Logan Kelly
EU AI Act checklist for AI agent operators — deadlines, risk tiers, log fields. Waxell maps the controls to exportable records.

On 2 December 2026, the nearest hard deadline most AI agent operators still face arrives: providers of generative AI systems that were already on the EU market before 2 August 2026 must have machine-readable marking of synthetic outputs in place under Article 50(2) — a date fixed by the new Article 111(4) that Regulation (EU) 2026/1744, the Digital Omnibus on AI, inserted into the Act. Miss the obligations in this tier of the Act and the fine ceiling is €15 million or 3% of worldwide annual turnover, whichever is higher, under Article 99(4). The often-quoted €35 million / 7% figure belongs to Article 5's prohibited practices, a different tier.
Most coverage of the Omnibus led with the delay — and the delay is real. The high-risk obligations attached to Annex III systems now apply from 2 December 2027, and AI embedded in Annex I regulated products from 2 August 2028, both fixed in the amended Article 113 of the Act as enacted in Regulation (EU) 2026/1744 (in force 27 July 2026). But Article 50's transparency obligations were not deferred: they have applied since 2 August 2026. If your agents talk to customers, draft public-facing text, or generate synthetic media, part of this checklist is not preparation. It is overdue.
This page is a hub. Every checklist row is tagged to its Article, and where a deep-dive post exists for a row, the row links down to it — so you can work the list top to bottom without re-reading the statute.
Which deadline is yours? Four dates to anchor on
2 August 2026 — already in force. Article 50 transparency obligations: disclosure of AI interaction, deployer disclosure of deep fakes and AI-generated public-interest text. Our breakdown of what the August 2026 deadline actually covered separates this from the deferred obligations.
2 December 2026 — roughly 13 weeks out. Article 50(2) machine-readable marking for generative systems placed on the market before 2 August 2026 (Article 111(4) as inserted by the Omnibus). The same date starts the new Article 5 prohibitions the Omnibus added on non-consensual intimate material and child sexual abuse material. Why marking alone is a fragile control is covered in our analysis of the December 2 marking deadline.
2 December 2027. Chapter III obligations (Articles 9–15, plus deployer duties under Article 26) for systems that are high-risk under Article 6(2) and Annex III.
2 August 2028. The same obligations for AI systems that are high-risk under Article 6(1) and Annex I — AI embedded in regulated products such as medical devices and machinery.
Where does your agent sit? Classify before you build
The Act has no risk category called "AI agent." Classification follows the task the agent performs. Sort your own deployments against this table, then confirm the result against Annex III's text — and note Article 6(3): a system in an Annex III area that only performs a narrow procedural task, or improves the result of a previously completed human activity, may fall outside the high-risk tier if it does not materially influence the outcome. That assessment must be documented before the system is placed on the market or put into service.
Agent pattern | Likely tier | Key articles | Your deadline |
|---|---|---|---|
Customer-facing chatbot or assistant | Transparency obligations | Art. 50(1) | Live since 2 Aug 2026 |
Agent drafting text published to inform the public | Transparency (deployer) | Art. 50(4) | Live since 2 Aug 2026 |
Generative pipeline you provide to others | Transparency (provider marking) | Art. 50(2), Art. 111(4) | 2 Dec 2026 if on market pre-Aug 2026 |
Résumé screening, worker management | High-risk (Annex III, employment) | Arts. 9–15, 26 | 2 Dec 2027 |
Credit scoring, access to essential services | High-risk (Annex III, essential services) | Arts. 9–15, 26 | 2 Dec 2027 |
Safety component in critical infrastructure | High-risk (Annex III, infrastructure) | Arts. 9–15, 26 | 2 Dec 2027 |
Internal back-office agent, human retains the decision | Possibly outside high-risk via Art. 6(3) | Art. 6(3) — document the assessment | Assessment now, before deployment |
Article 50: Transparency checklist — live now
[ ] People interacting with your agent are informed they are dealing with an AI system, unless that is obvious to a reasonably well-informed person (Art. 50(1)).
[ ] Any deep fake your agents generate or manipulate is disclosed as artificially generated, and AI-generated or AI-manipulated text published to inform the public on matters of public interest carries a disclosure (Art. 50(4)) — the deployer-side duty most agent teams underestimate, unpacked in the August 2026 deadline post.
[ ] If you are the provider of a system generating synthetic audio, image, video or text: outputs are marked in a machine-readable format and detectable as artificially generated (Art. 50(2)); legacy systems have until 2 December 2026 (Art. 111(4)) — see why provenance-at-generation beats watermark-only marking.
Article 12: Record-keeping checklist — from 2 December 2027
[ ] The system technically allows automatic recording of events over its lifetime (Art. 12(1)) — retrofitted manual logging does not meet the "automatic" bar. What auditors actually ask for is covered in the audit-trail requirements post.
[ ] Logging covers the three purposes Article 12(2) names: identifying risk situations, post-market monitoring, and monitoring of operation by the deployer under Article 26(5).
[ ] Retention is set: providers and deployers each keep the logs under their control for at least six months, unless other Union or national law provides otherwise (Arts. 19(1), 26(6)) — a trace store that rolls off after 30 days cannot produce the record this presumes.
A working log schema that serves Article 12(2)'s stated purposes — the Act names the purposes, not the fields:
Field | Purpose | Example |
|---|---|---|
Timestamp | Ordering and retention enforcement | 2026-12-02T14:23:07Z |
Resolved identity | Tie the action to a person, not a service account | user: j.alvarez |
Tool call and decision | Trace what the agent did and what rule applied | crm.export → held for approval |
Model and prompt version | Reconstruct the state that produced the output | model 2026-08-12 / prompt v2.4 |
Hand-off record | Who passed work to whom, human or agent | agent A → reviewer B, v3 |
Article 14: Human oversight checklist — from 2 December 2027
[ ] An oversight pattern is chosen and documented, commensurate with the system's risk, autonomy and context (Art. 14(3)) — approval before execution versus monitoring with intervention is a design decision with statutory weight, compared in human-in-the-loop vs human-on-the-loop.
[ ] Overseers can intervene in operation or interrupt the system through a "stop" button or similar procedure that halts it in a safe state (Art. 14(4)(e)) — the statutory language is a halt in a safe state, which is a hard test for a kill path that depends on the agent cooperating.
[ ] Overseers can understand the system's capacities and limitations, monitor for anomalies, and decide to disregard or reverse its output (Art. 14(4)).
[ ] Oversight is assigned to named natural persons with the competence, training and authority to do it (Art. 26(2)) — an inbox nobody owns is not oversight.
Articles 9 and 15: Risk management and robustness checklist — from 2 December 2027
[ ] A risk management system exists as a documented, continuous, iterative process across the agent's lifecycle — covering reasonably foreseeable misuse, not just intended use (Art. 9(2)).
[ ] The system achieves and maintains appropriate accuracy, robustness and cybersecurity through its lifecycle, with accuracy metrics declared in the instructions for use (Arts. 15(1), 15(3)).
[ ] Adversarial behavior is in the test plan (Art. 15(1) covers cybersecurity as well as accuracy): prompt injection into tool results, poisoned tool descriptions, and resource exhaustion are the robustness failures specific to agents.
GDPR interaction checklist
[ ] GDPR still applies in parallel — outside narrow exceptions such as bias detection under Article 4a (formerly Article 10(5)), the AI Act does not hand you a new legal basis for processing personal data. Where your agents touch EU personal data, work through GDPR transparency for AI agents alongside this list.
[ ] Impact assessments are combined where both apply — a GDPR DPIA (GDPR Art. 35) and the Act's fundamental-rights impact assessment (Art. 27, which binds public bodies, private entities providing public services, and certain essential-services deployers) ask overlapping questions, and the EDPB's expectations for AI agents are moving, as tracked in the EDPB 2026 guidance post.
For how these obligations sit against NIST AI RMF, ISO/IEC 42001 and OWASP, see which AI governance frameworks apply to AI agents — this page stays scoped to the EU AI Act.
What to do before December 2
Classify this week. Sort each production agent against the table above and record the Article 6(3) reasoning for anything you keep out of the high-risk tier.
Close the Article 50 gaps first — those obligations are already live, and the marking deadline for legacy generative systems is 2 December 2026.
Start the records now, not in 2027. Retention floors of six months mean the log you will need at the December 2027 audit has to start accumulating well before then, and retrofitting automatic recording into a production agent is the expensive version of this work.
Assign the oversight owner by name. Article 26(2) expects competence, training and authority — a person, not a distribution list.
How Waxell handles this
The pattern in this checklist is that the Act keeps asking for the same two things: a control that operates before or during execution, and a record proving it operated. That is what Waxell's compliance mapping is built around — it maps policy categories to NIST AI RMF and to EU AI Act Articles 9, 12, 14, 15 and 26, and the evidence for each row is an export, not a questionnaire.
For Article 12's records, four distinct artifacts exist, each owned by its product: execution traces from Waxell Observe, the payload-free tool-call audit log from the Waxell MCP Gateway, the versioned hand-off record from Waxell Connect, and the lineage causality graph from Waxell Runtime. For Article 14, approval holds park destructive actions for a named person, and kill switches operate at agent, workflow and session level — the approval record captures what was held, who cleared it, and when. For Article 9, policies drawn from 50+ policy categories are evaluated before execution proceeds, and the policy definitions carry their full change history. For Article 15, the MCP Gateway scans tool descriptions for prompt injection at fingerprint time. And for the classification sweep the plan above begins with, Waxell Endpoints finds the AI already running on employee laptops — where the AI nobody has classified yet tends to surface first.
What Waxell does not do: certify anyone. NIST AI RMF is voluntary and non-certifiable, and the EU AI Act's conformity assessment applies to systems, not vendors. The obligations stay with the provider or deployer; Waxell enforces the controls and produces the evidence.
FAQ
Did the EU AI Act's obligations for AI agents get delayed?
Partially. Regulation (EU) 2026/1744 moved the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I embedded systems. Article 50's transparency obligations were not deferred and have applied since 2 August 2026.
What is the December 2, 2026 deadline?
It is the compliance date for Article 50(2) machine-readable marking for providers whose generative AI systems were already on the EU market before 2 August 2026, set by the new Article 111(4). The Omnibus's added Article 5 prohibitions on non-consensual intimate material and child sexual abuse material also apply from that date.
Are AI agents automatically high-risk under the EU AI Act?
No. There is no agent-specific category; classification follows the task. An agent screening job applicants sits in Annex III's employment area, while the same underlying model scheduling meetings does not — and Article 6(3) can take a narrow procedural system in an Annex III area out of the high-risk tier if the assessment is documented.
What does an AI agent have to log under Article 12?
The system must technically allow automatic recording of events over its lifetime, sufficient to identify risk situations, support post-market monitoring, and let the deployer monitor operation. Providers and deployers each keep the logs under their control for at least six months, unless other Union or national law sets a different period.
Does using a governance platform make an AI agent compliant?
No, and be wary of any vendor implying it. Obligations attach to the provider or deployer of the system, and conformity assessment applies to systems, not vendors. A governance layer contributes the enforced controls and the records — the classification, the assessment and the responsibility stay with you.
Sources
Official Journal of the European Union, "Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI)", 24 July 2026 — Article 113 as amended; new Article 111(4); recital 38.
EU Artificial Intelligence Act Explorer, "Article 50: Transparency Obligations", consolidated text.
EU Artificial Intelligence Act Explorer, "Article 12: Record-Keeping" and "Article 19: Automatically Generated Logs", consolidated text.
EU Artificial Intelligence Act Explorer, "Article 14: Human Oversight", "Article 26: Obligations of Deployers of High-Risk AI Systems" and "Article 27: Fundamental Rights Impact Assessment", consolidated text.
EU Artificial Intelligence Act Explorer, "Article 6: Classification Rules" and "Annex III: High-Risk AI Systems", consolidated text.
EU Artificial Intelligence Act Explorer, "Article 99: Penalties", consolidated text.
Start free with Waxell Observe and one governed MCP upstream — and let the first record in your Article 12 file be the run that happened today.
Agentic Governance, Explained




