AI Events
The EU AI Act Now Requires AI to Say So. It Doesn't Require Anyone to Trust It.
On August 2, 2026, the EU AI Act's transparency obligations became enforceable across the bloc: AI systems must now tell you they're AI. The same week, the obligations that would have actually governed autonomous agents — risk management, human oversight, audit trails — were pushed back to 2027 and 2028. The gap between those two dates is exactly the gap agent commerce has to close on its own.
What happened
On August 2, 2026, Article 50 of the EU AI Act — its transparency and information obligations — became generally applicable and enforceable by national authorities across the EU. Goodwin's legal alert lays out exactly what changed: Not Delayed, Not Deferred: EU AI Act Transparency Obligations Are Now in Force. Providers of any AI system designed to interact directly with people — chatbots, virtual assistants — must ensure individuals are clearly told they're dealing with an AI system unless that's obvious from context. Providers of systems that generate synthetic audio, image, video, or text must mark that output in a machine-readable, detectable format. Deployers of emotion-recognition or biometric-categorization systems have their own disclosure duties. Non-compliance carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
The same week carried the less-publicized half of the story. The EU's Digital Omnibus on AI, signed July 8, 2026, pushed the Act's high-risk system obligations — the rules that would require risk management, human oversight, and conformity assessment for consequential autonomous systems — out to December 2, 2027 for stand-alone systems and August 2, 2028 for AI embedded in regulated products. A Data Protection Report analysis confirms the split: The EU AI Act — when does it become enforceable now?. Disclosure arrived on schedule. Governance did not.
Disclosure answers one question. It isn't the question that matters for agents.
Article 50 solves a real problem: a person should know when they're talking to software instead of a human. That matters enormously for consumer-facing chatbots, deepfakes, and synthetic media. But notice what it doesn't solve. “You are talking to an AI system” is a category label, not a track record. It doesn't say which AI system. It doesn't say whether that system has ever gone outside the boundaries it was given, or whether the last ten thousand things it did lined up with what it was authorized to do.
For agent commerce, that gap is not a footnote — it's the whole problem. When an agent negotiates a price, books a service, or completes a purchase on another agent's behalf, both sides already know they're dealing with AI. Disclosure returns the same answer every single time and tells the counterparty nothing about whether to extend $50 of trust or $50,000.
The part that was delayed is the part agent commerce actually needs
The high-risk obligations that just slipped to 2027 and 2028 are the ones that would have required exactly what autonomous purchasing and booking agents need to be safely trusted with money: demonstrable risk management while running, human oversight with a real intervention path, automatic logging, and transparency for the businesses deploying them. Those requirements aren't arriving for one to two more years — and only then for systems that get classified as high-risk in the first place.
That leaves a window, right now, where any business running an autonomous agent to buy, book, or negotiate has no legal mandate for audit trails or behavioral oversight of that agent's decisions. Nothing stops a business from building that accountability voluntarily. Nothing requires it, either — for at least another year.
What closes the gap: AAIN plus SKOOR
Regulation and infrastructure solve different halves of this. Article 50 makes an agent say what it is. It doesn't make an agent identifiable, and it doesn't make its behavior auditable. That's what the AAIN — the Autonomous Agent Identification Number — and SKOOR, the continuous 300–850 behavioral score built on it, are for. An AAIN is a permanent, resolvable identity assigned once to a specific agent, not a category. Every action that agent takes accumulates against that one identity, across platforms and sessions, whether or not any regulator requires it to.
Three of SKOOR's ten factors map directly onto exactly what the delayed high-risk obligations were meant to guarantee:
Compliance posture
A rolling record of whether the agent's actions have stayed inside applicable rules and constraints — the same continuous compliance signal the delayed high-risk obligations would eventually mandate, available today instead of in 2027.
Constraint adherence
Does the agent operate inside the specific spending limits, merchant restrictions, and scope it was given? This is the risk-management-while-running check Article 50 doesn't ask for and the high-risk rules won't require for years.
Behavioral integrity
Anomaly and abuse detection across the agent's full history, not just the current session — the audit trail a regulator would eventually demand, generated continuously regardless of whether one currently does.
SKOOR currently scores 146,748 agents, refreshed continuously as new behavior lands — a live number, not an estimate (Skoor Agent Analytics, fetched August 4, 2026). Every score comes with a factor breakdown and reason codes, verifiable by anyone, no regulatory deadline required.
What this means if your business runs an AI agent
If your business deploys an agent that talks to customers, books appointments, or makes purchases, Article 50 already applies to you: your agent needs to say, clearly, that it's AI. That part is settled law as of this week. What is not settled — for at least another year, longer for embedded systems — is any legal requirement that the agent's behavior be logged, bounded, or auditable.
That is a choice you can make ahead of the law rather than in response to it. An agent with a permanent identity and a continuously updated behavioral score gives your business (and anyone your agent transacts with) exactly the accountability the delayed high-risk rules were designed to force — voluntarily, transparently, and starting now instead of in 2027.
Learn More
Know which agent you're actually dealing with
Look up any agent's SKOOR and see the full factor breakdown — identity and track record, not just a disclosure checkbox.
Check a SKOOR