What a rule is actually aimed at
The abstract version of this debate is about intelligence. The regulated version is about consequences, and the harms are specific enough to write down.
- A decision that affects someone's credit, employment, care or immigration status, taken by a system nobody in the organisation can explain.
- An automated interaction where the person on the other end has no idea they are dealing with a machine.
- Synthetic audio or video that is convincing enough to be used as evidence of something that never happened.
- An agent that holds standing access to a production system and exceeds the authority somebody meant to give it.
- A failure with no record: the organisation cannot say what the system did, on whose instruction, or who approved the exception.
Why agents change the argument
A chatbot that gives bad advice produces an output a person can ignore. An agent that sends the email, updates the record or releases the payment produces a fact. That is the line the regulatory conversation is now crossing, and the industry has been catching up in public. OWASP published a Top 10 dedicated to agentic applications on 9 December 2025, and its entries are dominated by authority failures rather than by bad text: identity and privilege abuse, agents given more agency than the job needs, rogue agents. Gartner predicted in May 2026 that by 2027 40% of enterprises will demote or decommission autonomous agents because of governance gaps found only after a production incident. Note what that says. The gap was there all along, and the incident is what made anyone look.
What the EU AI Act requires, and when
Regulation (EU) 2024/1689 applies in phases rather than on one date, and one of those dates moved recently, so a plan built last year is probably wrong. Enforcement powers for the AI Office and the national market surveillance authorities became applicable on 2 August 2026, which is the month this stopped being a planning exercise.
- 1 August 2024. The Act enters into force.
- 2 February 2025. General provisions, the AI-literacy duty and the prohibited practices apply.
- 2 August 2025. Obligations for general-purpose AI models apply, and member states designate their authorities.
- 2 August 2026. Core enforcement begins for general-purpose AI, the prohibitions, the Article 50 transparency duties and AI literacy.
- 2 December 2026. New prohibitions covering deepfakes and child sexual abuse material, plus a transitional deadline for providers of synthetic content.
- 2 December 2027. The Annex III high-risk rules apply. This is the date that moved: the Digital Omnibus, in force since 27 July 2026, deferred it from 2 August 2026.
- 2 August 2028. High-risk AI embedded in products that are already regulated under Annex I, such as medical devices and machinery.
The penalties are tiered, not a single number
Article 99 is often quoted as one figure, which overstates the exposure of an ordinary deployment and understates the exposure of a prohibited one. A prohibited practice can reach EUR 35 million or 7% of global annual turnover, whichever is higher. A high-risk or transparency breach reaches EUR 15 million or 3%. Giving an authority misleading information reaches EUR 7.5 million or 1%. Small and medium enterprises face the lower figure in each tier. If you are quoting a number to a board, quote the tier that matches what you are actually doing. One more thing to get right in that room. These are ceilings the law allows, not amounts anyone has been ordered to pay. The Commission's own enforcement framework page, dated 24 August 2026, still describes penalties in the conditional, and there is no public record of a penalty decision having been issued. If you meet a specific figure attached to an early case, ask which primary source it came from.
The honest case against, and what survives it
There is a real argument on the other side. Compliance cost lands hardest on the organisations least able to carry it, and a rule written around model capability ages badly, because capability moves faster than legislative drafting. The deferral above is evidence for that view: the high-risk date slipped by 16 months because the obligations were not implementable on the original schedule. My reading is that the durable rules are the ones that regulate what a system is allowed to do rather than how capable it is. An obligation to identify the actor behind an action, to bound what that actor may do, and to keep a record of it will survive the next model release. A threshold expressed in training compute will not.
The questions a rule keeps asking, and where they get answered
Regulation keeps returning to four questions about an automated decision: who acted, what were they allowed to do, who approved the exception, and what is the record. Difinity.ai answers those in the execution path rather than in a report assembled afterwards. An agent holds no credential and cannot reach a system itself, so every action it proposes goes to the tool gateway, which holds the credential, applies the rules the organisation set, then decides and acts. Anything that changes something elsewhere is read by a judge before it runs, and that judge can only refuse or escalate; it can never permit something the deterministic rules already refused. Only the person the agent is acting for may approve one of its actions, and that person is shown the whole action and its arguments rather than a summary. The run trail records the message, each guardrail verdict, each proposed action, the tool gateway's decision, approvals asked for and answered, and the outcome, and it cannot be edited. Governed run records can contribute operational evidence to wider EU AI Act, ISO/IEC 42001, risk, and audit processes. Difinity does not determine that an organisation or AI system is compliant, and it does not provide ISO/IEC 42001 certification.
When this answer changes
Two things move it. If the omnibus process shifts the high-risk date again, read the timeline above against the European Commission's own implementation page rather than against this one; it already moved once, in July 2026. And if your systems only retrieve and summarise, the transparency duties are most of what binds you today, and the rest of this is planning for something you have not built yet. Sourcing caveats, because this page carries dates people will act on. The deferral here comes from the Commission's implementation timeline plus one independent summary, and neither gives the legislative instrument number for the Digital Omnibus itself, so anyone citing it in legal advice should chase that citation. And a story about the first enforcement fines is circulating, with named companies and a total. It is left out of this page because it could not be traced to any European Commission source, and because the Commission's own most recent enforcement statement records no penalty decision at all. Where a striking regulatory number has no primary source behind it, treat it as invented until somebody shows you the decision.
Frequently asked questions
Is AI already regulated, or is this all still coming?
Both. Sector rules for lending, for medical devices, for privacy and for consumer protection already apply to a system that happens to use AI. The EU AI Act adds AI-specific duties in phases, with the prohibitions and general-purpose model obligations already binding and the Annex III high-risk rules due on 2 December 2027.
Does any of this apply to us if we only use someone else's model?
Yes. Obligations attach to the role you play rather than to whether you trained anything. A deployer that puts a model into a decision affecting people carries duties of its own, and the Article 50 transparency duties apply to how you present the system to the people using it.
What happens if an AI agent does something nobody authorised?
Legally, the organisation that deployed it answers for it. There is no version of this where the model is the responsible party. That is the practical reason to bound what an agent may do before it runs, rather than to rely on reviewing what it did.
Should we wait for the rules to settle before building controls?
No, and the timeline is the argument against waiting. Deadlines have moved once already, and every version of every rule asks for the same things: a named accountable owner, bounded authority, and a record of what happened. Build those and the specific dates matter much less.
Sources and further reading
- European Commission, AI Act implementation timeline (retrieved 2 September 2026) (opens in a new tab)
- Regulation (EU) 2024/1689, Article 50 transparency obligations (opens in a new tab)
- Regulation (EU) 2024/1689, Article 99 penalties (opens in a new tab)
- European Commission FAQ on Article 50 transparency obligations (opens in a new tab)
- European Commission, enforcement of AI Act rules and new transparency requirements from 2 August 2026 (opens in a new tab)
- European Commission, the enforcement framework of the AI Act (page dated 24 August 2026) (opens in a new tab)
- OWASP Top 10 for Agentic Applications 2026, published 9 December 2025 (opens in a new tab)
- OWASP Top 10 for Large Language Model Applications, 2025 edition (opens in a new tab)
- Gartner on uniform agent governance and enterprise agent failure, 26 May 2026 (opens in a new tab)