Skip to main content
PALO PALO FRAMEWORK

European policy contribution / Discussion proposal 0.2

Governing delegated
AI action in Europe.

The AI Act provides the legal foundation. PALO proposes an open operational profile linking accountable authority, agent actions and verified effects.

Fabrizio Degni / Chief AI Officer Sources reviewed: 22 September 2026 Independent proposal / No EU endorsement

Coverage exists.
Execution needs a common language.

Agentic AI is not outside the AI Act by definition. The unresolved question is how to make delegated authority, control of consequential actions and evidence of effects consistent across systems.

Requirements on risk management, logging, human oversight, cybersecurity and actor responsibilities already reach many agentic deployments. Applicability depends on purpose, role and context. Autonomy alone does not create an EU high-risk category. AI Act: Articles 3, 6, 9-15 and 25-26.

The Omnibus is enacted law. Regulation (EU) 2026/1744 entered into force on 27 July 2026. It changes duties, institutional powers and application dates. Our analysis reads it together with the base Act. Read the adopted amendment.
IMPLEMENTATION

From duties to controls

Connect legal objectives to mandates, exact-action approval, limits and intervention procedures.

INTEROPERABILITY

Evidence that travels

Make authority, decisions and observed effects understandable across orchestrators and reviewers.

POSSIBLE LEGISLATION

Prove the residual gap

Test whether consequential uses outside existing duties require proportionate new obligations.

A Commission-hosted report already identifies accountability and oversight challenges in autonomous action sequences. PALO contributes a practical method for examining them. The report is research, not binding guidance. StepUp StartUps, January 2026.

What the Omnibus already addresses

The new Article 4a(2) expressly considers outputs influencing future operations in the context of exceptional bias detection and correction. It does not provide a general mandate or unrestricted data-use permission. Articles 57 and 75 change sandbox and supervision arrangements. Article 96 supports practical implementation and complementarity. These are foundations for the proposal, not omissions.

Chapter III Sections 1-3, except Article 6(5), apply from 2 December 2027 for Article 6(2)/Annex III and 2 August 2028 for Article 6(1)/Annex I. Other duties and transitional rules have their own dates. The 2 December 2026 Article 50(2) transition concerns relevant systems already marketed before 2 August 2026. See the provision-level analysis and PDF page references.

Existing international work matters: IMDA updated its agentic governance framework to v1.5 in May 2026. PALO proposes EU provision mapping, interoperable action/effect evidence and comparative tests as a complementary contribution. IMDA framework .

02 / Complementarity

Twelve controls, anchored in existing duties.

This mapping is a proposed implementation method. It does not mean the law mandates these identifiers, or that a PALO component establishes compliance.

Existing legal anchors, operational gap and PALO evidence
Proposed control Legal anchor and gap Operational contribution Current boundary
DAG-01
Accountable system boundary
Articles 3, 6, 9, 25 and 26

A documented system can still lack a clear owner for a delegated action.

Name the owner, actors, tools and external resources.

Inspect PALO evidence

Published schema; deployment accountability requires review.
DAG-02
Identity and current mandate
Articles 9, 12, 14 and 15

No common mandate representation is prescribed for every agentic workflow.

Bind scope, expiry and purpose to a verified workload.

Inspect PALO evidence

Reference identity and mandate controls; production identity remains deployment-specific.
DAG-03
Bounded subdelegation
Articles 9, 15 and 25

Compound responsibility and permission expansion need explicit tests.

Keep every child within the authority of its ancestors.

Inspect PALO evidence

Unreleased prototype; constrained schema inheritance.
DAG-04
Purpose and data conditions
Articles 9, 10 and 15; other data-protection law separately

Permission to act is not a lawful basis for processing or disclosing data.

Bind data fitness, recipients, egress and freshness.

Inspect PALO evidence

Developer preview; connector observations are not independently attested.
DAG-05
Action-bound enforcement
Articles 9, 14 and 15

A policy decision detached from the actual tool call can be bypassed.

Check exact arguments and current policy before the effect.

Inspect PALO evidence

Contract implemented; non-bypassability must be proven for each connector.
DAG-06
Meaningful human approval
Articles 13, 14 and 26

A generic approval cannot justify an irreversible effect or override another denial condition.

Require exact-action prior human approval for consequential actions with absent or unproven reversibility.

Inspect PALO evidence

Strengthened proposed profile rule; reference approval contracts exist, but deployment enforcement and human competence require tests.
DAG-07
Shared exposure
Articles 9 and 15

Individually permitted actions may exceed a shared organisational limit.

Reserve cumulative limits across concurrent agents.

Inspect PALO evidence

Unreleased central SQLite prototype; no replicated authority or HA guarantee.
DAG-08
Replay and uncertain execution
Articles 12 and 15

A timeout cannot safely be treated as no effect.

Consume authority once and reconcile uncertain effects.

Inspect PALO evidence

Reference single-use capability; external idempotency is connector-specific.
DAG-09
Revocation and intervention
Articles 14, 26, 72 and 73

A stop signal does not prove that an external transaction stopped.

Separate future denial from verified in-flight containment.

Inspect PALO evidence

Unreleased supported-connector cancellation; arbitrary irreversible effects cannot be stopped.
DAG-10
Verified effects
Articles 9, 12, 15 and 72

An agent success message is not an authoritative outcome observation.

Observe actual outcomes separately from execution receipts.

Inspect PALO evidence

Prototype verifier path; observation trust and completeness are external assumptions.
DAG-11
Minimised, reviewable evidence
Articles 11, 12, 19 and 26; data-protection law separately

Integrity checks do not establish truth, lawful retention or complete coverage.

Protect provenance, integrity, access and retention.

Inspect PALO evidence

Prototype signatures; managed keys, anchoring and tenant isolation remain open.
DAG-12
Change, incidents and remedy
Articles 9, 17, 25, 27 where applicable, 72 and 73

Static assessments can become stale as tools and delegation change.

Reassess new tools, changed mandates and unresolved outcomes.

Inspect PALO evidence

Prototype incident lifecycle; legal reporting and remedies need organisational processes.

Read the base Act with the 2026 amendment . GDPR, EU-institution data protection and sector rules require separate applicability analysis.

One evidence chain.
Distinct decisions.

1. Mandate Owner, purpose, permissions, expiry and delegation.
2. Decision Current policy, evidence, approval and limits.
3. Execution Controlled tool call and a single-use authority record.
4. Observation Verified effect, mismatch or explicit uncertainty.

Children stay within ancestor authority. Concurrent actions share declared limits. Revocation stops future controlled starts. Outcome verification remains separate from permission and execution acknowledgement.

Allowed is not verified. Signed evidence can establish origin and integrity. It does not prove that a statement is true, that an external action was reversible or that a system is compliant.

Theoretical, technical and operational layers

PALO Framework connects six governance phases. PALO-AM defines accountable delegation and oversight. PALO-AI supplies selected runtime contracts and reference controls. The proposed European profile connects these to a vendor-neutral review and evaluation method.

Proposed implementation language

For in-scope systems initiating or delegating actions, identify who grants and supervises authority; establish permitted action scope, limits, intervention arrangements and records proportionate to the risks; assess sequences and component interactions; permit equivalent technical and organisational means.

This is suggested guidance within existing duties. It does not create new duties for excluded actors or uses. Read the drafting options.

Proposed legislative extension

If evidence demonstrates an unresolved coverage problem, consider targeted duties for clearly defined consequential delegated actions: provider capabilities, deployer mandates, bounded subdelegation, proportionate evidence, intervention and explicit supervisory competence.

Scope thresholds, exemptions, actor responsibilities and enforcement require impact assessment and legal drafting. No blanket classification of all agents as high-risk is proposed.

Current PALO capabilities

The methodology, schemas and review tools are available. PALO-AI is a developer preview. Swarm coordination and supported-connector cancellation are unreleased prototypes under one central authority. Production identity, isolation, managed keys, non-bypassable connectors, recovery and independent assurance remain deployment requirements.

Prior approval for consequential irreversible actions

Under this proposed profile, a materially consequential action with absent or unproven reversibility requires valid human approval before dispatch. Bind approval to the exact target, parameters, effects, limits and expiry. The executing agent cannot downgrade its action class. Approval never overrides another denial condition.

Compensation is a separately authorised action; it does not undo the original effect. Time-critical safety cases need a separately justified control design. The agent cannot grant itself an emergency exception. These are proposed evaluation requirements, not a claim of current runtime enforcement or a universal legal rule.

Download six supplementary approval tests . Every case is marked NOT RUN.

Start with evidence.
Keep the legislative option precise.

  1. Prepare and disclose Confirm submitting capacity, contribution rights, interests and any applicable Transparency Register requirements.
  2. Technical dialogue Request a scoping discussion with the European AI Office and routing to the relevant teams. This is intake, not endorsement.
  3. Evaluate in a bounded pilot Use synthetic procurement, public-service and software-operation scenarios, an independent evaluator and preferably two implementations.
  4. Contribute to guidance and practice Use Article 96 implementation work and an appropriate voluntary Article 95 route. Article 56 is specific to GPAI duties.
  5. Contribute to standards Work through relevant standards bodies and CEN-CENELEC JTC 21 processes. Presumption of conformity requires the applicable Official Journal citation.
  6. Assess the need for legislation Compare options, rights impacts, burdens and residual harms. Use review opportunities under Article 112 or earlier justified action.
  7. Commission proposal Political prioritisation, consultation, impact assessment where appropriate, scrutiny, interservice work and College adoption.
  8. Co-legislator approval and implementation Parliament and Council readings, negotiations, formal adoption, publication, application dates, supervisory preparation and evaluation.

The proposed twelve-week pilot begins after resources and participants are confirmed. It is a planning assumption. Institutional timelines and acceptance cannot be guaranteed.

Which sandbox, committee or legal instrument?

AI Office sandbox competence under Article 57(3a) is tied to Article 75(1). National sandboxes and an EDPS route for EU bodies have their own scope. A research demonstration is not automatically a regulatory sandbox.

Guidance cannot amend the Act. Delegated or implementing acts need a specific legal empowerment. Standards, voluntary participation, procurement and legislation have separate procedures. The full dossier covers second reading, conciliation, third reading and the possibility of non-adoption.

Process sources: Commission , Council , standardisation .

Specific standards contribution routes

The candidate routes are WG 2 for operational processes, WG 3 for logging including prEN ISO/IEC 24970, WG 4 for trustworthiness logging and human oversight (prEN 18229-1 and -3), and WG 5 for cybersecurity. The dossier maps each route to DAG controls and evidence still needed.

JTC 21 project listings identify routing candidates. Current draft clauses, editions and admission must be checked before claiming alignment or harmonised status.

Pilot readiness comes first. Confirm participants, evaluator independence, resources, rights, baseline and isolated infrastructure before starting the twelve-week clock. Synthetic data reduces exposure but does not eliminate privacy or live-resource risks. If there is only one implementation, report a feasibility study and leave interoperability unproven.

05 / Lessons from actual outcomes

Adoption requires more than a plausible gap.

ADOPTED VOLUNTARY TOOL

GPAI Code of Practice

An expert and stakeholder process produced a practical instrument tied to specified legal duties. The useful precedent is scope and participation, not automatic transfer of its legal basis to agents.

Official outcome
WITHDRAWN PROPOSAL

AI Liability Directive

The 2022 proposal was withdrawn in 2025. A recognised problem can still fail to become law. Necessity, overlap and political feasibility need evidence; the withdrawal does not establish a single cause.

Withdrawal record
IMPLEMENTATION CORRECTION

Digital Omnibus on AI

Adopted simplification and revised dates show that standards, capacity and burden matter. PALO should measure integration and review costs before claiming that additional controls simplify compliance.

Enacted amendment

These are strategy lessons inferred from documented outcomes. They are not estimates of this proposal's probability of approval. The full dossier also examines the 2026 transparency code's uptake.

06 / Operational toolkit

Build a reviewable evidence inventory.

Use the same twelve controls for a technical workshop, pilot or institutional review. Export your declarations and a test plan with every test marked NOT RUN .

Review support, not a compliance score. Reviewed means a named person declares that they reviewed referenced evidence. The workbench does not verify that evidence. Not-applicable items require a reason. Entries stay in this page's memory until you export; reloading clears them. Avoid confidential or personal data in a public submission.

Download and inspect

Validate a review file from the repository

Use node scripts/validate-eu-agentic.mjs path/to/review.json . This checks structure and review declarations, with no remote evidence access. The runtime and its adversarial tests are separate tools.

Profile 0.2 strengthens the approval rule. Earlier 0.1 inventories need a fresh review; imports are not silently upgraded.

07 / Evidence and provenance

Sources, status and open questions.

The supplied authentic-English OJ PDF has 41 pages. Its SHA-256 is recorded in the downloadable source register. Legal provisions, official explanatory material, our interpretation and proposed controls have different authority.

  1. AI Act: Regulation (EU) 2024/1689 (Original adopted law; read with amendments)
  2. Digital Omnibus on AI: Regulation (EU) 2026/1744 (Enacted amendment; Official Journal PDF reviewed)
  3. European AI Office: structure and general contact (Official organisational information)
  4. Lucilla Sioli: official biography (Official role verification)
  5. Agentic AI: European talent and regulatory assets (Commission-hosted StepUp StartUps research; not binding guidance)
  6. AI Act standardisation (Official process explanation)
  7. GPAI Code of Practice (Voluntary implementation precedent)
  8. Transparency Code: 31 July 2026 uptake announcement (Historical participation figure; section lists overlap; no proof of effectiveness)
  9. Withdrawal of Commission proposals, C/2025/5423 (AI Liability Directive withdrawal record)
  10. Planning and proposing law (Commission procedure)
  11. Ordinary legislative procedure (Council procedure explanation)
  12. Better Regulation (Consultation and evidence process)
  13. Transparency Register (Conditions for covered policy meetings)
  14. NIST AI Agent Standards Initiative (International technical work; no EU legal equivalence)
  15. IMDA agentic governance framework v1.5: May 2026 update (International governance reference; no EU legal equivalence)
  16. IMDA update announcement: 20 May 2026 (Official update and deployment examples)
  17. JTC 21 working groups and projects (Secretariat project listings; routing, not clause-level equivalence)
  18. ISO/IEC 24970: AI system logging (FDIS under development; not evidence of EU harmonisation)
  19. EDPS: synthetic data (Privacy assessment remains necessary)
  20. Transparency Register scope guidance (Personal-capacity distinction depends on the actual activity)
Still to establish: pilot participants, independent results, confirmed resources, submitting capacity and the appropriate institutional workstream. No endorsement, funding or production qualification is implied. Contact and legal status should be rechecked before submission.

Proposed by Fabrizio Degni , Chief AI Officer and creator of PALO. This is an independent contribution intended for scrutiny and improvement.