What you will need to show about a live agent

Dated 4 September 2026, and hedged. Named overseer, authority to stop the writes, what the log has to contain. Most support, sales, and document workflows are probably not high-risk under the EU AI Act. The evidence is still worth having.

This note is dated 4 September 2026. The application calendar for the EU AI Act has already moved once this year, including material published in July 2026 on Regulation (EU) 2026/1744 and the Chapter III dates. Do not take the next four paragraphs as a determination that your workflow is in scope. We are not your counsel.

Most of the queues we put an agent on (helpdesk triage, CRM hygiene, invoice extraction with a person on payment facts) are unlikely to be high-risk systems under Annex III. If they are not, the deployer duties that attach to high-risk systems do not bite. Plenty of vendors will imply that they do, because a compliance story sells. We will not.

What you still need, because your own IT, finance, or customers will ask, is evidence that a person could see what happened and could have stopped it.

A named overseer, with authority

Pick a natural person who can pause the agent. Not a shared inbox. Not “the vendor”. Someone with competence on this queue, training on what the agent is allowed to write, and the actual authority to stop it without opening a ticket with us first.

Article 26 language about deployers assigning human oversight to named natural persons is the shape of this, for systems that are in fact high-risk. For the rest, it is still good operations. If the only person who understands the agent is on leave, you do not have oversight. You have a dependency.

Write down who that is, who covers them, and how they stop a write. We will put a named owner from our employed team on the monthly run. That does not replace your overseer. It is who they call.

What the log has to contain

Minimum useful set: the record identifier, the event that triggered the run, the fields read, the proposal, whether a person approved, the fields written, and the time. Store it where your team can query it without asking us for a CSV.

If logs are under your control, high-risk deployers are told to retain automatically generated logs for at least six months. Again, your workflow may not be high-risk. Six months is still a sensible default for a write path into a CRM or ERP, because disputes arrive late.

Do not keep prompts that contain data you would not put in an email. If the prompt had a customer name, treat the log line as personal data and give it the same retention and access rules as the ticket.

Evidence as a by-product, not a product

We do not sell an EU AI Act package. The map, the permission set, the exception types, and the write log are what you get because the agent has to be operable. If a later review asks who could stop it and what it changed last Tuesday, you should be able to answer from those artefacts.

If your counsel has already told you the workflow is high-risk, bring that to the assessment. We will not certify you. We will tell you whether the design produces the evidence they are asking for, or whether you should not put the agent live yet.