From duties to controls
Connect legal objectives to mandates, exact-action approval, limits and intervention procedures.
European policy contribution / Discussion proposal 0.2
The AI Act provides the legal foundation. PALO proposes an open operational profile linking accountable authority, agent actions and verified effects.
Agentic AI is not outside the AI Act by definition. The unresolved question is how to make delegated authority, control of consequential actions and evidence of effects consistent across systems.
Requirements on risk management, logging, human oversight, cybersecurity and actor responsibilities already reach many agentic deployments. Applicability depends on purpose, role and context. Autonomy alone does not create an EU high-risk category. AI Act: Articles 3, 6, 9-15 and 25-26.
Connect legal objectives to mandates, exact-action approval, limits and intervention procedures.
Make authority, decisions and observed effects understandable across orchestrators and reviewers.
Test whether consequential uses outside existing duties require proportionate new obligations.
A Commission-hosted report already identifies accountability and oversight challenges in autonomous action sequences. PALO contributes a practical method for examining them. The report is research, not binding guidance. StepUp StartUps, January 2026.
The new Article 4a(2) expressly considers outputs influencing future operations in the context of exceptional bias detection and correction. It does not provide a general mandate or unrestricted data-use permission. Articles 57 and 75 change sandbox and supervision arrangements. Article 96 supports practical implementation and complementarity. These are foundations for the proposal, not omissions.
Chapter III Sections 1-3, except Article 6(5), apply from 2 December 2027 for Article 6(2)/Annex III and 2 August 2028 for Article 6(1)/Annex I. Other duties and transitional rules have their own dates. The 2 December 2026 Article 50(2) transition concerns relevant systems already marketed before 2 August 2026. See the provision-level analysis and PDF page references.
Existing international work matters: IMDA updated its agentic governance framework to v1.5 in May 2026. PALO proposes EU provision mapping, interoperable action/effect evidence and comparative tests as a complementary contribution. IMDA framework .
02 / Complementarity
This mapping is a proposed implementation method. It does not mean the law mandates these identifiers, or that a PALO component establishes compliance.
| Proposed control | Legal anchor and gap | Operational contribution | Current boundary |
|---|---|---|---|
|
DAG-01
Accountable system boundary |
Articles 3, 6, 9, 25 and 26
A documented system can still lack a clear owner for a delegated action. |
Name the owner, actors, tools and external resources. | Published schema; deployment accountability requires review. |
|
DAG-02
Identity and current mandate |
Articles 9, 12, 14 and 15
No common mandate representation is prescribed for every agentic workflow. |
Bind scope, expiry and purpose to a verified workload. | Reference identity and mandate controls; production identity remains deployment-specific. |
|
DAG-03
Bounded subdelegation |
Articles 9, 15 and 25
Compound responsibility and permission expansion need explicit tests. |
Keep every child within the authority of its ancestors. | Unreleased prototype; constrained schema inheritance. |
|
DAG-04
Purpose and data conditions |
Articles 9, 10 and 15; other data-protection law separately
Permission to act is not a lawful basis for processing or disclosing data. |
Bind data fitness, recipients, egress and freshness. | Developer preview; connector observations are not independently attested. |
|
DAG-05
Action-bound enforcement |
Articles 9, 14 and 15
A policy decision detached from the actual tool call can be bypassed. |
Check exact arguments and current policy before the effect. | Contract implemented; non-bypassability must be proven for each connector. |
|
DAG-06
Meaningful human approval |
Articles 13, 14 and 26
A generic approval cannot justify an irreversible effect or override another denial condition. |
Require exact-action prior human approval for consequential actions with absent or unproven reversibility. | Strengthened proposed profile rule; reference approval contracts exist, but deployment enforcement and human competence require tests. |
|
DAG-07
Shared exposure |
Articles 9 and 15
Individually permitted actions may exceed a shared organisational limit. |
Reserve cumulative limits across concurrent agents. | Unreleased central SQLite prototype; no replicated authority or HA guarantee. |
|
DAG-08
Replay and uncertain execution |
Articles 12 and 15
A timeout cannot safely be treated as no effect. |
Consume authority once and reconcile uncertain effects. | Reference single-use capability; external idempotency is connector-specific. |
|
DAG-09
Revocation and intervention |
Articles 14, 26, 72 and 73
A stop signal does not prove that an external transaction stopped. |
Separate future denial from verified in-flight containment. | Unreleased supported-connector cancellation; arbitrary irreversible effects cannot be stopped. |
|
DAG-10
Verified effects |
Articles 9, 12, 15 and 72
An agent success message is not an authoritative outcome observation. |
Observe actual outcomes separately from execution receipts. | Prototype verifier path; observation trust and completeness are external assumptions. |
|
DAG-11
Minimised, reviewable evidence |
Articles 11, 12, 19 and 26; data-protection law separately
Integrity checks do not establish truth, lawful retention or complete coverage. |
Protect provenance, integrity, access and retention. | Prototype signatures; managed keys, anchoring and tenant isolation remain open. |
|
DAG-12
Change, incidents and remedy |
Articles 9, 17, 25, 27 where applicable, 72 and 73
Static assessments can become stale as tools and delegation change. |
Reassess new tools, changed mandates and unresolved outcomes. | Prototype incident lifecycle; legal reporting and remedies need organisational processes. |
Read the base Act with the 2026 amendment . GDPR, EU-institution data protection and sector rules require separate applicability analysis.
Children stay within ancestor authority. Concurrent actions share declared limits. Revocation stops future controlled starts. Outcome verification remains separate from permission and execution acknowledgement.
PALO Framework connects six governance phases. PALO-AM defines accountable delegation and oversight. PALO-AI supplies selected runtime contracts and reference controls. The proposed European profile connects these to a vendor-neutral review and evaluation method.
For in-scope systems initiating or delegating actions, identify who grants and supervises authority; establish permitted action scope, limits, intervention arrangements and records proportionate to the risks; assess sequences and component interactions; permit equivalent technical and organisational means.
This is suggested guidance within existing duties. It does not create new duties for excluded actors or uses. Read the drafting options.
If evidence demonstrates an unresolved coverage problem, consider targeted duties for clearly defined consequential delegated actions: provider capabilities, deployer mandates, bounded subdelegation, proportionate evidence, intervention and explicit supervisory competence.
Scope thresholds, exemptions, actor responsibilities and enforcement require impact assessment and legal drafting. No blanket classification of all agents as high-risk is proposed.
The methodology, schemas and review tools are available. PALO-AI is a developer preview. Swarm coordination and supported-connector cancellation are unreleased prototypes under one central authority. Production identity, isolation, managed keys, non-bypassable connectors, recovery and independent assurance remain deployment requirements.
Under this proposed profile, a materially consequential action with absent or unproven reversibility requires valid human approval before dispatch. Bind approval to the exact target, parameters, effects, limits and expiry. The executing agent cannot downgrade its action class. Approval never overrides another denial condition.
Compensation is a separately authorised action; it does not undo the original effect. Time-critical safety cases need a separately justified control design. The agent cannot grant itself an emergency exception. These are proposed evaluation requirements, not a claim of current runtime enforcement or a universal legal rule.
Download six supplementary approval tests . Every case is marked NOT RUN.
The proposed twelve-week pilot begins after resources and participants are confirmed. It is a planning assumption. Institutional timelines and acceptance cannot be guaranteed.
AI Office sandbox competence under Article 57(3a) is tied to Article 75(1). National sandboxes and an EDPS route for EU bodies have their own scope. A research demonstration is not automatically a regulatory sandbox.
Guidance cannot amend the Act. Delegated or implementing acts need a specific legal empowerment. Standards, voluntary participation, procurement and legislation have separate procedures. The full dossier covers second reading, conciliation, third reading and the possibility of non-adoption.
Process sources: Commission , Council , standardisation .
The candidate routes are WG 2 for operational processes, WG 3 for logging including prEN ISO/IEC 24970, WG 4 for trustworthiness logging and human oversight (prEN 18229-1 and -3), and WG 5 for cybersecurity. The dossier maps each route to DAG controls and evidence still needed.
JTC 21 project listings identify routing candidates. Current draft clauses, editions and admission must be checked before claiming alignment or harmonised status.
05 / Lessons from actual outcomes
An expert and stakeholder process produced a practical instrument tied to specified legal duties. The useful precedent is scope and participation, not automatic transfer of its legal basis to agents.
Official outcomeThe 2022 proposal was withdrawn in 2025. A recognised problem can still fail to become law. Necessity, overlap and political feasibility need evidence; the withdrawal does not establish a single cause.
Withdrawal recordAdopted simplification and revised dates show that standards, capacity and burden matter. PALO should measure integration and review costs before claiming that additional controls simplify compliance.
Enacted amendmentThese are strategy lessons inferred from documented outcomes. They are not estimates of this proposal's probability of approval. The full dossier also examines the 2026 transparency code's uptake.
06 / Operational toolkit
Use the same twelve controls for a technical workshop, pilot or institutional review. Export your declarations and a test plan with every test marked NOT RUN .
Use
node scripts/validate-eu-agentic.mjs path/to/review.json
. This checks structure and review declarations, with no remote evidence access. The runtime and its adversarial tests are separate tools.
Profile 0.2 strengthens the approval rule. Earlier 0.1 inventories need a fresh review; imports are not silently upgraded.
07 / Evidence and provenance
The supplied authentic-English OJ PDF has 41 pages. Its SHA-256 is recorded in the downloadable source register. Legal provisions, official explanatory material, our interpretation and proposed controls have different authority.
Proposed by Fabrizio Degni , Chief AI Officer and creator of PALO. This is an independent contribution intended for scrutiny and improvement.