TheSoftware LensSee engineering differently
Agentic EconomyBy Imtiaz Hassan

How the EU AI Act Is Reflected in the Agentic Economy

I have written and spoken about the Agentic Economy, where enterprises hire agents by the task and pay by signed outcome. The EU AI Act is now in force. This is how its rules are reflected in that economy when the client is an agent.

Why it mattersFor CEOs, CTOs, CIOs and business owners

If your AI agents touch EU customers, the EU AI Act already applies to them: the transparency rules since 2 August 2026, the high-risk rules from December 2027, with fines up to 7 per cent of turnover. This article shows how those rules fall on the Agentic Economy I have described, where agents hire agents, and what to build first.

Summary
  1. Somebody is always the employer. Every hire needs a named provider, a named deployer and a declared purpose. The registry, the hire-token and the receipt supply all three.
  2. Risk is decided at the moment of hire. The same capability is ordinary analytics in one call and high-risk in the next. Risk class in the manifest, purpose in the hire request, checked every time.
  3. The receipt is now evidence. Logging, the right to an explanation and incident reporting all describe the signed receipt. Keep it in write-once storage. Logs are not receipts.
  4. Europe just priced audit-ready evidence. Agents will prefer the capability whose hire carries less exposure for its principal. That is the audit-ready moat, with a statute behind it.

Bottom line. An Agentic Economy that settles by signed receipt already meets most of the Act. That is no coincidence; both were built to make AI accountable for what it does.

Below: the full article, for technical teams ↓
Watch the episodeHire the AI Agent | SaaC, the End of SaaSThe Software Lens on YouTube →

"The Act asks for a description, a record of every decision and a named owner. The agentic economy trades in a manifest, a receipt and a registry. Same objects, two vocabularies."

What this article is about

In this article I show how the EU AI Act gets reflected in the Agentic Economy of the AI world, the economy I have described where enterprises hire agents by the task, by the decision, by the signed outcome, and trust moves from promise to signed evidence on every decision a system makes.

The Act is now in force, amended in July 2026. So I have taken it as it stands and worked it through that economy, rule by rule, for the case the Act never pictured: the client is not a person but an agent.

New to the idea? The Agentic Economy, Explained is a five-minute read. Technical readers who want the recap on video: Hire the AI Agent: SaaC, the End of SaaS on YouTube, with the written version in From SaaS to SaaC.

Important definitions

Six words carry the whole model. Think of a staffing agency.

  • Capability. A piece of work an agent can hire, the way a company hires a contractor for one job. This is SaaC, Software as a Capability: you buy the outcome, not a seat. (the full article)
  • Manifest. The capability's CV: what it does, what it will never do, what it costs, how well it performs, and who stands behind it. (how a capability is built)
  • Hire-token. The contract for one job: who hired the capability, for what purpose, under which rules, in which country.
  • Receipt. The signed timesheet for every single decision: what went in, what came out, which rules were applied, which versions ran, signed by both sides and kept where nobody can edit it.
  • Registry. The agency's book: where capabilities are listed, compared, hired and rated on their track record. (why the track record is the moat)
  • OLA. The service level a capability promises in its manifest, and is measured against on every receipt. Hire it, measure it, release it if it falls short.

That is the vocabulary. Everything below uses only those six words.

Case study: a claims agent hires a fraud scorer

An insurer's claims agent needs a fraud score. It looks one up in a registry, hires it for a single claim, gets the score back, and releases it. Three hundred milliseconds. Nobody in the room.

Apply the EU AI Act to that one transaction and it acquires a provider, a deployer, a risk class, a logging duty, a monitoring duty and a fine. The Act was written for AI systems in general: a company that deploys one, people who use it. The Agentic Economy is a perfect scenario for applying it, because every rule in the Act has somewhere concrete to land, and the places it lands are ones most teams have not looked at.

One caution before the rules. The Act was amended in July 2026 and will change again as guidelines and standards arrive. This is a snapshot of 10 October 2026, not a permanent map.

What changed this summer, in four lines

The deadline for high-risk systems (hiring, credit, education, essential services and the rest) moved from August 2026 to 2 December 2027, and to 2 August 2028 for AI inside already-regulated products. The rules for systems that talk to people or generate content did not move: they have applied since 2 August 2026. The bans and the fines, up to 35 million euro or 7 per cent of worldwide turnover, are unchanged. And the whole thing reaches any company, anywhere, whose system's output is used in Europe.

Now the rules, as they are reflected in the Agentic Economy when the client is an agent.

Rule 1: When the client is an agent, somebody is still the employer

An HR team buys a CV-screening capability and its recruiting agent hires it for every vacancy. Under the Act, the vendor is the provider and the HR team is the deployer, each with its own duties. The twist is this: if the HR agent starts using that capability for something the vendor never intended, say ranking existing staff for redundancy, the HR team becomes the provider, with the provider's full obligations, and nobody at the company will have noticed.

The Agentic Economy already has the structure to answer this, and it is the staffing agency from the definitions above. The registry names who published the capability: that is the provider. The hire-token names who hired it and for what purpose: that is the deployer, with the declared purpose as proof the use was not changed. The receipt is the timesheet, signed by both sides. Three signed records answer the question "who is responsible for this decision?" without a meeting.

Takeaway: every hire must name a provider, a deployer and a purpose, in writing, at the moment it happens.

Rule 2: Risk is decided at the moment of hire

The same fraud score is ordinary analytics when it flags a duplicate invoice and high-risk AI the moment it influences whether a person gets credit or insurance. The Act classifies by what the system is used for, not by what the component does. In a human world, the deployer reads the instructions and decides. In an agent world, the decision has to happen inside the hire.

That is why, in SaaC, a capability's manifest declares its risk class, and a hire request declares the caller's purpose. The registry checks one against the other: a capability declared low-risk cannot be hired into a high-risk purpose; a high-risk capability can only be hired by a caller that carries the deployer's duties, human oversight included. The July amendment made this sharper: a provider who decides a system is exempt from the high-risk tier must now register that decision. "We assessed ourselves out of scope" leaves a record.

Takeaway: risk class in the manifest, purpose in the hire request, checked at hire time, every time.

Rule 3: The receipt is now evidence

The Act never uses the word receipt. It describes one, repeatedly. High-risk systems must log automatically for their whole life; providers and deployers must keep the logs; a person affected by a decision has the right to an explanation of the system's part in it; serious incidents must be reported within fixed windows.

Put those together and you have the signed receipt that the Agentic Economy settles in: what went in, what came out, which policies applied, which versions ran, who hired it, for what, in which region, signed. The Act turns the thing you settle on into the thing you will be audited on. A receipt is now proof a trade happened, the log a regulator will ask for, the explanation a customer is entitled to, and the fastest way to find every hire an incident touched.

The one move I would make this quarter is unchanged from my earlier piece on regulatory posture: route the receipt stream into write-once storage with legal hold. On the day the high-risk chapter applies, the thing you will need most is a year of records that can only be created from now. Logs are not receipts. Logs are what you reconstruct from when you do not have receipts.

Takeaway: if your agents do not emit signed receipts today, start there.

HIRE, MEASURE, RELEASE is the commercial grammar of the Agentic Economy: hire against a declared service level, measure continuously, release when it underperforms. The Act contains the same cycle. Providers must run post-market monitoring for the life of a system; deployers must monitor too; a provider who finds a system non-conforming must correct, withdraw or recall it and tell the deployers.

The difference is who moves first. In the Act, the provider and the authorities drive withdrawal. In the agentic economy, the receipt stream drives it: a service-level breach shows up in the measurements, the hire is released, the registry's reputation score moves. The second mechanism is faster, and it produces the evidence the first one demands.

Takeaway: a publisher that measures and releases on evidence is already meeting the monitoring duties as a side effect of running a business.

Rule 5: The marking has to survive the chain

A customer asks an assistant for a letter. The assistant hires a drafting capability. The drafting capability hires a retrieval capability. Only the first hop meets the customer; only the last one wrote the text.

The Act's transparency rules are written for the moment a machine meets a person: say you are a machine, and mark what you generate. Machine-to-machine hires do not need to announce themselves to each other. But the marking on generated content has to still be there when it reaches the customer, three hops later. That is a provenance problem, and the receipt chain is the answer: if every hop's receipt references the previous one, "which parts of this did a machine write?" is a query, not a reconstruction.

Takeaway: provenance travels in the receipts, hop by hop, or it does not travel at all.

Rule 6: Borders are negotiated at hire time

A capability published in Dallas and hired by an agent in Dublin is inside the Act on the same terms as one published in Dublin. So the hire request carries the caller's jurisdiction, the manifest declares which regions the capability can run in, the hire is pinned to a compliant region, and every receipt records where it ran. "Did any of this leave the Union?" becomes a filter on the archive.

Takeaway: region on the manifest, region on the hire, region on every receipt.

What this does to the Agentic Economy

Reflected in the Agentic Economy, the Act gives its three pillars a legal footing before the market has finished building them. The description is now required. The receipt is specified in everything but name. The public database the Act creates for high-risk systems is a one-jurisdiction prototype of the registry. Brussels was not thinking about agents hiring agents. It arrived at the same objects anyway, because it was trying to make AI systems accountable for what they do, and that is the problem the Agentic Economy was designed around. That is why the Act is reflected in it so cleanly.

The cost of the law falls along an architectural line, not a sectoral one. A publisher whose capabilities emit signed receipts, declare a risk class and name an owner will meet most of the high-risk chapter as a by-product of trading, and will find December 2027 mostly paperwork. A publisher whose systems emit logs and whose contracts are PDFs has a reconstruction project with sixteen months on the clock.

And Europe is now the first place where audit-ready evidence has a price. An agent choosing between two equivalent capabilities will prefer the one whose hire carries less regulatory exposure for its principal, and registries will learn to rank on it. That is the audit-ready moat from The Four Moats, with a statute behind it.

What I cannot yet answer

Who is liable when five capabilities from four publishers in three countries share one high-risk decision? The Act says who becomes the provider; it does not say how responsibility is apportioned. Who reports a serious incident when a receipt stream detects it in minutes and no person was in the loop? How do a general-purpose model provider's duties combine with a capability publisher's? And can a database designed for thousands of registered systems serve an economy with millions of capabilities, versioned daily?

If any of those is your field, in law, policy, a regulator or a university, I would like to compare notes.

The small print

This is an architect's reading of the Act as it stands on 10 October 2026, not legal advice. The regulation was amended in July 2026 and will change again as guidelines and standards arrive; check the dates and duties above against the text on EUR-Lex before relying on them, and take advice on your own situation.

For readers who want the article numbers:

Rule Where it lives in the Act
Somebody is always the employer Articles 3, 16, 25 and 26 (provider, deployer, value chain)
Risk is decided at hire Article 6 and Annex III; Article 49 (registration, including self-assessed exemptions)
The receipt is evidence Articles 12, 19 and 26 (logging and retention); Article 86 (right to explanation); Article 73 (serious incidents)
Measure and release Article 72 (post-market monitoring); Article 20 (corrective action and withdrawal)
Marking survives the chain Article 50 (transparency), in force since 2 August 2026
Borders at hire time Article 2 (scope)
The fines Article 99
What moved in July 2026 Regulation (EU) 2026/1744, the Digital Omnibus on AI

← Back to The Software Lens library