EU AI Act

A real-time control layer for the obligations that are already in force.

The EU AI Act imposes duties on high-risk systems and bans certain practices outright. Compiled monitors AI-agent behavior in real time and enforces your policies inline — the operational control that turns AI-governance obligations into something you can prove. Real-time inline allow, flag, or block decisions — with full audit trail in your environment.

EU AI ActHigh-risk AI systemsProhibited practicesGPAI obligationsReal-time enforcementAuditabilityAI-agent governanceIn-tenant
7%
Maximum fine for GPAI model violations
Global annual turnover
3%
Maximum fine for high-risk system violations
Global annual turnover
Feb 2025
Prohibited practices provisions entered into force
No grace period for banned uses
Aug 2026
High-risk AI system obligations fully applicable
Preparation window closing
Regulatory landscape

What is in force and what is required

The EU AI Act entered into force on August 1, 2024. Its obligations are phased: the prohibited practices provisions became applicable in February 2025, GPAI model obligations in August 2025, and the full high-risk AI system requirements apply from August 2026. For organizations deploying AI agents today, the prohibited practices obligations are live and the preparation window for high-risk obligations is closing.

01
Articles 5 and 6 — Prohibited practices and high-risk systems

Banned uses and high-risk classification

Article 5 prohibits specific AI practices outright — including real-time remote biometric categorization in public spaces for law enforcement (with narrow exceptions), AI systems that exploit vulnerabilities to manipulate behavior, and social scoring systems. These prohibitions are not subject to the full compliance timeline; they applied from February 2025. Article 6 defines high-risk AI systems by reference to Annex III, which covers systems used in critical infrastructure, employment, education, essential services, law enforcement, migration, and justice. Deployers of high-risk systems carry independent obligations regardless of whether they built the system.

  • Assessment of whether any deployed AI system falls within a prohibited practice under Article 5
  • Classification of AI systems against Annex III high-risk categories
  • For high-risk systems: conformity assessment, technical documentation, and registration
  • Deployer obligations under Article 26: monitoring, human oversight, and incident reporting
02
Articles 9 and 26 — Risk management and human oversight

Ongoing risk management and operational control

Article 9 requires providers of high-risk AI systems to implement a risk management system that operates throughout the entire lifecycle of the AI system — including post-deployment. Article 26 places obligations on deployers to implement appropriate technical and organizational measures for human oversight, to monitor operation, and to report serious incidents. The obligation is operational, not documentary: a risk management system that exists only in policy documents, with no real-time control on what the AI system actually does, does not satisfy the Article 9 standard.

  • Risk management system covering the full AI system lifecycle, including deployment
  • Technical measures enabling human oversight of high-risk AI system outputs
  • Monitoring of AI system operation for deviations from expected behavior
  • Incident reporting procedures for serious incidents involving high-risk AI systems
03
Articles 53–55 — GPAI model obligations

General-purpose AI model governance and acceptable-use enforcement

Articles 53 through 55 impose obligations on providers of general-purpose AI models with systemic risk, including adversarial testing, incident reporting to the AI Office, and cybersecurity measures. Organizations that deploy GPAI models in agentic configurations — where the model autonomously selects tools, invokes APIs, and takes actions — inherit exposure under both the GPAI provisions and the high-risk deployer obligations. The maximum fine for GPAI violations is 7% of global annual turnover.

  • Assessment of whether deployed GPAI models carry systemic risk under Article 51
  • Acceptable-use policy enforcement for GPAI model integrations
  • Adversarial testing documentation where required
  • Real-time monitoring of GPAI model behavior in agentic configurations
Enforcement reality

Obligations you cannot satisfy with documentation alone

The EU AI Act is structured to require operational controls, not merely paper compliance. Article 9's risk management system must "operate on a continuous basis," and Article 26's human oversight requirement must be technically and organizationally implemented — not described in a policy that no system enforces. National supervisory authorities are establishing their AI Act enforcement programs, and the first enforcement actions under the prohibited-practices provisions are expected in 2025 and 2026.

The practical compliance challenge for most enterprises is that their AI agents operate without a real-time control layer. An agent can invoke a prohibited practice, produce a discriminatory output from a high-risk system, or violate an acceptable-use policy, and the first indication is a log entry reviewed the following day — by which time the action is complete and the violation has occurred. Documentation of a policy that was not technically enforced is not a defense in an Article 9 proceeding.

Compiled is the operational layer that makes the Article 9 risk management obligation provable. Every AI-agent action is assessed against your policies before it completes. The compliance program moves from "we have a policy" to "we enforced it, inline, with a timestamped record of every decision."

Risk scenarios

Where AI Act exposure arises in deployed systems

Prohibited manipulation techniqueBlock

An AI agent in a customer service context generates a response that uses a persuasion technique targeting a user's demonstrated cognitive vulnerability — a prohibited practice under Article 5(1)(b). Compiled intercepts the response before it is delivered, blocks it, and logs the finding with attribution to Article 5 of the EU AI Act.

High-risk system output outside human oversightFlag

An AI system used for employment screening — a high-risk category under Annex III — generates a recommendation that would automatically advance or reject a candidate without human review. Compiled flags the output before it is acted on, routing a finding to the designated human reviewer under the Article 26 oversight obligation.

GPAI model invoked outside acceptable-use scopeBlock

An AI agent uses a GPAI model integration to perform a task that falls outside the organization's defined acceptable-use policy for that model — generating content that violates the provider's usage terms in a way that creates regulatory exposure. Compiled blocks the invocation before the output is generated and logs the attempted use with policy attribution.

Agentic system acquiring capabilities beyond defined scopeFlag

A GPAI-powered agent begins autonomously invoking additional APIs and accumulating permissions not defined in its original scope — a pattern the OWASP Top 10 for Agentic Applications (Dec 2025) identifies under privilege escalation. Compiled detects the scope expansion and flags it for human review before the agent gains additional access.

How Compiled works

Turning AI-governance obligations into provable controls

Compiled deploys as an out-of-band gateway in your environment — outside agent code, in the path of every agent action. This is the architecture the industry is converging on: NIST NCCoE, Microsoft Entra Agent ID, AWS Bedrock AgentCore, and Google Agent Gateway all reflect the same principle. Compiled is that layer, behavioral rather than rule-based, operating inside your tenant.

Inline, before the action

Every AI-agent action is assessed before it completes. There is no gap between the policy and the enforcement. A prohibited practice is blocked before it affects a user; a high-risk output is flagged before it is acted on.

Article 9 risk management

Compiled's continuous, real-time assessment of agent behavior constitutes the operational risk management system Article 9 requires. The audit trail demonstrates that the system "operates on a continuous basis" as the regulation specifies.

Article 26 human oversight

Flagged outputs are routed to a human reviewer before being acted on — the technical implementation of the deployer's Article 26 oversight obligation. The reviewer's decision is logged in your environment.

Prohibited practice detection

Antibodies tuned to Article 5 prohibited practices detect manipulation techniques, social scoring patterns, and other banned behaviors in real time — before a user is affected and before the violation is complete.

Acceptable-use enforcement

Your GPAI model acceptable-use policies and scope restrictions are compiled into antibodies. An agent action outside the defined scope is blocked or flagged, with the specific policy cited in the finding.

Audit trail for regulators

Every decision is timestamped, scored, and policy-attributed inside your environment. The record demonstrating that your Article 9 risk management system was operating is generated automatically, in your own infrastructure.

Regulatory readiness

What you produce for a national authority investigation

National supervisory authorities investigating EU AI Act compliance will look for evidence that the organization's risk management system was operational — not just documented. Compiled produces a structured record from inside your environment that answers the operational question directly.

TimestampUTC timestamp of each AI-agent action and its assessment, to the millisecond
Agent identityThe specific AI system or agent model that initiated the action, recorded in the finding
VerdictAllow, flag, or block — rendered before the action completed, demonstrating the risk management system was operational at the time of the action
Risk scoreBehavioral risk score against the matched policy, providing a quantified basis for the verdict
Article attributionThe specific EU AI Act article — Article 5 prohibited practice, Article 9 risk category, or your own governance policy — that the finding matched
Human oversight logFor flagged findings: the human reviewer's decision and outcome, demonstrating that the Article 26 oversight obligation was discharged
Continuity evidenceAggregate system activity logs demonstrating that the risk management system operated continuously over the assessment period
FAQ

Questions from AI governance teams

Chat with usBook a 30-minute walkthroughAI-agent governance