{"id":32588,"date":"2026-07-19T08:00:00","date_gmt":"2026-07-19T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/how-do-you-ensure-that-an-agentic-ai-solution-complies-with-the-transparency-requirements-of-the-ai-act\/"},"modified":"2026-07-19T10:00:38","modified_gmt":"2026-07-19T08:00:38","slug":"how-do-you-ensure-that-an-agentic-ai-solution-complies-with-the-transparency-requirements-of-the-ai-act","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/how-do-you-ensure-that-an-agentic-ai-solution-complies-with-the-transparency-requirements-of-the-ai-act\/","title":{"rendered":"How do you ensure that an Agentic AI solution complies with the transparency requirements of the AI Act?"},"content":{"rendered":"<p>To ensure that an <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">Agentic AI solution<\/a> complies with the transparency requirements of the AI Act, your organization must demonstrate that the system is traceable, documentable, and verifiable. This applies in particular if your Agentic AI application is classified as high-risk under the regulation. In this article, we answer the most frequently asked questions about transparency, documentation, and human oversight at Agentic AI in light of the AI Act.  <\/p>\n<h2>What transparency requirements does the AI Act impose on high-risk AI systems?<\/h2>\n<p>The AI Act requires providers and users of high-risk AI systems to ensure transparency at four levels: technical documentation, logging of system behavior, understandable information for users, and demonstrable human oversight. These requirements are intended to enable accountability and prevent arbitrary or uncontrollable decisions. <\/p>\n<p>Specifically, this means that a high-risk AI system must meet the following transparency requirements:<\/p>\n<ul>\n<li><strong>Technical documentation:<\/strong> a complete set of documents for the system, including its design, operation, training data, and known limitations.<\/li>\n<li><strong>Automatic logging:<\/strong> The system must log events so that it is possible to verify later which decisions were made and on what basis.<\/li>\n<li><strong>User Information:<\/strong> People who work with the system or are affected by it must understand that they are dealing with AI and what the system does.<\/li>\n<li><strong>Accountability:<\/strong> The logic behind decisions must be transparent to regulators and stakeholders.<\/li>\n<\/ul>\n<p>High-risk AI is defined in Article 6 of the AI Act and includes, among other things, systems used in eight specific domains, including access to essential services, employment and workforce management, and the administration of justice. Systems that perform profiling of natural persons are always considered high-risk, regardless of the context. Most of the obligations for high-risk Annex III systems will take effect on August 2, 2026.  <\/p>\n<h2>What makes Agentic AI different from regular AI under the AI Act?<\/h2>\n<p>Agentic AI differs from conventional AI in that the system takes initiative on its own, links decisions sequentially, and carries out actions without human approval at every step. This autonomous nature makes the application more complex to assess under the AI Act, because the chain of responsibility is less direct than in a single-decision model. <\/p>\n<p>Whereas a traditional AI model processes a single input and produces a single output, an Agentic AI system can go through a series of steps: retrieving information, making a decision, performing an action, evaluating the result, and then initiating a new step. This makes it more difficult to determine exactly which step led to which result. <\/p>\n<p>This is relevant to the AI Act for two reasons. First, greater autonomy increases the potential risk: the more the system acts independently, the greater the impact of an error or an undesirable outcome. Second, the multi-step operation requires logging and documentation at the level of individual actions, not just at the level of the final result. If your Agentic AI solution makes decisions that directly affect people, there\u2019s a good chance it will be classified as high-risk.   <\/p>\n<h2>What documentation is required for an Agentic AI solution?<\/h2>\n<p>For an Agentic AI solution classified as high-risk, comprehensive technical documentation is required. This documentation must be up to date, accessible to regulators, and sufficiently detailed to fully understand the system\u2019s operation, limitations, and risks. <\/p>\n<p>The required documentation must include, at a minimum:<\/p>\n<ol>\n<li><strong>System Description:<\/strong> A detailed description of the system&#8217;s purpose, operation, and limitations.<\/li>\n<li><strong>Risk management system:<\/strong> a documented analysis of risks and the measures taken to manage them.<\/li>\n<li><strong>Training Data and Data Quality:<\/strong> Information about what data were used, how they were selected, and what quality checks were performed.<\/li>\n<li><strong>Performance metrics:<\/strong> measurable indicators that demonstrate the system&#8217;s accuracy and reliability.<\/li>\n<li><strong>Change History:<\/strong> An overview of substantial changes to the system, including an assessment of whether those changes alter the risk classification.<\/li>\n<\/ol>\n<p>Additional obligations apply to General-Purpose AI (GPAI) models: providers must prepare technical documentation in accordance with Annex XI, inform downstream providers about capabilities and limitations in accordance with Annex XII, and make a summary of the training data used publicly available. If your Agentic AI solution is built on a GPAI model, these obligations also apply to the underlying layer of the system. <\/p>\n<h2>How do you explain what led to an Agentic AI decision?<\/h2>\n<p>Explainability in Agentic AI requires a combination of technical logging, structured reasoning traces, and understandable reporting. The goal is to enable you to reconstruct, after the fact, which input, which step, and which weighting led to a specific decision or action. <\/p>\n<p>In practice, this means that you need to organize explainability at three levels:<\/p>\n<ul>\n<li><strong>Action Level:<\/strong> Every action taken by the system is logged with a timestamp, context, and the reason for that action.<\/li>\n<li><strong>Decision-making level:<\/strong> The reasoning behind a decision is documented, including which alternatives were considered and why a particular course of action was chosen.<\/li>\n<li><strong>Outcome level:<\/strong> The final result is linked to the chain of actions and decisions that preceded it, ensuring that a complete audit trail is available.<\/li>\n<\/ul>\n<p>This poses a technical challenge for systems that use large language models or neural networks, because the internal workings of these models are not always immediately interpretable. A practical approach is to incorporate structured interim reports into the workflow of the Agentic AI system, so that each step is explicitly documented in understandable language. Regulators and stakeholders do not need to understand the underlying model architecture, but they do need to be able to understand why a decision was relevant to them.  <\/p>\n<h2>When is human oversight required for Agentic AI?<\/h2>\n<p>Human oversight is required for all high-risk AI systems, including Agentic AI applications that fall into that category. The AI Act requires providers and users to take measures to ensure that humans can effectively monitor, correct, and, if necessary, shut down the system during operation. <\/p>\n<p>The law distinguishes between two forms of oversight. In the case of <strong>oversight during use<\/strong>, people must be able to recognize abnormal behavior and intervene before harm occurs. <strong>Post-use oversight<\/strong> involves the ability to review decisions and correct their consequences. Both forms are relevant to Agentic AI, precisely because the system independently carries out multiple steps.   <\/p>\n<p>In practice, this means that you build explicit checkpoints into your Agentic AI solution: moments when a human assesses the progress before the system continues. This is particularly required when the system makes decisions that are irreversible or have direct consequences for people, such as denying a service, initiating a payment, or modifying customer data. The greater the autonomy and the impact, the more frequent and thorough human oversight must be.  <\/p>\n<h2>How can you verify that your Agentic AI solution complies with the AI Act?<\/h2>\n<p>You can verify whether your Agentic AI solution complies with the AI Act by first determining the risk classification, then identifying the obligations for that class, and finally systematically assessing whether your system and organization meet each requirement. This is an ongoing process, not a one-time check. <\/p>\n<p>A practical approach consists of the following steps:<\/p>\n<ol>\n<li><strong>Classify the system:<\/strong> determine whether your Agentic AI solution is high-risk based on Article 6 and Annex III. Also check whether the system performs profiling of individuals, as that is always considered high-risk. <\/li>\n<li><strong>Identify the obligations:<\/strong> For each obligation, determine whether you are classified as a provider, deployer, or importer. Anyone who offers the system under their own name or makes substantial modifications to it assumes all the obligations of a provider. <\/li>\n<li><strong>Audit the documentation:<\/strong> verify that the technical documentation is complete, up-to-date, and accessible to regulatory authorities.<\/li>\n<li><strong>Test the logging:<\/strong> Verify that the system automatically records sufficient data to allow decisions to be reconstructed retrospectively.<\/li>\n<li><strong>Evaluate the oversight mechanism:<\/strong> assess whether the built-in checkpoints for human oversight work in practice and whether employees know how to intervene.<\/li>\n<li><strong>Repeat in case of changes:<\/strong> Any substantial modification to the system requires a new assessment of the risk classification and compliance.<\/li>\n<\/ol>\n<p>Organizations that are not yet fully compliant can, in the meantime, adopt a Code of Practice to establish a presumption of compliance until harmonized standards become available. This provides a structured path toward full compliance without having to wait for final standards. <\/p>\n<h2>How Pegamento Helps Agentic AI Achieve AI Act Compliance<\/h2>\n<p>Complying with the transparency requirements of the AI Act is not a mere administrative formality, but an integral part of building and managing a responsible <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI solution<\/a>. At Pegamento, we understand this challenge because we don\u2019t view Agentic AI as a standalone product, but rather as an evolution from task automation to self-thinking assistants that take the initiative and act independently. What used to be called RPA has evolved into Agentic AI: systems that not only follow instructions but also reason, prioritize, and act.  <\/p>\n<p>Our approach is built on proven modules that you can combine without the need for costly customization, and that were designed from the outset with auditability and transparency in mind. Specifically, we offer: <\/p>\n<ul>\n<li><strong>Built-in audit trails<\/strong> so that every decision and action taken by the system is traceable.<\/li>\n<li><strong>Structured checkpoints<\/strong> for human oversight at the moments that really matter.<\/li>\n<li><strong>Documentation support<\/strong> that meets the requirements of the AI Act, including technical dossiers and risk assessments.<\/li>\n<li><strong>A single point of contact<\/strong> for development, implementation, management, and compliance, so you don&#8217;t have to manage a complex supplier structure.<\/li>\n<li><strong>ISO 27001-certified security<\/strong> as the foundation, supplemented by ISO 9001 and ISO 26000, to ensure information security and quality.<\/li>\n<\/ul>\n<p>Would you like to know how your current or planned Agentic AI solution measures up against the AI Act requirements? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Contact us<\/a>, and we\u2019ll work with you to determine the best approach for your situation.<\/p>\n<div class=\"wp-block-seoaic-faq-block\">\n    <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n            <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Geldt de AI Act ook voor Agentic AI-oplossingen die we intern gebruiken en niet aan derden aanbieden?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, de AI Act maakt onderscheid tussen aanbieders (die het systeem ontwikkelen of op de markt brengen) en deployers (die het systeem in gebruik nemen). Ook als je een Agentic AI-oplossing uitsluitend intern inzet, ben je als deployer gebonden aan verplichtingen zoals menselijk toezicht, logging en het naleven van de instructies van de aanbieder. Als je het systeem bovendien zelf hebt ontwikkeld of substantieel hebt aangepast, gelden alle verplichtingen van een aanbieder, inclusief technische documentatie en conformiteitsbeoordeling.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat zijn de meest gemaakte fouten bij het inrichten van logging voor Agentic AI?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De meest voorkomende fout is dat organisaties alleen het eindresultaat loggen in plaats van elke individuele stap in de beslissingsketen. Voor Agentic AI is het juist essentieel dat tussenliggende acties, overwogen alternatieven en de context op het moment van beslissen worden vastgelegd. Een tweede veelgemaakte fout is het ontbreken van een retentiebeleid: logs moeten lang genoeg bewaard worden om audits en klachtenprocedures te ondersteunen, en de AI Act stelt daar specifieke eisen aan voor hoog-risico systemen.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe bepaal ik of een aanpassing aan mijn bestaande Agentic AI-systeem &#039;substantieel&#039; is en dus een nieuwe conformiteitsbeoordeling vereist?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Een aanpassing is substantieel als deze de bedoelde werking, het risiconiveau of de prestaties van het systeem significant be\u00efnvloedt. Denk aan het toevoegen van nieuwe beslissingsbevoegdheden, het wisselen van het onderliggende AI-model, het uitbreiden naar een nieuw toepassingsdomein, of het aanpassen van de drempelwaarden voor geautomatiseerde beslissingen. Bij twijfel is het verstandig om de aanpassing te documenteren en expliciet te toetsen aan de oorspronkelijke risicoklassificatie; als de uitkomst verandert, is een volledige herbeoordeling verplicht.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Kunnen we al beginnen met bouwen aan een conforme Agentic AI-oplossing, of moeten we wachten tot alle geharmoniseerde normen beschikbaar zijn?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Je hoeft niet te wachten: de kernvereisten van de AI Act zijn al vastgesteld en de meeste verplichtingen voor hoog-risico Annex III-systemen gaan in per 2 augustus 2026. Je kunt nu al beginnen door de risicoklassificatie te bepalen, technische documentatie op te bouwen en logging en toezichtmechanismen in te richten op basis van de huidige wettekst. Zolang geharmoniseerde normen nog niet beschikbaar zijn, kun je aansluiten bij een erkende gedragscode (Code of Practice) om een vermoeden van conformiteit te verkrijgen.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe leg ik een beslissing van mijn Agentic AI uit aan een klant die geen technische achtergrond heeft?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De AI Act vereist niet dat je de technische werking van het model uitlegt, maar wel dat de betrokkene begrijpt dat een AI-systeem een rol heeft gespeeld en wat de relevante uitkomst voor hem of haar is. Praktisch gezien betekent dit dat je in de workflow gestructureerde, mensvriendelijke samenvattingen genereert die in begrijpelijke taal beschrijven welke informatie is meegewogen en tot welke conclusie het systeem is gekomen. Bied daarnaast altijd een duidelijk contactpunt aan waar betrokkenen terecht kunnen met vragen of bezwaren over de beslissing.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat gebeurt er als mijn Agentic AI-oplossing is gebouwd op een extern GPAI-model, zoals een grote taalmodel-API? Wie is dan verantwoordelijk voor de AI Act-compliance?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De verantwoordelijkheid is gelaagd: de aanbieder van het GPAI-model is verantwoordelijk voor de verplichtingen op modelniveau, zoals technische documentatie conform Annex XI en het informeren van downstream-aanbieders over capaciteiten en beperkingen. Als jij het GPAI-model integreert in een hoog-risico Agentic AI-oplossing en deze onder eigen naam aanbiedt of substantieel aanpast, neem je de volledige verplichtingen van een aanbieder over voor het eindproduct. Het is daarom cruciaal om contractueel vast te leggen welke informatie de GPAI-aanbieder aan jou moet leveren, zodat jij jouw eigen technische dossier compleet kunt maken.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe frequent moeten de breekpunten voor menselijk toezicht zijn, en wie in onze organisatie mag die toezichtrol vervullen?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De AI Act schrijft geen vaste frequentie voor, maar stelt dat het toezicht effectief moet zijn: de toezichthouder moet afwijkend gedrag tijdig kunnen herkennen en ingrijpen voordat schade ontstaat. De frequentie hangt dus af van de snelheid, autonomie en impact van jouw specifieke Agentic AI-oplossing. De persoon die de toezichtrol vervult, moet voldoende kennis hebben van het systeem om afwijkingen te beoordelen en bevoegd zijn om het systeem te pauzeren of te stoppen; dit hoeft geen technisch expert te zijn, maar mag ook geen louter formele rol zijn zonder echte interventiemogelijkheid.            <\/p>\n        <\/div>\n        <\/div>\n","protected":false},"excerpt":{"rendered":"<p>AI Act Transparency for Agentic AI: From Mandatory Audit Trails to Human Oversight \u2014 Everything You Need to Know.<\/p>\n","protected":false},"author":2,"featured_media":32589,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-32588","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=32588"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32588\/revisions"}],"predecessor-version":[{"id":32591,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32588\/revisions\/32591"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/32589"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=32588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=32588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=32588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}