Article

Does the EU AI Act Apply to Your AI Agents?

What the Act actually asks of agent operators, what became enforceable August 2, 2026 — and which half of the record is already running.

Jul 31, 20266 min readBy Tragentics Editorial
Does the EU AI Act Apply to Your AI Agents?

It can — because the EU AI Act regulates what your agents are used for, not the technology underneath them. High-risk uses carry automatic record-keeping duties, enforceable since August 2, 2026. Tragentics's side of that record is already running: every routed call is logged automatically, metadata-only, retained beyond the Act's floor — while classification and input-data logs remain honestly yours.

What changed on August 2, 2026

Tragentics didn't have to change anything on deadline day — the record it keeps was already being written, call by call, long before the clock ran out. What changed is the law around it: on August 2, 2026, the EU AI Act's obligations for high-risk AI systems became broadly enforceable for providers and deployers, and Article 12's record-keeping requirements are on that list.

The stakes are not abstract. Non-compliance with high-risk provider obligations carries administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Record-keeping is one of the cheapest obligations to meet — and one of the most expensive to be missing when someone asks.

That's why this deadline belongs in every AI agent security plan: the Act turned "can you show what your agents did?" from a good practice into a legal expectation for systems in scope.

Is your agent high-risk under the Act?

Tragentics can't classify your system for you — and neither can any platform. The Act's classification is use-based, not technology-based: an agent is not in scope because it's an agent, and not exempt because it's "just calling an API." What matters is the deployment context — the Act's high-risk categories cover specific use areas, and whether your agent's job falls inside one is a determination you make about your system, with counsel where it's close.

This article describes platform capabilities and public facts about the Act — it is not legal advice, and no platform can make you compliant. Assess your own obligations with qualified counsel.

The practical read: if your agents do back-office plumbing, you may be outside the high-risk regime entirely. If they touch the Act's sensitive use areas, assume the record-keeping expectations apply and build accordingly — the duties fall on the system's provider or deployer, which is you, not your transport.

What Article 12 actually requires: automatic logs, for the system's lifetime

The transport half of Article 12 has been running on Tragentics since your agents' first call. The requirement itself, in operator's terms: Article 12 expects high-risk systems to automatically record events over the lifetime of the system — logging the system generates itself, not documentation someone writes after the fact — sufficient to trace how the system was used, and retained: a six-month minimum for most sectors, with your own obligations potentially requiring longer.

"Automatic" is the word that catches teams out. A wiki page of incidents doesn't satisfy it; neither does logging you plan to add before the audit. The record has to exist because the system wrote it — which is exactly what a recording transport layer is for.

The split: what your transport records, and what remains yours

Tragentics hands you the transport side of the Article 12 record ready-made — and is precise about the part it deliberately doesn't hold:

What Article 12 expects

What Tragentics provides

What remains yours

The period of each use

Timestamp and measured duration on every routed call

Tying calls to your own input and output records

Traceability of operation

Status, error classification, and a trace ID correlating every leg of a multi-step call

The decision logic and input data behind each call

Retention

At least 12 months, automatic — revocation records for seven years

Retaining your endpoint logs for the period your obligations require

The caveat to plan for: Article 12 expects logs sufficient to trace the input data behind an output. Tragentics is content-blind — it never reads or stores payloads — so that input record is yours to keep at your own endpoint. The call metadata supplements it; it never replaces it.

That honesty is the design. The anatomy of the record itself — what a trail must capture and why metadata is enough for the transport layer — is covered in our guide to AI agent audit trails, and the platform-fit detail lives in the EU AI Act reference.

What the record looks like on Tragentics

Every call your agents make through Tragentics is written to the record automatically — six fields, on every lane: when (timestamp plus a trace ID that correlates a fan-out under one request), who (caller and target by permanent ID, with owning accounts), what kind (sync, async, broadcast, pool, scheduled, or external relay), outcome (success, error, timeout, or rejected, with upstream HTTP status), duration (end-to-end latency), and volume (byte counts — never the content itself).

Retention runs on its own: call and authorization records for at least 12 months, agent revocation records for seven years, with nothing for you to operate. Each record is scoped to its owner and tamper-resistant, with no browser write path into the logs. And none of it required a line of logging code in your agents — the same record that supports the Act is the one you'd hand a security review, produced the same way: proof of every call, without storing the payload.

The infrastructure half is done; the rest is honestly yours

Here's the operator's short list, stated without varnish: classify your system, with counsel where it's close. Log input data and decision context at your own endpoint — the content a content-blind transport deliberately never sees. Keep your records for the period your obligations require. And meet the rest of the high-risk regime — risk management, human oversight, transparency — none of which a transport layer can do for you.

The Act's clock started August 2. Your transport's record started earlier.

What Tragentics changes is the half nobody wants to build: the automatic, durable, metadata-only account of every call your agents make, running from their first call to their last — supporting your record-keeping obligations while your data stays yours. The agents you already own have been writing that record all along.

Frequently asked questions

Does the EU AI Act apply to agents built on GPT or Claude APIs?

The model API doesn't decide it — the use does. The Act classifies systems by deployment context, so an agent built on any API can be in or out of the high-risk regime depending on what it's used for. Classify the system you've built, with qualified counsel where the call is close.

What retention does Article 12 require?

The Act sets a six-month minimum for most sectors, and your own regime can require longer. Tragentics keeps call and authorization records automatically for at least 12 months — beyond the floor — and agent revocation records for seven years, with no retention lifecycle for you to operate.

Do I still need my own logs if my transport keeps records?

Yes. Article 12 expects traceability down to the input data behind an output, and a content-blind transport never sees that content — so input and decision logs live at your endpoint, kept by you. The transport record supplies the who-called-whom, when, and outcome half automatically.

What are the penalties for missing record-keeping?

Non-compliance with high-risk provider obligations — record-keeping among them — carries administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Enforcement of the high-risk regime began August 2, 2026, so the record has to exist before the question arrives.

Free to start

Your agents are already running.
Make sure they're running securely.

Your AI agent network, your infrastructure, your keys — protected.

  • Cancel anytime
  • AES-256-GCM encrypted
  • Full audit logs
  • Keys never exposed