厘清AI代理在欧盟法律下的合规路径,助力企业规避多重监管风险。
AI Agents Under EU Law
- 构建九类部署场景的监管触发映射图,明确行动与法规关联。
- 指出高风险代理因行为漂移不可追溯,难满足欧盟法案基本要求。
- 提出十二步合规架构,强调清单化管理外部操作与数据流。
AI代理——即能自主规划、调用外部工具并执行多步骤动作链的AI系统——正大规模应用于企业客户客服、招聘、临床决策支持及关键基础设施管理等场景。欧盟《人工智能法案》(2024/1689号法规)以风险为基础框架进行规制,但该法案并非孤立存在:提供商还需同时遵守GDPR、网络安全法案、数字服务法案、数据法案、数据治理法案、行业特定立法、NIS2指令以及修订后的产品责任指令。本文首次系统性地整合了(a)2026年1月前由标准制定请求M/613推动的欧洲标准化组织CEN/CENELEC JTC 21草案统一标准;(b)2025年7月发布的GPAI实践准则;(c)2025年4月获批的M/606指令下CRA统一标准计划;以及(d)2025年11月发布的数字综合提案。我们提出一个包含九类代理部署形态的实用分类体系,将具体行为与监管触发条件对应;识别出在网络安全、人工监督、跨多方动作链透明度以及运行时行为漂移方面的代理特有合规挑战。据此提出一套十二步合规架构,并建立从代理动作到适用法律的监管触发映射。结论表明,当前无法追溯行为漂移的高风险代理系统,难以满足欧盟人工智能法案的基本要求。因此,供应商首要合规任务是全面盘点代理的外部操作、数据流、连接系统及受影响人员。
原文摘要 · Abstract (English)
AI agents - i.e. AI systems that autonomously plan, invoke external tools, and execute multi-step action chains with reduced human involvement - are being deployed at scale across enterprise functions ranging from customer service and recruitment to clinical decision support and critical infrastructure management. The EU AI Act (Regulation 2024/1689) regulates these systems through a risk-based framework, but it does not operate in isolation: providers face simultaneous obligations under the GDPR, the Cyber Resilience Act, the Digital Services Act, the Data Act, the Data Governance Act, sector-specific legislation, the NIS2 Directive, and the revised Product Liability Directive. This paper provides the first systematic regulatory mapping for AI agent providers integrating (a) draft harmonised standards under Standardisation Request M/613 to CEN/CENELEC JTC 21 as of January 2026, (b) the GPAI Code of Practice published in July 2025, (c) the CRA harmonised standards programme under Mandate M/606 accepted in April 2025, and (d) the Digital Omnibus proposals of November 2025. We present a practical taxonomy of nine agent deployment categories mapping concrete actions to regulatory triggers, identify agent-specific compliance challenges in cybersecurity, human oversight, transparency across multi-party action chains, and runtime behavioral drift. We propose a twelve-step compliance architecture and a regulatory trigger mapping connecting agent actions to applicable legislation. We conclude that high-risk agentic systems with untraceable behavioral drift cannot currently satisfy the AI Act's essential requirements, and that the provider's foundational compliance task is an exhaustive inventory of the agent's external actions, data flows, connected systems, and affected persons.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。