See what Trussed catches that your current tool misses, live in your stack

    No migration, no commitment, just a direct comparison in your environment.

    Set up a technical evaluation
    Compliance Guide

    EU AI Act Enforcement August 2026: Runtime Controls for High-Risk AI

    Most EU AI Act obligations for high-risk AI systems apply from 2 August 2026. For enterprises running AI agents and automated decision workflows, readiness means demonstrable runtime controls: risk management in operation, human oversight with intervention capability, automatic logging, transparency for deployers, and continuous policy enforcement, not pre-deployment documentation alone. GPAI model duties largely applied earlier (2 August 2025). Supervisory review will expect attributable audit trails and evidence that agent and tool actions stay within approved risk bounds over the system lifetime.

    August 2026 readiness pillars

    Four operational pillars frame how enterprises translate high-risk duties into controls that hold up under supervisory review.

    Scope and roles

    Classify high-risk use cases and allocate provider versus deployer duties.

    Runtime enforcement

    Identity, least privilege, and tool-call policy at orchestration time.

    Human oversight

    Designed intervention, stop, and approval gates for high-impact actions.

    Audit evidence

    Tamper-evident logs, policy versions, and post-market monitoring trails.

    Control architecture for agent estates

    A practical runtime stack for attributable agents, enforced tool boundaries, oversight gates, and reconstructable audit evidence.

    1. Identity layer

      Authenticate agents, tools, and principals so every material action is attributable.

    2. Policy enforcement points

      Evaluate allow, deny, and approval rules at orchestration and tool-broker boundaries.

    3. Oversight gates

      Require human approval or stop capability on high-impact actions with residual risk.

    4. Evidence plane

      Retain tamper-evident events plus policy and configuration baselines for audit reconstruction.

    Readiness checklist for AI governance leaders

    • In-scope high-risk and critical agent use cases are inventoried with provider and deployer roles assigned.
    • Least-privilege tool and data access is enforced at runtime per agent or task, with attributable credentials.
    • Human oversight gates can intervene, stop, or approve high-impact actions, and interventions are logged with reason codes.
    • Automatic logs cover prompts, tool calls, decisions, denials, overrides, and outcomes with correlation across the chain.
    • Audit packages can link risk assessments, policy versions, runtime events, and post-market monitoring outcomes.
    • Continuous monitoring detects policy bypass, permission creep, and post-deployment behavior drift.

    What August 2026 actually changes for enterprises

    Regulation (EU) 2024/1689 phases obligations over time. Prohibited practices and AI literacy applied from 2 February 2025. General-purpose AI (GPAI) model obligations largely applied from 2 August 2025. The majority of remaining provisions, including core duties for high-risk AI systems, apply from 2 August 2026. A narrower set of high-risk systems that are safety components of products under specified Union harmonisation legislation have an extended date of 2 August 2027.

    For AI governance leaders, the practical shift is supervisory expectation. Market surveillance authorities (and the AI Office for GPAI) form the core enforcement architecture. After 2 August 2026, organizations using high-risk systems should assume reviewers will ask how risk is managed throughout the lifecycle, how humans can understand and interrupt operation, how automatic logs support traceability and post-market monitoring, and how deployers monitor live behavior. Policies and one-time impact assessments without continuous operational controls will not answer those questions.

    Enterprises that embed agents into HR, credit, access, critical infrastructure adjacent workflows, or other Annex III-style contexts must treat classification and role allocation as foundational work. Provider versus deployer status can shift when an organization builds, fine-tunes, integrates, or substantially determines the purpose of a system. Mixed duties are common on internal agent platforms and must be allocated contractually and operationally before control design begins.

    High-risk duties that map to runtime governance

    Several high-risk obligations map more cleanly to runtime architecture than to static documentation. Providers must operate a risk management system across the lifecycle: identify, estimate, evaluate, and mitigate risks as systems change. They must design for effective human oversight so natural persons can understand, monitor, and intervene in or interrupt operation. They must provide automatic logging over the system lifetime sufficient for traceability and post-market monitoring, meet transparency requirements so deployers understand capabilities, limitations, and oversight roles, and run a quality management system covering compliance, design control, testing, data governance, and post-market monitoring.

    Deployers must assign human oversight, ensure input data relevance where applicable, monitor operation, and keep logs under their control for an appropriate period. For agentic systems that call tools, change state in enterprise systems, or chain model decisions, those duties are continuous. Pre-deployment conformity evidence ages poorly when prompts, tool catalogs, permissions, or model versions drift after go-live.

    Runtime technical controls that align most directly with these duties include: strong identity and authentication for agents, tools, and calling principals; least-privilege, task-scoped credentials instead of shared long-lived secrets; allow, deny, or require-approval policy at tool-call and action boundaries; structured logging of prompts, tool invocations, decisions, human overrides, and outcomes; and policy enforcement at inference or orchestration time, not only at procurement or training. Separation of duties between autonomous agent steps and human approval gates for high-impact actions supports the Act’s human oversight design goals without prescribing a single reference stack.

    Pre-deployment assessments alone do not answer lifecycle questions. Supervisors will look for controls that still operate after tools, prompts, permissions, and models change.

    From documentation-only compliance to continuous controls

    Common gaps appear when organizations stop at pre-deployment assessments. Approved use cases expand quietly through new tools. Prompts and retrieval corpora change without re-validation. Agents inherit broad roles meant for humans. Shared API keys erase attribution. Oversight is defined in a RACI but never wired into the path of execution. Logs capture model outputs but omit tool arguments, denials, and human reason codes.

    Close those gaps with an explicit mapping exercise. For each in-scope high-risk or enterprise-critical agent use case, list the applicable duties (risk management, oversight, logging, transparency, quality and post-market monitoring), name control owners, and define the runtime enforcement point. Establish change control that triggers re-validation when tools, permissions, models, or oversight rules change. Define retention, access control, and integrity protection for logs sufficient for deployer and provider obligations and for supervisory inquiry.

    Internal audit and risk functions should sample live agent behavior against approved use policy, oversight effectiveness, and log completeness, not only review artifacts from the original release. GPAI duties that applied from August 2025 remain material wherever enterprises integrate or fine-tune general-purpose models inside high-risk or agentic workflows; those upstream obligations do not disappear when the 2026 high-risk wave arrives.

    Structuring audit evidence for supervisory review

    The Act sets duties; it does not prescribe one enterprise agent reference architecture. Evidence expectations will vary by authority, sector, and use case. Secondary guidance, standards, and national market-surveillance practice will continue to evolve, so control mappings should be re-checked against official updates closer to August 2026. Classification of novel multi-agent systems depends on intended purpose and regulatory context and may need case-specific legal analysis outside the scope of this guide.

    Within those limits, durable evidence packages share a common shape. They show the approved intended purpose and residual risk posture, the versioned policies and oversight rules in force at the time of operation, the runtime events that prove those rules executed, and the monitoring outcomes that show ongoing effectiveness. Prefer immutable or tamper-evident stores and clear retention schedules over ad hoc log exports assembled after a request arrives.

    • Tie evidence to duties: Organize packages around risk management, human oversight, record-keeping, transparency, and monitoring, not generic security screenshots.
    • Version everything material: Retain policy, model, prompt, tool catalog, and approval-rule versions alongside event streams.
    • Prove enforcement, not intent: Include denials, quarantines, and override paths so reviewers see controls operating under stress.
    • Revisit mappings: Schedule periodic review against implementing acts, standards, and internal use-case changes before and after August 2026.

    Assess runtime readiness for August 2026

    Trussed AI focuses on runtime governance and security for enterprise AI agents, including policy enforcement, agent permissions, tool approval workflows, and audit logging that support operational compliance evidence.

    Request a Demo