Agentic AI is already in enterprise deployment. By the end of 2026, Gartner forecasts 40 percent of enterprise applications will feature task-specific AI agents. By 2028, Deloitte reports 75 percent of organisations intend to deploy agents — while only 21 percent have a mature governance framework to oversee them.
The EU AI Act applies to agents where they are part of a high-risk regulated use case. The Act is technology-neutral by design. Article 3(1) defines an AI system as a machine-based system with varying levels of autonomy that may exhibit adaptiveness after deployment and that infers from input how to generate outputs influencing physical or virtual environments. Every word of that definition applies to an agentic architecture.
But the way an agent satisfies the Act’s essential requirements differs structurally from a static, bounded AI system. Agents plan. They call tools. They execute multi-step workflows without per-action human approval. They send emails, modify databases and post content on behalf of their users. They adapt based on feedback.
The compliance questions change accordingly.
What follows is a practical checklist. If you advise AI providers on compliance, procure agents for enterprise deployment, or build agentic systems and need to understand your obligations, these are the nine things that distinguish compliant agentic AI from a system that has not addressed the essential requirements.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.