TL;DR
The EU AI Act's 8 high-risk categories in Annex III decide whether an agent carries the heavy obligations. Most ERP agents fall outside all 8.
Category 4, "Employment, workers' management and access to self-employment", is the one that catches ERP. It covers systems used "to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons".
That wording reaches further than an HR module. A labour-allocation agent that assigns work by individual performance is inside category 4 regardless of which product it ships in.
High-risk obligations start 2 December 2027, which is 451 days from today. General applicability arrived 2 August 2026, already past.
Penalties run to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher, for deployer and transparency breaches. The prohibited-practice tier is EUR 35,000,000 or 7%.
What actually decides whether an ERP agent is high-risk?
What it decides about a person, not what it is called or which vendor sells it.
This is the part most vendor material skips. The Act does not classify software, it classifies intended use. Annex III lists 8 areas, and an AI system is high-risk when it is intended for one of them. Six of the 8 have nothing to do with an ERP: biometrics, critical infrastructure, education, law enforcement, migration and border control, and the administration of justice.
Two do reach into enterprise systems. Category 5 covers access to essential private and public services, including creditworthiness and insurance pricing. And category 4, employment and workers' management, is the one that quietly covers a great deal of what an operations team automates.
Which agents are inside, and which are outside?
Read the category 4 wording carefully, because the second half is broader than the first.
The Act covers systems intended "for the recruitment or selection of natural persons", which is the obvious case. It then also covers systems intended "to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships".
Task allocation based on individual behaviour. That is not an HR feature description. That is a description of what a modern operations agent does.
Agent. Likely inside Annex III?. Why
Purchase order follow-up, supplier email. No. Decides about orders and suppliers, not about people
Invoice matching, reconciliation, payables. No. Financial records, no natural person evaluated
Demand forecasting, safety stock. No. Decides about inventory
Recruitment screening or candidate ranking. Yes, category 4. Named explicitly
Performance monitoring or scoring of staff. Yes, category 4. "monitor and evaluate the performance and behaviour"
Work allocation that ranks by individual performance. Probably, category 4. "allocate tasks based on individual behaviour"
Credit limit or payment terms set by an agent. Possibly, category 5. Creditworthiness of natural persons
The middle rows are the ones worth arguing about internally before a regulator does. An agent that assigns the next job to whoever is nearest is allocating by location. An agent that assigns it by who completes that job type fastest is allocating by individual behaviour, and the wording does not care that it lives inside a supply chain module rather than an HR one.
How long is there, actually?
Longer than the headlines suggest for high-risk, and no time at all for the rest.
Milestone. Date. From today, 7 September 2026
Entered into force. 1 August 2024. 767 days ago
Prohibited practices and AI literacy. 2 February 2025. 582 days ago
Governance and general-purpose AI rules. 2 August 2025. 401 days ago
General applicability, transparency rules. 2 August 2026. 36 days ago, already live
High-risk systems in Annex III areas. 2 December 2027. 451 days
High-risk embedded in regulated products. 2 August 2028. 1,059 days
451 days sounds generous. Against an ERP change cycle it is not. A vendor ships a release wave roughly every 6 months, so that window holds about 2 to 3 releases. If the answer involves a supplier's roadmap rather than your own configuration, you are asking for it in the next release conversation, not the last one.
And the transparency obligations are not in the future at all. They arrived 36 days ago.
What do the obligations actually require?
Seven things, and none of them are a document you write once. The Act requires high-risk systems to have:
"adequate risk assessment and mitigation systems"
"high-quality of the datasets feeding the system to minimise risks"
"logging of activity to ensure traceability of results"
"detailed documentation providing all information necessary"
"clear and adequate information to the deployer"
"appropriate human oversight measures"
"high level of robustness, cybersecurity and accuracy"
Three of those are things an ERP is unusually well placed to deliver. Logging for traceability is what a transaction layer already does. Human oversight is the approval step most agents already route through. Information to the deployer is documentation the vendor owes you.
The two that will hurt are dataset quality and risk assessment, because both are about your data and your process, not the vendor's product. Nobody can supply those for you.
Who carries the obligation, you or the vendor?
Both, in different roles, and the penalty article treats them separately.
Article 99 sets fines of up to EUR 15,000,000 or 3% of total worldwide annual turnover, whichever is higher, for breaches of provider obligations, deployer obligations and transparency obligations alike. The prohibited-practices tier is EUR 35,000,000 or 7%. Supplying false or misleading information to authorities carries EUR 7,500,000 or 1%. For SMEs the Act applies whichever of the percentage or the fixed amount is lower.
The phrase that matters for an ERP customer is deployer obligations. Buying a compliant product does not discharge them. If you configure an agent to allocate work by individual performance, you made that choice, and the human oversight measure has to exist in your process.
How does this land against what the vendors have shipped?
Better than you might expect, and none of it is framed this way.
The governance tooling that arrived this year maps onto the Act's requirements almost line by line. Microsoft's runtime toolkit judges each sensitive call and logs the decision, which is logging for traceability plus human oversight. SAP put its agents under an ISO 42001 control tower, which is the risk-management system in a recognised form. Workday's Agent System of Record sets roles and tracks performance, which is the closest thing to a register of deployed systems.
When we compared how 4 vendors govern agents, the striking gap was cost. Read against the Act, a second gap appears: none of the four names Annex III classification as something the tooling helps you determine. They give you controls. Deciding which of your agents needs them is still a manual reading of a legal annex against a configuration screen.
What should an operations team do in the next quarter?
Inventory your agents by what they decide, not by which module they live in. One column: does this system evaluate, rank, allocate to, or make decisions about a natural person. That single question sorts most of the estate in an afternoon.
Flag the allocation agents specifically. They are the ones where a reasonable person reads the product description and concludes "supply chain feature", and a reasonable lawyer reads Annex III and concludes "category 4".
Check what your vendor already logs. Traceability is an obligation you may largely already meet, and knowing that changes the size of the remaining job.
Put the question in the next release conversation. 451 days holds 2 or 3 vendor releases. If the gap needs a product change, that is a roadmap conversation with a deadline attached.
FAQ
Does the EU AI Act apply if we are not in the EU?
It applies based on where the system is used and who it affects, not solely where the vendor sits. A business with EU staff or EU customers should assume it is in scope and take advice.
Is a purchase order agent high-risk?
On the Annex III wording, no. It decides about orders and suppliers rather than about natural persons.
Is a work allocation agent high-risk?
If it allocates based on individual behaviour or personal characteristics, the wording of category 4 reaches it. Allocation by location or by queue order is a different case.
What are the penalties?
Up to EUR 15,000,000 or 3% of worldwide annual turnover for deployer and transparency breaches, and EUR 35,000,000 or 7% for prohibited practices, whichever is higher in each case.
When do the high-risk rules bite?
2 December 2027 for the Annex III areas, and 2 August 2028 for high-risk systems embedded in regulated products.
The last mile
The Act automates nothing. It sets a boundary and leaves the reading of it to you.
Which is the honest shape of the whole agent question. A vendor can log every action, sandbox every runtime and route every exception to a human, and none of that decides whether allocating tomorrow's work by yesterday's performance is the optimal call for this team, this week, at this service level. The system of record can prove what happened. Turning that into the right decision, defensibly, inside the system a team already runs on, is the layer Cognilium works in. Under this Act, being able to explain the decision stops being good practice and starts being an obligation.
This is reporting on published regulation, not legal advice. Classification under Annex III is fact-specific and should be taken with counsel.
Share this article
Weekly AI engineering brief
One email a week. New model releases, agent patterns, and lessons from production systems we ship.
No spam, no client data sales. Unsubscribe any time.

Ali Ahmed
AI Solutions Engineer, Cognilium AI
Ali Ahmed
AI Solutions Engineer, Cognilium AI
Ali Ahmed is an AI Solutions Engineer at Cognilium AI.
