (GPAI) model providers took effect.
- Aug 2, 2026 — General application: enforcement and fines live, Article 50 transparency obligations apply.
- Dec 2, 2027 — High-risk standalone systems (Annex III) must comply, delayed from 2026 by the Digital Omnibus (Regulation (EU) 2026/1744).
- Aug 2, 2028 — High-risk systems embedded in regulated products (Annex I).
The delay of the high-risk clock is not a holiday. Transparency (Article 50) and AI literacy (Article 4) are live obligations for deployers today; the logging and human-oversight duties in Articles 12, 14, and 26 bind high-risk systems and apply from December 2027 (Annex III). Building logging and oversight now is still the smart move — it is proven good practice ahead of the deadline, not a live legal duty for most deployers.
Are you a deployer or a provider?¶
The Act treats these differently. If you build models or AI systems, you carry provider duties. If you use AI agents inside your company — even agents built on someone else's model — you are typically a deployer, and your duties center on using the system as intended, keeping oversight, and keeping records. Most companies reading this are deployers. This checklist is for you.
The deployer evidence checklist¶
1. An agent inventory with classification. List every AI agent in production: what it does, what data it touches, who it affects. Tag each one against the Act's risk logic: prohibited (stop immediately), high-risk (Annex III use cases like hiring, lending, education), limited-risk (interacts with people or generates content — Article 50 transparency applies), or minimal risk.
2. Automatic logging (Article 12 logic). High-risk systems must automatically generate logs during operation. Even if your agents aren't high-risk, tamper-evident logs of what each agent did, decided, and touched are the single most useful artifact in any audit — or incident. Log the prompt, the tool calls, the decision, and the human who approved it.
3. Human oversight by design (Article 14 logic). Someone must be able to understand, monitor, and intervene in — or stop — the agent. “A human reviews everything” doesn't scale; tiered oversight does: low-risk actions run free within guardrails, high-impact actions (spending money, contacting customers, changing data) require approval.
4. Transparency disclosures (Article 50). If your agent talks to people or generates content, EU users must be told they're interacting with AI, and synthetic content must be marked. This is live now, with a grace period to December 2026 for machine-readable marking on older systems.
5. An incident response runbook. When an agent misbehaves — leaks data, takes a wrong action, gets prompt-injected — who does what in the first hour? Regulators and customers both ask this question after an incident. Having the runbook beforehand is the difference between a bad day and a liability event.
6. Documentation you can hand over. Technical description, intended purpose, known limitations, oversight arrangements, and your logging approach. You don't need a law firm's binder; you need a coherent, current document set.
A 90-day plan¶
Days 1–30: Build the inventory and classify every agent. Kill or fix anything in prohibited territory. Turn on comprehensive logging if it isn't already.
Days 31–60: Implement tiered human oversight — approval gates on high-impact actions. Add AI disclosures to every user-facing agent.
Days 61–90: Write the incident runbook, assemble the documentation pack, and run a tabletop exercise: simulate an agent incident and see whether your evidence holds up.
Start with the building blocks¶
You don't need consultants to begin. Our AI Agent Risk Audit Kit ($19) walks you through inventory and risk-tiering, and the Agent Incident Response Runbook ($19) gives you the incident process. The full system — tiering, approvals, spend controls, audit trails — is in the Studio Edition playbook ($29).
This article is practical guidance, not legal advice. Verify dates and obligations against the current consolidated text of Regulation (EU) 2024/1689 and consult counsel for your situation.