October 6, 2026
Posted by Shelley Leveson
The European Union’s AI Act is the world’s first comprehensive legal framework for artificial intelligence. It takes a risk-based approach, applying stricter obligations to AI systems that could significantly affect people’s safety or fundamental rights.
The regulation entered into force on August 1, 2024, with requirements phased in over time. High-risk AI requirements were originally scheduled to apply in 2026 and 2027, depending on the type of system. The recent Digital Omnibus on AI pushed those to December 2, 2027 and August 2, 2028, respectively. While that buys organizations some time, it’s recommended to start preparing now.
Much of the discussion around the AI Act has focused on governance, including documentation, risk assessments, transparency, and oversight. As AI systems become more autonomous, security teams face another set of questions.
How should an AI system obtain access to enterprise resources? How should its credentials and permissions be managed? Can its actions be traced? And when something goes wrong, can its access be revoked quickly enough to prevent further actions?
These are identity security questions. This article explains where identity security fits into the EU AI Act, from protecting credentials and brokering secure access to governing what AI agents can do at runtime.
What Is the EU AI Act?
The EU AI Act, formally Regulation (EU) 2024/1689, establishes a common framework for the development, deployment, and use of artificial intelligence across the European Union. Its goals are to encourage trustworthy AI, protect health and fundamental rights, and create a consistent regulatory environment across member states.
The Act classifies AI systems according to risk. Systems posing minimal risk face few obligations, while high-risk systems are subject to requirements covering areas such as risk management, record-keeping, human oversight, cybersecurity, and post-market monitoring.
It also distinguishes between providers, which develop or place AI systems on the market, and deployers, which use them in their operations. Many enterprises adopting commercial AI platforms will act as deployers, while organizations building or substantially modifying AI systems may also have provider responsibilities.
The full text of the official regulation is available on EUR-Lex: Regulation – EU – 2024/1689 – EN – EUR-Lex. The 2026 consolidated update is available here.
While the AI Act covers a broad range of governance and technical topics, this article focuses on the identity security and runtime access controls that help organizations operate AI systems securely and support several of the regulation’s operational requirements.
Why the AI Act Matters to Security Teams
The AI Act introduces new responsibilities for legal, compliance, engineering, platform, and security teams alike. Many of those responsibilities depend on how AI systems are secured and operated in practice.
That becomes especially important when AI systems move beyond generating answers and begin taking actions.Reading a document is one thing. Updating a customer record, approving a financial transaction, provisioning cloud infrastructure, or accessing sensitive data is another. As AI systems become more autonomous, organizations need confidence that those actions are appropriately authorized, governed, and traceable.
As AI systems become more autonomous, organizations need to:
- assign a clear identity to each agent
- protect the credentials used to access enterprise resources
- limit access to the current task
- control what actions the agent is permitted to take
- revoke authority immediately when needed
- preserve a reliable record of sensitive activity
These requirements intersect with the AI Act’s provisions for risk management, record-keeping, human oversight, cybersecurity, and deployer responsibilities. They also expose weaknesses in traditional identity models. Shared service accounts, long-lived API keys, and static permissions make it harder to attribute actions, constrain authority, and interrupt autonomous activity.
Identity security helps turn governance requirements into operational controls by establishing trusted identities, brokering secure access, enforcing policy, and recording activity.
Mapping Identity Security to the EU AI Act
Securing AI agents requires control over how they gain access to enterprise resources and how they use that access once a session begins.
The Akeyless Identity Security Platform secures both how AI agents gain access and how they exercise that access. The Akeyless Gateway authenticates the agent and establishes a short-lived, policy-controlled connection to the target system without giving the agent direct connectivity or exposing the underlying credential. Runtime Authority builds on that foundation with continuous evaluation and action-level enforcement, helping organizations control agent behavior, preserve human oversight, and maintain detailed audit records.
The following table highlights the AI Act provisions most relevant to identity security and shows how Akeyless capabilities help organizations address them.
| EU AI Act provision | What the regulation requires | How Akeyless helps |
|---|---|---|
| Article 9(1) | Establish, implement, document, and maintain a risk-management system for high-risk AI systems. | Akeyless provides identity, access, and runtime controls that support the security component of an organization’s broader AI risk-management program. |
| Article 9(2)(a)–(d) | Identify, evaluate, and address risks arising from intended use, foreseeable misuse, and post-market monitoring. | Authentication records, access policies, secret-access logs, and runtime telemetry help identify access-related risks, while local policy enforcement and least-privilege controls reduce them. |
| Article 9(5)(a)–(b) | Reduce risks through system design where feasible and apply controls where risks cannot be eliminated. | Gateway-mediated access, dynamic secrets, short-lived credentials, and runtime authorization reduce credential exposure and limit what AI agents can do when risks remain. |
| Article 12(1) | Enable automatic event logging throughout the lifetime of a high-risk AI system. | For activity governed through Akeyless, authentication, access, policy decisions, runtime events, and session activity are automatically recorded and can be forwarded to SIEM platforms for centralized monitoring. |
| Article 12(2)(a)–(c) | Use logging to identify potentially risky situations and support post-market and deployer monitoring. | Authentication records, secret-access logs, runtime events, and SIEM integrations provide security evidence for monitoring, investigation, and operational review. |
| Article 14(1) | Design high-risk AI systems so natural persons can oversee them effectively while they are in use. | Runtime Authority evaluates intent, enforces runtime policy, and enables authorized personnel to monitor, approve, restrict, or stop governed agent activity. |
| Article 14(2)–(3) | Use proportionate oversight measures to reduce residual risk, considering the system’s autonomy, context, and level of risk. | Policies can vary access conditions, credential lifetimes, approval requirements, and permitted actions according to the agent, resource, and task. |
| Article 14(4)(a) | Help overseers understand relevant system behavior and remain alert to anomalies, dysfunctions, and unexpected performance. | Live session visibility, policy decisions, and prompt-to-action audit records help security teams monitor governed agent activity and investigate anomalous, unexpected, or out-of-policy behavior. |
| Article 14(4)(e) | Allow authorized personnel to intervene in or interrupt the system and bring it to a safe halt. | Runtime Authority enables security teams to deny requests, revoke authority, or terminate governed sessions when agent activity becomes unsafe or unauthorized. |
| Article 15(1) | Maintain appropriate levels of accuracy, robustness, and cybersecurity throughout the system’s lifecycle. | Gateway-mediated access, dynamic secrets, local policy enforcement, and runtime controls strengthen the cybersecurity aspects of AI system operation. |
| Article 15(5) | Protect high-risk AI systems against unauthorized attempts to exploit vulnerabilities, including through appropriate preventive, detective, and response measures. | Akeyless complements model-level defenses by reducing access-related exposure through dynamic Secrets, short-lived credentials, agent authentication, local policy enforcement, and runtime control. |
| Article 26(1)–(2) | Apply appropriate technical and organizational measures and assign oversight to people with suitable authority, competence, and support. | Akeyless turns approved access requirements into enforceable policy and gives authorized personnel visibility, approvals, and intervention controls for AI agent activity. |
| Article 26(5)–(6) | Monitor high-risk AI systems, act when risks emerge, and retain automatically generated logs under the deployer’s control. | Authentication records, secret-access logs, runtime telemetry, and SIEM forwarding support monitoring, incident response, audit retention, and operational evidence. |
| Article 73(1)–(4) | Providers of high-risk AI systems must report serious incidents to the relevant market surveillance authorities within specified timelines. | Detailed session records and prompt-to-action audit evidence can support incident investigation and provide technical evidence for reporting and follow-up. |
Related recitals: The recitals in the Act’s preamble provide context for interpreting its requirements. Those most closely connected to the provisions above include Recital 65 on lifecycle risk management; Recital 71 on logging and traceability; Recital 73 on human oversight; Recitals 74 and 76 on robustness and cybersecurity; and Recital 91 on deployer responsibilities.
Note: The EU AI Act also covers governance, documentation, data quality, transparency, testing, conformity assessment, and other obligations beyond identity security. This mapping addresses only the identity, access, runtime-control, and audit capabilities relevant to Akeyless. It is not a comprehensive compliance checklist or a claim that using Akeyless alone establishes compliance.
Identity Security Checklist for AI Act Readiness
The AI Act’s requirements continue to roll out in phases. While the implementation timelines were recently extended, organizations should not wait until the compliance deadlines to address how AI systems authenticate, access enterprise resources, and perform privileged actions. Identity discovery, architectural changes, and policy design often take longer than expected.
Establish Visibility
- Inventory AI identities and access paths: Identify the agents, applications, and automated workflows that can access enterprise systems. Document what they reach, how they authenticate, and whether they connect directly.
- Find exposed and persistent credentials: Locate API keys, passwords, tokens, certificates, and cloud credentials embedded in code, configuration files, agent frameworks, prompts, or automation pipelines.
- Assign ownership: Establish accountable owners for each production AI system and its access policies across security, platform, AI engineering, legal, and compliance teams.
Reduce Standing Access
- Move agents to gateway-mediated access: Replace direct connections and agent-held credentials with a controlled gateway that authenticates the agent, applies policy, and establishes the approved connection.
- Use short-lived credentials and sessions: Grant access only when required and limit its duration to the task.
- Apply least privilege: Restrict each agent to the specific resources and operations needed for its assigned function.
- Identify higher-risk actions: Define the commands and transactions that should be blocked, restricted, or routed for human approval.
Govern Activity and Preserve Evidence
- Enforce runtime authorization: Evaluate what an agent is attempting to do after access is granted, particularly for sensitive or consequential actions.
- Create intervention procedures: Ensure authorized personnel can deny requests, revoke access, terminate governed sessions, and respond to abnormal behavior.
- Preserve traceable records: Record the agent identity, requested resource, policy decision, session event, action taken, and any human intervention.
- Test the controls: Run scenarios involving compromised agents, excessive permissions, unexpected requests, policy violations, and emergency termination.
- Review when the system changes: Reassess controls when an agent’s purpose, tools, connected resources, model, or degree of autonomy changes.
Timing note: Organizations should begin with discovery and risk prioritization, then phase technical changes according to system criticality and the AI Act provisions that apply to their role and use case.
Support AI Act Identity Requirements with Akeyless
The EU AI Act raises the bar for how organizations govern AI identities, access, oversight, and accountability. Akeyless helps organizations implement the identity security controls needed to support AI Act readiness while reducing the risks associated with autonomous AI agents.
Schedule a demo to learn how the Akeyless Identity Security Platform helps organizations secure AI agents and meet AI Act identity security requirements.
Frequently Asked Questions
What is the EU AI Act?
The EU AI Act is a risk-based regulatory framework for artificial intelligence. It sets different requirements based on how an AI system is used and the level of risk it may pose. Higher-risk systems are subject to more extensive obligations around governance, risk management, cybersecurity, logging, transparency, and human oversight.
Who needs to comply with the EU AI Act?
The Act can apply to providers, deployers, importers, distributors, and product manufacturers involved with AI systems in the EU. It may also apply to organizations outside the EU when their AI systems are placed on the EU market or their outputs are used in the EU. Specific responsibilities depend on the organization’s role and the system’s classification.
Does the EU AI Act apply to AI agents?
The Act does not treat AI agents as a separate regulatory category. Its requirements depend on the classification and intended use of the broader AI system. When an agent is part of a covered system, its identity, access, permissions, and actions may become part of the organization’s security and governance responsibilities.
How do you secure AI agents under the EU AI Act?
Start by identifying which agents can access enterprise systems and how they authenticate. Replace embedded or persistent credentials with short-lived, policy-controlled access, apply least privilege, and route connections through a controlled gateway. For higher-risk actions, add runtime authorization, human approval, intervention controls, and detailed audit records.
Why are long-lived credentials a risk for AI agents?
Persistent API keys, passwords, certificates, and tokens can be exposed through code, configuration files, prompts, logs, or compromised agent environments. Because they may remain valid long after the original task ends, they can provide continued access if stolen. Short-lived credentials and sessions reduce both credential exposure and the duration of usable access.
What is runtime authorization?
Runtime authorization governs what an AI agent is allowed to do after access has been granted. It can evaluate intent, enforce action-level policy, require approval for sensitive operations, restrict permissions, and stop a session when behavior becomes unsafe or unauthorized.