The EU AI act is here and will force enterprises to answer a question the market has largely postponed: how much authority should an AI agent have, and how will that authority be controlled while the agent is working?
In most enterprises, that authority is assembled from permissions, credentials, policies and workflow logic spread across several systems. Each component controls part of the process. Few enterprises can see the full chain clearly enough to determine what an agent is allowed to do at a given moment, why that authority remains appropriate, or how it changed as the work progressed.
This gap is a critical risk - and closing it just became a compliance requirement.
Articles 10–15 require enterprises to govern the data used by high-risk AI systems, maintain technical documentation, record events during operation, support effective human oversight and protect systems against misuse and interference.
Written policies and enterprise intention is insufficient - enterprises must be able to reconstruct what happened, which data influenced an outcome, which controls were applied and whether those controls remained effective throughout operation.
This burden of evidence goes far beyond existing solutions - and there’s only a short window to implement the necessary capabilities.
While I am sure this is the cause of some panic - the Act is forcing enterprises to do what they needed to do anyway to effectively and safely use agentic systems: Implement an operational control layer that can govern agentic decisions in real-time, at scale and with appropriate authority and full traceability.
This level of control will then accelerate enterprise deployment of agentic capabilities as it addresses one of the biggest hurdles enterprises are grappling with today. No one wants to give agents meaningful authority unless they can constrain that authority.
But agentic AI that is fully controlled, responsible and accountable is a game changer - plus there’s the added bonus of avoiding heavy compliance fines.
At IndyKite we have built an agentic control layer for this purpose. The IndyKite Platform connects governed data access, contextual authorization, runtime policy enforcement, provenance and decision traceability across agents, tools and enterprise systems. It evaluates access and action as context changes, while creating the evidence enterprises need to demonstrate that controls remained active throughout execution.
We want to support enterprises to reach their compliance obligations so we developed an e-guide that explains what Articles 10–15 require, the technical capabilities enterprises need to implement, and how to translate regulatory obligations into an operational architecture for trusted AI - read it here.









