More than 7 million AI agents run inside businesses, but fixed regulatory risk tiers can't keep up with their dynamic behavior. The EU AI Act misses the point: agent risk is a moving target.
There are more than 7 million AI agents running inside businesses right now. But a growing number of them aren't doing what they were built for. Not because someone reprogrammed them, but because they were handed a new permission, a new tool, or a new database to access.
The risk categories regulators assign to these agents are fixed. The agents, however, are anything but.
The EU AI Act, which came into force two years ago, goes fully live this August. The heaviest obligations arrive in waves through 2027 and 2028, but the architecture for policing how companies build and use AI is already here. It follows a run of headline-grabbing incidents, including the recent breach of Hugging Face by OpenAI's models.
I've been warning businesses about this risk for months, and it's certainly true that we collectively need real guardrails to match. But I'm not convinced this regulation hits the mark.
### The Illusion of Fixed Risk Tiers
The prevailing regulatory impulse is to treat AI like any other industrial asset, sorting models and agents into tier-based buckets. The EU AI Act tries to neatly divide these systems into "Prohibited," "High-Risk," and so on. But this is a dangerous illusion of safety.
These frameworks are blind to the dynamic nature of the agentic era. We're dealing with non-human identities that act with real autonomy, calling external APIs, chaining tools together, and evolving their execution paths on the fly. Legislation better suited to governing the production of tin cans doesn't work effectively for such dynamic, evolving systems.
Low-risk tools, deployed without governance, can quickly become high-risk. It's the equivalent of an intern waking up one morning with sign-off authority on six-figure contractsโno interview, no manager approval, no one noticing the job description changed. These are not static systems. Their behavior is self-directed, and their execution paths are non-deterministic. The same agent, given the same task, won't necessarily take the same route twice.
### The Accountability Gap Nobody's Talking About
Beyond safety controls, there's a gaping hole in the current regulatory conversation that we urgently need to address: agent accountability. Every agent needs a human who is accountable for what it does. That's not a new idea. Workplaces have run on some version of this philosophy for hundreds of years, holding senior people responsible for the actions of their teams, juniors, and trainees.
If an agent is making active business decisions, executing contracts, or moving data, it cannot exist in an anonymous legal vacuum. An enterprise must have a direct, traceable line connecting the agent back to a human. Without an ironclad system of agent accountability, the entire corporate adoption of autonomous networks collapses under the weight of unmanaged liability.
### Why Compliance Is Actually Good for Business
The good news for firms is that, done right, the same controls that satisfy a regulator are the ones that let you run AI at scale with confidence. In this case, what is good for security is good for business.
Take token spend, data access, and resource usage. A business needs visibility into all three to run agents at scale without costs or risks spiraling out of control. It turns out that's largely the same visibility a regulator wants to see for a "high-risk" system. The infrastructure is the same. Only the reason for building it changes.
Adopting a high-risk framework isn't simply about pleasing an auditor. It's about establishing the foundational stability required to trust your own systems enough to actually use them. Done well, this means turning complex, daunting regulatory requirements into practical safeguards that give businesses the confidence to deploy and scale AI responsibly.
- **Fixed risk categories ignore evolving agent behavior**
- **Human accountability is the missing link in AI governance**
- **Regulatory compliance and operational efficiency share the same foundation**
### The Path Forward
Agents represent a significant productivity opportunity for businesses. The question for regulators and businesses alike is whether we can build the conditions for humans and agents to work together effectively over the long term. Regulation doesn't need to be an obstacle. It can be the framework that gives enterprises the certainty they need to innovate boldly.
But that only happens if we stop treating AI like a static tool and start recognizing it for what it is: a dynamic, autonomous participant in the workplace that demands the same oversight we give to any senior employee. The EU AI Act may not have all the answers, but the conversation it's sparked is the right one to be having.