GovCompass
AI governance

Why your agentic stack is one high-risk system

By GovCompass.ai· Last updated August 2026· The EU Commission draft guidelines on high-risk classification are in consultation until 23 July 2026; obligation dates shifted under the AI Omnibus.

Under the EU AI Act, splitting an autonomous workflow across several agents does not split its regulatory classification. The Commission's draft guidelines on high-risk classification, published in May 2026, state that a complex system made up of several AI components, including an agentic stack of orchestrators and sub-agents, is assessed as a whole. An orchestrator coordinating sub-agents toward a high-risk decision is one high-risk system, and the full weight of the Act's high-risk obligations attaches to the stack, not to its parts.

This is part of our work on agentic AI, the condition that changes how all seven pillarspillarA responsible-AI principle as something an organization actively holds rather than merely endorses: one of the seven pillars of responsible AI, one per principle. A pillar is held, not implemented, by naming the harms that would breach the principle, assessing their risk, and placing controls that reduce it. Distinct from agentic AI, which is not one of the seven but a condition that changes how all of them are governed. See principle, harm, risk, agentic AI.Open full entry → of responsible AIresponsible AIThe set of principles an AI system should live up to: fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, and human oversight. Widely shared and sitting under the EU AI Act and the major frameworks. On their own the principles are statements of intent; the law turns them into duties that cannot be met unless they are carried inside the organization's governance, which is how responsible AI lands in governance rather than beside it. The seven principles are organized into seven pillars, one pillar per principle. See principle, pillar, governance. The seventh principle carries two names in practice: human oversight in the seven-pillar model, and human-centricity in the IAPP AIGP body of knowledge; the substance overlaps.Open full entry → are governed.

The architecture instinct that fails

When a team designs an agentic system, the natural move is decomposition. One agent retrieves data, another reasons over it, a third drafts an action, an orchestratororchestratorThe agent that coordinates other agents and tools toward a combined goal. It is the integration point where stack-level accountability and classification sit.Open full entry → coordinates them, and a final agent executes. Each component looks narrow. Each, taken alone, seems to do something procedural and low-stakes. The tempting conclusion is that no single component is high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry →, so the system as a whole escapes the high-risk regime.

The Commission's draft guidelines close that door. They state that where multiple AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → form part of a more complex system whose combined purpose or joint outputs materially influence a decision, the combined configuration is treated as a single AI system for classification purposes. Split architectures are assessed as a whole, precisely to prevent classification being circumvented by design. The guidelines extend this explicitly to interconnected and agentic systems coordinating linked actions where those actions serve a high-risk purpose.

What this means in practice

The practical implication is direct. If your agentic stackagentic stackThe orchestrator, sub-agents, and tools that together perform an autonomous workflow. Under the EU AI Act it is classified and governed as one system, not as separate parts.Open full entry →, taken end to end, materially influences a decision that falls within one of the Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry → high-risk areas, employment, credit, essential services, education, biometrics, critical infrastructure, migration, or law enforcement, then the entire stack is high-risk. The narrow scope of any individual agent does not save it. Even a component performing only a preparatory or procedural task may be classified as high-risk where, as part of an agentic system, it contributes to outputs that materially influence an Annex III use case.

This means the obligations attach to the stack as a whole: a risk management system under Article 9, data governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry → under Article 10, technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry → under Article 11, record-keepingrecord-keepingThe EU AI Act obligation for high-risk AI systems to allow automatic recording of events over the system's lifetime, laid down in Article 12. Deployers must keep the logs under their control for a period appropriate to the system's purpose, at least six months, under Article 26(6). Logs are what make decisions reconstructable afterward. See evidence, human oversight.Open full entry → under Article 12, transparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → under Article 13, human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry → under Article 14, accuracy and robustnessrobustnessA system's ability to perform reliably under realistic conditions including noise, edge cases and adversarial pressure, the engineering core of the safety-and-reliability principle.Open full entry → under Article 15, and a conformity assessmentconformity assessmentThe pre-market process demonstrating a high-risk AI system meets the EU AI Act's requirements, leading to CE marking and registration.Open full entry → before the system is placed on the market or put into service.

The classification has to be done at the stack level

For an AI Officer, the consequence is a change in how classification is performed. You cannot classify agent by agent and sum the results. You have to identify the stack, define its combined intended purpose, and classify the whole against Annex III. If the combined output materially influences a high-risk decision, the stack is in scope, and every agent within it inherits the obligations that follow.

This also means your AI inventoryAI inventoryA register of all AI systems an organization builds, buys or embeds, with owners and risk tiers. It is the prerequisite for governing any of them.Open full entry → needs to record agentic stacks as units, not just individual models. An inventory that lists five "low-risk" agents and misses that together they form one high-risk hiring system is an inventory that has misclassified its single most significant exposure.

Timing

The draft guidelines remain in consultation until 23 July 2026 and are non-binding, with authoritative interpretation ultimately resting with the Court of Justice of the European Union. The high-risk obligation dates have shifted under the AI Omnibus, with rules for designated high-risk areas now expected to apply from December 2027 and product-embedded systems from August 2028. That extension is not a reason to wait. Classifying an agentic stack, building its technical documentation, and preparing a conformity assessment is eighteen months of work for a complex deployment, and the interpretive position the guidelines set out is the baseline regulators will use. Capture the classification now, document it against the draft guidelines, and refine at final adoption.

The practical step

Take each agentic deployment in your inventory. Draw the stack boundary: every agent, orchestrator, and tool that contributes to a single combined purpose. Define that combined purpose in the language of Annex III. Classify the whole. Where the stack is high-risk, the obligations are the standard Chapter III obligations, and they are owned at the stack level, with a single accountable party for the whole, not distributed across the agents in a way that leaves the integration ungoverned.

Legal referencesArt. 11Art. 6Art. 9
Continue withAccountability
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.