Back to blog

The AI Agent Compliance Checklist for 2026

Mar 18, 2026

EU AI Act enforcement for high-risk systems begins 2 December 2027 (Annex III), with embedded high-risk products following on 2 August 2028, under the Digital Omnibus deferral pending final EU adoption. Penalties reach 35 million EUR or 7% of worldwide annual turnover. If your agents operate in Annex III high-risk categories (finance, healthcare, employment, critical infrastructure), you need six capabilities in place.

The checklist

1. Agent registry and identity management

Every AI agent needs a unique, verifiable identity. You need a central registry of all agents, their capabilities, access permissions, and operational status. Article 13 requires transparency. Article 9 requires lifecycle risk management. Both start with knowing what agents exist. The NIST AI Risk Management Framework reinforces this with its emphasis on mapping and governing AI systems.

Asqav gives every agent a unique identity backed by a cryptographic key pair. The dashboard provides a real-time registry of all agents, their status, and signing activity.

2. Immutable audit trails

Every action by every agent must be automatically recorded in a log that is tamper-evident rather than merely access-controlled. Article 12 requires automatic recording. Article 19 requires six-month retention. Article 26 extends these obligations to deployers.

Standard application logs fail because they can be modified by anyone with server access. Tamper-evidence requires cryptography, not just access controls.

Asqav signs every action with ML-DSA (NIST FIPS 204). Records are stored immutably and exportable for regulator review.

3. Policy enforcement and action gating

Before an agent executes a high-risk action, it must be checked against defined policies. If the action violates a policy, it is blocked before execution. Article 9 requires lifecycle risk management. Article 14 requires intervention capability.

Asqav evaluates each action against configured policies before signing. Rejections are logged. Policies are managed centrally, independent of agent code.

4. Human oversight for high-risk decisions

Article 14 requires that high-risk AI systems be effectively overseen by humans. The ISO 42001 AI management standard similarly emphasizes human oversight as a core governance control. The system must provide enough context for informed decisions. The human must be able to reject the action.

Asqav's signing groups support multi-party approval with configurable thresholds. Approvals and rejections are both recorded in the audit trail.

5. Instant agent revocation

If an agent is compromised, you need to revoke its authorization in seconds, not minutes. Article 14 requires the ability to intervene in or interrupt AI system operation. A redeployment is not an interruption.

Revoking an agent in Asqav invalidates its signing key immediately. Any subsequent signing request is rejected.

6. Compliance documentation and export

You need structured documentation on demand: agent registries, audit trail exports, policy configurations, approval histories. Article 19 requires logs be available to authorities on request. Article 11 requires technical documentation.

Asqav provides one-click export of audit trails, agent registries, and policy configurations in structured JSON with signatures intact.

Scoring yourself

  • Green: Capability in production today.
  • Yellow: Partial solution or planned but not implemented.
  • Red: No capability and not started.

More than two yellows or any reds is a gap that will surface during the first compliance review under these regimes. See the compliance documentation for what each capability maps to. Or create a free account and start with your highest-risk agent today.

Stay ahead of AI compliance

Get practical insights on AI agent security and compliance obligations. No spam, unsubscribe anytime.