Governance
Waiting for regulatory certainty before designing for it is a reasonable-sounding plan that produces a scramble. Most of what is being asked for is good engineering anyway, which makes the preparation cheap.
Yaju Team · 20 July 2026
Nobody can tell you exactly what will be required of an agent deployment in three years. Anyone claiming otherwise is selling certainty rather than compliance.
What is reasonably stable is the shape. Across frameworks, the same handful of obligations keep appearing, and they are mostly things a well-run system does regardless.
Every framework we have read assumes the operator can enumerate their systems. An organisation that cannot list its agents, their owners and their purposes cannot comply with anything, because every subsequent obligation is per-system.
This sounds trivial until you try it in an organisation that has been building agents enthusiastically for a year. The inventory is the first deliverable, and the reason ownership per agent matters so much.
Not why the model produced a particular token, which is not achievable and is not what is being asked. What the agent did, what it drew on, which identity it acted as, and when.
A complete, exportable audit trail is the practical answer. It is also the thing you want regardless of regulation, because the first time an output is disputed internally you will need exactly the same record.
The recurring requirement is meaningful human oversight, with emphasis on meaningful. A person who rubber-stamps four hundred approvals a day is documented oversight and not actual oversight.
This is the argument for treating approval as a property of specific high-consequence actions rather than as blanket review. Fewer approvals that a person genuinely considers is both better practice and a stronger position to defend.
Frameworks ask for evidence that performance was monitored rather than assumed. Evals running on every execution, with criteria written down and scores retained, is that evidence.
A team that scores continuously has an answer. A team that assessed quality during a pilot and stopped has an anecdote.
Lawful basis, minimisation, retention limits, transfer safeguards, subject rights. These obligations exist today under data protection law, and the AI-specific frameworks largely assume them rather than replacing them.
Organisations already doing this properly have less new work than they expect.
Inventory your agents with a named owner each. Turn on complete audit logging and decide retention deliberately. Write evaluation criteria for your highest-volume agents. Identify which actions genuinely warrant human approval and make that boundary real rather than procedural. Document your lawful basis and your retention periods.
Every item on that list improves the system whether or not the regulation arrives in the form anyone expects. That is what makes it worth doing before the text is final rather than after.
We build the platform so these are properties of the system rather than projects for the customer: ownership and attribution per agent, policy enforced at the point of action, complete audit trails, evals on every run, and processing in the EU by default.
We are not going to tell you that using Yaju makes you compliant. Compliance is a property of how an organisation operates, and a platform can make it achievable or difficult. We are aiming for achievable.
The AI Governance pages cover enforcement, and the Trust Center covers compliance and subprocessors. Questionnaires can go to contact@capconsultor.eu.