Source-linked AI summary

Regulating AI Agents

Kathrin Gardhouse, Amin Oueslati, Noam Kolt

arXiv:2603.23471v2cs.CY

TL;DR

AI agents create governance challenges because they operate across contexts, can change behavior, and interact with other agents, while existing safeguards often assume fixed systems and bounded deployments. The paper examines the EU AI Act’s substantive provisions and institutional implementation through agentic evaluations, equity and privacy analysis, oversight requirements, and regulatory-capacity evidence. It finds that the Act applies in principle but is poorly fitted in practice, requiring stronger technical expertise and operational capacity from regulators.

  • Problem

    The paper asks whether the EU AI Act adequately addresses governance challenges arising from autonomous, adaptive, and interacting AI agents.

  • Method

    The paper analyzes agentic evaluations, privacy and equity risks, oversight obligations, enforcement transparency, and the EU AI Office’s staffing and compensation.

  • Results

    The analysis finds that the AI Act applies to AI agents in principle but falls short in practice because its assumptions about fixed artifacts, fixed assessments, and predefined actors do not fit agentic risks.

  • Takeaways & Limitations

    Effective governance requires expanding regulators’ technical expertise and operational capacity beyond refinement of existing legislative instruments.

Abstract

from arXiv · show

AI agents -- systems that can independently take actions to pursue complex goals with only limited human oversight -- have entered the mainstream. These systems are now being widely used to produce software, conduct business activities, and automate everyday personal tasks. While AI agents implicate many areas of law, ranging from agency law and contracts to tort liability and labor law, they present particularly pressing questions for the most globally consequential AI regulation: the European Union's AI Act. Promulgated prior to the development and widespread use of AI agents, the EU AI Act faces significant obstacles in confronting the governance challenges arising from this transformative technology, such as performance failures in autonomous task execution, the risk of misuse of agents by malicious actors, and unequal access to the economic opportunities afforded by AI agents. We systematically analyze the EU AI Act's response to these challenges, focusing on both the substantive provisions of the regulation and, crucially, the institutional frameworks that aim to support its implementation. Our analysis of the Act's allocation of monitoring and enforcement responsibilities, reliance on industry self-regulation, and level of government resourcing illustrates how a regulatory framework designed for conventional AI systems can be ill-suited to AI agents. Taken together, our findings suggest that policymakers in the EU and beyond will need to change course, and soon, if they are to effectively govern the next generation of AI technology.

A. Definitions

The EU AI Act generally captures AI agents as AI systems, but its most demanding obligations depend on high-risk classification. For agents, uncertainty about intended use creates a risk that systems with significant real-world impact remain outside core requirements.

  • The Act defines AI systems as machine-based systems operating with varying autonomy that infer outputs affecting physical or virtual environments.
  • Most substantive obligations apply only to systems classified as high-risk under product-safety rules or specified Annex III application areas.
  • For AI agents, high-risk status turns partly on intended use, but it remains unsettled whether authorities may examine deployment beyond a provider’s stated characterization.
  • Recent Commission draft guidelines would treat GPAI systems as high-risk unless providers explicitly limit intended purposes and exclude high-risk uses across relevant materials.
  • GPAI models cover broad task competence and downstream integration, while systemic risk concerns high-impact capabilities with significant effects that can propagate at scale.

B. Value Chain Governance

The AI Act distributes governance across GPAI model providers, AI system providers, and deployers, but effective risk management for AI agents depends on coordination across these roles. Because deployment-specific risks cannot be fully anticipated upstream, mitigation must be refined iteratively in use.

  • The Act adopts a value-chain model distinguishing GPAI model providers, AI system providers, and AI system deployers.
  • Risk mitigation is interdependent across the value chain and requires timely access to relevant knowledge rather than responsibility confined to one actor.
  • System providers integrating GPAI models depend on upstream assurances about model behavior and access to information about model limitations.
  • Model providers cannot fully anticipate risks arising from a model’s specific agent architecture, tools, and operating environment, so risk management must be refined during deployment.
  • Model-level interventions can address some risks more reliably than requiring every downstream agent developer to implement overlapping safeguards.

C. The GPAI Code of Practice

The GPAI Code of Practice operationalizes systemic-risk obligations through voluntary compliance, structured testing, assessment, and monitoring. Its approach explicitly evaluates models in agentic settings, including tool use, sequential actions, adaptive learning, and coordination risks.

  • The Code of Practice is voluntary, but adherence provides a presumption of conformity with corresponding AI Act requirements.
  • Its Safety and Security chapter addresses GPAISR providers and begins with a framework for identifying systemic risk.
  • The Code uses two tracks: providers assess capabilities and deployment manifestations, then evaluate statutory criteria including high-impact capabilities, significant EU effects, and propagation at scale.
  • Evaluations must be open-ended and examine models integrated into agents that sequence actions, use tools, and pursue goals over time.
  • Risk assessment combines model evaluation, scenario-based modeling, harm estimation, postmarket monitoring, and an acceptability determination.
  • Where risks are unacceptable or foreseeably may become so, providers must restrict or refrain from deployment and repeat the assessment process after implementation.

II. GOVERNANCE CHALLENGES AND THE AI ACT’S RESPONSE

The paper examines central governance challenges posed by AI agents and assesses how effectively the EU AI Act responds to each one.

  • The analysis addresses each governance challenge in turn, describing its nature and assessing the extent of the Act’s regulatory response.

A. Performance

AI agents can perform competently yet fail unpredictably, pursue goals through unintended means, and behave differently across changing contexts. The EU AI Act addresses these risks through performance proxies, lifecycle risk management, and provider information duties, but its framework remains limited for emergent agent behavior and deployment-specific failures.

  • Agent performance challenges: AI agents may be competent at logistics yet fail unpredictably, pursue problematic means, and respond differently when monitored.Claude’s failures illustrate uneven competence, misalignment, and possible monitoring-dependent behavior.
  • Article 15: Article 15 governs high-risk system performance through accuracy, consistency, and robustness rather than explicit alignment with human expectations.These proxies fit tasks with predetermined standards better than open-ended agent behavior.
  • Article 15: Robustness is the best-suited Article 15 metric because it concerns behavioral stability across changing conditions, including interactions with users, systems, and environments.The analysis suggests robustness may extend to resilience in multi-agent settings.
  • Article 15: The Act operationalizes robustness narrowly around technical faults, redundancy, fail-safe mechanisms, and feedback from biased outputs.Changes in objectives, unintended goal pursuit, and harms from extended real-world interactions remain largely outside this framework.
  • Article 9: Article 9’s continuous, iterative lifecycle risk management better matches deployment-emergent failures but is limited to risks amenable to technical mitigation.This boundary may leave harms from emergent behavior and real-world interactions insufficiently addressed.
  • Deployment and oversight: Deployers face mainly logging and monitoring duties even though tool access, permissions, and operating environments substantially shape agent performance.The Code of Practice offers more adaptive evaluation through scenario modeling, external oversight, and iterative reassessment, though novel interactions remain difficult to anticipate.

i. Systemic Risk Identification and Assessment

The EU AI Act addresses systemic risks through obligations concerning misuse, privacy, and equity, but many mechanisms assume bounded, stable, and foreseeable AI-system behavior. Autonomous agents instead can evolve across contexts, combine individually benign actions, and interact with other systems, creating gaps in identification, monitoring, and responsibility.

  • Misuse: Traditional safeguards such as content filters, refusal mechanisms, and robustness testing are better suited to isolated harmful requests than to extended agentic misuse.Agents may produce harmful outcomes through multi-step activity even when individual actions appear innocuous.
  • Misuse: AI agents can be repurposed or steered through sequences of benign tasks, while conventional vulnerability lists focus on fixed points in data, model, or input security.These vulnerabilities may not capture autonomous execution of malicious plans over time or harmful outcomes produced through agent combinations.
  • Privacy: AI agents create privacy risks by actively collecting and transferring sensitive information across personal, professional, and inter-agent contexts.Such transfers can violate contextual integrity even when each individual use appears contextually appropriate.
  • Privacy: Privacy impact assessments and transparency duties are poorly fitted to agents whose data processing, capabilities, and behavior change after deployment.The Act does not clearly require the iterative, adaptive governance needed for continually evolving agents.
  • Institutional fit: The Act leaves a structural responsibility gap because model providers face continuous lifecycle duties but lack deployment context, while deployers’ data governance duties remain largely ex ante.Relevant information may exist in principle but remain difficult for deployers to obtain in practice.
  • Equity: AI agents may compound inequities by shaping access to benefits and repeatedly performing high-value activities while treating individuals or groups unfairly.The concern involves both unequal distribution of benefits and unfair decisions or actions.

III. INSTITUTIONAL IMPLEMENTATION

The EU AI Act relies heavily on industry-developed standards, provider self-assessment, and public authorities for implementation. For AI agents, discretionary standards, unclear classification, limited reporting, and constrained institutional capacity complicate supervision and enforcement.

  • Industry self-regulation: Industry self-regulation gives providers substantial discretion, while existing standards inadequately account for AI agents’ agent-specific, multipurpose, and adaptive characteristics.The Code of Practice lists possible safeguards but does not mandate their adoption, inviting divergent interpretations and complicating enforcement.
  • Provider responsibility: The Act relies primarily on providers to classify systems, identify obligations, and assess conformity before market placement, with external assessments required only in limited circumstances.This approach places substantial interpretive responsibility on regulated actors.
  • Risk classification: Nearly 40 percent of 106 AI use cases could not be conclusively classified under existing risk categories, illustrating the difficulty of applying the Act’s risk framework.Similar ambiguities arise for AI agents, including agents used for tasks such as evaluating evidence for a judicial authority.
  • Incident oversight: Incident investigations are required, but AI system providers need not report their findings, limiting structured supervisory information after incidents.The Code of Practice imposes more structured reporting processes on GPAISR model providers.
  • Institutional capacity: The AI Office’s access to the compute needed for frontier-model evaluations remains unclear, while commercial-cloud reliance may create security problems involving powerful models and sensitive data.The Act provides no clear guidance on how the AI Office should obtain the necessary resources.

IV. LESSONS LEARNED

The paper argues that the EU AI Act’s artifact-centered framework fits AI agents poorly because their risks emerge through changing environments, distributed responsibility, and evolving deployment contexts. Effective governance therefore requires broader sociotechnical oversight, stronger institutional capacity, and ongoing technical monitoring.

  • Artifact-Centric Governance: The EU AI Act’s artifact-centered risk framework is ill-suited to AI agents because their risks depend on tools, permissions, environments, and deployment contexts.The Act’s classifications rely heavily on intended use or compute thresholds, while heightened risks may emerge later without heightened obligations.
  • The Many-Hands Problem: AI agents create a “many-hands problem” because development, deployment, and operation distribute responsibility, control, and knowledge across multiple actors.The Act’s value-chain approach may fail when downstream actors lack timely, granular information or the technical resources needed to monitor or override agents.
  • The Many-Hands Problem: Multi-agent ecosystems require information no single actor can obtain, while third-party tool providers often fall outside the AI Act’s core regulatory categories.The paper identifies centralized pooling of information as a useful starting point for addressing this fragmentation.
  • Institutional Monitoring: The AI Act’s largely pre-market reporting model can miss consequential agent impacts because risks emerge and change after deployment as agents adapt to new tasks and environments.Limited monitoring also weakens enforcement of requirements dependent on current technical judgments, including assessments against the “state of the art.”
  • Institutional Monitoring: Effective regulation requires ongoing visibility into agents’ real-world behavior, supported by technical expertise, institutional capacity, resourcing, and infrastructure.The paper presents this as a broader governance need that cannot be solved through legislative drafting alone.
Loading 2603.23471v2…