Discussion about this post

User's avatar
State of Play's avatar

Thanks for this. The detail that turns the week-one attachment argument from a compliance nicety into a continuous operational problem is the rate: KPMG's Q2 2026 AI Pulse survey (2,145 C-suite respondents, 20 countries) found employee AI-agent adoption jumped from 23% to 56% in a single quarter. A register is a stock control being asked to track a flow that just doubled in three months, so Art 25(1)(c) provider-conversion is happening continuously across the org, not as the rare edge case the register format assumes. The leaver-checklist gap you flag is the same problem on the exit side: the population needing offboarding is growing exactly as fast as the population needing onboarding.

Mike Schlottman's avatar

This is exactly the piece GRC teams need before their next AI Act gap assessment. The register point is what will actually bite: you cannot classify or disclose agents you don't know exist, and that gap is the same shadow IT problem I chased for years before it had an AI Act price tag. Article 25 turning a deployer into a provider without anyone approving anything is the sharpest trap in the piece.

4 more comments...

No posts

Ready for more?