Skip to content

Main Insight

Highlights from Tech Policy Press article “The EU AI Act is Not Ready for Agents,” examining how the EU AI Act applies to AI agents and governance challenges.

EU AI Act meets AI Agents

May 7, 2026

This blog highlights key arguments from our recent Tech Policy Press article, “The EU AI Act is Not Ready for Agents,” on how the relationship between the EU AI Act and AI agents is evolving and the governance challenges posed by increasingly autonomous AI systems. Read the original academic paper and the shorter Tech Policy Press article built upon it.

AI agents, systems that independently pursue complex goals with limited human oversight, have entered the mainstream. They are now widely used to produce software, conduct business activities, and automate everyday personal tasks. But they also introduce unique risks.

Why AI Agents Challenge the EU AI Act

In a new piece published in Tech Policy Press, The Future Society team members Kathrin Gardhouse and Amin Oueslati examine how effectively the EU AI Act—the most comprehensive AI regulation to date—governs AI agents. Our research suggests that the EU AI Act applies to agents in principle, but falls short at the operative compliance layer, as we demonstrate across five governance challenges: performance, misuse, privacy, equity, and oversight. Across each, existing regulatory assumptions begin to strain.

AI Agents and Emerging Governance Risks

Recent incidents underscore these challenges: from agents causing major infrastructure disruptions to cases where they are manipulated into leaking sensitive data. AI agents behave differently from earlier AI models: they operate over extended periods, adapt through interaction, and take actions in the world that may be difficult—or impossible—to reverse.

The Tech Policy Press piece draws on our broader academic paper, which develops these arguments in detail and can be accessed here.

How the EU AI Act Should Account for AI Agents

We do not challenge the Act’s underlying logic, but argue that its operationalisation must better account for AI agents. Upcoming technical standards for high-risk systems offer one such opportunity, while guidance from the AI Office could help clarify how obligations for general-purpose AI models apply in agentic deployment contexts.

For more on agents under the EU AI Act, read our report “Ahead of the Curve: Governing AI Agents under the EU AI Act”, which was the first comprehensive analysis of regulation of AI agents in the European Union.

For more insights, research, and expert analysis, follow The Future Society on LinkedIn.

Team members

Kathrin Gardhouse

Kathrin Gardhouse

Amin Oueslati

Amin Oueslati

Related resources

How To Make International AI Verification a Reality

How To Make International AI Verification a Reality

Countries outside the U.S.–China AI race can build the verification technologies needed to make an international agreement to slow AI development enforceable. This memo suggests research priorities.

What compute on European soil might buy Europe and what it depends on

What compute on European soil might buy Europe and what it depends on

Across Europe, there is growing appetite for locating large compute capacity at home. This post maps what the benefits' proponents claim such a buildout might bring and the key open questions these claims stand or fall on.

Buyer Beware: What AI-Enabled Weapons in Africa Reveal About Verification

Buyer Beware: What AI-Enabled Weapons in Africa Reveal About Verification

AI rules cannot reliably protect people when compliance cannot be checked. In a new CIGI policy brief co-authored by George Gor (TFS) and Kofi Yeboah (Mozilla), AI-enabled weapons in Africa serve as a case study of how procurement and regional verification can test supplier claims, reduce risks to civilians and...

The Case for Cross-Border AI Incident Infrastructure

The Case for Cross-Border AI Incident Infrastructure

AI incidents are scaling fast, and coordinated global governance is lagging behind. This report proposes addressing this challenge through the development of internationally-distributed incident management infrastructure. Our recommendations aim to enable governments, multilateral bodies, and frontier AI companies to jointly detect, prepare for, and respond to AI incidents across jurisdictions.

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

The EU's AI Act and Code of Practice requires providers of the most advanced AI models to meet the ‘state of the art’ (SOTA) in safety and security. In a new policy memo, we argue that SOTA is best understood as a process-driven concept, advanced by the broader expert ecosystem.

Future-Proofing EU AI Gigafactories: Four Design Imperatives

Future-Proofing EU AI Gigafactories: Four Design Imperatives

The EU's AI Gigafactory initiative is its largest planned compute investment to date. Our new memo identifies four imperatives that the initiative must address to deliver on Europe's frontier AI ambitions.