← All Articles Radar Editorial
Regulation Deep Dive

The EU AI Act's High-Risk Deadline Landed Before Anyone Agreed How an AI Agent Proves Who It Is

By AI SaaS Radar Team · Aug 2026 · 8 min read

On August 2, 2026, the EU AI Act's obligations for high-risk AI systems became enforceable. Conformity assessment, CE marking, registration in the EU database, and fines that scale up to 35 million euros or 7% of global annual turnover, whichever is larger. Legal analysis circulating around the deadline put the number of companies actually ready for it at roughly 22%, meaning about 78% were not.

That gap alone would be a story. But the timing of a second, much quieter development makes it a sharper one. Around March 2026, the IETF published a draft standard nicknamed AIMS, written with input from Defakto, AWS, Zscaler, and Ping Identity, proposing a reference architecture for how an AI agent proves its own identity and gets authorized to call tools and services on a company's behalf. It combines three existing frameworks, SPIFFE, WIMSE, and OAuth 2.0, into something closer to a passport system for autonomous software. It is still a draft, not a finished, ratified specification.

A compliance deadline for systems nobody can fully identify yet

The practical problem is straightforward. If your company runs an AI agent that a regulator would classify as high-risk under the Act, you are now obligated to document its behavior, register it, and prove it operates within its intended scope. But the underlying plumbing for one of the most basic questions involved, which specific agent instance took which specific action under which specific authorization, is still being worked out at the standards level. Enterprises are being asked to prove control over systems whose identity and access model the industry has not finished agreeing on.

This is not a new pattern in tech regulation. Rules regularly arrive ahead of the infrastructure needed to comply with them cleanly. What is unusual here is how tight the window is: the compliance deadline and the draft standard's publication both land within the same several-month stretch of 2026, rather than years apart.

Why agent identity is the harder problem

Traditional access control assumes a human or a static service account behind every credential. An AI agent complicates that assumption. It can be spun up dynamically, delegate to sub-agents, call third-party tools mid-task, and act with a scope that shifts depending on the prompt it received. SPIFFE and WIMSE were built to give workloads cryptographically verifiable identities; wiring that into OAuth's authorization model, specifically for agents, is what AIMS is attempting. Until something like it is finalized and adopted, the honest answer to "who did this and were they authorized" is often reconstructed from logs after the fact, not proven at the moment of the action.

What this means for companies with high-risk systems

Waiting for AIMS to become a finished RFC before building an audit trail is not a viable compliance strategy given the deadline has already passed. Companies with AI systems that plausibly fall under the Act's high-risk categories need to be able to show, today, what access each agent held, what it did with it, and how that maps to documented intent, even if the tooling for doing so cleanly is still catching up to the regulation.

The two stories are really one story. A hard legal deadline forces companies to answer questions about AI agent behavior and control that the technical community is still building the standard vocabulary to answer precisely. Expect the gap between what regulators require and what the identity infrastructure can cleanly prove to be a recurring theme through the rest of 2026, not a one-time collision.

Stay ahead of the AI SaaS market

Sourced, dated analysis on security, funding, and benchmarks. Straight to your inbox.

No spam. Unsubscribe anytime.