Sources checked: 7 September 2026
Start with the action
Write down what the agent may read, propose and execute. A mailbox connection does not automatically authorise it to send every message. Distinguish a proposal, human approval and technical execution.
Example: preparing a quotation
An agent may summarise a fictional customer request and suggest draft wording. An employee checks scope and commitments. Pricing and sending require separate approval. If the request is unclear, the draft remains open rather than inventing missing agreements.
What a reviewer needs
A reviewer needs access to the information used, the proposed action and relevant uncertainty. Allow time to review and the ability to reject. An approval button has little value if the employee cannot verify the response or the action has already happened.
Stopping and recovery
Define which errors stop the agent, who is notified and how work continues manually. Test a missing file, an unavailable supplier and an incorrect result using synthetic data. Restrict access to what is needed and retain only appropriate audit metadata; keeping every prompt by default increases the amount of sensitive information.
Review changes
More permissions or a new purpose may require another assessment. The AI Act considers the actual application and role; the word agent does not determine a risk class by itself. Processes affecting people need an appropriate expert review.
What you can use it for
An authority map with an owner, approval point, stop conditions and recovery route.
This guide provides general information. Assessment of a specific application depends on your role, data and intended use.
Sources and further reading
This article was prepared with AI assistance and checked against our editorial and sourcing guidelines.
