At 9:14 in the morning, an AI agent emails a supplier.
It asks for a revised quote, proposes different delivery terms and says it is ready to place the order. The supplier knows the message came from software. The harder question is who sent it.
Was the agent acting for an employee, a department or the company? What authority had it been given? Did another agent delegate the task? Who answers for the promise it just made?
On 20 July, the European Commission published its final guidance on Article 50 of the EU AI Act. Most of it is what you would expect: chatbots should identify themselves, synthetic content should be marked, deep fakes should be labeled.
Then, on page twelve, the register shifts.
An agent needs a principal
Paragraph 31 considers agents that make bookings, manage correspondence, negotiate or conclude contracts, and execute purchases.
It says an in-scope agent must be designed to disclose both its artificial nature and the person on whose behalf it acts. The reasons are revealing: transparency of origin, delegation of authority and accountability for the consequences.
This is the beginning of caller ID for autonomous software:
The guidance even points toward electronic attestations associated with EU Digital Identity Wallets and proposed European Business Wallets as a possible way to verify an agent's identity, attributes and authorizations.
“I am an AI agent for Acme” is disclosure. A credential establishing whom the agent represents and what it may do is closer to proof. Article 50 applies from August 2nd, and this is the clearest official view of how the Commission expects its transparency rule to apply to agents.
The agent can cross a border the company never did
The agent may run in California for a company with no European office, and neither fact necessarily puts it outside the Act.
The AI Act can apply to providers outside the EU when they place systems on the EU market. It can also reach providers and deployers outside the EU where their systems produce output used in the Union, depending on how the system is offered, put into service and used.
Headquarters outside Europe is not a safe harbor. For an agent system, the border may be crossed by the action rather than the company.
Delegation must not erase the sender
Now imagine that a procurement agent delegates research to one agent, negotiation to another and correspondence to a third. The final agent emails the supplier.
Which agent identifies itself? Whose name does it give? Which company answers for what it says?
Picture the supplier at the other end of that chain. They have an email promising an order, a sender that resolves to nothing in particular, and a decision to make about whether to start cutting steel.
The guidance expressly considers complex multi-agent architectures. It does not prescribe a technical identity protocol, but the operational implication is difficult to avoid: the component that crosses the human boundary needs access to the identity and authority it is carrying. The identity has to survive the hand-off.
That is where a conventional agent inventory begins to fail, because knowing that an agent exists is not enough. You need to know what it delegated, which component eventually acted and whether the identity traveled with the task.
The unit of control has become the chain of delegation.
"Reasonably likely" is a runtime question
Not every agent action requires disclosure. Backend exchanges that are not intended to reach a person generally fall outside the direct-interaction duty. The practical question is therefore whether this agent, or something downstream from it, crossed into a direct interaction with a person.
That boundary moves. The same agent may spend most of one run exchanging structured data, then send an email or contact a customer during the next. Agents select tools, recipients and sub-tasks based on context. A system that was internal last month can gain an email tool this month.
Where a provider cannot reliably know in advance whether an agent will encounter a person, the guidance says disclosure should be built into the architecture wherever direct human interaction is reasonably likely.
The guidance does not create a universal duty to record every agent action, or mandate continuous monitoring or any particular product. It is also non-binding, and only the Court of Justice can authoritatively interpret the Act. But it exposes the weakness of static evidence.
A design document establishes what the system was intended to do, a test what it did under selected conditions, an inventory that somebody knew it existed. A runtime trace establishes the path it actually took.
For agent systems, important parts of the compliance case become runtime properties rather than design-time assumptions.
Those facts live in the execution of the system, not in the paperwork about it.
Reprieve, for a different problem
At almost the same time, the Digital Omnibus postponed the main high-risk obligations. The requirements for standalone Annex III systems now apply from December 2027, while those for high-risk systems embedded in regulated products apply from August 2028. That delay was real, but Article 50 still applies from August 2nd 2026, apart from a limited transition for machine-readable marking by some existing generative systems.
The market heard the delay much more clearly than it heard the agent guidance, and boards that heard reprieve slowed their programs down (the word “delay” travels a great deal faster than the word “guidance”).
Those are different programs, though. The delay gives organizations more time to build conformity processes for defined high-risk systems. It gives them no additional time at all on the agent questions, which arrive now.
Six questions, before the edge cases
Turn the supplier's question around and point it at your own estate. Before debating every edge case, an organization should be able to answer some basic questions.
A procurement spreadsheet cannot answer those questions, which require evidence from the system in operation.
That is the problem Classie is built to address. It discovers agents and AI activity from telemetry rather than surveys and declared inventories, records the interactions that reach people, and keeps the policy decision alongside the activity it governed.
None of this makes the disclosure for you, issues the credentials, or tells you what is legally in scope, and it certainly does not replace counsel. It makes the runtime estate visible enough for those decisions to rest on evidence.
The first generation of AI transparency asked whether content was made by AI. The agent generation asks something harder: who sent this agent, what authority was it carrying, and what did it do with that authority?
