EU AI Act Regulation (EU) 2024/1689

EU AI Act: Risk Levels, New Dates, and What AI Agents Must Show

The EU gave high-risk AI 16 more months, but the requirements haven’t changed. The Digital Omnibus moved the Annex III deadline from August 2, 2026 to December 2, 2027, but risk management, automatic logging, and human oversight still apply. If your AI agents help decide credit, life and health insurance, hiring, or access to essential services, they may count as high-risk. Use the extra time to build the records you’ll need to show.

EU AI Act Regulation (EU) 2024/1689
EU AI Act: Risk Levels, New Dates, and What AI Agents Must Show

What Is the EU AI Act?

The EU AI Act is the European Union’s law on artificial intelligence. It takes a risk-based approach: it bans a short list of practices, sets strict requirements for high-risk systems, adds transparency duties for systems such as chatbots and AI-generated content, and leaves minimal-risk AI largely alone. An AI agent falls into a tier based on what it’s used for.

Lumenova AI is an agentic AI governance platform that produces the evidence behind those obligations while agents run: the inventory, the policy that limits each agent, adversarial test results, and a record of every decision. Your team or assessor still runs the conformity assessment.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026. It deferred the high-risk deadlines but left the requirements in place, and the Article 50 transparency duties have applied since August 2, 2026.

Key Dates

  1. 27 Jul 2026The Digital Omnibus, Regulation (EU) 2026/1744, enters into force.
  2. 2 Aug 2026Article 50 transparency obligations apply.
  3. 2 Dec 2026Two new Article 5 prohibitions apply, and generative systems placed on the market before Aug 2, 2026 must meet the Article 50 marking requirement.
  4. 2 Dec 2027Annex III high-risk obligations apply, covering creditworthiness, life and health insurance risk and pricing, employment, and essential services.
  5. 2 Aug 2028High-risk obligations apply to AI in products covered by Annex I.

CORE CHECKS

What the Act Asks of High-Risk Systems

Obligations apply from December 2, 2027, for providers and deployers alike.

Risk Management

A risk management process that runs across the lifecycle: risks identified, evaluated, and mitigated, and the assessment kept current as the system changes.

Logging and Record-Keeping

Automatic logging of events over the system’s lifetime, so a result can be traced to its inputs and the system that produced it.

Human Oversight

Qualified people who can properly understand the system’s output, decide not to use it, step in, and stop it.

Accuracy, Robustness, and Cybersecurity

Consistent performance across the lifecycle, and resilience against attempts to manipulate the system, like adversarial inputs and data poisoning.

Deployer Duties

Use the system as instructed, assign competent people to oversee it, monitor it, and keep the logs under your control for at least six months.

Fundamental Rights Impact Assessment

Deployers of credit scoring and life and health insurance pricing systems must assess the system’s impact on people before first use.


How Lumenova AI Supports Your EU AI Act Work

Every High-Risk Use Case on the Inventory

Register each agent under its use case with owner, approver, and risk tier, so every Annex III use case is visible before its deadline.

Limits in Writing

Write what each agent may do as policy a person can read, test, and change, enforced before the action runs, with version history.

Oversight at the Point of Action

Policy blocks an action before it runs, and your application routes the blocked case to a person who can approve, change, or stop it.

Logs That Trace Each Decision

Each decision record keeps the policy evaluated, the outcome, and the input, linked to the trace of what the agent did before and after.

Adversarial Testing

Black-box probes look for weaknesses, each finding can become a policy, and the attacks that worked are replayed after the fix.

Evidence for Conformity Work

Decision records and findings export as CSV or JSON for the conformity assessment your team or assessor runs.


How to Get Ready

  • Classify each system and your role in it, provider or deployer, and note the date that applies;
  • Register each agent with an owner and an approver;
  • Write each high-risk agent’s limits as policy;
  • Decide which logs each high-risk agent must keep, and for how long;
  • Test adversarially, and keep the replay with the report;
  • If you deploy credit scoring or insurance pricing systems, plan the fundamental rights impact assessment.

Frequently Asked Questions

The Act classifies AI by use. An agent used for a purpose listed in Annex III, such as assessing creditworthiness, pricing life or health insurance, or screening job candidates, is high-risk. An agent that drafts internal summaries usually isn’t, though the Article 50 transparency duties can still apply.

From December 2, 2027 for systems listed in Annex III, and from August 2, 2028 for AI in products covered by Annex I. Regulation (EU) 2026/1744 set both dates and entered into force on July 27, 2026.

High-risk systems must record events automatically so results can be traced and risks monitored (Article 12). Deployers must keep the logs under their control for at least six months, unless other law sets a different period (Article 26). Lumenova AI records each agent decision with the policy, outcome, and input, and traces every step.

A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name. A deployer uses a system under its own authority. A bank that builds its own credit agent is usually both. A bank that licenses a vendor’s agent is usually a deployer, unless it substantially modifies the system or changes its intended purpose.

No platform can do that alone. Compliance depends on how you classify, document, and assess each system. Lumenova AI supplies the controls and evidence the high-risk requirements call for: an inventory, enforced limits, human-oversight routing, adversarial test results, and decision records you can export.

Control, Test, and Prove What Your AI Agents Do

This is one piece of Lumenova AI. See how it connects to the rest on your own use case.

Book a discovery call