Your Colleague Built an Agent
An employee builds an MS Copilot agent, then shares it with the whole company. Where the EU AI Act comes in.
An employee builds an MS Copilot agent for their own work. It drafts proposals in the company template, pulls pricing from the right SharePoint folder, and saves them an hour a day. After three weeks, they share it with the team. A month later, it’s in an all-staff email with a link.
Somewhere in that sequence, the company acquired obligations under the EU AI Act. The intuitive answer for where: at the sharing. Private use was the employee’s own business. Distribution made it the company’s.
That answer reads the regulation backwards.
The obligations attached in week one, before anyone else knew the agent existed. Sharing changed something, just not that. The gap between those two answers decides whether a company governs employee-built AI or merely finds out about it.
The Personal Use Exemption Covers Your Holiday, Not Your Job
The AI Act defines a deployer in Article 3(4):
a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity
“Personal non-professional activity” is quite narrow actually. Article 2(10) adds the word “purely”: the AI Act does not apply to deployers who are natural persons using AI in the course of a purely personal non-professional activity. Asking Copilot where to go in September: covered. Building an agent that drafts your weekly reports: professional, however few people know about it. The exemption follows the activity, not the account.
And the deployer of that professional use is the company, not the employee: the agent runs in the company’s tenant, on a company license, for company work, which is use “under its authority” on any serious reading, and Article 3(4) asks nothing about whether the company knew. (No regulator has ruled on an employee-built agent yet. This is interpretation, the mainstream one, and mine.) So the company was a deployer of that agent for three weeks without knowing it existed.
If a compliance training taught you that the company only becomes a deployer at sharing, the rule has a real source. For tools a company never provided and merely tolerates (an employee’s private ChatGPT account in a browser), there is a serious argument that the employer lacks authority over the use. Lawyers split on that case.
An agent built inside the company’s own Copilot is not that case. The company licensed the platform, enabled the feature, and controls the tenant. Article 4 makes the same assumption: before and after the omnibus softened it, the AI literacy provision is addressed to providers and deployers for the people using AI systems on their behalf. Staff using AI for work is the deployer’s use. A legal person has no other way to use anything.
What Sharing Changed
Legally, almost nothing. Practically, two things moved.
Scale. One person relying on an agent is an anecdote. A company relying on it is a dependency, with the error surface to match. If the pricing sheet it reads is stale, that’s now every proposal it touches.
Deniability. Before the email, the company’s gap was factual: no inventory, no awareness. After the email, the use is announced, organization-wide, in writing. Whatever duties exist are now duties the company visibly isn’t performing.
Which leaves the question with actual money on it. The company deploys a Copilot agent, fine. When does it become the deployer of that particular agent, and what extra obligations arrive when it does? Take a harmless one: an agent that walks employees through submitting business-trip reports, shared with the whole company.
There are two layers here. If the agent counts as nothing more than a configuration of Copilot, there is no separate deployer question: the company was deploying Copilot all along, and the agent is one way of using it. If the agent counts as its own AI system (an open question, below), the deployer analysis repeats: first use for work under company authority, so the company was the agent’s deployer while its creator was still its only user. Under neither reading is sharing the moment deployer status begins.
What sharing plausibly triggers is a different concept. The AI Act defines putting into service as supplying an AI system for first use “directly to the deployer or for own use.” An agent distributed org-wide starts to look like a system the company put into service for its own use. And whoever develops an AI system and puts it into service is its provider, the role with the heavy obligations. Follow that logic to its end and the company is the provider of this particular agent: it developed the system (through its employee) and rolled it out for its own use.
Two conditions stand between that sentence and settled law: whether the agent is an AI system in its own right at all, and whether an internal rollout happens “under its own name or trademark,” as the provider definition in Article 3(3) requires. Both are unresolved, and for the trip-report agent, comfortably little turns on them. Under the AI Act, obligations scale with risk class, not with the number of systems on your list, and provider of a minimal-risk system is a nearly empty role.
A benign agent adds almost nothing to what the Copilot rollout already required: literacy, transparency where output leaves an informed audience, prohibited-practice hygiene. What it adds is one unavoidable task: someone has to look at its purpose and classify it. Everything heavier waits on that.
One thing the email did not do: internal sharing is not “placing on the market”. Making available on the market means supply in the course of commercial activity. Colleagues are not a market. The comfort is narrower than it looks, though. Market supply is not the only route to the heavy provider obligations: for a high-risk agent, putting into service for the company’s own use is enough. What stays internal stays light only while the purpose does.
Microsoft Ships the Gate Open
The product mechanics deserve a closer look, because two default settings decide more than most written AI policies do.
A new Copilot agent is private. Microsoft’s documentation gives its creator three options: keep it private, share it with specific people or groups, or share it with anyone in the organization via link. Whether employees can use that third option is an admin setting. Its default value: all users may share org-wide.
Unless your admin changed a setting, every licensed employee can distribute an AI agent to your entire company. No approval step. That all-staff email needed no one’s permission.
Microsoft’s documentation also states that changes to the sharing controls apply only to new sharing actions: existing shared agents remain accessible. Tighten your policy next quarter and every agent shared before the change stays in circulation.
There is also an approval gate. Agents submitted to the organizational catalog go through admin review before they appear in the company’s agent store. The gate exists. The sharing link walks around it.
Two more details for whoever owns offboarding. Only an agent’s creator can delete it, though admins can reassign ownership if they know the agent exists. And nothing in the sharing flow retires an agent when its creator leaves: it keeps answering questions from a knowledge base nobody is updating.
None of this is a criticism of Microsoft, and roughly the same story applies to custom GPTs, Gemini Gems, and every other build-your-own-assistant feature: the vendor optimizes for adoption, the defaults follow. But an AI Act compliance program that audits policies and never audits tenant settings is auditing the wrong document.
Purpose Is Where It Turns
Everything so far is manageable. The modest obligations that travel with any minimal-risk agent: AI literacy under Article 4, applicable since February 2, 2025, though the omnibus softened it from ensuring literacy to supporting its development. And transparency under Article 50 from August 2, 2026, which turns on people knowing they’re dealing with AI. Inside the company, that’s obvious. It stops being obvious when the agent’s output reaches customers. Weeks away, not next year.
The structural risk is different, and it has a specific address: Article 25(1)(c).
A deployer becomes the provider of a high-risk AI system if it modifies the intended purpose of an AI system, including a general-purpose one, such that the system becomes high-risk. And when that happens, Article 25 is explicit about the consequence: the original provider stops being the provider of that system. Microsoft exits. You inherit the full Article 16 stack: risk management, technical documentation, conformity assessment, registration, the works.
One more twist. The departing provider normally owes the new one cooperation and documentation under Article 25(2), except where it clearly specified that its system is not to be turned into a high-risk one. Microsoft’s use terms restrict high-risk uses. Check your agreement before assuming the handover comes with help.
Copilot’s intended purpose is general productivity. An agent is, functionally, a purpose machine: you give it instructions, knowledge, and a job. Which means the distance between “deployer of Copilot” and “provider of a high-risk AI system” is one agent built with the wrong job description.
The recruiting team builds an agent that pre-screens CVs against role requirements. That’s employment, Annex III, point 4: high-risk. Article 25(1)(c) has no seniority threshold, no requirement that anyone approved anything.
The high-risk obligations themselves now apply from December 2, 2027, after the omnibus moved the dates. That’s runway. Use it.
Two things are not waiting for 2027.
First, the prohibitions, in force since February 2025 and carrying the top fine tier: €35 million or 7% of global turnover. The relevant one for this story is Article 5(1)(f), emotion inference in the workplace. An agent that reads sentiment in the team’s messages so a manager knows “how everyone’s doing”? An enthusiastic employee can build a prohibited practice in an afternoon, with knowledge sources and a friendly name.
Second, a detail from Article 26(7) that reframes the whole sharing question: before using a high-risk AI system at the workplace, employers must inform the affected workers and their representatives. For high-risk agents, an announcement to staff isn’t the moment the trouble starts. It’s a legal requirement.
Is an Agent Even a Separate AI System?
No one can tell you yet. The Commission’s guidelines on the AI system definition predate the no-code agent wave and don’t address it. The May 2026 draft guidelines on high-risk classification come closest, but they answer a neighboring question: multi-component and agentic setups are classified as one system when their linked parts jointly serve a high-risk purpose. Direction confirmed, purpose decides, slicing doesn't help. Who answers for a single no-code agent remains open.
There are two defensible readings.
One: a declarative agent is a saved configuration of Microsoft’s system, instructions plus knowledge plus permissions, and the AI system remains Copilot, with Microsoft as its provider.
Two: an agent with its own name, its own purpose, its own knowledge, its own tool permissions, its own user base, and an entry in a store is an AI system built on a general-purpose model, and someone other than Microsoft is answering for it. A saved prompt sits at one end. An org-wide Copilot Studio agent with autonomous triggers sits at the other. The vocabulary (”agent,” “skill,” “Gem”) is marketing. The AI Act’s question is functional.
Two reasons not to lose sleep over the metaphysics. For a benign internal agent, both readings land in nearly the same place: thin obligations either way. And in the scenario where the readings would diverge, the high-risk one, Article 25(1)(c) settles the question by making you the provider regardless.
One more fear worth retiring: building agents does not make your company a provider of a general-purpose AI model. Under the Commission’s GPAI guidelines, that role attaches to modifications that significantly change the model, with an indicative threshold of training compute above roughly a third of what trained the original. Instructions and knowledge files are not training compute. Your agents are prompting, not pre-training.
What to Actually Do About It
The duties in the AI Act share one hidden precondition: you can’t train people on agents, disclose agents, purpose-check agents, or classify agents you don’t know exist. The inventory comes first.
For the people building agents, six rules that fit on one page:
There is no personal AI at work. Work account plus work task equals the company’s deployment, even if no one knows. The exemption you’re thinking of covers your holiday planning.
Building is fine. Repurposing is the event. The moment an agent starts touching decisions about people (hiring, performance, promotion, credit, claims, access to anything), stop and ask before you share.
The short forbidden list is absolute. No agents that infer colleagues’ emotions, score people, or nudge them manipulatively. Not with approval, not as a pilot, not as a joke.
Four questions before you hit Share. What does it do? Whose data does it read? Who will rely on it? Could its output touch a decision about a person?
Label what leaves the team. People outside your context need to know they’re reading AI output.
Your agents outlive your tenure. When you change roles or leave, hand them over or kill them.
For whoever owns “the AI thing” at your company, six checks:
Open the admin center today and look at the agent sharing setting. If nobody changed it, it’s set to everyone.
Route org-wide distribution through the catalog. The approval gate is already built. Make the link route the exception.
Build the register. One row per agent: name, owner, purpose, knowledge sources, audience. This is the unglamorous document that makes every other obligation performable.
Add agents to the leaver checklist. Reassign or retire them when their creator walks out.
Put agent-building into your AI literacy training. Article 4 has applied since February 2025 (now an effort obligation after the omnibus, but applicable), and the person most in need of it is your most enthusiastic builder.
Name the escalation trigger in plain words. “An agent that helps decide about people goes to [name] before sharing.” One sentence, on the intranet, beats a policy nobody opens.
The Question the AI Act Asks
The all-staff email didn’t create the company’s obligations. It ended the period in which no one could see them.
And an email is the polite version. Most agents move through links, team channels, and word of mouth: no announcement, no list, no owner once the creator changes jobs. The population grows every quarter, mostly useful, occasionally one job description away from Annex III.
The register you haven’t built yet is a list of things you already answer for.
The AI Act doesn’t ask whether you knew.





This is exactly the piece GRC teams need before their next AI Act gap assessment. The register point is what will actually bite: you cannot classify or disclose agents you don't know exist, and that gap is the same shadow IT problem I chased for years before it had an AI Act price tag. Article 25 turning a deployer into a provider without anyone approving anything is the sharpest trap in the piece.