By Rafael Luque Ocaña

When an agent chains actions, who's responsible? Article 26(2) answers with three words

The AI Act requires assigning human oversight to people with the necessary competence, training and authority. The third is the one that gets skipped, and it's the only one that matters once the system has already acted.

A system that suggests always has a human at the end: someone reads the proposal and decides. When something goes wrong, the question of who's responsible has an obvious answer, even if an uncomfortable one.

An agent that chains actions doesn't. There were five steps, none confirmed one by one, and nobody chose the outcome. The question is still legitimate — it just no longer answers itself.

For high-risk systems — only for them, and from 2 December 2027 for those of Annex III —, the AI Act answers it in a two-line sentence.

The three words in Article 26(2), and the clause that follows them

"Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support."

The first two read well and are fulfilled with training. The third is the one that gets skipped, and it's the only one that decides whether the designation means anything.

Authority isn't knowing how the system works. It's being able to stop it.

One precision the full quote forces: the English text carries a clause the three words don't cover — "as well as the necessary support". It isn't a fourth quality of the person; it's something the deployer owes them, and it's absent from the Spanish text, which stops at «la competencia, la formación y la autoridad necesarias». The three words remain three. The support clause is what makes the third one usable.

What "authority" means, according to the Regulation itself

There's no need to interpret it: Article 14 describes what the person in charge of oversight must be able to do. Among other things, "decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output of the high-risk AI system", and "intervene in the operation of the system… or interrupt" its execution.

Disregard. Override. Reverse. Interrupt. These are the verbs of someone who can stop something already in motion, not of someone who audits it afterwards.

And that's where the practical test of whether a designation is real comes from: if the designated person can't stop the agent without asking anyone's permission, they don't have the authority the article requires. They have the responsibility, which is a different thing — and a considerably worse one.

Where the provider's role ends and the deployer's begins

It's worth separating the two, because this is the boundary that blurs most when the conversation turns to agents.

Article 14 belongs to the provider: designing the system so it can be effectively overseen, and defining the oversight measures — either built into the system, or suitable for the deployer to put into practice.

Article 26(2) is yours: assigning that oversight to specific people with competence, training and authority.

And Article 26(3) closes the division of labour: you have "freedom to organise your own resources and activities for the purpose of implementing the human oversight measures indicated by the provider".

In other words: you don't invent the measures, but the organisation is yours. You can't delegate the designation to the provider, or expect the system to come with the question of who's responsible in your company already settled.

What autonomy changes — and it's in the text

There's a word here that tends to go unnoticed and that holds up everything else. Article 14(3) says the oversight measures shall be "commensurate with the risks, level of autonomy and context of use".

The Regulation names autonomy as a factor of proportionality. It doesn't create a separate regime for agents — no such regime exists — but it does say that more autonomy calls for different oversight measures. Which is exactly what you'd expect, and it's worth knowing that it's written into the text, not inferred from it.

There's another piece in the same article that ages oddly with agents: the warning about automation bias, "the possible tendency of automatically relying or over-relying on the output". It's written for a system that provides information a person then decides on. With an agent that acts, the problem shifts: there's no longer an output to over-rely on — there's an action already taken.

The obligation, and how you comply with it

This distinction deserves to be stated without ambiguity, because content about agents crosses it constantly.

What the Regulation requires: assigning oversight to people with competence, training and authority, with measures proportionate to the risk, the level of autonomy and the context.

What it doesn't say: that agent levels exist, or categories by type of action, or authorisation thresholds, or approval matrices. None of that appears in Article 26 or Article 14.

Classifying an agent's actions by reversibility — and requiring prior approval for the ones that can't be undone — is a reasonable way to implement Article 26(2) when the system is autonomous. It's implementation, not obligation. It works because it operationalises the proportionality the article asks for, not because the article imposes it.

Confusing the two is the usual attribution mistake, in its hardest-to-spot form: here the measure is a good one, and presenting it as mandatory turns it into a false citation.

The three questions you answer beforehand

None of them needs its own article, and none of them is answered by the system.

Who is designated, by name. Not "the operations team". One person, because the article says "natural persons".

What they can stop without asking permission. If the answer is "nothing, I'd have to escalate it", the designation is nominal — and that's exactly how it will read in writing the day someone reviews it.

What it was decided the agent can do on its own, and who decided it. That's what turns a list of permissions into a defensible decision instead of a checked box.

All three can be answered in five minutes before deployment. None of them can be answered afterwards, when what's on the table is an action already carried out and a question about who authorised it.

Content in accordance with Articles 14 and 26 of Regulation (EU) 2024/1689.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.