CydentiCydenti
NHI Glossary

What Is EU AI Act?

The EU AI Act is the European Union's regulation governing the development, deployment, and use of artificial intelligence systems within the EU market. Adopted in 2024, it takes a risk-based approach, classifying AI systems into categories — unacceptable risk (banned), high-risk, limited risk, and minimal risk — with obligations scaled to the potential harm each category poses. High-risk systems, such as those used in critical infrastructure, employment, or law enforcement, face requirements around risk management, data governance, transparency, human oversight, and technical robustness. Providers and deployers of AI systems must maintain documentation, conduct conformity assessments, and in many cases register their systems in an EU database. The Act applies extraterritorially to any provider placing AI systems on the EU market, regardless of where the provider is based, with obligations phasing in through 2026 and beyond.

Why It Matters

As organizations deploy AI agents that can call APIs, access databases, and take autonomous action, each of those agents typically operates through one or more non-human identities — API keys, OAuth tokens, or service accounts — that grant it real permissions in production systems. The EU AI Act's requirements for human oversight, risk management, and traceability are difficult to satisfy if you cannot answer a basic question: what can this AI agent actually access, and who granted it that access? This is not a hypothetical gap. Non-human identities already outnumber human employees 45 to 1 in many organizations, and AI agents are multiplying that ratio further, often provisioned quickly with broad, unreviewed permissions. An over-privileged AI agent that can read customer records or trigger financial transactions is both a security incident waiting to happen and a compliance failure under the Act's transparency and oversight obligations. Regulators reviewing high-risk AI deployments will expect evidence of what an AI system's underlying identities can do, not just what the model was trained to do.

How Cydenti Helps

Cydenti maps the non-human identities behind every AI agent and MCP server in your environment — the API keys, OAuth tokens, and service accounts that give agents real-world reach — and shows exactly what each one can access. That mapping turns the EU AI Act's abstract human-oversight and risk-management requirements into a concrete, auditable inventory: which agents exist, what they can touch, and where permissions exceed what the agent's task actually needs. Continuous monitoring flags over-privileged or newly provisioned agent identities before they become an incident or an audit finding. For teams building AI governance programs ahead of the Act's compliance deadlines, that visibility is the starting point worth understanding in more depth.

Explore →

Frequently Asked Questions

Does the EU AI Act apply to companies outside the EU?

Yes. The Act applies extraterritorially to any provider or deployer that places an AI system on the EU market or whose AI system's output is used within the EU, regardless of where the company is headquartered. A US or UK company selling AI-powered software to EU customers falls within scope.

How does the EU AI Act relate to AI agent security?

The Act requires human oversight, risk management, and transparency for high-risk AI systems, but says little about the underlying credentials — API keys, tokens, service accounts — that let AI agents act. Meeting those obligations in practice requires visibility into what each agent's non-human identity can actually access.

Ready to secure your future?

Discover the machine identities you didn't know you had — in 27 minutes, for free.

NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.

No commitment • No credit card • Data hosted in Europe • Response within 24h

What Is the EU AI Act? | Cydenti