AI Assurance Institute Logo AI Assurance Institute

Training

Operational Control and Regulatory Compliance of AI Agents under the EU AI Act

Advanced professional education on operational governance of AI agents after deployment

Overview

This course addresses the operational compliance of AI agents under Regulation (EU) 2024/1689 (the EU AI Act). Where an agent's intended purpose places it in a high-risk class, the Act does not end at placing the system on the market. Providers and deployers carry obligations that continue in production: risk management, logging, human oversight, accuracy and robustness, quality management, deployer duties, and post-market monitoring.

The course works through those obligations as they apply to live agents. It uses the Act's own tests - intended purpose, the state of the art, and risk management - to turn the listed articles into purpose-specific controls that can be operated and audited after go-live.

Why agents need a separate operational treatment

An agent that can choose a next action is not the same object as a static model behind a form. The Act still classifies by intended purpose, not by the word "agent." Many agent uses will sit outside Annex III. Many will not. The course starts from that classification and then stays with the systems that do carry high-risk duties.

Once those duties apply, the operational problem is specific. Oversight has to reach the action the agent takes, not only the output it prints. Logs have to reconstruct a sequence of tool calls, not a single inference. Monitoring has to notice drift in behaviour and in the environment the agent can reach. Incident handling has to assume the system may keep acting until it is stopped.

Articles in scope

The course is built around the articles already named for this programme. It does not add other chapters of the Act as course content.

Classification remains purpose-specific. The course does not treat every agent as high-risk, and it does not treat high-risk status as optional once the intended purpose meets the Act's tests.

What you will learn

By the end of the course, participants will be able to:

Course structure

Six modules. Each module stays inside the articles listed above.

1. Regulatory context and the Article 8 lenses

How the Act classifies systems by intended purpose. When an agent is high-risk and when it is not. How intended purpose, state of the art and the risk-management system are used together so compliance is not a clause list detached from the live system.

2. Human oversight under Article 14

What "effective" oversight means for a system that acts with limited intervention. Assignment of the oversight role. Conditions under which a person can understand the agent, override it, or stop it. Escalation and the limits of oversight that exists only as a policy statement.

3. Logging, traceability and observability

Article 12 record-keeping as it applies to a sequence of perceptions, plans and acts. What has to be reconstructable after the fact. How observability in production supports both oversight and later assessment. Accuracy, robustness and cybersecurity under Article 15 as they affect the running agent.

4. Post-market monitoring under Article 72

The provider's duty to collect and analyse data on how the high-risk system performs in use. Drift, unexpected tool use and changes in operating conditions. When monitoring becomes a reporting matter. The deployer's related duty under Article 26 to use the system as instructed and to watch its operation.

5. Operational risk controls and incident response

Article 9 applied after deployment: identifying and treating risks that appear only when the agent is connected to tools, data and other systems. Stopping a run. Containing an agent that has left its intended environment. Recording the incident so the risk-management file can be updated.

6. Integration, documentation and audit readiness

How Articles 17 and 8 require the operational controls to sit inside a quality-management system, not beside it. What a notified body or market-surveillance authority would need to see to assess the live agent against the claimed purpose. Documentation here means the technical and operational record the Act already requires. The course does not add a separate product pack.

Who the course is for

The course is written for people who already work with high-risk or candidate high-risk AI in production, or who must show that an agent's operational controls meet the articles above. Typical participants are compliance, risk, quality, product and engineering leads responsible for agents after release. It is not an introductory survey of the EU AI Act.

Register for upcoming training