[{"data":1,"prerenderedAt":649},["ShallowReactive",2],{"navigation-en":3,"{\"language\":\"default\",\"resolve_relations\":[\"article.author\"],\"version\":\"published\"}news\u002Fai-compliance-in-motion-adapting-to-agentic-systems":303},{"_uid":4,"groups":5,"component":4},"navigation",[6,99,194,242],{"_uid":7,"link":8,"label":14,"tiers":15,"hidden":26,"columns":88,"component":89,"in_footer":90,"in_header":90,"brand_link":91,"brand_label":93,"footer_link":94,"footer_text":9,"panel_width":95,"footer_label":9,"footer_order":96,"brand_cta_link":97,"footer_heading":98,"brand_cta_label":9},"3a984d45-c4a4-4620-b9a0-e89311aad748",{"id":9,"url":9,"story":10,"linktype":12,"fieldtype":13,"cached_url":11},"",{"full_slug":11},"helia","story","multilink","Product",[16,57],{"_uid":17,"items":18,"style":53,"hidden":26,"marker":54,"component":55,"marker_color":56},"a7cc3e35-c73c-4b31-adb6-287a7a0f5a5f",[19,29,37,45],{"_uid":20,"icon":21,"link":22,"label":25,"hidden":26,"component":27,"description":28},"06faf34e-21ae-4e85-9c18-d349c8e43767","i-lucide-mountain-snow",{"id":9,"url":9,"story":23,"linktype":12,"fieldtype":13,"cached_url":24},{"full_slug":24},"helia\u002Fhorizon-scanning","Horizon Scanning",false,"nav_item","We flag what changed the moment it lands",{"_uid":30,"icon":31,"link":32,"label":35,"hidden":26,"component":27,"description":36},"1b053d0c-5196-4a3d-b446-0d975ad3a0bf","i-lucide-trending-up",{"id":9,"url":9,"story":33,"linktype":12,"fieldtype":13,"cached_url":34},{"full_slug":34},"helia\u002Fimpact-assessment","Impact Assessment","See what a change means and where the gaps are",{"_uid":38,"icon":39,"link":40,"label":43,"hidden":26,"component":27,"description":44},"a77dbf68-4115-4712-99cd-cc1c687b6db3","i-lucide-route",{"id":9,"url":9,"story":41,"linktype":12,"fieldtype":13,"cached_url":42},{"full_slug":42},"helia\u002Frisk-control","Risk & Control","Every gap comes with an AI-drafted fix to approve",{"_uid":46,"icon":47,"link":48,"label":51,"hidden":26,"component":27,"description":52},"74a1f93b-9b82-42be-8052-9037a25eef70","i-lucide-database",{"id":9,"url":9,"story":49,"linktype":12,"fieldtype":13,"cached_url":50},{"full_slug":50},"helia\u002Fdata-management","Data Management","One versioned source of truth for rules and controls","rows","tile","nav_tier","secondary",{"_uid":58,"items":59,"style":84,"hidden":26,"marker":54,"heading":85,"component":55,"description":86,"marker_color":56,"heading_style":87},"3fe1e99d-1af4-4266-808b-a6d42a292b7d",[60,68,76],{"_uid":61,"icon":62,"link":63,"label":66,"hidden":26,"component":27,"description":67},"cfb434b2-8dd3-4a2e-b7a3-55026f8f6e69","i-lucide-compass",{"id":9,"url":9,"story":64,"linktype":12,"fieldtype":13,"cached_url":65},{"full_slug":65},"helia\u002Fregulatory-nexus","Regulatory Nexus","Every rule linked to its controls, evidence and owners",{"_uid":69,"icon":70,"link":71,"label":74,"hidden":26,"component":27,"description":75},"a7d84ff1-8690-4117-95b2-7570d58c2ebd","i-lucide-folder-kanban",{"id":9,"url":9,"story":72,"linktype":12,"fieldtype":13,"cached_url":73},{"full_slug":73},"helia\u002Ftask-management","Task Management","Findings become assigned, reviewed and evidenced work",{"_uid":77,"icon":78,"link":79,"label":82,"hidden":26,"component":27,"description":83},"37996c4e-dc18-4619-9d4e-1ad1aa5f1435","i-lucide-vault",{"id":9,"url":9,"story":80,"linktype":12,"fieldtype":13,"cached_url":81},{"full_slug":81},"helia\u002Fvault","Vault","Regulator-ready evidence in a single click","labels","Helia Foundation","always included","inline","2","nav_group",true,{"id":9,"url":9,"story":92,"linktype":12,"fieldtype":13,"cached_url":11},{"full_slug":11},"Explore Regulatory AI",{"id":9,"url":9,"linktype":12,"fieldtype":13,"cached_url":9},"wide","1",{"id":9,"url":9,"linktype":12,"fieldtype":13,"cached_url":9},"RegAI Helia",{"_uid":100,"link":101,"label":103,"tiers":104,"hidden":26,"columns":88,"component":89,"in_footer":90,"in_header":90,"panel_width":95,"footer_order":193},"b819acc3-3bd1-4e78-808f-430a5106bfd3",{"id":9,"url":9,"linktype":102,"fieldtype":13,"cached_url":9},"url","Solutions",[105,139,158],{"_uid":106,"items":107,"style":53,"hidden":26,"marker":136,"heading":137,"component":55,"description":138,"marker_color":9,"heading_style":9},"ced8b335-a7d1-4076-b875-513e850185f7",[108,115,122,129],{"_uid":109,"icon":9,"link":110,"label":113,"hidden":26,"component":27,"in_footer":90,"in_header":90,"description":114},"a0f46fa6-82f1-4c85-81e1-3a3684b54eaa",{"id":9,"url":9,"story":111,"linktype":12,"fieldtype":13,"cached_url":112},{"full_slug":112},"solutions\u002Famlr","Financial  Economic Crime​","AMLR, Sanctiewet,  technical standards (FEC)​",{"_uid":116,"link":117,"label":120,"hidden":26,"component":27,"description":121},"d89ecacc-8bb4-49e1-b02f-df32bb824c32",{"id":9,"url":9,"story":118,"linktype":12,"fieldtype":13,"cached_url":119},{"full_slug":119},"solutions\u002Fdora","Digital Resilience​","DORA and related  regulations​",{"_uid":123,"link":124,"label":127,"hidden":26,"component":27,"description":128},"65a2c9e5-b3a4-4465-9d16-9ef734ffbee9",{"id":9,"url":9,"story":125,"linktype":12,"fieldtype":13,"cached_url":126},{"full_slug":126},"solutions\u002Fesg","ESG","ESG-related regulations (CSRD, ESRS, SFDR)​",{"_uid":130,"link":131,"label":134,"hidden":26,"component":27,"description":135},"25031048-0045-4cea-b5ed-8e1af3a2b240",{"id":9,"url":9,"story":132,"linktype":12,"fieldtype":13,"cached_url":133},{"full_slug":133},"solutions\u002Fai-act","Model & AI​","AI Act and related regulations​","bar","Implementation engines","Scoped to one regulatory domain and deployed into your existing policy, control and data framework",{"_uid":140,"items":141,"style":53,"hidden":26,"marker":136,"heading":155,"component":55,"description":156,"marker_color":157,"heading_style":9},"4cb9d0fb-ae60-4a6d-8ce9-a63ac15bbffa",[142,149],{"_uid":143,"link":144,"label":147,"hidden":26,"component":27,"description":148},"3319bb12-c3e1-4f03-8628-55db20ab7bca",{"id":9,"url":9,"story":145,"linktype":12,"fieldtype":13,"cached_url":146},{"full_slug":146},"solutions\u002Fmicar","MiCAR","and related regulations",{"_uid":150,"link":151,"label":154,"hidden":26,"component":27,"description":148},"4f20f819-0ed2-4bed-9f6e-4c79a6ebdada",{"id":9,"url":9,"story":152,"linktype":12,"fieldtype":13,"cached_url":153},{"full_slug":153},"solutions\u002Faifmd","AIFMD","Compliance-in-a-box","Packaged for a firm type whose regulatory perimeter is largely defined by a single regime","accent",{"_uid":159,"items":160,"style":84,"hidden":26,"marker":191,"heading":192,"component":55,"in_header":26,"footer_order":88,"marker_color":9,"footer_column":90,"heading_style":9},"c3852bfb-8d89-443f-99fd-754307e49dcc",[161,167,173,179,185],{"_uid":162,"link":163,"label":166,"hidden":26,"component":27},"e1b66107-6600-4633-a6df-4961e8af20d9",{"id":9,"url":9,"story":164,"linktype":12,"fieldtype":13,"cached_url":165},{"full_slug":165},"services\u002Fregulatory-change","Regulatory Change Management",{"_uid":168,"link":169,"label":172,"hidden":26,"component":27},"366e6e5a-39b9-4623-a37e-c19a0c9438a9",{"id":9,"url":9,"story":170,"linktype":12,"fieldtype":13,"cached_url":171},{"full_slug":171},"services\u002Fintegrated-risk-management","Integrated Risk Management",{"_uid":174,"link":175,"label":178,"hidden":26,"component":27},"9cf11ffe-1fbb-48e4-b8c6-bef6b0b04f6b",{"id":9,"url":9,"story":176,"linktype":12,"fieldtype":13,"cached_url":177},{"full_slug":177},"services\u002Fnon-financial-risk","Non-Financial Risk",{"_uid":180,"link":181,"label":184,"hidden":26,"component":27},"c2fb0349-60a7-47f2-8fe7-194bfae736fc",{"id":9,"url":9,"story":182,"linktype":12,"fieldtype":13,"cached_url":183},{"full_slug":183},"services\u002Fresponsible-ai","Responsible AI",{"_uid":186,"link":187,"label":190,"hidden":26,"component":27},"dc05a25f-81f0-4060-b940-ed2e02ea2f39",{"id":9,"url":9,"story":188,"linktype":12,"fieldtype":13,"cached_url":189},{"full_slug":189},"services\u002Fsustainable-finance","Sustainable Finance","none","Services","4",{"_uid":195,"link":196,"label":199,"tiers":200,"hidden":26,"columns":96,"component":89,"in_footer":26,"in_header":90,"panel_width":240,"footer_order":241},"0ef586ba-e957-44b3-9bca-e3dbab796458",{"id":9,"url":9,"story":197,"linktype":12,"fieldtype":13,"cached_url":198},{"full_slug":198},"clients","Clients",[201,209],{"_uid":202,"items":203,"style":53,"hidden":26,"marker":191,"component":55,"in_footer":26,"in_header":26},"5029d714-3b1c-46c9-8184-57601f8a292c",[204],{"_uid":205,"link":206,"label":199,"hidden":26,"component":27,"description":208},"d95827bc-7fb0-464b-b6be-1fe7a1ad5046",{"id":9,"url":9,"story":207,"linktype":12,"fieldtype":13,"cached_url":198},{"full_slug":198},"Who we work with, across the sector and its supervisors",{"_uid":210,"items":211,"style":53,"hidden":26,"marker":191,"component":55,"in_footer":26,"in_header":26},"51f99e1b-7670-4f52-8bc4-672c19e34fa8",[212,219,226,233],{"_uid":213,"link":214,"label":217,"hidden":26,"component":27,"description":218},"e744d61a-0416-41e8-aedc-c3401dd02cac",{"id":9,"url":9,"story":215,"linktype":12,"fieldtype":13,"cached_url":216},{"full_slug":216},"banking","Banking","Capital, prudential reporting and a widening AML agenda",{"_uid":220,"link":221,"label":224,"hidden":26,"component":27,"description":225},"20d27513-7541-4143-9caa-bc93b4805905",{"id":9,"url":9,"story":222,"linktype":12,"fieldtype":13,"cached_url":223},{"full_slug":223},"insurance","Insurance","Solvency II, IFRS 17, and a growing conduct and ICT load",{"_uid":227,"link":228,"label":231,"hidden":26,"component":27,"description":232},"7b671952-5705-4e90-8e95-b037f1522cc6",{"id":9,"url":9,"story":229,"linktype":12,"fieldtype":13,"cached_url":230},{"full_slug":230},"asset-management","Asset management","AIFMD II, conduct rules and sustainability disclosure",{"_uid":234,"link":235,"label":238,"hidden":26,"component":27,"description":239},"849a3ffb-e943-4043-83fa-d70f0926e2cb",{"id":9,"url":9,"story":236,"linktype":12,"fieldtype":13,"cached_url":237},{"full_slug":237},"pension-funds","Pension funds","The Wtp transition and IORP II, with the data underneath","narrow","3",{"_uid":243,"link":244,"label":245,"tiers":246,"hidden":26,"columns":96,"component":89,"in_footer":90,"in_header":90,"panel_width":240,"footer_order":302},"32580ef8-5802-4f5e-a36c-fa38d56a9504",{"id":9,"url":9,"linktype":102,"fieldtype":13,"cached_url":9},"Company",[247],{"_uid":248,"items":249,"style":53,"hidden":26,"marker":54,"component":55,"heading_style":9},"19e06ab9-9671-4711-bc0b-9e57c0ba9952",[250,254,262,270,278,286,294],{"_uid":251,"link":252,"label":199,"hidden":26,"component":27,"in_footer":90,"in_header":26},"fb8cfc24-0903-4d96-9510-a528472f667c",{"id":9,"url":9,"story":253,"linktype":12,"fieldtype":13,"cached_url":198},{"full_slug":198},{"_uid":255,"icon":256,"link":257,"label":260,"hidden":26,"component":27,"description":261},"38b711d4-31f3-4981-8513-4d9a4e65ff35","i-lucide-building-2",{"id":9,"url":9,"story":258,"linktype":12,"fieldtype":13,"cached_url":259},{"full_slug":259},"about","About us","What we do, how we work, and where we came from",{"_uid":263,"icon":264,"link":265,"label":268,"hidden":26,"component":27,"description":269},"f2bef759-a957-426b-a1e0-e73248b14063","i-lucide-users",{"id":9,"url":9,"story":266,"linktype":12,"fieldtype":13,"cached_url":267},{"full_slug":267},"team","Team","The people you would actually be working with",{"_uid":271,"icon":272,"link":273,"label":276,"hidden":26,"component":27,"description":277},"02418345-4aef-4413-9f5e-7fff2ade80fc","i-lucide-newspaper",{"id":9,"url":9,"story":274,"linktype":12,"fieldtype":13,"cached_url":275},{"full_slug":275},"news","News & insights","What changed, what it means, and what we did about it",{"_uid":279,"icon":280,"link":281,"label":284,"hidden":26,"component":27,"description":285},"4254d80d-2645-4a32-8dde-fbb8e5a0c98e","i-lucide-briefcase",{"id":9,"url":9,"story":282,"linktype":12,"fieldtype":13,"cached_url":283},{"full_slug":283},"careers","Careers","What it is like to work here, and how to reach us",{"_uid":287,"icon":288,"link":289,"label":292,"hidden":26,"component":27,"description":293},"33676272-e0f6-49bd-b759-a9a63857103a","i-lucide-leaf",{"id":9,"url":9,"story":290,"linktype":12,"fieldtype":13,"cached_url":291},{"full_slug":291},"sustainability","Sustainability","Our EcoVadis rating & what sits behind it",{"_uid":295,"icon":296,"link":297,"label":300,"hidden":26,"component":27,"in_header":26,"description":301},"2885e2cf-cb3d-4861-8db2-49683dc9b7d0","i-lucide-mail",{"id":9,"url":9,"story":298,"linktype":12,"fieldtype":13,"cached_url":299},{"full_slug":299},"contact","Contact","Where we are, and who answers when you write","5",{"data":304,"headers":627},{"story":305,"cv":613,"rels":614,"links":626},{"name":306,"created_at":307,"published_at":308,"updated_at":309,"id":310,"uuid":311,"content":312,"slug":605,"full_slug":606,"sort_by_date":594,"position":607,"tag_list":608,"is_startpage":26,"parent_id":609,"meta_data":594,"group_id":610,"first_published_at":611,"release_id":594,"lang":600,"path":594,"alternates":612,"default_full_slug":594,"translated_slugs":594},"AI Compliance in Motion: Adapting to Agentic Systems","2026-08-05T09:28:52.845Z","2026-09-02T13:28:34.387Z","2026-09-02T13:28:34.403Z",205752454582606,"3c7449a0-a33c-436a-bf44-2c8d41fb71e7",{"_uid":313,"body":314,"date":561,"kind":562,"image":563,"title":306,"topic":184,"author":567,"summary":602,"component":603,"source_url":604},"7f9ecfdb-2dcf-45d0-bd31-d71ffa0541c9",{"type":315,"content":316},"doc",[317,330,337,341,345,349,353,359,363,385,389,394,398,418,423,427,436,444,451,459,466,474,481,489,494,498,503,523,528,532,537,557],{"type":318,"content":319},"paragraph",[320,326],{"text":321,"type":322,"marks":323},"AI compliance is evolving, are your controls keeping up? ","text",[324],{"type":325},"italic",{"text":327,"type":322,"marks":328},"Interpretation of the AI Act is often grounded in traditional GenAI use cases. But what happens when AI becomes agentic, learning, acting, and adapting autonomously within its ecosystem? That’s when compliance needs to evolve too. In this post: how to govern AI that thinks, and moves, on its own.",[329],{"type":325},{"type":331,"attrs":332,"content":334},"heading",{"level":333},2,[335],{"text":336,"type":322},"Dynamic AI Agents, Static Compliance: Rethinking the AI Act for an Autonomous Era",{"type":318,"content":338},[339],{"text":340,"type":322},"The EU’s AI Act sends a clear signal: risk governance, transparency, and accountability are no longer optional, they are central to being compliant. But just as companies begin aligning with these new rules, a new technological frontier is reshaping compliance strategies: agentic AI.",{"type":318,"content":342},[343],{"text":344,"type":322},"This type of AI does not just assist, it acts and evolves. It independently pursues goals within a workflow, learns from its environment, and makes autonomous decisions across ecosystems involving multiple data sources and third-party applications. By orchestrating a range of models, it can steer and improve processes effectively and combine the strengths of various specialties and domains of expertise.",{"type":318,"content":346},[347],{"text":348,"type":322},"Agentic AI unlocks powerful capabilities such as multistep problem solving, but it also introduces a new level of risk and complexity, leading to additional compliance challenges. When these agents fall under the high-risk category, they are subject to strict regulatory oversight under the AI Act. However, even when organisations develop or use AI systems that are formally not classified as high-risk, a responsible AI approach, aligned with the spirit of the regulation, supports applying similar safeguards. This encourages organisations to proactively adopt comparable controls, strengthening governance and trust.",{"type":318,"content":350},[351],{"text":352,"type":322},"This blogpost explores how organisations can prepare in practice, and what it takes to operationalise AI ACT requirements in the age of agentic AI.",{"type":331,"attrs":354,"content":356},{"level":355},3,[357],{"text":358,"type":322},"What is Agentic AI, and Why Does It Matter?",{"type":318,"content":360},[361],{"text":362,"type":322},"Unlike traditional monolithic generative models or retrieval-augmented systems, agentic AI operates with a high degree of autonomy. These systems:",{"type":364,"content":365},"bullet_list",[366,373,379],{"type":367,"content":368},"list_item",[369],{"type":318,"content":370},[371],{"text":372,"type":322},"Pursue goals rather than simply producing outputs",{"type":367,"content":374},[375],{"type":318,"content":376},[377],{"text":378,"type":322},"Learn and adapt dynamically, updating their strategies or behaviours over time",{"type":367,"content":380},[381],{"type":318,"content":382},[383],{"text":384,"type":322},"Take action across both digital and physical systems",{"type":318,"content":386},[387],{"text":388,"type":322},"What sets agentic AI apart is its integration of core problem-solving capabilities, including memory, planning, orchestration, and the ability to interact with external applications. Together, these features make agentic systems highly effective in optimizing processes and executing decisions autonomously.",{"type":331,"attrs":390,"content":391},{"level":355},[392],{"text":393,"type":322},"A New Risk Landscape",{"type":318,"content":395},[396],{"text":397,"type":322},"Agentic AI fundamentally shifts the risk profile. As these systems increase in “agentness”, broader goals, greater adaptability, and more independence, the risks scale accordingly:",{"type":364,"content":399},[400,406,412],{"type":367,"content":401},[402],{"type":318,"content":403},[404],{"text":405,"type":322},"Emergent behavior: Agents learn through interaction, causing their behavior to shift in ways that are often unanticipated. As a result, static, upfront risk assessments are no longer sufficient. Risk management needs to be ongoing and responsive to how the system evolves in real-world conditions. This broadens and shifts the scope of risk evaluation across the AI value chain, risk mitigation is not confined to the development phase but becomes equally, if not more, critical during deployment",{"type":367,"content":407},[408],{"type":318,"content":409},[410],{"text":411,"type":322},"External integration risk: Agentic systems often autonomously interface with third-party tools, APIs, and environments, meaning that their operational boundary is constantly shifting. A vulnerability in any integrated service can cascade into the agent itself, significantly expanding the attack surface and creating a hard-to-control security environment",{"type":367,"content":413},[414],{"type":318,"content":415},[416],{"text":417,"type":322},"The accountability gap: These systems operate via countless micro-decisions, making it difficult to trace why something happened, complicating compliance with transparency and auditability standards under the AI Act",{"type":331,"attrs":419,"content":420},{"level":333},[421],{"text":422,"type":322},"The AI Act Through an Agentic Lens",{"type":318,"content":424},[425],{"text":426,"type":322},"While the AI Act provides a strong foundation, applying the requirements to agentic AI asks for a reinterpretation in four key areas:",{"type":331,"attrs":428,"content":430},{"level":429},4,[431],{"text":432,"type":322,"marks":433},"1. Risk management must account for real-time evolution and be ecosystem-aware",[434],{"type":435},"bold",{"type":318,"content":437},[438,442],{"text":439,"type":322,"marks":440},"(Articles 9, 15, 26) ",[441],{"type":325},{"text":443,"type":322},"Agentic systems evolve in production. Although the AI Act mandates risk evaluation before and after deployment, most of its risk mitigation requirements remain concentrated in the development phase. Consequently, this places the primary responsibility on the provider. Users are required to notify providers of emerging risks but are only obligated to implement risk mitigations in limited circumstances, unless the evolution of the agentic AI system is deemed a substantial modification by the user. However, what constitutes such a modification remains unclear at this stage. In practice, risk management must be continuous, with real-time monitoring and mitigation embedded into system operations. Fixed performance thresholds are insufficient. These systems adapt, which means compliance must ensure consistent reliability in dynamic environments, not just initial accuracy. Similarly, robustness must account for failure modes that arise over time, requiring systems to degrade safely and recover under unexpected conditions. Security must evolve as well. As agents increasingly integrate with external tools and APIs, their operational boundaries become fluid. Effective security requires active assurance across the full ecosystem, not just the core model.",{"type":331,"attrs":445,"content":446},{"level":429},[447],{"text":448,"type":322,"marks":449},"2. Human oversight must guide behaviour, not just approve outputs",[450],{"type":435},{"type":318,"content":452},[453,457],{"text":454,"type":322,"marks":455},"(Article 14) ",[456],{"type":325},{"text":458,"type":322},"Manual approvals are too slow. Oversight must be embedded into the system via dynamic guardrails, real-time intervention points, and escalation protocols. Providers must update risk controls based on post-market performance, while deployers need to contribute operational insights. Oversight becomes a shared, continuous responsibility throughout the system’s lifecycle.",{"type":331,"attrs":460,"content":461},{"level":429},[462],{"text":463,"type":322,"marks":464},"3. Transparency must reflect system evolution and complexity",[465],{"type":435},{"type":318,"content":467},[468,472],{"text":469,"type":322,"marks":470},"(Article 13) ",[471],{"type":325},{"text":473,"type":322},"One-time disclosures fall short. Effective transparency requires ongoing, real-world insight into what the system is doing and why. Simple, user-friendly explanations are more difficult to deliver when decisions come from complex, multivariate reasoning. But meaningful interpretability is still possible, by surfacing the key factors influencing decisions, even if full logic is irreducible.",{"type":331,"attrs":475,"content":476},{"level":429},[477],{"text":478,"type":322,"marks":479},"4. Documentation must be dynamic and auditable over time",[480],{"type":435},{"type":318,"content":482},[483,487],{"text":484,"type":322,"marks":485},"(Articles 11, 12, 18 & 19) ",[486],{"type":325},{"text":488,"type":322},"Agentic AI demands living documentation: regularly updated to reflect changes in logic, behaviour, and system architecture. Logging individual outputs is not enough, organisations need structured records of how decisions were made, with versioned archives that reflect the system’s evolution. Instead of archiving everything, the emphasis should be on retaining interpretable and relevant data that supports audits and investigations.",{"type":331,"attrs":490,"content":491},{"level":355},[492],{"text":493,"type":322},"From Principle to Practice: Governing Agentic AI",{"type":318,"content":495},[496],{"text":497,"type":322},"Identifying risks is only the beginning. The real challenge lies in translating the AI Act’s high-level requirements into operational governance. That requires changes across both technical systems and organisational processes.",{"type":331,"attrs":499,"content":500},{"level":429},[501],{"text":502,"type":322},"Here are three practical priorities:",{"type":364,"content":504},[505,511,517],{"type":367,"content":506},[507],{"type":318,"content":508},[509],{"text":510,"type":322},"Shared, ongoing risk assessment: Providers must build tools for detecting emergent risks. Deployers must monitor real-world system behaviour and its effects on end users and fundamental rights. Feedback loops are essential",{"type":367,"content":512},[513],{"type":318,"content":514},[515],{"text":516,"type":322},"Dynamic transparency and real-time monitoring: Agentic AI systems require traceability infrastructure: unique system IDs, behavioral dashboards, and activity logs that show how and why decisions were made, not just what the outcome was",{"type":367,"content":518},[519],{"type":318,"content":520},[521],{"text":522,"type":322},"Adaptive oversight, both technical and human: Controls must scale with speed. That means automated safeguards (like action filters and emergency shutdowns), layered permissions, and AI-literate human operators empowered to intervene when it counts",{"type":331,"attrs":524,"content":525},{"level":333},[526],{"text":527,"type":322},"Final Thought: Same Principles, New Execution",{"type":318,"content":529},[530],{"text":531,"type":322},"The core pillars of the AI Act, risk management, transparency, oversight, remain relevant. But how we apply them must evolve.",{"type":331,"attrs":533,"content":534},{"level":429},[535],{"text":536,"type":322},"Agentic AI requires governance that is:",{"type":364,"content":538},[539,545,551],{"type":367,"content":540},[541],{"type":318,"content":542},[543],{"text":544,"type":322},"Continuous, not one-off",{"type":367,"content":546},[547],{"type":318,"content":548},[549],{"text":550,"type":322},"Interpretative, not black-and-white",{"type":367,"content":552},[553],{"type":318,"content":554},[555],{"text":556,"type":322},"Collaborative, not siloed",{"type":318,"content":558},[559],{"text":560,"type":322},"Governing agentic AI isn’t just a technical task. It’s a shared responsibility, and an opportunity to lead. By aligning legal compliance with technical agility, organisations can build AI systems that are not only intelligent, but also safe, accountable, and worthy of trust.","2025-07-24 12:41:08","News",{"id":564,"alt":306,"filename":565,"fieldtype":566},205752448726532,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F294177895581993\u002F22151\u002F1749bcc91e\u002Fai-compliance-in-motion-adapting-to-agentic-systems.png","asset",{"name":568,"created_at":569,"published_at":570,"updated_at":571,"id":572,"uuid":573,"content":574,"slug":592,"full_slug":593,"sort_by_date":594,"position":595,"tag_list":596,"is_startpage":26,"parent_id":597,"meta_data":594,"group_id":598,"first_published_at":599,"release_id":594,"lang":600,"path":594,"alternates":601,"default_full_slug":594,"translated_slugs":594,"_stopResolving":90},"Nick Prince","2026-07-31T10:04:29.271Z","2026-09-01T07:36:42.229Z","2026-09-01T07:36:42.244Z",203991733374610,"06936a74-236d-4b47-b5a8-c066c2707565",{"bio":575,"_uid":581,"name":568,"role":582,"email":583,"facts":584,"phone":585,"photo":586,"quote":589,"linkedin":590,"component":591,"quote_source":9},{"type":315,"content":576},[577],{"type":318,"content":578},[579],{"text":580,"type":322},"Nick joined Ace + Company in 2017 and has led a number of engagements, ranging from Core Banking Transformations through to strategic data programmes. With more than 20 years in the IT\u002Fconsulting industry, Nick has gained significant experience across countries (New Zealand, the United Kingdom, the Netherlands), companies (Hitachi Consulting, Dimension Data, Datacraft, Thomson NZ) and business sectors (retail, media, telecommunications, financial services, government).","44ff03da-a51f-4316-a1b0-70ea7bf4785f","Partner","nick.prince@acecompany.nl",[],"06 1142 8430",{"id":587,"alt":568,"name":9,"focus":9,"title":9,"filename":588,"copyright":9,"fieldtype":566},203988286334972,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F294177895581993\u002F768x960\u002F84938a6f6c\u002Fteam-nick-prince.webp","Ace RegTech allows me to combine my passions, regulatory change management, technology and management consulting, into a hybrid offering currently missing in the Regulatory Change space. I’m excited to be part of a young, ambitious team that truly wants to provide sustainable services to our clients.","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fnick-prince-b2754a7\u002F","team_member","nick-prince","team\u002Fnick-prince",null,-240,[],203991674748537,"d52837d9-114c-41c4-8a96-34222867e753","2026-07-31T10:04:29.331Z","default",[],"AI compliance is evolving, are your controls keeping up? Interpretation of the AI Act is often grounded in traditional GenAI use cases. But what happens when AI becomes agentic, learning, acting, and adapting…","article","https:\u002F\u002Facecompany.nl\u002Fblog\u002Fresponsible-ai\u002Fai-compliance-in-motion-adapting-to-agentic-systems\u002F","ai-compliance-in-motion-adapting-to-agentic-systems","news\u002Fai-compliance-in-motion-adapting-to-agentic-systems",-100,[],205752346605937,"160fe28d-3e77-4220-8877-50f0ff26994a","2026-08-05T09:28:52.901Z",[],1788359998,[615],{"name":568,"created_at":569,"published_at":570,"updated_at":571,"id":572,"uuid":573,"content":616,"slug":592,"full_slug":593,"sort_by_date":594,"position":595,"tag_list":624,"is_startpage":26,"parent_id":597,"meta_data":594,"group_id":598,"first_published_at":599,"release_id":594,"lang":600,"path":594,"alternates":625,"default_full_slug":594,"translated_slugs":594},{"bio":617,"_uid":581,"name":568,"role":582,"email":583,"facts":622,"phone":585,"photo":623,"quote":589,"linkedin":590,"component":591,"quote_source":9},{"type":315,"content":618},[619],{"type":318,"content":620},[621],{"text":580,"type":322},[],{"id":587,"alt":568,"name":9,"focus":9,"title":9,"filename":588,"copyright":9,"fieldtype":566},[],[],[],{"age":628,"cache-control":629,"connection":630,"content-encoding":631,"content-type":632,"date":633,"etag":634,"referrer-policy":635,"sb-be-version":636,"server":637,"transfer-encoding":638,"vary":639,"via":640,"x-amz-cf-id":641,"x-amz-cf-pop":642,"x-cache":643,"x-content-type-options":644,"x-frame-options":645,"x-permitted-cross-domain-policies":191,"x-request-id":646,"x-runtime":647,"x-xss-protection":648},"5016","max-age=0, public, s-maxage=604800, stale-if-error=3600","keep-alive","gzip","application\u002Fjson; charset=utf-8","Wed, 02 Sep 2026 14:40:28 GMT","W\u002F\"8d2679b289ead96f457ddb006f952b60\"","strict-origin-when-cross-origin","5.959.0","nginx\u002F1.29.1","chunked","Origin,Accept-Encoding","1.1 0e9d65763124ffd5921e616a7b0081ce.cloudfront.net (CloudFront)","RK5v3CBcT-osDXRnMpS-BMGNSLDwXaiaSUc1m91Lo6pcqKMZX8VgKQ==","IAD55-P6","Hit from cloudfront","nosniff","SAMEORIGIN","19149f52-f14a-4164-afe4-70656eb27963","0.408964","0",1788365044640]