AI Regulatory Intelligence — by YRproject

factual analysis · traceable to primary sources

Explainer

Agentic AI: how do autonomous AI agents fall under the rules?

Adopted 2026-06-19 · ≈ 3 min read · Dirk Baaijen

Agentic AI — systems that plan, use tools and take actions on their own — has no dedicated category in the AI Act. Yet it is covered: through the GPAI regime, risk classification that follows the use, and the transparency and human-oversight duties. Open question: liability for autonomous actions.

Short answer: Agentic AI — systems that turn goals into steps, call tools and APIs, and take actions on their own — has no separate category in the AI Act. Yet it is not unregulated: the underlying model often falls under the GPAI regime, risk classification follows the concrete use, and the duties on transparency (Art. 50) and human oversight (Art. 14) apply in full. The sharpest open question is who is liable for what an agent does autonomously.

What sets agentic AI apart

Generative AI produces output on request: text, images, code. Agentic AI goes a step further. Such a system turns a goal into a plan, calls tools or APIs on its own, takes actions, and can thereby bind a user to consequences — sometimes with only limited human oversight. Think of an agent that schedules appointments, places orders, runs code or enters into obligations on a user's behalf.

The difference is not academic: it shifts the risk from "wrong output" to "wrong action".

The AI Act has no separate "agent" category

The AI Act is structured around the risks of AI systems, not around agents as a distinct species. Even so, agentic AI is covered along four lines:

  • The underlying model. If the agent is built on a general-purpose AI model, the GPAI obligations (Art. 53 and 55) apply to that model. See the GPAI regime.
  • Risk classification follows the use. If the agent is deployed in an Annex III context (for example recruitment, lending or critical infrastructure), the system is high-risk, with all the attendant duties. See the high-risk obligations.
  • Transparency (Art. 50). A user interacting with an AI system must be aware of it. See Article 50.
  • Human oversight (Art. 14). For high-risk systems a human must be able to intervene effectively — precisely the point that rubs against the autonomy that makes an agent useful.

The open question: who answers for what the agent does?

The AI Act was written before the breakthrough of agents. As systems carry out irreversible actions — a transaction, a message sent, a change in production code — the liability question becomes pressing: does responsibility lie with the provider of the agent, with the organisation deploying it (the deployer), or with the provider of the underlying model? Beyond the AI Act this touches product liability and contract law — a knot that legislators and courts have yet to cut.

International movement

Soft law runs ahead of legislation here. On 22 January 2026, at the World Economic Forum, Singapore presented its Model AI Governance Framework for Agentic AI — the world's first framework built specifically for agentic AI. It is voluntary, but stresses human accountability and "bounding by design": limit what an agent can do by constraining its tool access, permissions and scope of action. In the US, NIST is building dedicated single-agent and multi-agent control overlays on SP 800-53 through COSAiS (Control Overlays for Securing AI Systems), and in February 2026 launched an AI Agent Standards Initiative. The common thread: existing rules are not replaced, but supplemented with expectations on how to govern a system that acts on its own.

What to do

  • Treat an agent as high-risk until a classification shows otherwise — the impact of a wrong action is greater than that of wrong output.
  • Build human checkpoints before irreversible actions (payments, external communication, production changes).
  • Log and monitor every action so there is an audit trail of what the agent did and why.
  • Set contractual terms with the agent and model provider on responsibility, limits and indemnification.

Agentic AI is where the governance question of 2026 becomes sharpest: the technology runs ahead of the categories the law works with, and the first organisation that can demonstrably govern its agents has the edge.

Sources

  1. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
    Regulation (EU) 2024/1689 (AI Act), Art. 14 (human oversight), 50 (transparency), 53 and 55 (GPAI).
  2. https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai
    IMDA Singapore — Model AI Governance Framework for Agentic AI (22 January 2026), the world's first.
  3. https://www.nist.gov/itl/ai-risk-management-framework
    NIST AI Risk Management Framework; COSAiS builds single-/multi-agent overlays on SP 800-53.

Share on LinkedIn

Read next

A

AI for strategic workforce planning: usually not high-risk, as long as it does not become individual

AI for strategic workforce planning and skills forecasting at organisation level is usually not high-risk under the AI Act. But once it steers individual decisions, it can tip over. Data quality, governance and transparency remain crucial.

U

AI and insurability: covering AI risks and liability

Whether AI harm is insured depends on the policy, not the AI Act. The revised Product Liability Directive widens liability exposure, while insurers struggle with opaque, self-learning and agentic systems.

W

The most common AI Act mistakes and how to avoid them

The biggest AI Act pitfalls are not exotic edge cases: overlooking hidden AI, misjudging your role, classifying too heavily or too lightly, forgetting transparency, and treating compliance as a one-off project.

Dirk Baaijen

About this knowledge base

Compiled and maintained by YRproject — programme and project direction at the intersection of digital transformation, AI and regulation. Every factual claim is traceable to its primary source. YRproject is led by Dirk Baaijen About & method →

A project or programme? Work with YRproject →

The monthly briefing

AI regulation in five minutes: what changed, what is coming and what it means. No spam, unsubscribe anytime.

Your address is used for this only and stored on our own servers.