{"id":20888,"date":"2026-04-09T15:11:23","date_gmt":"2026-04-09T15:11:23","guid":{"rendered":"https:\/\/ideainthebox.com\/index.php\/2026\/04\/09\/agentic-ais-governance-challenges-under-the-eu-ai-act-in-2026\/"},"modified":"2026-04-09T15:11:23","modified_gmt":"2026-04-09T15:11:23","slug":"agentic-ais-governance-challenges-under-the-eu-ai-act-in-2026","status":"publish","type":"post","link":"https:\/\/ideainthebox.com\/index.php\/2026\/04\/09\/agentic-ais-governance-challenges-under-the-eu-ai-act-in-2026\/","title":{"rendered":"Agentic AI\u2019s governance challenges under the EU AI Act in 2026"},"content":{"rendered":"<div>\n<p> AI agents hold the promise of automatically moving data between systems and triggering decisions,  but in some cases, they can act without a clear record of what, when, and why they undertook their tasks. <\/p>\n<p> That has the potential to create a governance problem, for which IT leaders are ultimately responsible. If an organisation can\u2019t trace an agent\u2019s actions and don\u2019t have proper control over its authority, leaders can\u2019t prove that a system is operating safely or even lawfully to regulators. <\/p>\n<p> That\u2019s an issue set to become more important from August this year, as enforcement of the EU AI Act kicks in. According to the text of the Act, there will be substantial penalties for failures of governance relating to AI, especially when used in high-risk areas such as when personally-identifiable information is processed, or financial operations take place. <\/p>\n<div id=\"outline-container-org7793118\" class=\"outline-3\">\n<h3 id=\"org7793118\">What IT leaders need to consider in the EU<\/h3>\n<div class=\"outline-text-3\" id=\"text-org7793118\">\n<p> Several steps can be taken to alleviate high levels of risk, and of these, the ones that stand out for consideration include agent identity, comprehensive logs, policy checks, human oversight, rapid revocation, the availability of documentation from vendors, and the formulation of evidence for presentation to regulators. <\/p>\n<p> There are several options decision makers can consider that will help create the record of activities undertaken by agentic systems. For example,  a Python SDK (software development kit), Asqav, can sign each agent\u2019s action cryptographically and link all records to an immutable hash chain \u2013 the type of technique that\u2019s more associated with blockchain technology. If someone or something changes or removes a record, verification of the chain fails. <\/p>\n<p> For governance teams, using <b>a verbose, centralised, possibly-encrypted system of record<\/b> for all agentic AIs is a measure that provides data well beyond the scattered text logs produced by individual software platforms. Regardless of the technical details of how records are made and kept, IT leaders need to see exactly where, when, and how agentic instances are acting throughout the enterprise. <\/p>\n<p> Many organisations fail at this first step in any recording of automated, AI-driven activity. It\u2019s necessary to keep a registry of every agent in operation, with each uniquely identified, plus records of its capabilities and granted permissions. This \u2018agentic asset list\u2019 ties neatly into the requirements of the EU AI Act\u2019s article 9, which states: <\/p>\n<ul class=\"org-ul\">\n<li>Article 9: For high-risk areas, <b>AI risk management has to be an ongoing, evidence-based process<\/b> built into every stage of deployment (development, preparation, production), and be under constant review.<\/li>\n<\/ul>\n<p> Furthermore, decision-makers need to be aware of the Act\u2019s Article 13: <\/p>\n<ul class=\"org-ul\">\n<li>High-risk AI systems have to be designed in such a way that those deploying them can understand a system\u2019s output. Thus, <b>an AI system from a third-party must be interpretable by its users<\/b> (not an opaque code blob), and should be supplied with enough documentation to ensure its safe and lawful use.<\/li>\n<\/ul>\n<p> This requirement means the choice of model and its methods of deployment are both technical <i>and regulatory<\/i> considerations. <\/p>\n<\/div>\n<\/div>\n<div id=\"outline-container-org685ce7c\" class=\"outline-3\">\n<h3 id=\"org685ce7c\">Putting the brakes on<\/h3>\n<div class=\"outline-text-3\" id=\"text-org685ce7c\">\n<p> It\u2019s important for any agentic deployment to offer a facility for <b>the revocation of an AI\u2019s operating role<\/b>, preferably within a matter of seconds. The ability to revoke quickly should be part of emergency response processes. Revocation options should include the immediate removal of privileges, immediate ceasing of API access, and the flushing of queued tasks. <\/p>\n<p> The presence of human oversight, combined with the presentation of <b>enough context for humans to make informed decisions<\/b>, means that human operators must be able to reject any proposed action. It\u2019s not considered adequate for the person reviewing a decision to see only a prompt or a confidence score. Effective oversight needs information around context, every agent\u2019s authority, and time enough to intervene to prevent mis-steps. <\/p>\n<\/div>\n<\/div>\n<div id=\"outline-container-org2ebd0b8\" class=\"outline-3\">\n<h3 id=\"org2ebd0b8\">Multi-agent considerations<\/h3>\n<div class=\"outline-text-3\" id=\"text-org2ebd0b8\">\n<p> While every agent\u2019s action should be recorded automatically and retained, <b>multi-agent processes are particularly complex to track<\/b>, as failures can take place among chains of agents. It\u2019s therefore important for security policies to be tested during the development of any system that intends to utilise multiple agents. <\/p>\n<p> Finally, governing <b>authorities may require logs and technical documentation at any time<\/b>, and will certainly need them after any incident they have been made aware of. <\/p>\n<\/div>\n<\/div>\n<div id=\"outline-container-org3eca632\" class=\"outline-3\">\n<h3 id=\"org3eca632\">Conclusion<\/h3>\n<div class=\"outline-text-3\" id=\"text-org3eca632\">\n<p> The question to be considered by IT leaders considering using AI on sensitive data or in high-risk environments is whether every aspect of the technology can be identified, constrained by policy, audited, interrupted, and explained. If the answer is unclear, governance is not yet in place. <\/p>\n<p><em>(Image source: \u201cLast Judgement\u201d by Lawrence OP is licensed under CC BY-NC-ND 2.0. To view a copy of this license, visit https:\/\/creativecommons.org\/licenses\/by-nc-nd\/2.0)<\/em><\/p>\n<p>\u00a0<\/p>\n<p><a href=\"https:\/\/www.ai-expo.net\/?utm_source=AI-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\"><img class=\"lazyload\" decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" data-orig-src=\"https:\/\/www.artificialintelligence-news.com\/wp-content\/uploads\/2025\/08\/ai-expo-banner-2025.png\"><\/a><\/p>\n<p><strong>Want to learn more about AI and big data from industry leaders?<\/strong> Check out <a href=\"https:\/\/www.ai-expo.net\/\">AI &amp; Big Data Expo<\/a> taking place in Amsterdam, California, and London. The comprehensive event is part of <a href=\"https:\/\/techexevent.com\/\">TechEx<\/a> and co-located with other leading technology events. Click <a href=\"https:\/\/techexevent.com\/\">here<\/a> for more information.<\/p>\n<p>AI News is powered by <a href=\"https:\/\/techforge.pub\/\">TechForge Media<\/a>. Explore other upcoming enterprise technology events and webinars <a href=\"https:\/\/techforge.pub\/events\/\">here<\/a>.<\/p>\n<\/div>\n<\/div>\n<p>The post <a href=\"https:\/\/www.artificialintelligence-news.com\/news\/agentic-ais-governance-challenges-under-the-eu-ai-act-in-2026\/\">Agentic AI\u2019s governance challenges under the EU AI Act in 2026<\/a> appeared first on <a href=\"https:\/\/www.artificialintelligence-news.com\/\">AI News<\/a>.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>AI agents hold the promise of automatically moving data between  [&#8230;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[226],"tags":[],"class_list":["post-20888","post","type-post","status-publish","format-standard","hentry","category-technology"],"acf":[],"_links":{"self":[{"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/posts\/20888","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/comments?post=20888"}],"version-history":[{"count":0,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/posts\/20888\/revisions"}],"wp:attachment":[{"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/media?parent=20888"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/categories?post=20888"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/tags?post=20888"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}