Glossary · Chapter 04

EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law. Its core is a risk-based approach: the greater an AI system's risk to people, the stricter the obligations — from “prohibited” down to “no special requirements”. For companies deploying agents it is less a spectre than a blueprint: build identity, oversight, transparency and documentation in from the start, and most obligations are met along the way. This content reflects the post-Digital-Omnibus state of the Act and is not legal advice.

04.01The EU AI Act at a glance

The regulation applies directly in all EU member states and covers anyone who provides or deploys AI systems in the EU — including providers from outside. It sorts AI systems into risk classes with graduated obligations, and adds separate rules for general-purpose AI (the large foundation models). Violations can draw fines of up to €35 million or 7% of global annual turnover. The obligations take effect in stages — the key dates are in the timeline below.

Prohibitede.g. social scoring — Art. 5High-riskstrict obligations — Annex I & IIITransparency-obligedmark & disclose — Art. 50Minimal riskno special requirementsOBLIGATIONS↑ strict↓ noneback-office agents:usually lower tiers
Fig. — The EU AI Act risk pyramid: the higher the tier, the stricter the obligations.

04.02Risk classes

Four tiers. Prohibited practices (Art. 5): e.g. social scoring or manipulative systems — banned in the EU. High-risk (Annex I & III): AI in areas like hiring, credit decisions, critical infrastructure or regulated products — allowed, but with strict duties around risk management, data quality, oversight and documentation. Transparency-obliged (Art. 50): systems that interact with people or generate content — people must be able to tell. Minimal risk: the large remainder, with no special requirements. Most back-office agents sit in the lower two tiers — until their decisions directly affect people.

ExampleThe invoice agent proposing postings: minimal risk or transparency obligations. The same agent used to pre-screen job applications: high-risk under Annex III — with every obligation that entails.

04.03General-purpose AI (GPAI)

The foundation models agents are built on — since 2 August 2025, their providers face dedicated obligations: technical documentation, information for downstream users, a summary of training data, a copyright policy; for the most capable models, additional safety evaluations. For deploying companies this means, practically: model choice is also a compliance decision — and the provider's documentation belongs in your own AI system file.

04.04Article 50 — transparency obligations

The obligation with the biggest day-to-day impact on agents, applicable since 2 August 2026: people must be told when they interact with an AI system, and AI-generated content must be recognisable as such — marked in machine-readable form. For systems already on the market before August 2026, the marking grace period ends on 2 December 2026. Concretely: the agent answering supplier queries identifies itself as a system; the documents it produces carry a marking. Built properly, this is a platform feature, not per-case housekeeping.

04.05Article 14 — human oversight

High-risk systems must be designed so humans can effectively oversee them: understand their limits, interpret outputs correctly, intervene or switch them off. For agentic systems this is the regulatory version of what is operationally wise anyway — exception queues, four-eyes approvals, a stop switch per agent, and operations staff who understand the systems. Build oversight as a feature rather than a form, and Article 14 is met along the way.

04.06Provider vs. deployer

The AI Act assigns obligations by role. The provider develops an AI system and places it on the market; the deployer uses it under their own responsibility. Practically important: substantially modifying a system, or deploying it under your own name, can shift you into the provider role — with its obligations. In agent projects, the role question therefore belongs in the contract: who documents, who monitors, who reports incidents, who is liable for what.

04.07The timeline

The obligations arrive in stages: 2 Feb 2025 — prohibitions and AI-literacy duty · 2 Aug 2025 — GPAI obligations · 2 Aug 2026 — Article 50 transparency obligations · 2 Dec 2026 — end of the marking grace period · 2 Dec 2027 — high-risk obligations under Annex III · 2 Aug 2028 — high-risk AI in regulated products (Annex I). This reflects the Digital Omnibus, which pushed the original high-risk dates back. The sensible order inside a company: inventory and classification first, then marking, then the high-risk files.

04.08AI literacy (Art. 4)

The most overlooked obligation — applicable since 2 February 2025: whoever provides or deploys AI systems must ensure their people have sufficient AI literacy — appropriate to their role and the systems in use. For agent operators this means: the business team working the exception queue must understand what the agent can do, where it errs and when to stop it. That is exactly why this glossary exists.

04.09Sanctions & enforcement

The fine ranges are modelled on the GDPR and exceed it: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for most other violations. Enforcement is national (in Austria coordinated via RTR as the AI service desk) and EU-wide through the AI Office for GPAI. Realistically, enforcement starts not with raids but with questions — and the best answer is a well-kept file: inventory, classification, audit trail.