The agentic AI law builder · AI Transparency Institute · v5.4
LexAgentica is an interactive, comparative-law drafting aid for parliaments, ministries, regulators and civil-society drafters preparing a national law on agentic artificial intelligence, meaning systems that autonomously plan, decide and act, including concluding contracts and executing transactions. Instead of a blank page, it offers a library of modular provisions transposing mechanisms that have already proven themselves in analogous fields: the international nuclear liability conventions, UNCITRAL electronic-commerce instruments, the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744), the joint CNIL-CIANum exploratory note on agentic AI and the protection of personal data (2026), the Singapore Model AI Governance Framework, the international AI red-lines statements, the EU platform-work rules on algorithmic management, value-chain due-diligence law and zero-trust security standards. Select your country to have its legal tradition deduced automatically, including mixed systems such as Japan, South Africa or Egypt, then include or exclude each provision, choose policy variants, amend the texts, and export a consolidated bill ready for national legal drafting, translation and constitutional review.
Stamp a block to include it in the Act; stamp it again to set it to not included. Open a block to read the clause, its rationale and its sources, to choose drafting variants, or to amend the text yourself.
Agentic AI systems plan, decide and execute actions (concluding contracts, initiating payments, modifying records, deploying code) without human approval of each step. The legal question is no longer what such systems say, but what they do, and who answers for it.
No jurisdiction has to date adopted rules addressed specifically to agentic AI. The European Commission has confirmed that AI agents do not constitute a separate legal category: the definitions of an AI system (Article 3(1)) and of a general-purpose AI model (Article 3(63) of Regulation (EU) 2024/1689) suffice to cover them, so that existing obligations apply by extension rather than by design. The Commission describes its own regulatory considerations on agents as preliminary.1
Three questions remain unsettled within that framework: the attribution of liability along multi-party action chains; the effectiveness of human oversight over systems designed to act without it (Article 14); and the legal status of undertakings entered into by an agent on behalf of a principal.
Data protection authorities reach a parallel conclusion. In a joint exploratory note of July 2026, the CNIL and the French Conseil de l’IA et du Numérique find that the characteristics proper to agentic systems (decisional autonomy, persistent memory, interaction with a plurality of services, the capacity to act in the user’s name) place the founding principles of Regulation (EU) 2016/679 under tension and call for adapted modalities of implementation, including reinforced transparency on agentic action and human validation of the most critical decisions.3 Guidelines on the articulation of that Regulation with the AI Act, in preparation by the European Data Protection Board and the European Commission, are expected by the end of 2026.3
The compute, models and agent platforms on which such systems depend are supplied by a small number of undertakings established in a small number of jurisdictions.2 Where national law is silent, the conditions under which autonomous systems act upon persons are fixed by contract rather than by statute.
Legislating now permits these questions to be settled in advance of large-scale deployment, in conformity with the principle of legal certainty, rather than through litigation after the event.
References
Regulation (EU) 2024/1689 (the AI Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force since 27 July 2026.2 AI agents are not a distinct category under the Act: the definitions of an AI system and of a general-purpose AI model suffice to cover them, so that the rules applicable to AI systems and to GPAI models apply to agents.1 The provisions below are those most directly engaged; they are reproduced as comparative material.
The AI Act is a regional instrument, cited here for comparison and not as a text to be transposed. Where the present model Act departs from it (notably on strict liability channelled to the operator, mandatory financial security, and the legal effect of contracts concluded by agents), the departure is deliberate: the AI Act governs the placing of systems on the market and their conditions of use, and does not determine who answers, in civil law, for what an agent does.
References
In a joint exploratory note of 20 July 2026, the CNIL (the French data protection authority) and the Conseil de l’IA et du Numérique (CIANum) examine the application of Regulation (EU) 2016/679 (GDPR) to agentic AI.1 The note holds that agentic systems remain fully subject to the GDPR, while their proper characteristics (decisional autonomy, persistent memory, connection to a plurality of services, the capacity to act in the user’s name) call for adapted modalities of implementation. Its analysis is summarised below as comparative material; the articles of the model Act that give binding form to its recommendations are indicated in each entry.
The note is exploratory and does not create obligations; it is cited here as comparative material from a supervisory authority. Where the model Act goes further, converting the recommended safeguards into statutory duties of traceability, guardian validation, memory compartmentalisation, sandbox staging and safe interruptibility, the conversion is deliberate: the note identifies the safeguards, the Act makes them enforceable.
References
Because agentic AI is covered by extension rather than by design, three questions are left open by the AI Act. Each is answered by named articles of the model Act below; the figure may be reproduced, with attribution, for teaching and conference use.
The mapping is indicative, not exhaustive: several articles bear on more than one question, and the coherence engine will flag dependencies where an answer is included without the article it relies on.
References
LexAgentica is a comparative drafting aid for parliaments, ministries and civil-society drafters who need a coherent national law on agentic AI: systems that autonomously plan, decide and act, including concluding contracts and executing transactions. It converts the option space into modular blocks so that legislating becomes a sequence of explicit, documented choices rather than a blank page.
Every block hangs on two duties from moral philosophy given legal form: the positive responsibility to act to prevent foreseeable danger (perimeter of action, guardian role modelled on the keeper of an animal, meaningful human control, ex-ante checks and ex-post monitoring) and the negative responsibility to refrain from creating risks that have not been reasonably assessed and mitigated (the prohibition of unassessed risk creation, the red lines, the protection of persons and of the habitability of the planet, including the Jevons rebound effect).
Rather than inventing rules, the blocks transpose mechanisms that have already worked in analogous fields, each cited in its sources list: liability channelling, mandatory financial security and international peer review from nuclear law (Paris and Vienna Conventions, INES, OSART); attribution of electronic-agent contracts from UNCITRAL and the Singapore Electronic Transactions Act; iterative governance and sandboxes from the Singapore Model AI Governance Framework; identification, human determination and the termination obligation from the Universal Guidelines on AI; absolute prohibitions from the international AI red-lines statements; value-chain due diligence from the CSDDD and the UN Guiding Principles; algorithmic-management guarantees at the workplace from the EU Platform Work Directive (EU) 2024/2831; zero-trust architecture from NIST SP 800-207; and, for the treatment of agentic systems under regulation already in force, the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744), whose provisions are set out in the legal-sources panel above and cited article by article in the blocks below; and, for the protection of personal data in agentic operations, the joint exploratory note of the CNIL and the Conseil de l’IA et du Numérique (July 2026), whose recommended safeguards (traceability of the decisional chain, user control of data sources, human validation of critical actions, compartmentalised and expiring memories, sandboxed deployment and a user-side kill switch) are given binding form in the privacy, memory, oversight and security articles.
Three blocks (red lines, incident reporting, agent identity) are marked as the proposed international core, because they only function if compatible across borders. Everything else is national periphery, configurable by variant and amendment, under a proportionality and innovation principle so that obligations scale with documented risk.
Delegated decisions ("set by regulation") are deliberately flagged rather than hidden: that is where the political substance lives. The coherence engine checks structural dependencies, not legal validity. The model texts are English-language drafting proposals; they are not legal advice, and any bill derived from them requires national legislative drafting, official translation and constitutional review. Configurations exported as JSON are versioned so that divergent national adaptations remain comparable.
This tool produces a comparative drafting aid inspired by cited frameworks (UNCITRAL, EU AI Act (Reg. (EU) 2024/1689, as amended by Reg. (EU) 2026/1744), CNIL-CIANum note on agentic AI and personal data (2026), Singapore Model Framework, nuclear liability conventions, IAEA mechanisms, Universal Guidelines on AI, CeSIA/IDAIS red lines, CSDDD, NIST SP 800-207). It is not legal advice; national drafting, translation and constitutional review remain necessary. Your work autosaves in this browser where permitted; use Save config for a portable file.