For CISOs and compliance heads whose EU AI Act programmes are focused on model classification but have not yet addressed the agent-level obligations that are already in force.
The EU AI Act is now substantively in force. Most enterprise compliance programmes have responded by doing one thing: classifying their AI systems by risk tier. General-purpose AI models - minimal risk. Internal productivity tools - limited risk. Systems making decisions about employment, credit, or insurance - high risk, requiring conformity assessment, human oversight mechanisms, and detailed technical documentation.
This risk classification exercise is necessary. It is also incomplete in a way that most compliance teams have not yet recognised - because it focuses on AI systems as defined at the point of deployment, not on AI agents as they operate in production.
The distinction matters because an AI agent is not a static system. It is a dynamic actor that makes decisions, calls external data sources, and takes actions - often in combinations and sequences that were not fully specified at the time the system was classified. An agent classified as limited-risk at deployment may, in the course of its operation, access personal data, make employment-related recommendations, or trigger financial transactions in ways that push its functional behaviour into high-risk territory even if its system-level classification did not anticipate it.
Where the agent-level obligations begin
The EU AI Act’s high-risk category includes AI systems used in employment contexts - recruitment, performance evaluation, task allocation - and in access to financial services, including credit scoring and risk assessment. These are not edge cases for enterprise AI deployment. They are core use cases.
An AI agent that accesses HR data to make workflow recommendations sits in employment-related AI territory. An agent that reads income and employment data to assist with credit assessment decisions is in financial services AI territory. Under the EU AI Act, both of these trigger specific obligations that go significantly beyond what a standard AI governance programme typically addresses.
The obligations that most compliance teams have not yet fully mapped to their agent deployments:
Human oversight requirements. High-risk AI systems must be designed to allow natural persons to effectively oversee their operation.
For AI agents making or informing consequential decisions, this means there must be a defined mechanism for human review - not just a theoretical ability to override, but a documented, operational oversight process that is actually used.
Transparency and explainability. The output of high-risk AI systems must be interpretable by the humans overseeing them.
For an AI agent that reaches a credit recommendation through a multi-step reasoning process involving several data sources, the agent’s output needs to be explainable to the human reviewing it - what data it used, what logic it applied, why it reached the conclusion it did.
Data governance and record-keeping. High-risk AI systems must maintain logs that allow post-hoc auditing of their decisions.
For AI agents accessing personal employment or financial data, this means the data accessed, the decisions made, and the actions taken must be logged in a format that is auditable, for a retention period that satisfies regulatory requirements.
Accuracy and robustness. High-risk AI systems must achieve appropriate levels of accuracy and be robust to errors and inconsistencies.
For agents making decisions on the basis of data retrieved at runtime, this includes the accuracy of the underlying data - stale or incorrect input data is a robustness failure that falls within the Act’s accuracy obligations.
“Most compliance teams are treating the EU AI Act as a model classification exercise. The agent-level obligations - human oversight, explainability, audit logs, data accuracy - are the harder requirements, and they apply to systems that are already in production.”
The audit log requirement is the most immediate gap
Of the obligations listed above, the audit log requirement is the one where the gap between regulatory expectation and current enterprise practice is most acute - and most immediately addressable.
The EU AI Act requires that high-risk AI systems automatically generate logs of their operation to the extent necessary to identify situations that may result in a risk to health and safety or fundamental rights. For agents operating in employment and financial services contexts, this covers decisions about employment-related recommendations, credit-related assessments, and any action taken on the basis of personal data.
The practical question is: do you have an audit log for every data access event, every decision step, and every action taken by each AI agent operating in a high-risk context? Not a general system log. A per-agent, per-action log that is queryable, tamper-evident, and retained for a period consistent with the Act’s requirements.
Most enterprises do not.
The agents are in production. The decisions are being made. The data is being accessed. The log that the regulation requires exists only partially - perhaps at the application level, perhaps at the infrastructure level, but rarely as a comprehensive, agent-specific record that captures what the agent accessed, what it decided, and what it did, in a format that can be presented to a regulator.
The data accuracy obligation and the input data gap
The accuracy and robustness obligations in the EU AI Act have a dimension that most AI compliance programmes have not connected to their data infrastructure: the accuracy of the data that high-risk AI agents operate on is a compliance obligation, not just an operational concern.
An agent making a credit-related assessment on the basis of employment data that is two weeks old - sourced from a batch-sync cache rather than a live connection to the employer’s HRIS - is operating with input data whose accuracy cannot be guaranteed at the time of the decision. Under the Act’s robustness requirements, this is not a model quality problem. It is a system design problem that the deploying organisation is responsible for.
The practical implication: for AI agents operating in high-risk EU AI Act contexts and accessing employment or financial data, the data source architecture matters for compliance, not just for operational quality. Live, consent-based, auditable data access is not just better engineering - it is a compliance posture that is significantly more defensible than cached or document-based alternatives when a regulator asks how the system’s input data accuracy was ensured.
What the compliance programme needs to add
For organisations with AI agents already in production in employment or financial services contexts, the EU AI Act compliance gap can be addressed through a focused set of additions to the existing programme.
Agent-level risk classification review. Each agent in production should be assessed not on its system-level classification at deployment but on its actual functional behaviour - what data it accesses, what decisions it informs, what actions it takes. If that functional behaviour falls into high-risk territory, the high-risk obligations apply regardless of the original classification.
Audit log implementation for in-scope agents. For agents identified as high-risk, a per-agent audit log needs to be implemented - capturing data access events, decision steps, and actions taken, in a tamper-evident format, retained for the required period. This is most efficiently done at the data access layer rather than built separately into each agent.
Human oversight documentation. For each high-risk agent, there must be a documented human oversight process - who reviews the agent’s outputs, under what circumstances, and what the escalation path is when the agent’s decision requires human intervention. This documentation needs to reflect actual practice, not theoretical capability.
The EU AI Act is not waiting for enterprise compliance programmes to catch up with agent deployments. The obligations are in force now. The agents are in production now. The gap between the two is the compliance risk that most enterprise AI governance programmes have not yet closed - and the window for closing it proactively, rather than in response to a regulatory inquiry, is narrowing.







