A little over three years after the first consumer-facing large language models entered the market, AI has evolved at remarkable speed. Adoption is now broad-based, and 51% of business leaders have reported having a clear roadmap for their organisation’s AI initiatives according to PwC’s 29th Global CEO Survey.
At the same time, leading organisations are starting to deploy what are commonly described as AI agents - systems which can plan, decide and act with limited human intervention. These tools go beyond more familiar generative AI (GenAI) use cases because they can operate across various datasets, environments, and software tools to deliver an outcome.
Use cases for AI agents are expanding quickly. For instance, clinics are deploying agentic AI across radiology workflows to support faster and more accurate medical diagnoses - producing comprehensive insights by combining imaging, patient and lab data simultaneously. Financial firms are using them to automate complex legal work, including for contract review against preferred playbooks and extraction of key data points from large document sets to reduce manual hours.
For regulatory and compliance teams therefore, the task is clear. They will need to develop an agile regulatory framework and put guardrails in place to ensure that these autonomous systems remain compliant and trustworthy as their impact on business operations continues to increase.
The EU AI Act regulates both AI systems and general‑purpose AI (‘GPAI’) models. Its definition of an AI system expressly covers systems that operate with ‘varying levels of autonomy’. GPAI models are addressed separately and defined as models trained with ‘a large amount of data using self‑supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks’.
The key point is that the EU AI Act (or the Act) does not regulate AI agents as a standalone category, but instead it regulates AI by reference to the system’s intended use case and risk level (we have covered the main requirements of the regulation in this previous article). Determining the risk level of the AI system will decide the corresponding obligations which will apply. For example, an AI agent used to evaluate job candidates is likely to qualify as high-risk in terms of the Act and trigger requirements such as human oversight, transparency, and data security.
As a first step, organisations need to evaluate their specific role across the AI value chain (particularly, whether they are acting as providers or deployers in terms of the regulation) and assess whether the relevant use case of agentic AI falls within a specific risk category.
Against this backdrop, business leaders must also keep in mind that the European Commission has recently adopted targeted amendments to the Act through the AI Omnibus, including revised application dates for high-risk AI systems, easing compliance requirements for small mid-cap organisations, and provisions allowing for the processing of special categories of personal data for bias detection and correction purposes. In a sector moving this quickly, regulatory scanning is no longer optional for most regulatory teams.
Another critical question that businesses must consider is whether their AI agents will have access to or otherwise process personal data, in which case the GDPR remains applicable. Due to the autonomous nature of the technology and its complex architecture – which often include multi-step reasoning, chained tools and agents operating across various environments – compliance with the GDPR may start to sound like a daunting task for many businesses.
Spain’s supervisory authority (the ‘AEPD’) has already noted that traditional controller-processor relationships in terms of the GDPR can become blurred where agentic systems access or disclose information to third-party services to achieve their purposes. Consider for example, an employer’s AI agent that can access the platforms of airlines and car rental businesses to book employee travels and process billing data, or a healthcare agent that shares a customer’s treatment expenses to their insurance company to support a claim.
The UK’s Information Commissioner’s Office (ICO) has also pointed to several risks that agentic AI can raise. These include (i) unintended use, especially where an agent is designed for open-ended tasks or if it is connected to unrelated databases, (ii) inferencing that reveals special categories of personal data, and (iii) greater complexity when organisations need to respond to data subject rights requests across multiple data flows. Unless compliance is designed into the technology’s architecture from the start, increased autonomy is likely to cause further regulatory friction for organisations.
Agentic AI tools are likely to continue evolving over the next months. To keep pace with the changing enterprise capabilities, integration options and security features, businesses need regulatory frameworks which are highly effective and agile. We are setting out below steps that organisations can take to be better prepared:
Businesses should clearly define their strategic objectives when launching agentic projects. Whether it relates to cost reduction, customer satisfaction, or creating a competitive advantage, defining a clear goal will allow the organisation to identify a specific use case and purpose.
To clearly understand which tools are right for the organisation, regulatory teams should pitch-in with executive leadership to assess whether, for instance, the vendor offers contractual protections around data protection, incident management, intellectual property, and data access and retention. Prioritising cooperative, transparent vendors will translate into more effective risk management.
As mentioned above, various obligations may apply to the business depending on the use case, impact and scope of the technology. It is important for compliance teams to adopt a comprehensive view and scope their AI agent’s use case against all applicable requirements, including in terms of the EU AI Act, the GDPR or other sectoral regulations such as NIS2. Once there is a clear picture of the regulatory impact, the business can draw up, update or align its policy framework to meet such requirements.
If you would like to know more about agentic AI and its regulatory impact on your business, our Privacy & Data team can support you to understand and navigate the regulatory challenges along its AI innovation journey. For more information on how we can help, please reach out to our sector leaders below.