The EU AI Act gets teeth on August 2. It still was not written for agents.
The hardest obligations become enforceable in a month. Autonomous agents land inside the definitions by default and inside the gaps by design.
Photo: Night city with abstract digital business interfac. // GaaS News- The EU AI Act's high-risk obligations become applicable on August 2, 2026, two years after the law took effect.
- Agents are not a separate legal category. They fall under the existing definitions of an AI system and a general-purpose AI model.
- The technical standards for meeting the high-risk rules have slipped toward late 2026, so the obligations arrive before the manual for meeting them.
- No liability regime built for autonomous systems is finalized yet, which leaves the question of who pays to older law and national courts.
On August 2, the European Union's AI Act hits the deadline that gives it real force. That is the day the obligations for high-risk AI systems become applicable, two years after the law took effect. For most of the software industry it is a compliance date. For the agent economy it is something odder, because the law was drafted before autonomous agents worked the way they do now.
How the Act sees an agent
The Act does not treat an agent as its own category. By the European Commission's own guidance, agents fall under the existing definitions of an AI system and a general-purpose AI model. An agent is regulated as whatever it runs on and whatever it is used for. If that use sits in a high-risk category, the agent inherits the full high-risk regime, along with the Act's bans on manipulation and on exploiting vulnerable users. Our glossary covers the terms that are about to show up in vendor contracts.
That reads as tidy until you picture what an agent does. It plans, calls tools, and acts across live systems toward a goal you give it. Responsibility for its behavior is split between the model provider, the company that wired it together, and the customer who set the goal. A framework built around systems that mostly produce outputs does not map cleanly onto software that books the flight and moves the money.
Two gaps worth watching
The harmonized technical standards that tell companies how to actually satisfy the high-risk rules have slipped toward late 2026, so the obligations arrive before the instructions for meeting them. And there is still no finalized liability regime built for autonomous systems, which leaves the question of who pays when an agent causes harm to older law and national courts. Analysts at Tech Policy Press have argued the Act is not ready for agents for exactly these reasons.
What operators should do now
None of that moves the date. From August 2, a company running an agent inside a high-risk use, such as hiring, credit, or access to essential services, has to be able to produce the documentation, whether or not the standards behind it are final.
The sane move is to classify before you deploy. Work out whether your agent's job puts it in a high-risk bucket, write down how it reaches decisions, and keep a named human accountable for what it does. Our primer on what GaaS is explains why buying an outcome, rather than a tool, changes who carries the risk. The rules that fit agents are coming. They are simply going to land after the enforcement does.
Sources: European Commission, AI Act framework, EU AI Act Service Desk, Tech Policy Press.