EU AI Act and AI Agent Governance: Human Oversight, Record-Keeping and Operational Controls

Last updated: 10 October 2026

The EU AI Act establishes a risk-based framework for artificial intelligence and places particular emphasis on human oversight, risk management, transparency, record-keeping and accountability.

For organisations deploying autonomous or semi-autonomous AI agents, the important question is not simply whether an AI model is compliant. It is whether the organisation can control, supervise, understand and evidence what the deployed AI system actually does.

An AI agent can call tools, access systems, make decisions, create outputs and initiate actions with limited human involvement. That creates a governance problem that traditional model documentation alone does not solve.

A practical AI governance system therefore needs mechanisms for:

  • defining what an agent is allowed to do
  • restricting high-risk or prohibited actions
  • requiring human approval where appropriate
  • interrupting or redirecting an agent
  • recording significant actions and decisions
  • identifying who approved an action
  • reviewing violations and interventions
  • producing evidence of how operational controls are being used

FirstHelm is designed as a human-first control layer for autonomous AI. It provides controls including constraints, approval gates, interventions, activity logging and audit trails that organisations can use as part of their broader AI governance programme.

These capabilities can support compliance activities. They do not by themselves make an organisation compliant with the EU AI Act, and they are not a substitute for legal advice, organisational risk assessment or required technical and governance measures.

Why autonomous AI agents create a new EU AI Act governance challenge

Traditional software generally executes a relatively predictable sequence of instructions. An AI agent is different. An agent may interpret a goal, choose a tool, determine the next action, react to new information and continue operating without a person reviewing every individual step.

That creates several governance questions:

  • What is the agent allowed to do?
  • What actions require approval?
  • Who is responsible for approving those actions?
  • Can the agent be stopped quickly?
  • What happens when it violates a policy?
  • Can the organisation reconstruct what happened afterwards?
  • Can the organisation demonstrate that human oversight actually existed?

These questions become especially important where an AI system is used in a context subject to heightened regulatory requirements.

The governance challenge is therefore operational as well as technical. An organisation may have an AI policy stating that humans must oversee important decisions. That is useful, but it is not the same as having a runtime mechanism that prevents an agent from executing a restricted action without human approval.

Article 14: human oversight for AI systems

One of the most important concepts for organisations deploying higher-risk AI systems is human oversight.

The underlying principle is straightforward: appropriate human involvement should remain possible so that people can understand, monitor and, where necessary, intervene in the operation of the AI system.

For autonomous agents, this raises a practical implementation question: How does human oversight work when an AI system is capable of taking actions on its own?

A robust architecture can introduce control points around agent activity. For example:

Agent proposes action
policy evaluated
action allowed, blocked or escalated
human approval where required
action proceeds
activity recorded

This approach makes oversight part of the execution process rather than merely a statement in a governance document.

Approval gates

An approval gate allows an organisation to identify actions that should not be executed autonomously. Examples could include:

  • deploying software to production
  • sending a high-volume external communication
  • making a significant financial commitment
  • changing access permissions
  • deleting data
  • accessing particularly sensitive systems
  • executing an action above a defined risk threshold

The precise actions that require approval should be determined by the organisation's own risk assessment and applicable requirements.

Intervention

Approval is not the only form of human oversight. A human operator may also need to intervene while an agent is running. Operational intervention can include:

  • pausing an agent
  • resuming an agent
  • redirecting its mission
  • rejecting a proposed action
  • modifying an approved action
  • terminating an agent

This is particularly important for long-running agents, where the situation can change after the original mission begins.

Article 12 and AI agent record-keeping

Record-keeping becomes particularly important when AI agents can take multiple actions over time. A useful audit record should allow an organisation to reconstruct the relevant sequence of events. Depending on the system and applicable obligations, useful records may include:

  • agent identity
  • mission or task
  • action type
  • action description
  • timestamp
  • risk classification
  • constraint evaluation
  • approval request
  • approval decision
  • approving operator
  • intervention
  • violation
  • outcome
  • relevant cost or token information

The objective is not to record meaningless amounts of telemetry. The objective is to preserve the information needed to understand what happened, why it happened, and what human control was applied.

FirstHelm's activity log and approval records are designed around this operational model.

From AI policy to runtime enforcement

One common governance weakness is the gap between policy and execution. An organisation might have policies such as:

Agents must not send external communications without approval.

But a policy document does not itself stop an agent from making an API call. Runtime enforcement introduces an actual decision point:

Agent proposes action
Evaluate constraints
PASS → Execute
BLOCK → Stop
APPROVAL → Human decision
Approve
Reject

This architecture creates a clearer connection between governance policy and technical enforcement.

The importance of auditability

Auditability is not simply about storing logs. A useful AI agent audit trail should answer questions such as:

  • Which agent performed the action?
  • What was it trying to accomplish?
  • Which policy applied?
  • Was the action allowed automatically?
  • Did an approval gate apply?
  • Who approved it?
  • Did a constraint fail?
  • Did a human intervene?
  • What happened afterwards?

This makes the audit trail useful to engineering, security, risk, compliance and operational teams.

EU AI Act governance for multi-agent systems

The governance challenge becomes more complex when several agents collaborate. A multi-agent workflow may involve:

  • a research agent
  • a planning agent
  • an execution agent
  • a communication agent

Each agent may have different capabilities and risk profiles. Governance therefore needs to consider not only the individual agents but also the workflow connecting them. Questions include:

  • Which agent can invoke another agent?
  • Can one agent grant permissions to another?
  • Which actions require approval?
  • Where is the final decision made?
  • Which agent is responsible for an external action?
  • Can the workflow be stopped centrally?

A control-plane architecture can provide a central location for these controls rather than requiring every individual multi-agent agent framework to implement them independently.

Evidence matters more than policy statements

A mature AI governance programme should be able to demonstrate that its controls operate in practice. There is an important difference between:

Policy

"High-risk AI actions require human approval."

Evidence

"Agent X proposed action Y at time Z. The action was classified as high risk. The system created approval request A. Operator B rejected the request. The action was not executed."

The second provides operational evidence of governance. FirstHelm can support this evidence model through approval records, activity logs, interventions and constraint evaluations.

Building an EU AI Act control framework for AI agents

A practical implementation can be organised into six layers.

1. Agent inventory

Know which AI agents exist, what frameworks they use and what systems they can access.

2. Risk classification

Determine which agent actions present greater operational, legal, financial or security risk.

3. Constraints

Translate organisational rules into executable controls.

4. Human approval

Create approval gates for actions that should not be autonomous.

5. Intervention

Provide operators with mechanisms to pause, redirect or terminate agents.

6. Evidence

Record actions, decisions, approvals, violations and interventions.

Together, these layers provide a much stronger governance architecture than model documentation alone.

What FirstHelm supports

FirstHelm provides a control layer for autonomous AI that can be used to support these governance mechanisms. Relevant capabilities include:

  • agent registration
  • missions
  • constraints
  • approval workflows
  • activity logging
  • real-time interventions
  • autonomy management
  • audit export
  • compliance reporting

The platform is designed to sit between autonomous agent activity and organisational governance controls. This allows organisations to apply consistent controls across agents built with different frameworks — including autonomy management and activity logging.

EU AI Act AI agent governance checklist

Before deploying an autonomous AI agent, ask:

  • Do we have an inventory of the agent?
  • Do we know what systems and tools it can access?
  • Have we identified high-risk actions?
  • Are restricted actions technically controlled?
  • Are approval gates defined?
  • Can a human intervene during execution?
  • Can the agent be paused or terminated?
  • Are actions and decisions recorded?
  • Are approval decisions attributable to specific operators?
  • Can violations be investigated?
  • Can audit evidence be exported?
  • Have we mapped these controls to the applicable legal and organisational requirements?

If several answers are "no", the organisation may have a governance gap even if the underlying AI model is well documented.

Frequently asked questions

Q: Does the EU AI Act regulate AI agents?

A: The EU AI Act regulates AI systems according to their characteristics, uses and applicable risk categories. Whether a particular AI agent falls under specific requirements depends on how and where it is deployed.

Q: What is human oversight for an AI agent?

A: Human oversight means maintaining appropriate human ability to understand, monitor and intervene in the operation of an AI system. For agents, this can include approval gates, monitoring and runtime intervention.

Q: Do AI agents need human approval for every action?

A: Not necessarily. A risk-based architecture can allow low-risk actions to proceed autonomously while requiring approval for actions that meet defined risk criteria.

Q: What should an AI agent audit trail contain?

A: It should contain enough relevant information to reconstruct significant agent activity, decisions, approvals, violations and interventions. The exact requirements depend on the system and applicable obligations.

Q: Does FirstHelm make an organisation EU AI Act compliant?

A: No platform can determine compliance for an organisation simply by being deployed. FirstHelm provides capabilities that can support human oversight, record-keeping and operational governance. Organisations remain responsible for determining and demonstrating their own compliance.

Next steps

Organisations deploying autonomous AI should treat EU AI Act governance as an operational control problem, not solely a documentation problem. Start by identifying your agents, defining their boundaries, establishing approval points, providing intervention mechanisms and creating reliable records of agent activity.

FirstHelm provides the control layer for implementing these mechanisms across autonomous AI systems — supporting AI agent governance and an AI agent security architecture. See the docs to get started.