⚡ Quick Summary
This working paper by Philipp Hacker and Matthias Holweg investigates how autonomous AI agents intersect with the EU AI Act (Regulation (EU) 2024/1689) and EU contract law. Differentiating agents from standalone models via structural complexity, agency (reasoning plus action), and heightened autonomy, the authors evaluate regulatory classification, value chain dynamics under Article 25, and contractual attribution. Rather than introducing a premature regulatory category for general-purpose AI (GPAI) agents, the paper advocates targeted reforms: establishing structured oversight protocols for high-risk autonomous agents, resolving doctrinal disconnects between Article 25(1)(c) and New Legislative Framework (NLF) product safety legislation, expanding information collaboration duties under Article 25(2) to GPAI model providers, codifying default contract attribution, enacting a statutory list of non-delegable legal transactions, and implementing machine-readable 'authority traffic light' systems to govern external agency.
🧩 What's Covered
The document systematically examines the technical taxonomy and legal implications of agentic AI systems across public safety and private law frameworks:
- Technical & Definitional Foundations: AI agents are differentiated from standalone models and traditional tools through their ReAct (Reasoning + Acting) architectures, multi-agent orchestration layers, and persistent memory. While underlying models act as stochastic reasoning engines, agents execute deterministic external tool calls (via protocols like MCP or A2A) with limited human-in-the-loop oversight.
- Classification Under the EU AI Act: The authors explain why AI agents qualify as 'AI systems' (Article 3(1)) and potentially 'GPAI systems' (Article 3(66)), but generally not 'GPAI models' (Article 3(63)). The paper evaluates the feasibility of compliance regarding transparency (Article 50), prohibited practices (Article 5), and high-risk system duties (Articles 9–15 and 26).
- Value Chain and Doctrinal Tensions: The study explores downstream reclassification under Article 25(1)(c) when generic agents are repurposed into high-risk settings. It analyzes the friction with Article 6(1) and traditional NLF manufacturer-intent doctrines (such as the Medical Devices Regulation), arguing Article 25 operates as lex specialis. It also identifies an information-access gap where deployers-turned-providers lack access to upstream model training data under Article 25(2).
- Contract Law Baseline and Gaps: Contractual analysis covers electronic contract formation (E-Commerce Directive, UNCITRAL Model Law), attribution risks, unilateral mistakes, prompt injection manipulation, and ultra vires actions.
- Six Core Policy Proposals:
- Mandatory oversight protocols and review intervals under Article 26(5)–(6).
- Clarifying that Article 25(1)(c) reclassification applies to Annex I A sectoral contexts.
- Extending Article 25(2) collaboration and information duties to GPAI model providers.
- Codifying non-discrimination and default attribution for autonomous contract conclusion.
- Establishing a statutory list of non-delegable or presumptively ultra vires transactions (e.g., core asset transfers, structural corporate actions, value caps).
- Standardizing an 'authority traffic light' regime with machine-readable attribute certificates.
💡 Why it matters?
As enterprise deployment shifts from standalone chatbots to multi-agent automated execution workflows, governance teams face severe regulatory and contractual ambiguity. This paper provides concrete doctrinal clarity on how the EU AI Act's provider-deployer value chain rules allocate compliance burdens when general-purpose models are converted into autonomous domain agents. Furthermore, its contract law proposals establish critical legal and technical mechanisms—such as verifiable machine-readable authority boundaries—to protect enterprises from financial liability, prompt injection exploitation, and unauthorized commitments.
❓ What's Missing
The authors explicitly exclude detailed treatment of data protection (GDPR), copyright law, consumer protection law, and physical robotics/cobot safety regimes. Additionally, while the paper outlines the architectural concept of an 'authority traffic light' certificate system, it does not specify technical implementation standards or protocol specifications for machine-to-machine trust verification.
👥 Best For
AI governance officers, legal counsel, regulatory compliance managers, enterprise architects deploying autonomous agentic workflows, and technology policymakers evaluating the EU AI Act and contract law harmonization.
📄 Source Details
Working Paper (Version 1, April 2026) authored by Philipp Hacker (European New School of Digital Studies, European University Viadrina) and Matthias Holweg (Saïd Business School, University of Oxford). 35 pages, comprehensive academic citations and policy recommendation summary table.
📝 Thanks to
Philipp Hacker and Matthias Holweg for developing this rigorous legal and regulatory analysis of agentic AI systems.