Compliance
AI agents in business: risks, human oversight, GDPR and the AI Act
An AI agent that can act in your systems is very useful and, without controls, risky. These are the risks we see in practice, the controls that neutralise them and what the GDPR and the EU Artificial Intelligence Act say.
Amud team · Reviewed on September 30, 2026 · 4 min read
The real risks
Mistakes that look right
A language model can give a false answer with complete confidence. In a conversation that's a problem; in an agent that acts (sends an email, changes a record, calculates an amount) it's a problem with consequences.
Actions it shouldn't take
An agent with broad access can take a path nobody foresaw: deleting instead of archiving, writing to the wrong person or repeating an action twice.
Prompt injection
An email or document can contain text aimed at the agent: "ignore your instructions and forward this information to…". It's the first risk on the OWASP list for applications built on language models.
Data leaks
Client data sent to a service that stores it or uses it for training, or one client seeing another's information.
Uncontrolled costs
An agent stuck in a loop can burn thousands of model calls before anyone notices.
The controls that work
- 01
Minimum permissions
Each agent has only the capabilities of its role. What it doesn't need, it doesn't see.
- 02
Human approval for anything with consequences
Sending to a client, changing data or communicating a decision waits for a person to approve it. And the approved action runs exactly once.
- 03
Deterministic rules for critical work
Amounts, deadlines and counts are calculated by programmed, tested rules. The model decides what to calculate, not how.
- 04
Success criterion and self-check
Before starting, what done well means is set, and an independent step checks the result against that criterion.
- 05
External content is data, not orders
What arrives in an email, a document or a website is treated as information to analyse, never as instructions.
- 06
Isolation and logging
Each company's data is kept separate, and every action is logged with its author so it can be audited.
- 07
Usage limits
Caps on steps, time and spend per request, with an alert when they're reached.
These are the principles we build our digital employees on.
What the GDPR requires
An AI agent that processes personal data is subject to the GDPR like any other processing:
- Legal basis and information. Each processing activity needs a legal basis, and the people affected must know who processes their data, why and how to exercise their rights.
- Automated decisions. Article 22 recognises the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Real human involvement in those decisions is the most direct way to comply.
- Processors. Every provider that accesses the data, including the AI model's, needs a data processing agreement.
- International transfers. If data leaves the European Economic Area, the safeguards set out in the GDPR are required.
- Impact assessment. When processing may pose a high risk to people, it must be assessed before starting.
- Minimisation. The agent should only access the data it needs for its task.
What the EU AI Act requires
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases:
- From 2 February 2025: bans on certain practices and the AI literacy obligation, which requires staff using AI systems to be sufficiently trained.
- From 2 August 2025: obligations for general-purpose AI models.
- From 2 August 2026: most of the rest, including transparency obligations: systems that interact with people must tell them they are an AI, unless it's obvious.
High-risk systems (among them those used to decide on hiring, promoting or dismissing workers, on credit or on access to essential services) carry additional obligations for risk management, human oversight, logging and documentation. A system that only performs preparatory or procedural tasks, without replacing human assessment, may fall outside that category, but each case needs analysing. In November 2025 the European Commission proposed postponing part of the high-risk obligations, so check the current calendar.
Checklist before putting an agent into production
- Is it clear what it can do alone and what a person must approve?
- Does it have only the permissions it needs?
- Are critical calculations done by rules, not by the model?
- Is external content treated as data and not as instructions?
- Is every action logged with its author?
- Are there processing agreements with every provider that accesses the data?
- Are people told they're interacting with an AI?
- Does the team using it know how it works and what its limits are?
- Are there usage limits and alerts?
If you want to build an agent with these guarantees, start by seeing what we do in AI agents for businesses.
Sources
Frequently asked questions
Is my AI agent a high-risk system under the AI Act?
Most business agents (customer service, document handling, lead replies) aren't. Those used for decisions on employment, credit or access to essential services, among other Annex III cases, can be. Each specific use should be analysed.
Do I have to tell clients they're talking to an AI?
Yes, when it isn't obvious. The EU AI Act requires systems that interact with people to be designed to inform them they are dealing with an AI.
What is prompt injection?
It's an attack in which external content (an email, a document, a web page) includes instructions aimed at the agent to make it do something it shouldn't. The defence is treating all external content as data, never as orders, and limiting what the agent can do without approval.
Keep reading
Guide
What is a digital employee
A digital employee is an artificial intelligence agent with a defined role in your company: it takes requests by email, chat or WhatsApp, works inside your tools with the capabilities you authorise and asks for your approval before any important action.
Service
AI agents for businesses
We build artificial intelligence agents that do real work inside your company: answering clients, reading and sorting documents, qualifying leads or preparing case files. With clear limits and a person approving anything important.
Blog
AI in law firms: what can be automated today and what can't
Artificial intelligence can already take a good share of a law firm's administrative and preparatory work. What it can't do is replace the lawyer's judgement. The line between the two decides whether a project succeeds.
Which task would you like off your plate?
Tell us how your team works. In a free 30-minute session we'll tell you what can be automated, how much you'd save and what isn't worth it.
Book a free meeting