ApexClaw
HomeRegions › European Union
REGIONAL GOVERNANCE

AI agent governance in the European Union

An AI agent operating in the EU is governed less by a single agent law than by the intersection of the AI Act, sectoral regimes like DORA, and national implementations. The practical requirement is consistent across all of them: an action taken by software must be attributable, overseen, and reconstructable after the fact.

Get an Agent Trust Gap Brief

The short answer

There is no EU "agent act". There is the AI Act, whose obligations attach to risk classification and role — provider, deployer, importer — not to whether the system is agentic. Most enterprise agents are not high-risk systems. That does not make them unregulated: transparency duties, general-purpose model obligations upstream, DORA for financial entities, GDPR wherever personal data moves, and national measures all continue to apply.

The Digital Omnibus changed timing, not direction. The package deferred and simplified parts of the AI Act's application. Deferral is not repeal — the obligations that were already in force stayed in force, and the ones deferred are still coming. Planning as though the clock stopped is the error we see most often.

The durable position is to build the evidence an auditor will ask for regardless of which date applies: who authorised this action, under which policy, on what basis, and can you show it.

The instruments that actually bind

Named, dated, and separated from the guidance that carries no force of law. Where an instrument does not mention agents directly, that is stated rather than implied away.

InstrumentWhat it isBearing on agents
EU AI Act (Reg. 2024/1689)Risk-tiered horizontal regulation. Obligations follow classification and role.Applies by risk tier, not by agentic architecture. Transparency, logging, human oversight and record-keeping duties are the ones agent deployments hit first.
Digital OmnibusSimplification and deferral package amending application timing.Moved dates and eased some burdens. Did not remove the underlying duties. Confirm which dates bind your classification.
DORA (Reg. 2022/2554)Digital operational resilience for financial entities.ICT risk management, incident reporting and third-party oversight. An agent acting on financial systems is ICT, and its provider is a third party.
GDPR (Reg. 2016/679)Data protection.Art. 22 on automated decision-making with legal or similarly significant effects is the article agent deployments most often trip. Lawful basis and minimisation apply to everything the agent reads.
Italy Law 132/2025First national AI law in a member state.Sectoral duties and national oversight layered on the AI Act. Relevant if you deploy into Italy.
Spain — AESIANational AI supervisory agency.An operating national supervisor. Where a member state has stood one up, expect earlier and more specific enquiries.

Last verified 2026-08-07. This is a summary of published instruments for orientation, not legal advice. Obligations depend on your role, deployment and sector — confirm against the primary text and your counsel.

What this means for an agent deployment

Regulation in this region does not generally name "AI agents". It names outcomes: traceability, human oversight, accountability for automated decisions, incident reporting. An agent that acts — books, pays, sends, changes records — has to produce evidence of those properties on demand.

  1. Classify honestly before you architect. Most of the disagreement about EU obligations is really disagreement about classification. Write down the risk tier and the role, with reasoning, and keep it under version control.
  2. Log at the decision, not just the output. Record-keeping duties are satisfied by evidence of why an action was permitted — the policy consulted, the inputs, the human who approved — not by a transcript of what the model said.
  3. Make human oversight real and provable. An oversight claim you cannot evidence is a finding waiting to happen. If a person approved an action, the approval should be a signed artifact tied to that specific action.
  4. Treat Art. 22 as a design constraint. If an agent's action produces a legal or similarly significant effect on a person, the path to human review has to exist before deployment, not after a complaint.
  5. For financial entities, map to DORA's incident clock. Agent misbehaviour that degrades a critical function is an ICT incident with reporting timelines attached.

Common questions

Does the EU AI Act regulate AI agents specifically?

Not as a named category. Obligations attach to risk classification and to your role — provider, deployer, importer, distributor. An agent is governed by the tier its use case falls into, plus whatever sectoral and data-protection law already applied.

Did the Digital Omnibus cancel the AI Act?

No. It deferred and simplified parts of the application timetable. Duties already in force remained, and deferred duties are still scheduled. Confirm the dates that apply to your specific classification against the amended text.

What is the single most useful thing to build for EU readiness?

A per-action evidence record: what the agent tried to do, which policy allowed or blocked it, who approved it if approval was required, and what actually happened. That artifact satisfies record-keeping, supports oversight claims, and shortens every enquiry.

Does DORA apply to our AI vendor?

If you are a financial entity in scope, your ICT third-party providers fall within your oversight and contractual obligations. An agent platform that touches critical or important functions is squarely in that conversation.

Is GDPR Article 22 triggered by an agent?

It depends on effect, not autonomy. If a decision produces legal or similarly significant effects on a person and is made without meaningful human involvement, Art. 22 is in play — regardless of whether the software is called an agent.

What a supervisor asks under the EU regime

The control set barely changes across jurisdictions; the interrogation does. These are the instruments an examiner cites here, and the question each one turns into.

InstrumentStatusWhat the examiner actually asks
EU AI Act (risk tiers)In force; obligations phasing, Digital Omnibus deferral in playWhich risk tier does the agent's use case fall in, and where is the logging and human-oversight evidence?
GDPR Art. 22In forceIs there a solely-automated decision with legal effect, and what is the safeguard and human review path?
DORA (financial entities)In force Jan 2025Is the agent an ICT-driven process in scope, and can you evidence resilience and third-party risk controls?

Instruments and dates as verified 2026-08-12. Not legal advice.