Governing delegated AI action in Europe#
A PALO contribution to the implementation and future evolution of the EU AI Act
Discussion proposal v0.2 | 22 September 2026 | Fabrizio Degni, Chief AI Officer, creator and maintainer of PALO
Executive decision brief#
Europe should develop a proportionate, interoperable profile for the governance of delegated AI actions. The profile would connect a responsible organisation and its mandate to each consequential action, the permitted tools and data, human intervention, and evidence of the actual outcome. PALO offers an open reference implementation and a structured methodology for evaluating this approach.
The proposition is an operational specification gap within a substantially applicable legal framework, with a possible residual legislative gap to be demonstrated. It is not a claim that agents escape the AI Act. A system that plans and acts through tools can already fall within the Act's definition, prohibitions, high-risk requirements, transparency duties and, where applicable, the general-purpose AI rules. Applicability depends on the system, purpose, actors and context; autonomy does not itself create an EU high-risk category. AI Act.
The supplied Digital Omnibus is the enacted Regulation (EU) 2026/1744, dated 8 July 2026, published on 24 July and in force from 27 July. It simplifies implementation and changes important substantive and institutional provisions. It does not establish a general, interoperable protocol for mandates, subdelegation, action permissions, shared exposure or verified effects. That last observation is our reading of the instruments, not an official Commission finding. Omnibus.
We propose three connected workstreams:
- Now: technical dialogue and a twelve-week, synthetic-data evaluation pilot, with openly reviewable artifacts and an independent evaluation role.
- On evidence: contribute an implementation profile to Article 96 guidance, voluntary Article 95 work and relevant European standardisation work. Each has a different legal status and admission process.
- Only for demonstrated residual gaps: prepare a narrowly scoped legislative amendment. New mandatory cross-sector duties outside existing powers require legislation, not a declaration by the AI Office.
The immediate request is a technical scoping discussion and guidance on an appropriate institutional route. It is not a request for a PALO certification, exclusive supplier status, funding commitment or general exemption. No institutional endorsement, pilot partner or independent effectiveness result is claimed.
1. What the law already covers#
The AI Act regulates systems as well as models. Article 3(1) already accommodates varying levels of autonomy and adaptiveness. For high-risk systems, Articles 9, 11 to 15, 17, 25 and 26 provide substantial hooks for risk management, documentation, logging, oversight, security and value-chain responsibilities. Articles 72 and 73 address post-market monitoring and serious incidents. These obligations must be read with their scope, exceptions and application dates. A general-purpose model and the downstream agentic system using it are different regulatory objects.
| Existing legal anchor | Agentic application | What PALO adds as a proposed implementation method |
|---|---|---|
| Articles 3, 6 and 25 | Determine system boundaries, intended purpose, provider/deployer roles and changes that may change responsibility | System and agent inventory; documented delegation graph; change review |
| Article 9 | Identify foreseeable misuse and compound risks over an action sequence | Action-space inventory, cumulative exposure ceilings and scenario testing |
| Articles 11 and 12; Annex IV | Technical documentation and automatic recording for in-scope high-risk systems | Linked mandate, action claim, policy decision, execution receipt and outcome record |
| Articles 13, 14 and 26 | Usable instructions and effective human oversight | Approval bound to exact action details; escalation, revocation and intervention drills |
| Article 15 | Accuracy, robustness and cybersecurity for high-risk systems | Permission narrowing, replay protection, connector controls and adversarial tests |
| Articles 17 and 25 | Quality management and actor responsibilities | Release gates, change ownership, supplier evidence and explicit allocation of duties |
| Article 27 | Fundamental-rights impact assessment for specified deployers and systems | Action consequences, affected persons, remedy and consultation records where applicable |
| Article 50 | Specified transparency obligations | Interaction notices and provenance controls, separate from execution authorisation |
| Articles 53 and 55 | GPAI provider duties; additional obligations for systemic-risk models | Upstream evidence linked to downstream use; no automatic transfer of model compliance to the agent |
| Articles 72 and 73 | Monitoring and serious-incident duties | Outcome mismatch and uncertainty records, triage and competent-authority routing |
These are functional correspondences, not findings that PALO satisfies each provision. The public control matrix identifies implementation evidence and limits separately. AI Act, operative provisions.
The Omnibus changes the starting point#
Read the base Act together with its amending Regulation. Do not cite the November 2025 proposal as current law.
| Omnibus provision | Verified effect relevant to this proposal | Implication for PALO |
|---|---|---|
| Article 1(5), replacing AI Act Article 4; PDF p.16 | Providers and deployers support the development of AI literacy; no guaranteed individual attainment level is required | Train operators in delegation and stop procedures, without claiming the law requires a particular PALO competency score |
| Article 1(6), new Article 4a(2); PDF p.17 | Exceptional bias detection/correction processing can extend beyond high-risk providers subject to conditions; the text expressly considers feedback from outputs into future operations | Acknowledge the law already recognises feedback effects; this is neither a general data-use permission nor a mandate protocol |
| Article 1(3), new Article 2(13); PDF p.16 | Certain high-risk product obligations may be limited where specified sector rules provide equivalent protection, through the prescribed delegated acts | Reuse sector evidence and test equivalence; never self-declare an exemption |
| Article 1(22), Article 57; PDF p.23 | National sandbox deadline becomes 2 August 2027; an AI Office Union sandbox is possible for Article 75(1) systems; EDPS may establish a sandbox for EU bodies | Choose the competent sandbox for the particular system; an invitation or eligible plan is still needed |
| Article 1(31)-(32), Articles 75 and 75a-75d; PDF pp.26-33 | AI Office system-level competence and enforcement powers are specified, with defined scope and exclusions | Do not describe the Office as the regulator of every agentic system |
| Article 1(35)-(36), Articles 95 and 96; PDF p.34 | SME/SMC needs and complementary implementation receive attention; Article 96(1)(a) includes Article 26 | Offer reusable controls and evidence, with small-organisation proportionality |
| Article 1(39)-(40), Articles 111 and 113; PDF p.35 | Chapter III Sections 1-3, except Article 6(5), apply from 2 December 2027 for Article 6(2)/Annex III and 2 August 2028 for Article 6(1)/Annex I | Use the preparation window without implying that all other duties are postponed |
The Article 50(2) transition to 2 December 2026 applies to relevant systems placed on the market before 2 August 2026; it is not a blanket postponement of Article 50. Article 111 contains further transitional rules and must be applied to the actual facts. The Article 6(5) exception was checked directly in Article 1(40)(b), printed OJ page 35; it is expressly excluded from the two deferred dates. Omnibus, Article 1.
2. The gap that can be defended#
An execution and composition problem#
An organisation can document an AI system while remaining unable to show who authorised a particular tool call, whether a subagent exceeded its parent's authority, whether several individually small transactions exceeded a common limit, or whether a stop request prevented an external effect. Logging an agent's statement that it succeeded does not establish that the intended effect occurred.
Consider a synthetic procurement assistant. It may read an invoice, delegate supplier checks, amend a record and request a payment. A legitimate initial objective does not authorise every intermediate step. Supplier information may contain malicious instructions. Separate agents may each remain below an individual threshold while collectively exceeding the organisation's budget. A revoked agent may still have a queued job. A timed-out payment request may already have succeeded. These are testable control failures, not evidence of actual PALO customer incidents.
The relevant review unit is therefore system + deployment + delegation chain + action + effect, maintained over time. The proposed profile describes how to connect those units in reviewable evidence.
Three distinct gaps#
- Implementation gap: existing legal objectives need a practical translation into action-level controls. Guidance, tooling and standards can help without changing primary law.
- Interoperability and assurance gap: actors need a shared evidence vocabulary and tests across orchestrators, tools and verifiers. Multiple implementations should produce comparable records.
- Possible scope gap: consequential actions outside high-risk categories may not attract the same explicit duties under the AI Act. Other law may still apply. Whether new horizontal obligations are necessary requires evidence of harm, legal analysis and proportionality assessment.
A Commission-hosted StepUp StartUps report already identifies responsibility and oversight challenges in agentic workflows and recommends auditable control points. This is a research report by the named consortium, not binding Commission guidance or an endorsement of this proposal. Report page, 23 January 2026.
Relationship to other law and existing technical practice#
GDPR and, for EU institutions, Regulation (EU) 2018/1725 remain relevant to personal-data processing. Cybersecurity, product safety, sector requirements, contract and liability rules may apply independently. A PALO permission cannot establish a GDPR legal basis, validate a prohibited use, replace a sector authorisation or determine civil liability. A deployment assessment must identify the exact instruments and competent authorities; this proposal does not attempt an exhaustive cross-sector legal opinion. The Omnibus expressly preserves the data-protection framework. Omnibus Article 1(2)(b).
Identity, least privilege, policy engines and audit logs are established engineering practices. PALO's proposed contribution is their integration with lifecycle decisions, delegated authority and observed effects. Novelty should be tested through comparison, not asserted as an exclusive invention. NIST's AI Agent Standards Initiative and IMDA's Model AI Governance Framework for Agentic AI, launched in January 2026 and updated to v1.5 in May, provide relevant interoperability references, not EU legal equivalence. NIST initiative; IMDA framework v1.5.
IMDA's 20 May update adds multi-agent and third-party-agent considerations, automation-bias practices and deployment examples. PALO should build on that work through EU provision mapping, exchangeable action/effect evidence and comparative tests. It should not claim that operational agentic governance is an unoccupied field. These are our proposed points of comparison, not an IMDA assessment of PALO. IMDA update.
3. PALO's complementary contribution#
PALO combines three layers:
- PALO Framework: Frame, Classify, Assess, Control, Measure, Prove & Review. This connects organisational purpose, legal applicability, controls and evidence throughout the lifecycle.
- PALO-AM: the agentic governance methodology covering identity, delegated authority, autonomy, oversight, reversibility and assurance.
- PALO-AI: a developer-preview reference runtime implementing selected contracts and enforcement patterns. The released capability baseline is v2.7; additional swarm functionality is an unreleased reference extension.
The proposed European profile is an additional, openly reviewable specification. It does not rename these products or claim an EU mandate. Implementers may use equivalent architectures. The code repository is MIT licensed; contributions and any future standards submission must be reviewed for applicable intellectual-property and patent rules.
Theory: accountable delegation#
A mandate is a purpose-bound grant by an accountable person or organisation to an identified workload. It records scope, resources, permitted tools, data conditions, duration, limits and oversight. Delegation is a relationship among accountable actors and technical identities; it does not confer legal personality on an agent.
Authority should narrow down a delegation chain. Child permissions must stay within ancestor permissions, including data purposes, time and shared exposure. An action needs both a valid mandate and a current policy decision. Authority validity at planning time is insufficient if the mandate expires or is revoked before execution.
Outcome evidence is a separate dimension. The meaningful states include authorised, awaiting approval, denied, executed, verified, mismatched and unknown. An authorised action can fail; a completed request can have an unverified effect; a signed false statement remains false. A stop request and a confirmed absence of effects must remain distinct.
The minimum technical profile#
The companion technical specification defines twelve proposed control objectives, evidence contracts, adversarial tests and trust boundaries. The essentials are:
- A responsible owner and system boundary.
- A versioned, expiring mandate and a traceable delegation graph.
- Permission narrowing and limits on tools, arguments, data and purpose.
- A decision at the execution boundary, with a default stop when necessary evidence is absent.
- Human approval bound to the precise action, with meaningful intervention capacity; a blocking pre-dispatch gate for consequential actions whose reversibility is absent or unproven.
- Shared budgets, concurrency limits and replay prevention across the defined authority domain.
- Revocation reaching queued and future work; explicit treatment of in-flight effects.
- Separate execution and outcome evidence, including unresolved states.
- Evidence integrity, provenance, minimisation, access and retention controls.
- Change-triggered reassessment and incident escalation.
What is available and what remains open#
| Capability | Repository evidence | Maturity and limit |
|---|---|---|
| Lifecycle and agentic methodology | PALO-AM page, semantic foundation and control packs | Published methodology; not evidence of deployment effectiveness |
| Action Claim and Effect Contract | schemas/palo-agentic-action-claim.schema.json, schemas/palo-agentic-effect-contract.schema.json |
Implemented contracts; schemas do not prove the truth of statements |
| Policy and execution boundary | MCP runtime, Rego examples, capability consumption | Reference implementation; non-bypassability depends on the deployment and connectors |
| Human approval and outcome attestations | Approval, receipt and outcome schemas; runtime test suites | Prototype integration; requires trustworthy identities, verifiers and actual resource observations |
| Data fitness and disclosure | Data Fitness Decisions and Disclosure Contracts | Developer preview; source and connector observations are not independently attested |
| Shared swarm authority and cancellation | Swarm runtime and distributed-execution documentation | Unreleased prototype with one central SQLite authority; no high-availability or arbitrary external cancellation guarantee |
| Independent production assurance | Production-readiness profile and admission checks | Required but not supplied by repository tests; admission remains denied without deployment evidence |
See the capability matrix, production-readiness page, and distributed-execution limits. This proposal should not be presented as a production-qualified European infrastructure.
4. Deliverables for institutional reviewers#
The public proposal section provides the legal crosswalk, capability boundaries and a local review workbench. The workbench exports a structured review record and a reusable test plan. Its labels report the user's evidence declarations; they do not determine compliance or certify a system.
The proposed submission package contains:
| Artifact | Use by a reviewer | Evidence boundary |
|---|---|---|
| Position paper and provision-level crosswalk | Examine legal overlap and identify residual questions | Policy analysis and mappings, not official interpretation |
| Open technical profile | Compare controls and equivalent implementations | Proposed requirements, not a harmonised standard |
| Twelve-control review record and JSON schema | Record owner, applicability, evidence reference, reviewer and open issue | Structural validation; authenticity and adequacy need human review |
| Scenario and test-plan CSV | Reproduce authority, replay, revocation and outcome tests | Proposed evaluations with expected results, not completed trials |
| PALO reference schemas and runtime | Inspect implementation feasibility | Developer-preview trust boundary |
| Pilot protocol and results template | Measure safety, workload, cost and interoperability | No pilot results or participants invented |
| Draft implementation language and legislative option | Support legal-service discussion | Drafting suggestions; numbering and final wording require institutional work |
For inspection, investigators should receive a minimised evidence view with the mandate version, actor role, action digest, policy version, approval reference, execution identifier, effect observation and incident trail. Raw prompts, model chain-of-thought and unnecessary personal data are not default evidence requirements. Competent authorities' legal access rights are determined by law, not by this profile.
5. Proposed normative language#
The following text is proposed drafting, not enacted law. It deliberately states functional outcomes and permits equivalent means.
Option A: implementation guidance within existing duties#
Suggested guidance paragraph on Articles 9, 12, 14, 15, 25 and 26:
Where an in-scope AI system initiates or delegates actions affecting external resources, providers and deployers should identify the persons and organisations responsible for granting and supervising that authority. Measures appropriate to the intended purpose and risks should establish the permissible action scope, relevant limits, human intervention arrangements and records needed to reconstruct consequential actions. Assessment should address foreseeable risks arising from sequences of actions and interactions among components. Equivalent technical and organisational means may be used.
The guidance annex would describe mandates, exact-action approval, shared exposure, revocation, verified effects and minimised evidence as implementation examples. The proposed profile requires prior human approval for materially consequential actions that are irreversible or have unproven reversibility; prohibitions and other denial conditions remain binding after approval. Compensation is not reversal. This is proposed implementation language, not a claim that Article 14 mandates a separate approval for every action. It must not silently impose obligations on actors or uses outside the underlying law. Existing duties remain enforceable according to their terms; guidance does not create a new offence or certification scheme.
Option B: voluntary operational code#
Suggested commitment under an Article 95 initiative:
Participants will document the scope of delegated action and adopt proportionate controls for accountable authority, intervention and traceability. They will publish the scope of their commitment, maintain evidence of implementation, measure the agreed indicators, record limitations and review changes affecting risk. Participants may demonstrate equivalent controls and will not represent participation as regulatory certification.
Article 95 provides a relevant voluntary route, including for systems other than high-risk systems. The profile can inform standards separately. Article 56 concerns GPAI model duties under Articles 53 and 55 and is not a blanket legal basis for an agent-system code. Articles 56, 95 and 96, as amended by the Omnibus.
Option C: targeted legislative extension if the evidence supports it#
Working title: governance of consequential delegated actions. No article number is assigned.
- Scope. Apply additional duties only to clearly identified categories of AI deployment capable of materially affecting persons' rights, safety or significant resources through delegated external actions. Define measurable thresholds, exclusions and actor responsibilities in the legislative text following impact assessment. Mere use of an agent label, an LLM or an API is insufficient.
- Provider duties. Enable proportionate configuration of authority limits, recording, effective human intervention and communication of residual limitations. Supply downstream information needed to use those capabilities.
- Deployer duties. Identify an accountable owner, establish and maintain the operational mandate, configure permissions and intervention arrangements, and monitor action consequences within the deployer's control.
- Subdelegation. Preserve attribution to accountable organisations and prevent downstream grants from exceeding upstream authority. Document changes to membership, permissions and shared limits.
- Evidence. Maintain proportionate records linking authority, decisions and effects, with purpose limitation, access protection and justified retention. Distinguish observed facts from assertions and uncertainty.
- Incident response. Provide means to restrict future actions and manage in-flight activity according to technical feasibility. Require truthful reporting of confirmed, unknown, unsupported and too-late intervention outcomes. Do not prescribe impossible reversal of committed effects.
- Equivalence and burden. Accept equivalent controls and reuse evidence from applicable sector regimes. Provide proportionate SME/SMC measures and staged application without excluding affected persons' safeguards.
- Supervision and review. Allocate competence explicitly, align enforcement with existing mechanisms and review necessity and effectiveness against published indicators.
This option is not ready for formal tabling as legal text: the categories, thresholds, interactions, enforcement basis and economic effects require consultation and legal drafting. It is included so that reviewers can see the complete policy direction without mistaking a software profile for legislation.
6. The complete institutional route#
Stage 0: establish a credible submission#
Confirm the capacity in which Fabrizio Degni submits, the legal entity if any, contact details, contribution rights, relevant interests and the status of any Transparency Register entry. Describe PALO as an open-source contribution with documented limits. A direct email is an outreach route; it is not formal submission into an open consultation or a right to a meeting.
For policy meetings with Commission management, registration requirements apply to in-scope interest representatives. Verify applicability and provide the appropriate information before arranging a covered meeting; this does not prevent preparing or sending an initial inquiry. Commission transparency rules; Decision (EU) 2024/3082.
Stage 1: technical intake#
Address the proposal to Lucilla Sioli, Director, European AI Office, DG CONNECT, through the published general contact CNECT-AIOFFICE@ec.europa.eu, requesting routing to the relevant policy and technical units. The official role is Director of the European AI Office; this dossier does not assume a Commission position called Chief AI Officer. The sender's title remains Chief AI Officer. Official biography; AI Office contact and structure.
Request a 45-minute scoping discussion covering the legal gap, architecture, pilot and appropriate route. DG CONNECT's Regulation and Compliance and AI Safety functions are relevant candidates; assignment is for the Office to decide. JRC technical expertise, the AI Board, the Advisory Forum, national authorities, civil society and SMEs may be valuable participants, but none is named as a committed partner or automatic approver.
Gate: written scope, a designated contact if accepted, and agreement about what a pilot would test. A meeting is not endorsement.
Stage 2: evidence pilot#
Recruit willing operators, an evaluator independent of implementation decisions and, ideally, a second implementation. Agree test scope, data handling, oversight, results publication and stop conditions. A twelve-week schedule begins only after participants and resources are confirmed. If a regulated sandbox is sought, determine whether the competent route is national, AI Office Article 57(3a)/75(1), or EDPS Article 57(3). A research demonstration does not acquire sandbox status by naming itself one.
Gate: reproducible results, adverse findings, measured costs and a signed assessment of residual risk. A sandbox exit report does not itself certify the deployment. See the pilot protocol.
Stage 3A: guidance and voluntary practice#
Submit a concise implementation note under Article 96 with the provision-level crosswalk, evidence and burden analysis. The Commission develops guidance with the legally specified involvement, including the AI Board. No Parliament/Council co-decision is required to issue guidance, but it cannot amend the Act.
For voluntary commitments, seek a multi-stakeholder Article 95 process with governance, defined indicators and published limitations. Adoption by participants is distinct from Commission recognition, a harmonised standard and legal compliance. Do not reuse the Article 56 GPAI process indiscriminately.
Gate: acceptance into a relevant workstream and a published, accurately described output. There is no guaranteed deadline or right to inclusion.
Stage 3B: European standards#
Bring the implementation profile and tests to the relevant national standards body and CEN-CENELEC JTC 21 channels. Confirm an appropriate work item and current draft scope. A typical route includes proposal and expert work, consensus drafting, enquiry, comment resolution and formal approval. A workshop agreement or technical specification is not automatically a harmonised European standard.
The following is a proposed contribution map using the secretariat's current project listings. It is a routing hypothesis, not an assessment against licensed draft clauses or confirmation of participation. JTC 21 groups and projects.
| Candidate route | DAG controls | Proposed contribution | Evidence still required |
|---|---|---|---|
| WG 2, operational aspects: risk, quality and conformity work | 01, 02, 07, 12 | Deployment boundary, cumulative exposure and change-review examples | Current draft clauses, burden measures and process-owner review |
| WG 3, engineering: prEN ISO/IEC 24970 logging | 05, 08, 10, 11 | Mandate/action/effect event model and exchange fixtures | Draft information-model mapping and a second implementation |
| WG 4, trustworthiness: prEN 18229-1 logging and prEN 18229-3 human oversight | 06, 09, 10, 11 | Exact-action approval, intervention semantics and uncertainty records | Reviewer usability, approval-bypass and containment tests |
| WG 5, cybersecurity: prEN 18282 | 03, 04, 05, 08 | Delegation boundaries, tool mediation and adversarial cases | Current threat requirements and resource-boundary evidence |
Recheck groups, work items and editions when contributing. The ISO catalogue lists ISO/IEC 24970 as an FDIS under development, stage 50.20, at this review date. International approval, European adoption and OJ citation are separate decisions. ISO project status.
Only the applicable European process and subsequent Official Journal citation can give a standard the relevant presumption of conformity, and only for the requirements covered. PALO, a JSON schema, a successful pilot or membership of a committee does not confer that status. Commission explanation of AI standardisation.
Gate: acceptance and evidence of interoperability, followed by the applicable formal standardisation and citation decisions. These are separate from commercial procurement.
Stage 4: decide whether legislation is necessary#
Compare at least four options: existing-law implementation; voluntary profile; harmonised technical approach within existing law; targeted binding extension. Analyse harms, affected actors, rights, innovation, costs, competition, SME impact, enforceability, subsidiarity and proportionality. Test whether existing duties can already address the problem before adding new ones.
Article 112 supplies review opportunities: paragraph 2 includes a 2 August 2028 evaluation of specified issues and paragraph 3 a 2 August 2029 general review. Paragraph 10 allows appropriate amendment proposals when necessary; these dates are not a bar on earlier action. Article 7 and other delegated powers have bounded purposes. They cannot be used as a general power to create any desired horizontal regime. AI Act Articles 7, 97 and 112, with Omnibus amendments.
Stage 5: Commission preparation and adoption of a proposal#
If the Commission chooses to act: political prioritisation and service ownership; call for evidence and consultation; impact assessment where significant impacts are expected; Regulatory Scrutiny Board review as applicable; interservice consultation, legal scrutiny and College adoption. Consultation periods are commonly four weeks for calls for evidence and twelve weeks for legislative public consultations, subject to the applicable process and exceptions. A PALO submission informs this process but cannot initiate it as a formal legislative proposal in its own right. Planning and proposing law; Better Regulation.
Stage 6: Parliament and Council#
For an amendment using the ordinary legislative procedure, the Commission transmits the proposal to Parliament and Council; national parliaments examine subsidiarity, and other bodies are consulted where required. Parliament assigns committee responsibility, rapporteurs and amendments. Council working parties, COREPER and ministers develop the Council position. IMCO and LIBE are relevant precedents from the AI Act, not a pre-assigned committee allocation for a future file.
The co-legislators conduct first reading; negotiations may include trilogues, but informal agreement still needs formal approval. If necessary, second reading follows; unresolved disagreement may proceed to conciliation and third reading. Failure to approve the required common text ends the proposal. First reading has no fixed overall time limit. Second-reading and conciliation deadlines are procedural limits, not a prediction of total adoption time. Council procedure guide.
Stage 7: publication, implementation and evaluation#
After agreement: legal-linguistic finalisation, formal adoption and signature, Official Journal publication, entry into force and any staged application dates. Prepare required secondary acts, standards, guidance, supervisory capacity and operator transition. A regulation is directly applicable; national enforcement arrangements and sector interactions still need attention.
Delegated acts under Article 290 TFEU and implementing acts under Article 291 are distinct procedures and require an enabling provision. Under the amended AI Act Article 97(6), the listed delegated acts are subject to a three-month objection period, extendable by three months. Implementing acts follow the relevant committee procedure. Neither route provides an unrestricted substitute for amending essential elements of legislation.
Final gate: an adopted instrument with an applicable scope and date, followed by evidence of implementation. The Commission Director alone cannot approve a legislative extension. No adoption probability or guaranteed timetable can responsibly be assigned at this stage.
7. Precedents: what to borrow and what to avoid#
| Case | Documented outcome | Lesson for this proposal, explicitly an inference |
|---|---|---|
| GPAI Code of Practice, 2025 | Published after expert and stakeholder work; Commission and AI Board accepted it as an adequate voluntary compliance tool for specified GPAI duties | Anchor the work in a clear legal basis, concrete artifacts and broad participation. Its Article 56 basis does not transfer to all agent systems. Source |
| Transparency Code of Practice, 2026 | In its 31 July 2026 announcement, the Commission reported approximately 190 signatory organisations; this is a dated uptake figure, not a current unique-signatory count | Practical marking/labeling measures and a defined scope can support uptake. Section-specific lists can overlap. Signatures establish participation, not demonstrated effectiveness. Source |
| AI Liability Directive, 2022/0303(COD) | Proposal withdrawn in 2025; the Official Journal records withdrawal | A plausible gap does not ensure political agreement. Keep necessity, interaction with other law and burden explicit. Withdrawal alone does not prove any single causal explanation. Withdrawal notice; Parliament procedure account |
| AI Act implementation and the 2026 Omnibus | Adopted amendments address implementation burdens and delays, including revised high-risk dates | Implementation capacity and available standards matter. Deliver workable controls and measurable burden before arguing for expansion. Omnibus recitals 2 and 40 |
These examples support a sequencing judgment, not an empirical probability model. The strongest opening is a reusable technical contribution that helps implementation and preserves a later legislative option. The weakest opening would claim that agents are wholly unregulated, that PALO is already independently qualified, or that the EU should mandate one supplier.
8. Anticipated objections and responses#
| Objection | Response and evidence needed |
|---|---|
| Existing AI Act duties already cover this | Agree on applicable coverage; test whether a shared operational profile reduces inconsistent implementation. Escalate only residual scope problems. |
| This adds cost for SMEs | Offer a minimal mandate and evidence pack, reuse existing identity/logging, and measure reviewer time and integration effort against baseline. Do not claim savings before the pilot. |
| Another proprietary governance platform | Keep the specification public and permit equivalent implementations; seek independent implementers and avoid mandatory PALO branding. |
| The model can bypass the policy engine | Enforce at actual connector/resource boundaries with separate credential custody; list unsupported paths and deny production claims until tested. |
| Signatures do not prove truth | Separate origin/integrity verification from authoritative observation and independent assurance. |
| Kill switches cannot undo transactions | Record revocation and containment separately; manage irreversible effects through separately authorised compensation and remedies. |
| Logging creates surveillance and data risks | Minimise payloads, restrict access and define retention by purpose and applicable law; do not require raw reasoning traces. |
| Agent architectures change too quickly | Standardise stable functional invariants and versioned evidence, with change triggers and review; avoid mandating a protocol or model family. |
9. Immediate action plan and unresolved facts#
First 30 days, proposed: finalise the submission identity and open-specification commitment; obtain an independent legal critique; publish the reviewed proposal section when the maintainer decides to release it; send the scoped inquiry; recruit pilot participants and an independent evaluator; record conflicts of interest. No outreach has been sent by preparing this package.
Next 60 days, conditional: agree pilot sponsorship and resourcing, select use cases and a second implementation, freeze evaluation methods and begin the agreed programme. The twelve-week evaluation starts from readiness, not from the letter date.
After evaluation: release reproducible findings and an implementation note, seek the appropriate guidance/standards route, and decide whether evidence justifies legislative work. Time windows are planning assumptions, not institutional commitments.
Open facts: submitting legal entity or personal capacity; confirmation of the public project address for correspondence; Transparency Register status where applicable; pilot partners; available people and budget; ownership of contributions; independent evaluation capacity; real deployment evidence. The proposal remains reviewable without inventing these facts. The letter uses the verified name and role, includes the repository's published project contact and avoids financial or partnership commitments.
Source and version note#
The review was conducted on 22 September 2026 against the English-language Official Journal PDF of Regulation (EU) 2026/1744 and official public sources linked beside the relevant claims. The reviewed PDF has SHA-256 0bea4d808256b08275777949ba9cb3c70b7d02e4ebb3ac9b205671b1f552d386. The OJ PDF is a source document, not an enclosure to the submission. Page references use printed OJ pagination, 1-41. The base Act URL is the original adopted text; this dossier applies the 2026 amendments explicitly rather than representing that URL as a consolidated text.
The analysis distinguishes enacted law, official explanatory material, source-based interpretation, PALO implementation evidence and proposed policy. Verify intervening amendments, corrigenda, standards citations and official contact details immediately before submission. Institutional acceptance, legal compliance and production qualification remain separate determinations.
PALO FRAMEWORK