Where it applies, and to whom.
Providers, deployers, importers and distributors placing AI on the EU market or whose output is used in the EU — including non-EU companies (extraterritorial).
How Prefactor maps to EU AI Act.
EU Regulation 2024/1689 (AI Act), issued by European Commission and Member State authorities, applies to providers, deployers, importers, distributors of AI in the EU. This page covers what affects AI agent teams specifically and how to map controls to it.
Source: official EU AI Act reference. This page is practical guidance — confirm interpretation with your counsel.
What it requiresContinuous risk management process across agent lifecycle
How Prefactor addresses itContinuous evals and drift detection on live traffic surface new failure modes; per-agent risk scoring and versioned eval history make this an ongoing, documented process — not a point-in-time review.
What it requiresAutomatic logging that enables traceability
How Prefactor addresses itEvery agent run is captured as structured, timestamped trace data — LLM calls, tool invocations, decisions and outcomes — retained as an immutable, exportable record.
What it requiresEffective human intervention and override
How Prefactor addresses itRuntime guardrails route high-risk or low-confidence actions to a human for approval before they execute; every intervention and override is logged as evidence.
What it requiresPerformance, robustness, attack resilience
How Prefactor addresses itEval suites measure accuracy and groundedness on real traffic and catch regressions before they ship; runtime guardrails defend against prompt injection and out-of-policy actions.
What it requiresContinuous performance monitoring in production
How Prefactor addresses itContinuous monitoring with drift detection and alerting on quality, cost and behaviour after deployment — a live feed, not a periodic manual check.
What it requiresDocumentation and information for deployers
How Prefactor addresses itEval results, trace samples and policy history tied to specific agent versions, exportable as dated technical documentation generated from real runtime data.
The detail, in full.
Frequently asked questions
Does using a 'compliant' provider make us compliant?
Can Prefactor make us compliant?
Key provisions for AI agents
- Risk-based tiers (prohibited, high-risk, limited, minimal)
- Article 9: risk management
- Article 12: record-keeping
- Article 14: human oversight
- Article 15: accuracy, robustness, cybersecurity
- Article 72: post-market monitoring
Who is affected
Providers, deployers, importers, distributors of AI in EU
Evidence collection
Auditors and reviewers typically expect:
- Continuous, dated evidence — not point-in-time snapshots
- Override and intervention records — proof humans actually retained control
- Eval results tied to specific agent versions
- Risk decisions tied to changes
- Incident records, even minor ones
- Plain-language documentation
Common gaps in EU AI Act for AI agents
1. Logs not tamper-evident — application database isn't audit evidence.
2. Human oversight is theoretical — system allows override but nobody uses it.
3. Post-market monitoring is reactive — only investigated when something breaks.
4. No change management — prompts edited in production with no record.
5. Retrieval corpus not in scope of data governance — only training data is considered.
Implementation timeline
30 days: Inventory agents in scope. Begin technical documentation. Enable comprehensive tamper-evident logging.
90 days: Operate risk management. Stand up human oversight. Establish post-market monitoring cadence. First self-assessment.
180 days: Complete documentation. Pre-conformity review. Incident reporting workflow. Full readiness.