# What is the EU AI Act? A plain English guide for teams running AI agents

Updated August 2026. General information, not legal advice.

The EU AI Act is the world's first comprehensive law regulating artificial intelligence. It entered into force on 1 August 2024 and has switched on in stages. On 2 August 2026 the transparency obligations became enforceable, while the Digital Omnibus agreement of 7 May 2026 deferred the high risk obligations to 2 December 2027.

## Who it applies to

The Act is extraterritorial, like the GDPR. It covers providers who place AI systems on the EU market and deployers who use them in the EU, wherever those companies are based. A US or UK company selling into Europe is in scope.

## The four risk tiers

- Prohibited: banned outright since February 2025 (social scoring, harmful manipulation, scraping facial images at scale, emotion recognition at work and school).
- High risk: AI in hiring, credit, insurance, education, critical infrastructure, medical devices, law enforcement. Full compliance programme: risk management, documentation, record keeping, human oversight, registration.
- Limited risk: transparency duties. Chatbots must disclose they are AI; synthetic media must be labelled.
- Minimal risk: most software. No new obligations.

General purpose AI models got their own obligations from August 2025.

## Timeline

- August 2024: entry into force
- February 2025: prohibitions and AI literacy duties
- August 2025: general purpose AI model rules
- August 2026: general application date, Article 50 transparency obligations enforceable
- December 2027: deferred deadline for Annex III high risk systems (Digital Omnibus)
- August 2028: deferred deadline for high risk AI embedded in regulated products

## What it means for AI agents

An agent that calls APIs, sends emails, or moves money is performing actions, and that action layer falls under the Act's logging and cybersecurity expectations. Three articles do most of the work:

- Article 12, record keeping: automatic event logging, kept generally at least six months.
- Article 14, human oversight: a person must understand, intervene, and stop the system. Risky actions should wait for a human.
- Article 26, deployer obligations: use as intended, assign competent oversight, keep logs, monitor operation.

In chains of agents, the compliance boundary follows every agent performing a high risk function. If you cannot say which agent did what, on whose behalf, at what cost, you cannot meet the record keeping duty.

## Penalties

Up to 35 million euros or 7 percent of global turnover for prohibited practices; up to 15 million euros or 3 percent for most other breaches.

## What to do now

1. Inventory your AI systems and agents.
2. Classify against the risk tiers.
3. Turn on logging where the work happens, in the request path.
4. Give agents named identities, budgets, a stop mechanism, and human approval on risky actions.
5. Keep evidence exports ready.

Bridle does steps 3 to 5 as a byproduct of running your agents through one gateway: see [EU AI Act compliance](https://agentbridle.com/eu-ai-act.md) or join the beta at https://agentbridle.com/#waitlist.
