EU AI Act Faces Agent-Risk Gap
New criticism argues that the EU AI Act’s static risk categories may not fit AI agents that act across tools, data and APIs.

The EU AI Act is now running into one of the hardest questions in AI governance: how do you regulate systems that change behaviour depending on context?
What happened
A new critique argues that the EU AI Act’s risk buckets are poorly suited to AI agents. Unlike a static model, an agent can call APIs, use tools, access data, spend tokens and change its behaviour depending on the environment.
That means two deployments of the same underlying model can carry very different levels of risk depending on what the agent is allowed to do.
Why it matters
This is an enterprise AI governance signal. Companies do not only need to classify models; they need visibility into agent behaviour. That includes tool access, permissions, data flows, token spend, resource usage and escalation rules.
If agents become common inside companies, compliance will move from paperwork into monitoring and control systems.
The bigger picture
AI regulation is shifting from model governance to workflow governance. The market opportunity may sit with tools that help companies understand what agents are doing in real time, rather than simply documenting which model they use.
