Skip to content
Agent Trust AI Culture Updated Aug 13 2026

The EU AI Act: Are You Prepared for What’s Next?

The EU AI Act: Are You Prepared for What’s Next?
AUTHOR | Lucas Thomas, Head of Legal

Given the plethora of LinkedIn posts on the subject, if you deploy a general purpose agent or other AI system to the EU market, you are likely aware that the majority of EU AI Act Article 50 transparency rules went into effect on 2 August 2026. At a high level, Article 50 requires providers and deployers of AI systems to: 

  • inform users when they interact with AI
  • ensure synthetic and generative media is machine-readable and detectable
  • disclose deepfakes
  • label public-interest AI text or biometric systems

I would consider these rules the low-hanging-fruit of the Act’s obligations. The more difficult task will be preparing for the compliance obligations for high-risk AI systems under Annex III of the Act, which will apply on 2 December 2027.  This additional runway is a gift, not a reprieve. Doing nothing now would be a mistake.

As legal counsel for Monte Carlo AI, the industry leading agent trust platform (don’t just take my word for it), I want to ensure that all companies placing a high-risk agent or other AI system on the market are focused on documenting data governance, testing for bias, and building infrastructure for continuous post-market monitoring. 

Companies that work now to get the infrastructure for their AI systems right will be far better positioned than those who treat a deadline extension as permission to wait. Regulators will not be sympathetic to those who had years to prepare and still cannot demonstrate compliance when enforcement arrives.

With that framing in mind, I want to walk through some of Annex III’s hardest operational requirements and explain why Monte Carlo’s agent trust platform – which also includes monitoring of the underlying data – belongs in any serious compliance architecture. 

A note upfront: this post reflects my views as a legal professional, for an agent trust company no less, and should not be treated as legal advice. 

The Crux of Your Compliance Obligations

These regulatory obligations will apply to any provider of a “high-risk” agent or other AI system deployed to the EU market. Although the Annex III currently lists 8 functional categories that would constitute high-risk AI systems (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the justice system), they are very broad and will likely lead to uncertainty when the December 2027 deadline comes around. Not only can the high-risk categories be amended and expanded over time, but even the current published guidelines are still evolving.

This means that the classification for most AI deployments will require genuine legal judgment rather than a mechanical lookup, which is why I recommend building a compliance infrastructure now, while the runway exists, rather than waiting for every interpretive question to resolve. 

Data Quality & Lineage for Bias Audits:

Article 10 of the Act requires documented data governance, including provenance, representativeness, and bias mitigation. Training, validation, and testing datasets must be relevant, sufficiently representative, and, to the extent possible, free of errors. 

This is a harder requirement than it looks. Most AI teams can describe their bias testing methodology, but far fewer can back it up with that auditable record: exactly what data trained or fed an AI system, where it came from, and whether quality or freshness issues arose. This is precisely the kind of evidence regulators will want to see — and the foundation of any credible agent trust program.


Continuous Post-Market Monitoring:

Article 72 of the Act creates arguably the biggest gap for most companies. It requires providers to operate a monitoring system that actively and systematically collects, documents, and analyzes data on the performance of their systems throughout their lifetime. In short, compliance is not a point-in-time event. 

What Article 72 actually requires is an operational early-warning system for changes in data inputs, feature distributions, and output quality that could degrade system performance and reintroduce the kinds of risks that were assessed at launch. This is the core of agent trust: an agent’s outputs are only as reliable as the data feeding it in production, and that reliability has to be verified continuously, not just at launch. Monte Carlo’s anomaly detection and drift monitoring on data pipelines, coupled with our metric monitors (latency/tokens/errors), trajectory monitors on what the agent actually did, and LLM-as-a-judge evaluations on live traffic, serve as exactly this kind of early-warning system — built to catch an agent drifting from trustworthy behavior before it causes harm.

Two recent real world examples of Monte Carlo catching post-market agent quality problems include (1) helping a global operator of a financial marketplace identify an agent that was hallucinating figures into a financial report that didn’t match what the agent’s own queries were returning, and (2) troubleshooting and fixing an agent’s response generation to ensure the agent’s output was actually coming from the correct data. 

Both are textbook agent trust failures — an agent producing confident, wrong output — caught only because the underlying data and behavior were being monitored. This type of detection and resolution is precisely what regulators will want to see as part of a post-market monitoring system, and, more importantly, catches bad outputs and wrong actions as they happen.

Incident Reporting Readiness:

Article 73 of the Act requires prompt reporting of serious incidents. Companies without instrumentation to detect anomalous behavior will struggle to meet the required reporting timelines, let alone conduct the required follow-up investigation. Monte Carlo’s observability and alerting infrastructure operationalizes the detect–triage–resolve–report workflow compliance teams need, with agent-level visibility built-in rather than bolted on.

Audit Trails:

To comply with Article 43 conformity assessment obligations, regulators are going to want evidence, not assertions. Monte Carlo’s metadata catalog and lineage graphs function as a compliance evidence layer, showing the full history of what data was used, when, by which system, and whether any quality issues were flagged before they ever reached an agent’s output.

Summary Table of The Most Weighty Annex III Requirements

Weighty requirements from the EU AI Act Annex III
Weighty requirements from the EU AI Act Annex III

So What’s My Point?

The EU AI Act does not reward companies that can describe their compliance program on paper. It rewards companies that can produce auditable, time-stamped, reliable evidence showing that they tested for bias, monitored for drift, detected incidents promptly, and took documented corrective action. That is ultimately an infrastructure problem as much as a legal one.

If your company is or will be a provider or deployer of a high-risk AI product to the EU, and you want to: be the thought leader for these emerging obligations; ensure your company is in compliance; and earn yourself a pat-on-the-back (and maybe even a promotion or pay raise, depending on what you’re into), implementing a full-lifecycle agent trust tool that connects data quality to agent quality is likely the answer. Monte Carlo is the only platform that can do it today.

If you want to speak with someone about how Monte Carlo may be able to help you, request a demo today.

See how you can trust your agents in production

Read more posts

G2 names Monte Carlo as #1 leader for the 13th consecutive quarter

X