surehand
All articlesRegulation

EU AI Act obligations for deployers of AI agents, after the 2026 Omnibus

Reference6 min readSurehand

You bought the agent. A vendor built it. The EU AI Act calls you a deployer, and Article 26 is your article. It is short and practical. Use the system as instructed. Put competent people on oversight. Monitor it. Keep the logs. Tell the people affected. The dates moved in July 2026. The duties did not.

In one sentence: the Act asks the company running the agent to prove trained people watch it, it runs as intended, and the logs exist.

Where it comes from

Regulation (EU) 2024/1689 entered into force on 1 August 2024. High-risk duties were due on 2 August 20269. The Commission proposed a "Digital Omnibus on AI" in November 2025 to push that back7. It became Regulation (EU) 2026/1744. It was published on 24 July 2026 and in force from 27 July, "days before several EU AI Act obligations were due to apply"7.

The Act splits the world in two. Providers build a system or sell it under their name. Deployers use it. A deployer is "a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity"1.

License an agent and point it at your AP queue? You are the deployer. The vendor is the provider. Build your own and run it? You may be both.

What the text says

Article 26 lists the deployer's duties for high-risk systems. Six matter for an agent that acts.

Use it as instructed. Deployers "shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use"2. The provider's instructions become your operating limits.

Put competent people on oversight. Deployers "shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support"2. An approver who cannot decline is not oversight.

Article 14 is addressed to providers. It says what the system must let those people do. That includes "to decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output". It also includes the power "to intervene in the operation of the high-risk AI system or interrupt the system through a 'stop' button or a similar procedure"3.

Monitor it, and stop it if needed. Deployers "shall monitor the operation of the high-risk AI system on the basis of the instructions for use"2. If they have reason to think it presents a risk, they inform the provider and the market surveillance authority "and shall suspend the use of that system"2. Financial institutions meet the monitoring duty by following their existing governance rules under EU financial services law2.

Keep the logs. Deployers "shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control"2. The period must suit the purpose and be "of at least six months, unless provided otherwise in applicable Union or national law"2. Article 12 makes providers build systems that "technically allow for the automatic recording of events (logs) over the lifetime of the system"4. So the system must log. You must keep what you control.

Tell the workers. Before a high-risk system goes live at work, employers "shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system"2.

Tell the people decided about. Deployers of Annex III systems "that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system"2. Where GDPR requires a data protection impact assessment, use the provider's information for it2.

Which agents are high-risk

Article 26 only applies if the agent is high-risk. Use decides that, not technology. Annex III has the list. Two entries catch back-office agents.

  • Employment. Systems used "to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons" at work6. Your agent routes tickets to named staff by past performance? That is close to the line.
  • Essential services. Systems used "to evaluate the creditworthiness of natural persons", and systems "for risk assessment and pricing in relation to natural persons in the case of life and health insurance"6. A claims agent on a life or health book should assume it is in scope.

An agent matching supplier invoices to purchase orders is not on the list. Nor is an agent that answers tickets from your policy manual. Check the annex. Then check with counsel.

The dates, after the Omnibus

ObligationApplies fromSource
Prohibited practices, AI literacy (Article 4)2 February 20259
Transparency (Article 50)2 August 2026. Content generators already on the market get until 2 December 2026 for Article 50(2)9
High-risk, Annex III uses (employment, credit, essential services)2 December 20277,9
High-risk, Annex I products (machinery, medical devices)2 August 20287,9

The Omnibus also softened Article 4. Providers and deployers now "shall take measures to support the development of AI literacy of their staff"10. The old text said "ensure, to their best extent, a sufficient level"10. Trained people are still expected. The duty got softer.

What this means for a team running agents

This is not legal advice. It is what we would do with the text in front of us.

  1. /01

    Classify each agent by use. One line per agent. What it decides, about whom, under which Annex III entry, if any. Most will be out of scope. Write that down too. The reasoning is your evidence.

  2. /02

    Name the oversight people now. Article 26(2) is the cheapest duty to meet and the easiest to fail. One named approver per agent. Give them the authority to decline and the training to know when.

  3. /03

    Get the logs under your control. "To the extent such logs are under their control" is the phrase to negotiate. If the record lives only in the vendor's platform, you lose it when you leave. Ask for export in an open format. Ask how you would prove the export was not altered.

  4. /04

    Treat the instructions for use as a contract. Get them in writing. Run the agent inside them. Record the version.

  5. /05

    Do the transparency work this year. Article 50 was not deferred. If your agent replies to customers or staff, they need to know it is an agent5.

  6. /06

    Do not wait for December 2027. Your internal audit already wants every Article 26 duty. Trained approvers. Monitoring. Kept logs. Informed staff.

Where it is going

The Omnibus bought sixteen months. The harmonised standards that define "compliant" are still being written. Our view: they will ask for what every control framework asks for. A documented scope. Named roles. A monitoring routine. A log nobody can quietly edit. Teams that already keep those will find the Act adds paperwork, not architecture.

Gatehouse fit

Gatehouse was not built for the Act, but it produces what Article 26 describes. One named approver per deployment, with the power to decline. Signed, versioned rules that record the instructions in force. Monitoring per run. A record chained by SHA-256 and exported in open formats, so the logs stay under your control after you leave. Surehand holds no certification against the Act and claims no conformity. The Trust page lists what is in place and what is not.

At a glance

CategoryRegulation
InstrumentRegulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Your role if you buy an agentDeployer (Article 3(4))
Your articleArticle 26. Articles 12, 14 and 50 shape what you receive
Key dates2 Aug 2026 (transparency), 2 Dec 2027 (Annex III), 2 Aug 2028 (Annex I)
Minimum log retentionSix months (Article 26(6)), longer where other law says so
Typical ownerCompliance classifies. The process owner names oversight. IT keeps the logs

Sources

  1. [1]Regulation (EU) 2024/1689 (AI Act), Article 3: Definitionsartificialintelligenceact.eu In text
  2. [2]Regulation (EU) 2024/1689 (AI Act), Article 26: Obligations of deployers of high-risk AI systemsartificialintelligenceact.eu In text
  3. [3]Regulation (EU) 2024/1689 (AI Act), Article 14: Human oversightartificialintelligenceact.eu In text
  4. [4]Regulation (EU) 2024/1689 (AI Act), Article 12: Record-keepingartificialintelligenceact.eu In text
  5. [5]Regulation (EU) 2024/1689 (AI Act), Article 50: Transparency obligationsartificialintelligenceact.eu In text
  6. [6]Regulation (EU) 2024/1689 (AI Act), Annex III: High-risk AI systemsartificialintelligenceact.eu In text
  7. [7]AI Omnibus enters into force: high-risk deadlines move, Acompli, July 2026acompli.ie In text
  8. [8]Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lexeur-lex.europa.eu
  9. [9]Timeline for the Implementation of the EU AI Act, European Commission AI Act Service Deskai-act-service-desk.ec.europa.eu In text
  10. [10]Regulation (EU) 2024/1689 (AI Act), Article 4: AI literacy, as amendedartificialintelligenceact.eu In text

Read next

[ your next step ]

Bring us the queue nobody wants.

One process, studied in writing. You keep the document, whatever it says.

support@surehand.io