Trend 1 — enforcement moves to runtime

In 2024–2025, "AI governance" meant documents and review boards. In 2026, the pressure is on the runtime: a control that fires on every agent run, not a policy someone signed. The EU AI Act's logging (Art. 12) and oversight (Art. 14) duties are only satisfiable at runtime, which is why policy-as-code is moving from nice-to-have to baseline.

Trend 2 — evidence is the default, not the audit

Teams are shifting from "we have a policy" to "we can export the log that proves the policy held." Conformity assessments now expect artifacts: the rule, the decision, the timestamp. A rules file plus its logs is becoming the unit of compliance evidence — which is exactly what an enforced policy produces and a PDF never will.

Trend 3 — obligations land on the deployer

As the EU AI Act matures (with high-risk obligations currently tracking toward 2 December 2027 under the Digital Omnibus), the duties increasingly sit with whoever deploys the system, not the model provider. That makes deployers the ones who need enforceable policy and the evidence to show it — and the ones who cannot outsource conformity to a vendor.

What this means for your stack

If your agent can take a high-risk action, assume a reviewer and a runtime control are both required. Encode the policy, gate the high-risk actions, log everything, and keep the obligation map current. Treat the rules file as a living artifact, re-extracted on every release.

Authoritative references

  • EU AI Act (Reg. 2024/1689): https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  • AI Act explorer: https://artificialintelligenceact.eu/
  • European Commission AI policy: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai