Notes from the CISO

Who Sent the Agent?

The EU AI Act's August 2nd transparency deadline is not merely about chatbot labels. It is about identity, delegated authority and evidence.

Supplier inbox · external09:14

Re: Quote 4471 — revised delivery terms

Procurement Assistant assistant@—————.com AI agent
Thanks for the quote. Could you revise for a 14-day delivery window? We can accept the higher unit price at that schedule, and I am ready to place the order today.
Acting for
not stated
Authority to commit
unknown
Delegated by
unknown
Accountable party
unknown
A supplier's view of the 9:14 email. The AI label is there. The principal, the authority to commit, and the accountable party are all blank.
TL;DR
  • What happened. On 20 July the European Commission published its final guidance on Article 50 of the EU AI Act. It applies from August 2nd.
  • What it asks for. An AI agent that corresponds, negotiates or buys on someone's behalf should say two things: that it is software, and who it is acting for.
  • Why that is hard. Agents delegate to other agents. The one that finally emails a person is often several hand-offs away from the authority it is carrying.
  • What it means in practice. Whether an agent reached a person, on whose authority, and whether it disclosed anything, are facts about the run. A design document or an inventory cannot answer them.
  • What did not happen. The Digital Omnibus delayed the Act's high-risk obligations to 2027 and 2028. This deadline was not part of that.

At 9:14 in the morning, an AI agent emails a supplier.

It asks for a revised quote, proposes different delivery terms and says it is ready to place the order. The supplier knows the message came from software. The harder question is who sent it.

Was the agent acting for an employee, a department or the company? What authority had it been given? Did another agent delegate the task? Who answers for the promise it just made?

On 20 July, the European Commission published its final guidance on Article 50 of the EU AI Act. Most of it is what you would expect: chatbots should identify themselves, synthetic content should be marked, deep fakes should be labeled.

Then, on page twelve, the register shifts.

01 · The principal

An agent needs a principal

Paragraph 31 considers agents that make bookings, manage correspondence, negotiate or conclude contracts, and execute purchases.

It says an in-scope agent must be designed to disclose both its artificial nature and the person on whose behalf it acts. The reasons are revealing: transparency of origin, delegation of authority and accountability for the consequences.

This is the beginning of caller ID for autonomous software:

I am an AI agent.transparency of origin
I am acting for this principal.delegation of authority
This is the identity behind the action.accountability for the consequences
The three claims, set against the three reasons paragraph 31 gives for asking.

The guidance even points toward electronic attestations associated with EU Digital Identity Wallets and proposed European Business Wallets as a possible way to verify an agent's identity, attributes and authorizations.

“I am an AI agent for Acme” is disclosure. A credential establishing whom the agent represents and what it may do is closer to proof. Article 50 applies from August 2nd, and this is the clearest official view of how the Commission expects its transparency rule to apply to agents.

A merchant holding a sealed letter up against the signet ring in his other hand, comparing the two
Checking the impression against the ring that made it.
02 · Jurisdiction

The agent can cross a border the company never did

The agent may run in California for a company with no European office, and neither fact necessarily puts it outside the Act.

The AI Act can apply to providers outside the EU when they place systems on the EU market. It can also reach providers and deployers outside the EU where their systems produce output used in the Union, depending on how the system is offered, put into service and used.

A merchant at his desk studying a sealed letter, with a shut counting-house far away across a boundary line
Scope can follow the output into the Union even when the company never sets foot there.
Headquarters outside Europe is not a safe harbor. For an agent system, the border may be crossed by the action rather than the company.
03 · Delegation

Delegation must not erase the sender

Now imagine that a procurement agent delegates research to one agent, negotiation to another and correspondence to a third. The final agent emails the supplier.

Which agent identifies itself? Whose name does it give? Which company answers for what it says?

procurement-agentreceives the task, holds the mandateidentity held
research-agentgathers pricing and lead timesinternal only
negotiation-agentsets the terms it is willing to offerinternal only
comms-agentwrites and sends the emailidentity not carried
Human boundary
supplierreceives a promise from a sender it cannot resolve, three delegations from the mandate
A disclosure placed only in the originating agent's interface does nothing for a supplier receiving a message three delegations later.
A merchant leaning over a counter, facing a receding line of identical clerks passing one sealed letter forward
Ask the last one who sent it, and he turns to the next.

Picture the supplier at the other end of that chain. They have an email promising an order, a sender that resolves to nothing in particular, and a decision to make about whether to start cutting steel.

The guidance expressly considers complex multi-agent architectures. It does not prescribe a technical identity protocol, but the operational implication is difficult to avoid: the component that crosses the human boundary needs access to the identity and authority it is carrying. The identity has to survive the hand-off.

That is where a conventional agent inventory begins to fail, because knowing that an agent exists is not enough. You need to know what it delegated, which component eventually acted and whether the identity traveled with the task.

The unit of control has become the chain of delegation.

04 · Runtime

"Reasonably likely" is a runtime question

Not every agent action requires disclosure. Backend exchanges that are not intended to reach a person generally fall outside the direct-interaction duty. The practical question is therefore whether this agent, or something downstream from it, crossed into a direct interaction with a person.

That boundary moves. The same agent may spend most of one run exchanging structured data, then send an email or contact a customer during the next. Agents select tools, recipients and sub-tasks based on context. A system that was internal last month can gain an email tool this month.

Where a provider cannot reliably know in advance whether an agent will encounter a person, the guidance says disclosure should be built into the architecture wherever direct human interaction is reasonably likely.

OBS-SEC Console
DetectionsDET-9E32B4
Undisclosed human contact
Detection · captured at the human boundary
An internal agent acquired an email tool, then wrote to a customer
Captured interaction
› comms-agent-prod → email.send (external recipient)
Message reached a person. No artificial-nature disclosure and no principal in the sent content.
Classified at design time
backend · no human contact
Tool added
email.send · 14 days ago
Delegation depth
3 hops from mandate
Principal on the wire
not carried
Policy agent.disclose_on_human_contact — Violated
Captured as the message left for an external recipient, fourteen days after the agent acquired the tool that made it possible.

The guidance does not create a universal duty to record every agent action, or mandate continuous monitoring or any particular product. It is also non-binding, and only the Court of Justice can authoritatively interpret the Act. But it exposes the weakness of static evidence.

A design document establishes what the system was intended to do, a test what it did under selected conditions, an inventory that somebody knew it existed. A runtime trace establishes the path it actually took.

For agent systems, important parts of the compliance case become runtime properties rather than design-time assumptions.

Those facts live in the execution of the system, not in the paperwork about it.
05 · The timetable

Reprieve, for a different problem

At almost the same time, the Digital Omnibus postponed the main high-risk obligations. The requirements for standalone Annex III systems now apply from December 2027, while those for high-risk systems embedded in regulated products apply from August 2028. That delay was real, but Article 50 still applies from August 2nd 2026, apart from a limited transition for machine-readable marking by some existing generative systems.

2 AUG 2026
Article 50 transparency
Applies now, apart from a limited transition for machine-readable marking by some existing generative systems.
DEC 2027
Annex III high-risk
Standalone systems. Postponed by the Digital Omnibus.
AUG 2028
Embedded high-risk
High-risk systems inside regulated products. Also postponed.
The Digital Omnibus moved the two high-risk dates. Article 50 kept the date it always had.

The market heard the delay much more clearly than it heard the agent guidance, and boards that heard reprieve slowed their programs down (the word “delay” travels a great deal faster than the word “guidance”).

Those are different programs, though. The delay gives organizations more time to build conformity processes for defined high-risk systems. It gives them no additional time at all on the agent questions, which arrive now.

06 · Evidence

Six questions, before the edge cases

Turn the supplier's question around and point it at your own estate. Before debating every edge case, an organization should be able to answer some basic questions.

01Which agents can contact people?
02On whose behalf does each one act?
03Can it delegate?
04Does the identity follow the task?
05Which interactions reached a person?
06Did a human genuinely review it?

A procurement spreadsheet cannot answer those questions, which require evidence from the system in operation.

AgentReaches peopleActing forDisclosure
quotes-agentyes · emailprocurement · northwindpresent
comms-agentyes · 3 hopsnot carriedabsent
ledger-agentno · internalfinance-opsnot required
scheduler-agentnew tool · 14dit-opsunverified
The same six questions, answered from telemetry instead of a survey.

That is the problem Classie is built to address. It discovers agents and AI activity from telemetry rather than surveys and declared inventories, records the interactions that reach people, and keeps the policy decision alongside the activity it governed.

None of this makes the disclosure for you, issues the credentials, or tells you what is legally in scope, and it certainly does not replace counsel. It makes the runtime estate visible enough for those decisions to rest on evidence.

The first generation of AI transparency asked whether content was made by AI. The agent generation asks something harder: who sent this agent, what authority was it carrying, and what did it do with that authority?

Know who sent the agent.
Article 50 applies from August 2nd.

Sources

  1. Regulation (EU) 2024/1689, EU AI Act, including Articles 2 and 50
  2. Regulation (EU) 2026/1744, Digital Omnibus on AI
  3. European Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50, C(2026) 5054 final, 20 July 2026