Jump to

AI Agent (Agentic AI)

What is an AI agent?

An AI agent (or agentic AI) is an AI system that pursues a goal by planning and executing multi-step tasks with limited human intervention: calling tools and APIs, browsing, writing to systems of record, or transacting. The term names the system in operation. This entry concerns what the law makes of such a system — chiefly, who answers for what it does.

How an agentic system works

An agent is not a new species of model: it is an architecture wrapped around a foundation model — usually a large language model — plus tool and function-calling interfaces, memory, and an orchestration loop that keeps the system moving towards its objective.

  • Planning: the model breaks the objective into ordered steps and revises the plan as intermediate results arrive;
  • Tool use: connectors — increasingly standardised through interfaces such as the Model Context Protocol — let the system query databases, browse, send messages or write to systems of record;
  • Memory: short-term context and longer-term stores let the agent carry state across steps and sessions;
  • Orchestration: a control loop sequences all of the above and decides when to retry, when to stop and when to hand back to a human.

How the AI Act treats agents

The EU AI Act has no separate “agent” category: an agent is assessed like any other AI system, but autonomy raises the stakes under the existing rules. People interacting with an agent must be told they are dealing with AI under Article 50; human oversight must be designed for a system that acts rather than suggests; and an agent operating in an Annex III domain — hiring, credit, essential services — takes high-risk classification with everything that follows.

The legal pressure points

  • Attribution: under Turkish contract law, an agent’s “declarations” generally bind the company deploying it — authority limits and spend caps belong in system design and in your counterparty terms;
  • The GPAI chain: agents built on foundation models inherit the GPAI value-chain questions — who is provider of what, and whose duties travel with the model;
  • Logging: the agent’s action trail is your liability evidence; retain it as deliberately as you retain contracts.

Turkish context

Türkiye has no AI-specific statute in force, so an agent’s acts are attributed under general contract and tort rules, and KVKK (Law No. 6698) applies wherever the agent touches personal data. In practice this cuts both ways: a Turkish company cannot disown its agent’s commitments, but it can bound them — order caps, confirmation steps for defined transaction types, and terms stating what the agent may and may not conclude. Turkish teams building agentic products for EU customers should also expect the EU AI Act’s requirements to arrive through those customers’ contracts even without any EU establishment.

Do: decide before launch which acts the agent may complete alone and which need a human signature, and write that split into both the system and the contract. Don’t: treat agent output as mere content; agent features convert content risk into action risk, and the mitigations are different.

Related guides: When the AI Acts for You.

Sources. Regulation (EU) 2024/1689 (AI Act).