EU AI Act and agent controls

Determine classification first, then bind human oversight and logging controls where required

01 / Source and scope

Who acts, and what changes?

Principal and authority origin

Provider or deployer of an AI system. Provider and deployer governance obligations.

Consequential action

Operate a system that may fall into a regulated risk category.

02 / Action-time control

Make the requested effect testable.

Applicability depends on system classification, role and staged commencement; not every agent is high risk. Determine classification first, then bind human oversight and logging controls where required.

OriginProvider and deployer governance obligations
RequestOperate a system that may fall into a regulated risk category
DecisionEvaluate and enforce before effect

03 / Evidence and responsibility

Permission, execution, and outcome are separate.

Classification rationale, instructions, oversight intervention and logs.

ProofGrid can contribute control evidence, but cannot classify a system or guarantee AI Act compliance.

Primary source

Check the governing material.

Architecture discussion

Map one consequential action from origin to observed outcome.

Request a Conversation