EU AI Act Article 9: What Your IGA Needs to Ship by 2027
TL;DR: The EU AI Act is law. If your organization uses AI agents to make access decisions — provisioning, certification, role assignment, anomaly response — those agents are high-risk AI systems under Annex III. Article 9 requires risk management, human oversight, and audit documentation. Conformity is architectural, not a feature flag.
The regulation: what it actually says
The EU AI Act (Regulation 2024/1689) entered into force in August 2024. It is binding EU law with enforcement timelines already running.
The provisions that matter for identity governance are concentrated in three areas:
Annex III — high-risk classification. AI systems used in "access to and enjoyment of essential private services" and in "employment, workers management and access to self-employment" are classified as high-risk. An AI agent that decides who gets access to enterprise systems, who loses access during a certification campaign, or who gets flagged for anomalous behavior falls squarely within this classification.
Article 9 — risk management system. Providers of high-risk AI systems must establish a risk management system that identifies foreseeable risks, estimates their likelihood and severity, adopts risk mitigation measures, and documents the residual risk. This is not optional. It is a conformity requirement.
Article 12 — record-keeping. High-risk AI systems must automatically log events to a degree that enables traceability of the system's operation throughout its lifecycle. Logs must record the input data, the decision, the human oversight actions taken, and any modifications to the system.
Article 14 — human oversight. High-risk AI systems must be designed to allow effective human oversight, including the ability to understand the system's capabilities and limitations, to monitor its operation, to intervene in real time, and to decide not to use the system or to halt its operation.
What this means for your IGA stack
Here is the practical reading for identity governance teams:
Every AI agent that makes access decisions must be classified. Not informally. Formally, per Annex III criteria, with documented justification for the classification level assigned. If your IGA vendor cannot tell you the risk classification of each AI agent in their platform, they are not compliant.
Every AI agent decision must be logged with enough detail to reconstruct the reasoning. "Access granted" is not sufficient. The log must record what input the agent received, what policy it evaluated, what decision it reached, and whether a human reviewed or overrode it. Article 12 is specific about this.
Human oversight cannot be optional. Article 14 requires that humans can intervene in, override, or halt AI agent operations. A governance platform that allows fully autonomous agent action with no override mechanism does not meet the requirement.
The risk management system must be continuous. Article 9 does not ask for a one-time risk assessment. It requires ongoing identification, estimation, evaluation, and mitigation of risks. Your IGA platform must support this lifecycle natively — not as a separate GRC process disconnected from the agents themselves.
What conformity looks like in practice
Conformity assessment under the EU AI Act is not a checkbox exercise. For an IGA platform with AI agents, a conforming architecture needs these capabilities as first-class primitives:
- Risk classification engine. Every AI agent registered in the platform receives a risk classification per Annex III criteria. The classification is versioned, auditable, and re-evaluated when the agent's scope changes.
- Human oversight hooks. Every agent action above a configurable risk threshold routes through a human approval workflow before execution. Oversight is not post-hoc review. It is pre-execution intervention capability.
- Decision-level audit trail. Every agent decision records the input context, applicable policies, the decision output, confidence scores where applicable, and the human oversight disposition. These records are immutable and exportable.
- Conformity assessment documentation. The platform generates the technical documentation required by Article 11 and Annex IV: system description, risk management procedures, data governance practices, human oversight measures, accuracy and robustness metrics, and cybersecurity measures.
- Continuous risk monitoring. The risk management system evaluates agent behavior against its classification on an ongoing basis and surfaces deviations — not once at deployment, but throughout the agent's lifecycle.
These are not aspirational. They are what the regulation requires of any platform deploying high-risk AI agents in scope of Annex III.
What SidantiX ships today
SidantiX includes an EU AI Act compliance module in production today. Here is what it covers:
- Risk classification per Annex III — every AI agent in the platform is classified at registration time. Classification follows the Annex III taxonomy and is re-evaluated on scope changes. The classification record is part of the agent's governance profile.
- Human oversight hooks — configurable intervention points on agent actions. High-risk actions route through human approval before execution. Oversight decisions are recorded in the same audit chain as the agent's decision.
- Article 12 audit trails — every agent decision is logged with input context, policy evaluation trace, decision output, and oversight disposition. Logs are cryptographically chained and tamper-evident. They are exportable in formats that auditors and regulators can independently verify.
- Conformity assessment documentation — the platform generates the technical documentation required by Article 11 and Annex IV. System descriptions, risk management procedures, data governance, oversight measures, and accuracy metrics are assembled from live platform data, not manually authored documents.
- Machine Constitution integration — the immutable safety invariant layer (published as an open spec) provides the runtime-immutable control plane that Article 14 oversight requirements point toward. Safety rules cannot be disabled by configuration, misconfiguration, or compromised credentials.
We did not build these features in response to the regulation. We designed the agent governance architecture from first principles — risk classification, human oversight, decision-level auditability — and the regulation arrived at the same requirements independently.
Timeline: what happens when
The enforcement calendar:
- August 2024 — EU AI Act entered into force.
- August 2025 — Prohibitions on unacceptable-risk AI systems took effect.
- August 2026 — General-purpose AI model obligations and governance structure provisions apply.
- August 2027 — High-risk AI system obligations apply in full. This is when conformity assessment, risk management, human oversight, and documentation requirements become enforceable for AI agents making access decisions.
Conformity requires changes to how agents are registered, how decisions are logged, how oversight is implemented, and how documentation is generated. These are architectural decisions, not feature additions. Twelve months is a reasonable timeline if the architecture already supports them. If it does not, the work is substantially larger.
What to do now
Three concrete steps for identity governance teams evaluating their EU AI Act readiness:
- Inventory your AI agents. Every AI component in your IGA stack that makes or influences access decisions needs to be cataloged. Include certification bots, anomaly detection engines, provisioning agents, and any AI-assisted recommendation systems.
- Classify them. Apply the Annex III criteria. If an agent touches employment access, essential services access, or biometric data, it is likely high-risk. Document the classification and the reasoning.
- Evaluate your vendor. Four questions for your IGA vendor: Can you show me the risk classification of each AI agent in your platform? Can you show me the human oversight mechanism? Can you export the audit trail for a specific agent decision? Can you generate the Article 11 technical documentation?
About the author: SidantiX is founded by an identity governance veteran with over two decades of experience building identity governance products used by Fortune 500 enterprises and government agencies worldwide. SidantiX was built from first principles to govern humans, non-human identities, and AI agents with cryptographic proof on every access decision.