LexAgentica

The agentic AI law builder · AI Transparency Institute · v5.4

deduced from country

Build your national Agentic AI Act

LexAgentica is an interactive, comparative-law drafting aid for parliaments, ministries, regulators and civil-society drafters preparing a national law on agentic artificial intelligence, meaning systems that autonomously plan, decide and act, including concluding contracts and executing transactions. Instead of a blank page, it offers a library of modular provisions transposing mechanisms that have already proven themselves in analogous fields: the international nuclear liability conventions, UNCITRAL electronic-commerce instruments, the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744), the joint CNIL-CIANum exploratory note on agentic AI and the protection of personal data (2026), the Singapore Model AI Governance Framework, the international AI red-lines statements, the EU platform-work rules on algorithmic management, value-chain due-diligence law and zero-trust security standards. Select your country to have its legal tradition deduced automatically, including mixed systems such as Japan, South Africa or Egypt, then include or exclude each provision, choose policy variants, amend the texts, and export a consolidated bill ready for national legal drafting, translation and constitutional review.

Stamp a block to include it in the Act; stamp it again to set it to not included. Open a block to read the clause, its rationale and its sources, to choose drafting variants, or to amend the text yourself.

Articles included 0/0 Red-line provisions 0 Open delegated decisions 0
Why legislate now

Agentic AI systems plan, decide and execute actions (concluding contracts, initiating payments, modifying records, deploying code) without human approval of each step. The legal question is no longer what such systems say, but what they do, and who answers for it.

No jurisdiction has to date adopted rules addressed specifically to agentic AI. The European Commission has confirmed that AI agents do not constitute a separate legal category: the definitions of an AI system (Article 3(1)) and of a general-purpose AI model (Article 3(63) of Regulation (EU) 2024/1689) suffice to cover them, so that existing obligations apply by extension rather than by design. The Commission describes its own regulatory considerations on agents as preliminary.1

Three questions remain unsettled within that framework: the attribution of liability along multi-party action chains; the effectiveness of human oversight over systems designed to act without it (Article 14); and the legal status of undertakings entered into by an agent on behalf of a principal.

Data protection authorities reach a parallel conclusion. In a joint exploratory note of July 2026, the CNIL and the French Conseil de l’IA et du Numérique find that the characteristics proper to agentic systems (decisional autonomy, persistent memory, interaction with a plurality of services, the capacity to act in the user’s name) place the founding principles of Regulation (EU) 2016/679 under tension and call for adapted modalities of implementation, including reinforced transparency on agentic action and human validation of the most critical decisions.3 Guidelines on the articulation of that Regulation with the AI Act, in preparation by the European Data Protection Board and the European Commission, are expected by the end of 2026.3

The compute, models and agent platforms on which such systems depend are supplied by a small number of undertakings established in a small number of jurisdictions.2 Where national law is silent, the conditions under which autonomous systems act upon persons are fixed by contract rather than by statute.

Legislating now permits these questions to be settled in advance of large-scale deployment, in conformity with the principle of legal certainty, rather than through litigation after the event.

References

  1. European Commission, AI Act Service Desk, Frequently Asked Questions, “How are AI agents addressed within the AI Act?” (2026).
  2. Michael Cembalest, J.P. Morgan Asset & Wealth Management, Eye on the Market, Outlook 2026 (January 2026); International Energy Agency, data-centre electricity demand analyses.
  3. CNIL and Conseil de l’IA et du Numérique (CIANum), IA agentique et protection des données personnelles : équation à inconnues multiples pour les utilisateurs, exploratory note, 20 July 2026, cnil.fr/fr/ia-agentique-cnil-cianum-note; European Commission, “Supporting the implementation of the AI Act with clear guidelines” (December 2025).
Legal sources: EU AI Act provisions applicable to agentic AI

Regulation (EU) 2024/1689 (the AI Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force since 27 July 2026.2 AI agents are not a distinct category under the Act: the definitions of an AI system and of a general-purpose AI model suffice to cover them, so that the rules applicable to AI systems and to GPAI models apply to agents.1 The provisions below are those most directly engaged; they are reproduced as comparative material.

Qualification
Art. 3(1): AI system: autonomy, adaptiveness after deployment, influence on physical or virtual environments · Art. 3(63): general-purpose AI model · Art. 3(23): substantial modification, relevant to behavioural drift after deployment · Recital 97: the interface as a system component · Art. 2(1)(c): providers established in third countries whose output is used in the Union · Art. 2(3): exclusion of military, defence and national-security purposes.
Prohibited practices
Art. 5(1)(a): materially distorting behaviour through subliminal, manipulative or deceptive techniques · Art. 5(1)(b): exploitation of vulnerabilities. The Commission indicates that compliance may require safeguards in the design and development of agents in order to avoid prohibited practices reasonably likely to cause significant harm.1
Transparency
Art. 50(1): natural persons must be informed that they are interacting with an AI system · Art. 50(2): machine-readable marking of synthetic content · Art. 50(4): disclosure of deep fakes. Applicable from 2 August 2026.
Requirements for high-risk systems
Annex III (classification) together with Arts. 8-15, in particular Art. 9 (risk management), Art. 10 (data governance), Art. 12 (automatic recording of events), Art. 13 (transparency and instructions for use), Art. 14 (human oversight, including the capacity to intervene, interrupt and stop) and Art. 15 (accuracy, robustness and cybersecurity, including resilience to data poisoning and adversarial examples) · Art. 16 (obligations of providers) · Art. 17 (quality management system) · Art. 26 (obligations of deployers; oversight entrusted to natural persons having the necessary competence, training and authority).
Value chain
Art. 25: responsibilities along the AI value chain, including the conditions under which a downstream actor becomes a provider · Art. 25(4): supply of information by third-party suppliers, supported by the Commission’s model contractual terms.
General-purpose AI models
Art. 53: technical documentation, information to downstream providers, copyright policy and training-data summary · Art. 51(1)(b) together with Annex XIII, point (e): the level of autonomy and the tool use of a model may be decisive in its designation as a model presenting systemic risk1 · Art. 51(2): presumption at 1025 floating-point operations · Art. 52: notification · Art. 55: evaluation, mitigation of systemic risk, incident reporting and cybersecurity.
Supervision, remedies and penalties
Art. 64 (AI Office) · Arts. 70 and 74 (national competent authorities; market surveillance) · Art. 71 (EU database) · Arts. 72-73 (post-market monitoring; reporting of serious incidents) · Art. 85 (right to lodge a complaint with a market surveillance authority) · Art. 86 (right to an explanation of individual decision-making) · Arts. 99-101 (penalties).
Measures in support of innovation
Arts. 57-58 (regulatory sandboxes, at least one per Member State) · Art. 60 (testing in real-world conditions) · Art. 62 (measures for SMEs).
Instruments of soft law
General-Purpose AI Code of Practice, Safety and Security chapter, which addresses agentic use expressly (Measure 5.1, point 7; Appendix 1.3.1, points (5) and (7); Appendix 1.3.3, points (1), (4) and (12); Appendix 3.2)1 · Code of Practice on the transparency of AI-generated content · Commission Guidelines on the definition of an AI system · Commission Guidelines on prohibited AI practices.

Dates of application, as amended

  • 2 Feb 2025: prohibited practices (Art. 5), definitions, AI literacy (Art. 4).
  • 2 Aug 2025: obligations of providers of general-purpose AI models (Arts. 53 and 55); governance.
  • 2 Aug 2026: transparency obligations (Art. 50); Commission enforcement powers in respect of GPAI models.
  • 2 Dec 2026: prohibition introduced by Regulation (EU) 2026/1744; Art. 50(2) for systems already placed on the market.
  • 2 Dec 2027: stand-alone high-risk systems (Annex III), deferred from 2 August 2026.
  • 2 Aug 2028: high-risk systems embedded in regulated products (Annex I).

The AI Act is a regional instrument, cited here for comparison and not as a text to be transposed. Where the present model Act departs from it (notably on strict liability channelled to the operator, mandatory financial security, and the legal effect of contracts concluded by agents), the departure is deliberate: the AI Act governs the placing of systems on the market and their conditions of use, and does not determine who answers, in civil law, for what an agent does.

References

  1. European Commission, AI Act Service Desk, Frequently Asked Questions, “How are AI agents addressed within the AI Act?” (2026).
  2. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, OJ L, 24 July 2026 (ELI: reg/2026/1744); Parliament 16 June 2026, Council 29 June 2026.
Legal sources: CNIL-CIANum note on agentic AI and personal data

In a joint exploratory note of 20 July 2026, the CNIL (the French data protection authority) and the Conseil de l’IA et du Numérique (CIANum) examine the application of Regulation (EU) 2016/679 (GDPR) to agentic AI.1 The note holds that agentic systems remain fully subject to the GDPR, while their proper characteristics (decisional autonomy, persistent memory, connection to a plurality of services, the capacity to act in the user’s name) call for adapted modalities of implementation. Its analysis is summarised below as comparative material; the articles of the model Act that give binding form to its recommendations are indicated in each entry.

GDPR principles under tension
Purpose limitation (Art. 5(1)(b)) and lawfulness (Art. 6): multi-task agents blur the perimeter of processing and loosen the link between new operations and the legal basis initially chosen · Minimisation (Art. 5(1)(c)): agents mobilise mail, files and browsing history, share them between agents and retain them in memory beyond demonstrated necessity · Accuracy (Art. 5(1)(d)): probabilistic outputs propagate errors between agents without alerting the user · Transparency (Art. 5(1)(a)) and storage limitation (Art. 5(1)(e)): diffuse, multiple memory instances complicate the control of what is retained and for how long. Given binding form here by: the perimeter of action · privacy and data protection in agentic operations · agent memory, personalisation and data minimisation.
Rights of the data subject
Arts. 15-22 GDPR: the circulation of data between agents, memory spaces and third-party services makes it difficult to know which agent collected an item, where it is held, whether it was transmitted onward and against whom rights are to be exercised; rectification and erasure become hard to execute completely and traceably. Given binding form here by: rights exercisable against the operator through the chain of trust · deletion that propagates to every memory space.
Automated individual decisions
Art. 22 GDPR: autonomous execution may fall within the regime of decisions based solely on automated processing; following the judgment of the Court of Justice in SCHUFA,2 human intervention excludes that qualification only where it is real, effective and exerts influence on the final decision; a purely formal validation does not suffice. Given binding form here by: human determination in the protection of persons · the guardian duty and meaningful human control.
Responsibility and security
Decentralised operation between models, agents and third-party services complicates the identification of controller and processor roles and the demonstration of accountability; the interconnection of components enlarges the attack surface, and a compromised agent carries live credentials. The note recalls that no agentic-specific liability regime exists: the proposed AI Liability Directive was withdrawn in 2025, leaving general civil-law regimes and Directive (EU) 2024/2853 on defective products. Given binding form here by: strict liability channelled to the operator · allocation across the value chain · cybersecurity of agentic AI systems.
Recommended safeguards: legal
Traceability permitting the decisional process to be reconstructed: for each task, the personal data mobilised, the agents intervening, the third-party services called, the exchanges and their chronology · user control over the data to which agents may accede, in particular sensitive data · sector-specific guidance on when agentic processing falls under Art. 22 and on the practical modalities of human supervision.
Recommended safeguards: technical
Detection and filtering of diverted or malicious uses at every model call, not only at the initial request · compartmentalised memories: one dedicated, isolated memory per agent and per processing, limited in size, with automatic expiry and cross-agent consistency checks · sandboxed deployment environments confining access to services and data · a kill switch at the user’s hand to interrupt any agentic process · classification of the possible actions on each connected service by risk level, with human validation before execution of the riskiest · independent evaluation of the data protection and security of agentic systems, with published results.
Pending guidance
Guidelines of the European Data Protection Board and the European Commission on the articulation of the GDPR with the AI Act, expected by the end of 20263 · Council of Europe draft guidelines on privacy and data protection in LLM-based systems (May 2026) · EDPB Guidelines 03/2026 on web scraping in the context of generative AI (July 2026).

The note is exploratory and does not create obligations; it is cited here as comparative material from a supervisory authority. Where the model Act goes further, converting the recommended safeguards into statutory duties of traceability, guardian validation, memory compartmentalisation, sandbox staging and safe interruptibility, the conversion is deliberate: the note identifies the safeguards, the Act makes them enforceable.

References

  1. CNIL and Conseil de l’IA et du Numérique (CIANum), IA agentique et protection des données personnelles : équation à inconnues multiples pour les utilisateurs, exploratory note, 20 July 2026, cnil.fr/fr/ia-agentique-cnil-cianum-note.
  2. CJEU, Case C-634/21 SCHUFA Holding, judgment of 7 December 2023.
  3. European Commission, “Supporting the implementation of the AI Act with clear guidelines” (December 2025).
The three open questions, and where this Act answers them

Because agentic AI is covered by extension rather than by design, three questions are left open by the AI Act. Each is answered by named articles of the model Act below; the figure may be reproduced, with attribution, for teaching and conference use.

How the AI Act treats agentic AI today REGULATION (EU) 2024/1689 · AS AMENDED BY REGULATION (EU) 2026/1744 · IN FORCE 27 JULY 2026 LEXAGENTICA COVERAGE BY EXTENSION AGENTIC AI SYSTEM plans, decides and executes actions without human approval of each step ARTICLE 3(1) AI system A machine-based system that operates with varying levels of autonomy, may exhibit adaptiveness after deployment, and infers how to generate outputs capable of influencing physical or virtual environments. ARTICLE 3(63) General-purpose AI model A model displaying significant generality, able to perform competently a wide range of distinct tasks, that may be integrated into downstream systems. EXISTING OBLIGATIONS ATTACH Art. 5 prohibited practices · Art. 50 transparency · Arts. 8-15 high-risk requirements · Art. 25 value chain · Arts. 53 and 55 general-purpose AI models AI agents are not a separate legal category: the definitions above are sufficient to cover them, so that obligations apply by extension rather than by design. The Commission describes its own regulatory considerations on agents as preliminary. WHERE THE EXTENSION GIVES WAY WHAT THE EXTENSION DOES NOT SETTLE LIABILITY Attribution along multi-party action chains Article 25 allocates roles along the value chain; it does not determine who answers, in civil law, for what an agent does. The AI Liability Directive was formally withdrawn on 6 October 2025, leaving fault-based claims to national tort law. OVERSIGHT Effectiveness of human oversight Article 14 requires that a system be capable of effective oversight by natural persons. It presumes a system that can be overseen; it does not say what oversight means for one designed to act without it, over many steps, at machine speed. COMMITMENTS Legal status of commitments entered into No provision determines whether a contract concluded by an agent binds its principal, on what authority the agent acts, or how a counterparty may verify it. The question falls to national contract and agency law. ANSWERED IN THIS ACT Strict liability channelled to the operator Allocation across the value chain Mandatory insurance and financial security Mandatory contract terms across the value chain Guardian duty and meaningful human control Perimeter of action, machine-enforced Termination obligation; oversight evasion prohibited Chain of trust and zero-trust architecture Legal effect of contracts concluded by agents Mandate, authority and verifiable agent identity Disclaimers void across the value chain Incident reporting and public agent registry Sources: European Commission, AI Act Service Desk, Frequently Asked Questions, “How are AI agents addressed within the AI Act?” (2026) · Regulation (EU) 2026/1744 of 8 July 2026, OJ L, 24 July 2026 · Withdrawal of the proposed AI Liability Directive, OJ C/2025/5423, 6 October 2025. LEXAGENTICA
Coverage of agentic AI under Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, and the corresponding provisions of the present model Act.
Liability: attribution along multi-party action chains
Article 25 AI Act allocates roles along the value chain and determines when a downstream actor becomes a provider; it does not determine who answers, in civil law, for what an agent does. The proposed AI Liability Directive was formally withdrawn on 6 October 2025,2 leaving fault-based claims to the national tort law of each Member State; Directive (EU) 2024/2853 on liability for defective products reaches software but still requires proof of defect, damage and causation. Answered here by: strict liability channelled to the operator · allocation across the value chain · mandatory insurance and financial security · mandatory contract terms across the value chain.
Oversight: effectiveness over systems designed to operate without it
Article 14 AI Act requires that a high-risk system be capable of effective oversight by natural persons, with measures commensurate with its level of autonomy. It presumes a system that can be overseen; it does not state what oversight means for one designed to act without it, over many steps, at machine speed. Answered here by: the guardian duty and meaningful human control · the machine-enforced perimeter of action · the termination obligation and the prohibition of oversight evasion (red lines) · the chain of trust and zero-trust architecture.
Commitments: legal status of undertakings entered into by an agent
No provision of the AI Act determines whether a contract concluded by an agent binds its principal, on what authority the agent acts, or how a counterparty may verify that authority. The question falls to national contract and agency law, which in most jurisdictions presupposes a human or corporate declarant. Answered here by: the legal effect of contracts concluded by agents (transposing UNCITRAL attribution rules) · mandate, authority and verifiable agent identity · disclaimers void across the value chain · incident reporting and the public agent registry.

The mapping is indicative, not exhaustive: several articles bear on more than one question, and the coherence engine will flag dependencies where an answer is included without the article it relies on.

References

  1. European Commission, AI Act Service Desk, Frequently Asked Questions, “How are AI agents addressed within the AI Act?” (2026).
  2. Withdrawal of Commission proposals, OJ C/2025/5423, 6 October 2025, concerning the proposal for a Directive on adapting non-contractual civil liability rules to artificial intelligence, COM(2022) 496, 2022/0303(COD).
Step-by-step guide: how to build your Act
  1. Select your country in the top bar. The tool deduces its legal tradition (common law, Romano-Germanic civil law, Asian legal principles, or a mixed system; Japan, for instance, combines civil law with common-law and Asian influences) and rewrites the guardian article and the optional comparative-law article in the doctrinal language your courts already know. The deduction is automatic: the tradition is shown in the top bar and beside the live text, and follows the country you select. Selecting a country also suggests the right variant of the data protection and cybersecurity articles (overlay where a general law appears to be in force, baseline where none is identified), based on international legislation trackers; the suggestion is indicative and can be overridden inside each block.
  2. Skim the gazette on the right. It always shows the complete, renumbered Act exactly as currently configured, so you can read your law at any moment.
  3. Walk through the chapters on the left, block by block. Press the stamp to switch a provision between Included and Not included. Open a block to read the full clause, the plain-language rationale explaining why it exists, and the legal sources it is drawn from.
  4. Choose your variants. Five articles offer real policy alternatives: military applications (carve-out or inclusion), the liability ceiling (capped with a public fund, or unlimited), the supervisory model (a dedicated authority, or a lean model relying on an existing regulator and international cooperation), and the privacy and cybersecurity articles (overlay on an existing general law, or a self-contained baseline if your country has none).
  5. Amend where national drafting requires. Inside any block, Amend text opens an editor; saved amendments are marked in the gazette and the export, and can be reset to the model text at any time.
  6. Watch the alerts above the gazette. Coherence errors (an article depending on one that is not included) should be resolved; advisory notes deserve a deliberate decision.
  7. Review the "Open decisions" annex at the end of the gazette: every dotted-underlined phrase delegates a real political choice to regulation. Assign each one to a ministry or committee before the bill goes further.
  8. Save and share. Save config (.json) produces a portable file of your entire configuration, so committees can exchange, compare and merge versions; Load config restores one. Your work also autosaves in this browser where permitted.
  9. Export. Download law (.txt) produces the consolidated Act with the open-decisions annex and source endnotes; Print renders the gazette alone. Then hand it to national counsel: this tool prepares a bill, it does not replace legislative drafting, translation or constitutional review.
Methodology note: how this tool was built

Purpose and audience

LexAgentica is a comparative drafting aid for parliaments, ministries and civil-society drafters who need a coherent national law on agentic AI: systems that autonomously plan, decide and act, including concluding contracts and executing transactions. It converts the option space into modular blocks so that legislating becomes a sequence of explicit, documented choices rather than a blank page.

Normative spine

Every block hangs on two duties from moral philosophy given legal form: the positive responsibility to act to prevent foreseeable danger (perimeter of action, guardian role modelled on the keeper of an animal, meaningful human control, ex-ante checks and ex-post monitoring) and the negative responsibility to refrain from creating risks that have not been reasonably assessed and mitigated (the prohibition of unassessed risk creation, the red lines, the protection of persons and of the habitability of the planet, including the Jevons rebound effect).

Comparative method

Rather than inventing rules, the blocks transpose mechanisms that have already worked in analogous fields, each cited in its sources list: liability channelling, mandatory financial security and international peer review from nuclear law (Paris and Vienna Conventions, INES, OSART); attribution of electronic-agent contracts from UNCITRAL and the Singapore Electronic Transactions Act; iterative governance and sandboxes from the Singapore Model AI Governance Framework; identification, human determination and the termination obligation from the Universal Guidelines on AI; absolute prohibitions from the international AI red-lines statements; value-chain due diligence from the CSDDD and the UN Guiding Principles; algorithmic-management guarantees at the workplace from the EU Platform Work Directive (EU) 2024/2831; zero-trust architecture from NIST SP 800-207; and, for the treatment of agentic systems under regulation already in force, the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744), whose provisions are set out in the legal-sources panel above and cited article by article in the blocks below; and, for the protection of personal data in agentic operations, the joint exploratory note of the CNIL and the Conseil de l’IA et du Numérique (July 2026), whose recommended safeguards (traceability of the decisional chain, user control of data sources, human validation of critical actions, compartmentalised and expiring memories, sandboxed deployment and a user-side kill switch) are given binding form in the privacy, memory, oversight and security articles.

Architecture: core and periphery

Three blocks (red lines, incident reporting, agent identity) are marked as the proposed international core, because they only function if compatible across borders. Everything else is national periphery, configurable by variant and amendment, under a proportionality and innovation principle so that obligations scale with documented risk.

Honesty about limits

Delegated decisions ("set by regulation") are deliberately flagged rather than hidden: that is where the political substance lives. The coherence engine checks structural dependencies, not legal validity. The model texts are English-language drafting proposals; they are not legal advice, and any bill derived from them requires national legislative drafting, official translation and constitutional review. Configurations exported as JSON are versioned so that divergent national adaptations remain comparable.

This tool produces a comparative drafting aid inspired by cited frameworks (UNCITRAL, EU AI Act (Reg. (EU) 2024/1689, as amended by Reg. (EU) 2026/1744), CNIL-CIANum note on agentic AI and personal data (2026), Singapore Model Framework, nuclear liability conventions, IAEA mechanisms, Universal Guidelines on AI, CeSIA/IDAIS red lines, CSDDD, NIST SP 800-207). It is not legal advice; national drafting, translation and constitutional review remain necessary. Your work autosaves in this browser where permitted; use Save config for a portable file.

Live consolidated text