The EU AI Act entered into force on August 1, 2024. Its obligations are phased: the prohibited practices provisions became applicable in February 2025, GPAI model obligations in August 2025, and the full high-risk AI system requirements apply from August 2026. For organizations deploying AI agents today, the prohibited practices obligations are live and the preparation window for high-risk obligations is closing.
Article 5 prohibits specific AI practices outright — including real-time remote biometric categorization in public spaces for law enforcement (with narrow exceptions), AI systems that exploit vulnerabilities to manipulate behavior, and social scoring systems. These prohibitions are not subject to the full compliance timeline; they applied from February 2025. Article 6 defines high-risk AI systems by reference to Annex III, which covers systems used in critical infrastructure, employment, education, essential services, law enforcement, migration, and justice. Deployers of high-risk systems carry independent obligations regardless of whether they built the system.
Article 9 requires providers of high-risk AI systems to implement a risk management system that operates throughout the entire lifecycle of the AI system — including post-deployment. Article 26 places obligations on deployers to implement appropriate technical and organizational measures for human oversight, to monitor operation, and to report serious incidents. The obligation is operational, not documentary: a risk management system that exists only in policy documents, with no real-time control on what the AI system actually does, does not satisfy the Article 9 standard.
Articles 53 through 55 impose obligations on providers of general-purpose AI models with systemic risk, including adversarial testing, incident reporting to the AI Office, and cybersecurity measures. Organizations that deploy GPAI models in agentic configurations — where the model autonomously selects tools, invokes APIs, and takes actions — inherit exposure under both the GPAI provisions and the high-risk deployer obligations. The maximum fine for GPAI violations is 7% of global annual turnover.
The EU AI Act is structured to require operational controls, not merely paper compliance. Article 9's risk management system must "operate on a continuous basis," and Article 26's human oversight requirement must be technically and organizationally implemented — not described in a policy that no system enforces. National supervisory authorities are establishing their AI Act enforcement programs, and the first enforcement actions under the prohibited-practices provisions are expected in 2025 and 2026.
The practical compliance challenge for most enterprises is that their AI agents operate without a real-time control layer. An agent can invoke a prohibited practice, produce a discriminatory output from a high-risk system, or violate an acceptable-use policy, and the first indication is a log entry reviewed the following day — by which time the action is complete and the violation has occurred. Documentation of a policy that was not technically enforced is not a defense in an Article 9 proceeding.
Compiled is the operational layer that makes the Article 9 risk management obligation provable. Every AI-agent action is assessed against your policies before it completes. The compliance program moves from "we have a policy" to "we enforced it, inline, with a timestamped record of every decision."
Compiled deploys as an out-of-band gateway in your environment — outside agent code, in the path of every agent action. This is the architecture the industry is converging on: NIST NCCoE, Microsoft Entra Agent ID, AWS Bedrock AgentCore, and Google Agent Gateway all reflect the same principle. Compiled is that layer, behavioral rather than rule-based, operating inside your tenant.
National supervisory authorities investigating EU AI Act compliance will look for evidence that the organization's risk management system was operational — not just documented. Compiled produces a structured record from inside your environment that answers the operational question directly.