Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

Should AI Agents Be Regulated and Classified in Your Industry?

The short version: yes, most industries using AI agents to make or influence decisions about people (hiring, lending, pricing, healthcare triage, legal advice) need some form of classification now, not when the law forces it. The EU AI Act already treats agents used in employment, credit and law enforcement as “high-risk” with fines up to 35 million euros or 7% of global turnover for the worst breaches. If you wait for your own government to tell you what box your AI agent belongs in, you’ll be building the paperwork after something has already gone wrong.

The question isn’t “should”, it’s “how soon”

I get asked this a lot in client calls now: do we need to worry about regulating our AI agents, or is this a problem for the big tech companies? Wrong question. The right one is: what does this specific agent do, who does it affect, and what happens the day it gets something wrong in front of a customer, a regulator, or a journalist.

I sat in on a session last year with a mid-sized recruitment agency, about 40 staff, who’d rolled out an AI screening agent to pre-filter CVs for a retail client. Nobody had classified it as anything. It wasn’t in a policy document. Nobody in compliance knew it existed. It was just “the tool Dave set up in March.” Then a rejected candidate complained that the filtering had screened out anyone with a five-year-plus employment gap, which disproportionately knocked out women who’d taken maternity leave. The agency hadn’t built the thing to discriminate. But under UK equality law, intent doesn’t matter, outcome does. They had no audit trail, no record of what the agent weighted, and no answer when asked to explain the decision. That’s the actual cost of not classifying: not a fine from a regulator who doesn’t exist yet, but a discrimination claim you can’t defend because you never wrote down what the system was doing.

What “AI agent” means legally right now

This is where most articles get sloppy. A chatbot that answers FAQs is not the same thing, legally or practically, as an agent that autonomously books appointments, approves refunds, screens applicants, or adjusts pricing without a human checking each decision. The distinction that regulators care about is autonomy plus impact:

Readers in Melbourne usually ask what this looks like for their sector, which is what the AI consultant in Melbourne page covers.

  • Low autonomy, low impact: a scheduling assistant that suggests times but a human confirms. Barely worth classifying beyond a line in your data policy.
  • High autonomy, low impact: an agent that auto-replies to support tickets with pre-approved answers. Worth a light internal record.
  • Low autonomy, high impact: a credit-scoring model that flags applications for human review. This is exactly the kind of thing the EU AI Act calls “high-risk” even with a human in the loop, because the human often just rubber-stamps the machine’s suggestion.
  • High autonomy, high impact: an agent that approves or denies loans, screens job candidates, sets insurance premiums, or triages legal cases on its own. This is where regulation already bites hardest and where getting caught unclassified is most expensive.

If your agent sits in that last category and you haven’t written down what it does, how it decides, and who’s accountable for it, you have a bigger problem than not being compliant. You have no idea what your own business is doing.

The 2026 regulatory landscape, industry by industry

Here’s the honest state of play, not the tidy summary you get from a law firm’s marketing page.

Financial services

The FCA in the UK and the SEC in the US have both said, in different words, that existing rules on model risk management already apply to AI agents used in credit decisions, fraud detection, and trading. You don’t get a pass because the decision was made by an agent instead of a spreadsheet. The EU AI Act specifically names “creditworthiness assessment” as high-risk. If you run a fintech or a lender and your agent scores applications, you need a documented risk classification, a human override process, and records you can produce on request.

HR and recruitment

Employment is one of the EU AI Act’s eight named high-risk categories, covering recruitment, promotion, and termination decisions. New York City’s Local Law 144 already requires bias audits for automated employment decision tools, published annually, with fines up to 1,500 dollars per violation per day it’s used unaudited. If your recruitment agent screens, ranks, or scores candidates, this isn’t a maybe.

Legal and professional services

No specific classification regime yet in most jurisdictions, but the professional conduct rules that already apply to solicitors giving negligent advice apply just as much when an AI agent drafts that advice. The Solicitors Regulation Authority in England and Wales has been clear that firms remain fully liable for AI output used in client work. Classification here is less about a legal category and more about internal sign-off: does a qualified person check every output before it goes to a client, yes or no.

Retail, marketing, and customer service

The lightest-touch category so far. An agent that personalises email subject lines or handles returns isn’t named as high-risk anywhere I’ve seen. But pricing agents that vary prices by customer profile are edging into scrutiny under consumer protection law in several US states, because dynamic pricing based on inferred financial vulnerability can shade into unfair commercial practice.

Manufacturing and logistics

Agents controlling physical processes, scheduling, or safety-critical decisions fall under existing health and safety frameworks, not new AI-specific ones, in most places. But insurers are starting to ask specifically about AI agent use when underwriting liability cover, and a bad answer on that questionnaire can raise your premium or void a claim.

A working classification method you can use

Forget waiting for a perfect legal definition. Here’s the process I take clients through, and it takes a half day, not a quarter.

  • Step 1: list every agent. Not the ones in your official AI policy, the ones running. Ask every department head what automated tool makes decisions without full human review. You will find more than you expect. The recruitment agency I mentioned found six agents nobody outside IT knew existed.
  • Step 2: map decision impact. For each one, ask: what’s the worst outcome if this gets it wrong for one person? A wrong product recommendation is annoying. A wrong loan rejection or a wrong candidate rejection is a legal exposure.
  • Step 3: assign a tier. Use four tiers: informational (no decision made), assistive (suggests, human decides), autonomous-low-stakes (decides, low harm potential), autonomous-high-stakes (decides, meaningful harm potential). Write the tier next to each agent’s name in one document.
  • Step 4: match tier to control. Informational agents need a data-use note. Assistive agents need a documented human override step. Autonomous-low-stakes needs monthly output sampling. Autonomous-high-stakes needs a named accountable owner, a bias or error audit at launch and then quarterly, and a human appeal route for anyone affected.
  • Step 5: date-stamp it. Regulators and courts care less about whether you were perfect and more about whether you were paying attention on the day something went wrong. A dated classification document from before the incident is worth more than a perfect policy written after.

That’s it. No consultant needed to run those five steps once, though I’d say the uncomfortable part isn’t the process, it’s steps one and two, because most businesses don’t want to know how many high-stakes decisions they’ve quietly handed to a system nobody fully understands.

The uncomfortable truth about why businesses classify at all

Here’s the bit nobody likes saying out loud. Most companies that do this well aren’t doing it because they care deeply about fairness or transparency for its own sake. They’re doing it because an unclassified, undocumented AI agent is a liability with no paper trail, and a documented one is a liability you can defend in court or in front of a regulator. Ethics and self-protection point in the same direction here, which is convenient, but let’s not pretend the motivation is always noble. I’ve sat with directors who wanted the classification document purely so that if something went wrong, they could point to the date they flagged the risk and say “we knew, we managed it, here’s the record.” That’s not cynicism, that’s just how insurance and liability work, and it’s a perfectly good reason to do the work even if you don’t care one bit about the philosophy of it.

The flip side of that truth: some businesses classify everything as “low risk” purely because a higher tier means more paperwork and slower deployment. I’ve seen this specifically with marketing automation agents that make targeting decisions based on inferred financial or health status, quietly labelled “assistive” when they’re clearly autonomous. That’s not a classification exercise, that’s a cover story, and it falls apart the moment a regulator or a journalist asks to see the underlying logic.

What happens if you skip this entirely

Three real consequences, not hypothetical ones:

  • Under the EU AI Act, high-risk systems placed on the market without the required conformity assessment can attract fines up to 15 million euros or 3% of global annual turnover, whichever is higher, and up to 35 million euros or 7% for the most serious prohibited-practice breaches.
  • Under New York’s Local Law 144, using an unaudited automated employment decision tool costs 500 dollars for a first violation and up to 1,500 dollars per day after, per tool, per unaudited use.
  • Insurance exposure: several UK commercial insurers now ask directly, on renewal, whether AI systems are used in decision-making, and an inaccurate answer can void a claim entirely if something goes wrong later.

None of these are theoretical for much longer. The EU AI Act’s high-risk provisions phase in through 2026 and 2027. The patchwork of US state laws, Colorado’s AI Act among them, keeps growing. The UK’s approach is still principles-based rather than a single law, but the regulators enforcing existing rules (the ICO on data, the FCA on finance, the EHRC on discrimination) are already applying them to AI agents without waiting for new legislation.

When to bring someone in rather than do this alone

If you’ve got one or two low-stakes agents, do the five-step process yourself this week. It takes an afternoon. Where it gets harder is when you’ve got agents touching credit, employment, health-adjacent decisions, or anything cross-border, because the classification rules differ by jurisdiction and by sector, and getting it wrong on paper is worse than not having paper at all. That’s the point where I’d bring in outside help rather than guess, and if you want a sense of what that looks like practically and what it costs, I’ve written a full breakdown on how much an AI consultant costs so you can weigh it against the fines above before deciding.

What I’d do this month

  • List every AI agent running in your business, including ones IT set up quietly.
  • Tier each one using the four-category method above.
  • Write the accountable owner’s name next to every high-stakes agent, not “the AI team”, an actual person.
  • Set a quarterly date to re-check the list, because new agents get switched on faster than policies get updated.
  • Keep the dated document even if nobody asks for it, because the day someone does, you want it to already exist.

Frequently asked questions

Do small businesses need to classify AI agents, or is this only for large companies?

Size doesn’t exempt you from most of these rules. The EU AI Act’s high-risk obligations apply based on what the system does, not how many staff you have. A five-person recruitment firm using an AI screening tool falls under the same employment classification as a 5,000-person one. What changes with size is the depth of the paperwork, not whether you need any.

What’s the difference between an AI agent and a chatbot for regulatory purposes?

The line regulators draw is autonomy and consequence. A chatbot answering questions with human review afterward is low risk. An agent that independently approves, denies, ranks, or prices something without a human checking each case is treated as making the decision itself, and that’s what pulls it into high-risk categories under laws like the EU AI Act.

What happens if my industry has no specific AI regulation yet?

Existing law still applies to the outcome, even without an AI-specific rule. If your AI agent discriminates in hiring, that’s still a discrimination claim under existing equality law. If it misprices a financial product, that’s still a consumer protection issue. The absence of an “AI law” for your sector doesn’t mean the absence of liability.

How often should we review our AI agent classifications?

Quarterly at minimum, and immediately whenever you add or change an agent’s function. Most businesses that get caught out haven’t ignored classification entirely, they classified once at launch and never revisited it after the agent’s role quietly expanded.

Primary sources

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.