14 AOÛ 2026
GOVERNANCE

The European AI Act is running at full strength since August 2 — and a documented legal gray area on autonomous agents lands exactly where AppH had already decided

All AI Act obligations, including the "high-risk" requirements of Annex III, are now enforceable — fines up to €35M or 7% of worldwide revenue. At the same time, a Waters Technology article documents a real blind spot in the text: it was written for static models, not for agents that autonomously chain actions together. A gray area AppH's design choice — never an action without human validation — didn't wait for the law to settle.

On August 2, full enforcement of the European AI Act became real, not a date to check off a calendar. All obligations are now in force, including those of Annex III for systems classified "high-risk" — recruitment, credit scoring, medical devices, among other categories. Fines go up to €35 million or 7% of annual worldwide revenue, whichever is higher. The European Commission confirmed this in a release in late July, and SMB compliance guides — like the one published by Delbion — began circulating soon after. For most SMB owners, concretely, nothing changed on the morning of August 2: no notification, no surprise audit. What matters is knowing whether your own AI use falls into a monitored category — and the conversational assistant an SMB uses to answer its customers generally doesn't.

That's where the second fact comes in, quieter but just as real: a Waters Technology article, citing a piece by AI ethicists, documents a structural gap in the text itself. The AI Act was drafted with models that answer a single request in mind — not agents that chain multiple actions together autonomously, deciding the next step themselves. For agentic systems classified as high-risk, the area remains legally ambiguous, by the cited experts' own admission. AppH doesn't claim to resolve this regulatory gap — nobody has, the entire sector is flying blind on this exact point. But the design choice made from day one lands, by construction, on the right side of the debate regulators are still having on paper: at AppH, no agent ever executes a real-consequence action alone. A quote stays a draft until the owner clicks "send." An Automations rule opens an event to handle, never a self-placed order. A single agent runs per account, never a swarm deciding among themselves. Put simply, for anyone who has never read a line of the AI Act: a human approves before anything important goes out — always, with no configurable exception.

For AppH

  • AppH's product structure (human validation before any real-consequence action) already lands on the cautious side of the debate European regulators are still having on paper for agentic systems — without needing to wait for legal clarification to decide.
  • An SMB owner using AppH never has to wonder "am I compliant" on the specific question of agent approval — because nothing autonomous executes without their click, a design principle, not a setting that could be switched off.

Against / the honest limit

  • AppH isn't a law firm and this isn't legal advice — Annex III's "high-risk" classification depends on the actual use (recruitment or HR management are scrutinized far more than a draft quote or invoice), and the regulatory gap Waters Technology documents means even experts don't yet have full clarity.
  • An SMB with a borderline use case (for instance, if it ever used AI to screen job applications) needs to consult real legal counsel, not treat this article as a compliance audit.

The easy move would be to write that AppH has "been AI Act compliant all along" — that would be both false and dishonest, because compliance depends on the precise use case, not a general architecture, and because the gap Waters Technology documents is unresolved by everyone, us included. What can honestly be said is more modest and, at the same time, more solid: when the law itself isn't yet sure how to treat an agent acting in an autonomous chain, the most defensible position for an SMB isn't to bet on the most permissive interpretation — it's to keep a human approving before anything sequential happens. That's the choice we made before the question became regulatory, not a response to the AI Act.

Reviewed by an AppH human
← Previous article (older)Next article (newer) →

← Back to news

Want us to walk you through how this applies to a real case?

Talk to AppH

Get new posts by email

One email when we publish new analysis — never spam, unsubscribe in one click.