Home/Insights/Compliance
Compliance

EU AI Act: what it concretely changes for your agents

Sofia Romano · Operations, SmartifyaApril 28, 202610 min

The EU AI Act has been progressively enforced since February 2025. If you deploy AI agents in the EU, here are the 6 points that really concern you — and 4 myths to ignore.

The 4 risk levels

The AI Act classifies AI systems into 4 levels: unacceptable risk (banned), high risk (strict obligations), limited risk (transparency), minimal risk (nothing).

  • Unacceptable risk: social scoring, subliminal behavioural manipulation — banned.
  • High risk: HR, education, access to essential services, justice — heavy documentation required.
  • Limited risk: chatbots, deepfakes, generated content — labelling mandatory.
  • Minimal risk: most B2B use cases (lead qualification, internal automation, etc.)

Your real obligations for most cases

If your agent doesn't touch recruitment, education, or essential services, you're probably in 'limited risk'. Your obligations:

1. Clearly inform when a human is interacting with an AI ('This email was drafted with the help of an AI assistant'). 2. Label generated content (image, video, audio). 3. Keep internal documentation on training data and uses.

The 4 myths to ignore

Many teams fear the AI Act wrongly. Here's what is NOT true:

  • Myth 1: 'Every agent must be audited by an external body.' False. Only high-risk systems are concerned.
  • Myth 2: 'We can no longer use US models.' False. The regulation applies to deployment, not the model's origin.
  • Myth 3: 'You must host in the EU.' Not mandatory for AI Act compliance (but yes for GDPR if you process personal data).
  • Myth 4: 'You must rewrite everything in open-source.' No such obligation.

Our practical checklist

For a typical agent at our clients, here's what we put in place:

  • Banner 'You are chatting with an AI assistant' from the first message
  • Logs of all interactions (GDPR-compliant, defined retention)
  • Internal documentation: model used, training data (if fine-tune), guardrails in place
  • One-click human escalation mechanism

The AI Act is not the monster some describe. For 80% of B2B cases, the compliance effort fits in half a day of paperwork + a few lines of code for the banners. We support you on this aspect in every one of our projects.

Let's talk about your project.

30 minutes to understand your need, 48 hours to send you a clear scope and a firm quote.