# EU AI Act compliance for AI agents

Updated August 2026. The high risk deadline moved to 2 December 2027. Deferred, not cancelled.

On 7 May 2026 the EU institutions agreed the Digital Omnibus, moving the obligations for Annex III high risk AI systems from 2 August 2026 to 2 December 2027, and for Annex I product embedded systems from 2 August 2027 to 2 August 2028. The Article 50 transparency rules were not deferred and apply now: chatbots must disclose they are AI, synthetic content must be labelled.

## Where the law stands

- 1 Aug 2024: the Act enters into force
- 2 Feb 2025: prohibited practices banned, AI literacy duties begin
- 2 Aug 2025: general purpose AI model obligations apply
- 2 Aug 2026: general application date, Article 50 transparency enforceable, penalty framework live
- 2 Dec 2027: deferred deadline for Annex III high risk systems
- 2 Aug 2028: deferred deadline for Annex I product embedded high risk AI

Scope is extraterritorial: providers placing AI on the EU market and deployers using it in the EU are covered wherever the company is based. Penalties: up to 35 million euros or 7 percent of global turnover for prohibited practices, 15 million or 3 percent for most other breaches, 7.5 million or 1 percent for misleading authorities.

## What teams running agents must have working by December 2027

- Article 12, automatic record keeping: high risk systems must automatically record events over their lifetime. Manual note keeping does not qualify.
- Articles 12 and 26, retention: deployers keep logs at least six months and produce them for market surveillance authorities on request.
- Article 14, human oversight: a person must understand the system, intervene while it runs, and stop it. For agents: approval steps before consequential actions and a kill mechanism that does not depend on the agent cooperating.
- Article 26, deployer obligations: use as intended, assign competent oversight, monitor operation, keep records.
- Article 49, registration: Annex III high risk systems go in the EU database before market placement.
- Article 73, serious incident reporting: within 15 days of awareness, 10 days if a death may have been caused, 2 days for widespread infringements or serious irreversible disruption of critical infrastructure.

## Why the deferral is not a reason to wait

Logs accumulate; they cannot be backdated. Six months of retained history in early 2028 means logging must be running by mid 2027. Oversight is a working muscle, not a policy paragraph. Two day incident deadlines are only meetable if the record already exists. Cloud Security Alliance research found 78 percent of organisations had taken no meaningful steps as of spring 2026.

## How Bridle maps to the Act

Bridle sits in your agents' request path, so the evidence is generated by the act of running: automatic per call logging against named agent identities (Article 12), approval holds and budget kill switches (Article 14), one click evidence pack exports (Article 26), and a minute by minute incident timeline when something goes wrong (Article 73).

Background reading: [What is the EU AI Act](https://agentbridle.com/what-is-the-eu-ai-act.md). Join the beta: https://agentbridle.com/#waitlist

General information, not legal advice.
