The term ‘AI agent’ is often used inconsistently in public debate, due in part to a blurry and still evolving demarcation between AI agents and other kinds of AI. Nevertheless, there is broad agreement that an AI agent must have the ability to receive and process input from their environment, and execute actions based on this processing that may interact with or affect their environment (e.g., issuing function calls). The term ‘Agentic AI’ is sometimes used to describe more sophisticated configurations that integrate multiple AI agents. Nevertheless, the precise interrelation between these two terms is still evolving.
Typically, an AI agent will contain at least a general-purpose AI (GPAI) model, and constitute an AI system as it will usually have some form of interface, which is considered a system component (recital 97 AI Act). A more precise statement than ‘typically’ is difficult to make as the term AI agent is not legally defined and is used colloquially for different kinds of artefacts. Thus, while AI agents are not a separate category of AI under the AI Act, the definitions of an AI system in Article 3(1) AI Act and of a GPAI model in Article 3(63) AI Act are sufficient to cover AI agents. This means that the rules applicable to AI systems and GPAI models under the AI Act also apply to AI agents.
Of the rules for AI systems, particularly relevant are the AI Act’s prohibitions of harmful manipulation and exploitation of vulnerabilities (Article 5(1), points (a) and (b), AI Act), compliance with which may require safeguards in the design and development of the AI agents to avoid prohibited practices that are reasonably likely to cause significant harm. From 2 August 2026 onwards, if the AI agent is intended to interact with natural persons or generate content, transparency rules will apply (Article 50 AI Act) – a Code of Practice to operationalise these rules was recently published. Furthermore, from 2 Dec 2027 respective 2 Aug 2028 onwards, if the AI agent classifies as a high-risk AI system, it is also subject to additional requirements that ensure its safety and trustworthiness for its intended usage (Chapter III AI Act).
As regards the GPAI models typically underlying AI agents, factors like the level of autonomy or tool use of the model can be decisive in the designation of the model as a model with systemic risk (Article 51(1)(b), Annex XIII, point (e), AI Act). Moreover, providers of GPAI models with systemic risk are subject to risk management obligations, which include considerations regarding the model’s autonomous capabilities and its agentic use (operationalised for example in Measure 5.1, point 7, Appendix 1.3.1, points (5) and (7), Appendix 1.3.3, points (1), (4), and (12), or Appendix 3.2, second paragraph, Safety and Security Chapter of the GPAI Code of Practice).
Given that developments related to AI agents are recent and fast evolving, the European Commission’s regulatory considerations are only preliminary at this stage. The AI Office continues to closely monitor these developments and, if need be, will consider developing strategies to address the potential risks posed by AI agents. For example, the AI Office’s recent call for tenders on technical assistance for AI safety includes a lot dedicated to the evaluation of the safety and security of AI agents.