The obligation arrives through procurement, not parliament
There is a comfortable assumption in this category that governance is
something regulated industries buy and everyone else defers. It is
backwards, and the timing gives it away: the AI Act's high-risk
obligations land on a bank in a year or two, and your enterprise buyer's
security questionnaire landed in your inbox last week.
You are not exempt. You are upstream. When a hospital or a
wholesale bank puts an agent into production, a meaningful part of that
agent is your platform — and every question their supervisor asks them,
they will ask you, contractually, with a deadline you did not set. The
companies that can answer will win those accounts from the ones that
cannot, and no statute will have been involved.
- Three reasons that have nothing to do with law
- Blast radius — you ship faster than anyone here and your
agents touch more accounts. Spend — an autonomous agent with an
API key is an unbounded cost centre until somebody bounds it.
Trust — "what did your agent do in my account" is the question
that decides enterprise renewals.
- It is an SDK call, not a platform migration
- Three lines in the agent's own code. No runtime to adopt, no
framework to standardise on, no proxy in front of your traffic —
because you already chose your stack and it was not this.
- Observe costs you nothing and tells you everything
- The first two rungs of the ladder refuse nothing. You can run the
whole thing in observe against production for a fortnight and find out
what your agents are actually doing before you decide whether to stop
any of it.