A payment service provider’s AI system flags a transaction as potentially linked to money laundering at 2 a.m., freezes the account, and moves on. Three days later, the client turns out to be legitimate, and the freeze causes them to miss a contractual deadline. Who answers for that: the institution, the vendor, the analyst who set the confidence threshold, or the agent itself?

This scenario illustrates the type of accountability challenge that CyberAId is addressing: agentic AI orchestrating detection, investigation, and response with a degree of autonomy that no traditional SIEM rule engine ever had. It is also precisely the kind of condition that the human oversight principles in Article 14 of the EU AI Act are designed to address, particularly where the system qualifies as high-risk.

The deadline moved. The question did not.

Until recently, 2 August 2026 was the date compliance teams were building toward  when the AI Act’s high-risk obligations, including human oversight under Article 14, were due to apply. Following the Digital Omnibus on AI, approved by the Council on 29 June 2026, those obligations have been postponed to 2 December 2027 for stand-alone high-risk systems under Annex III and to 2 August 2028 for high-risk systems embedded in regulated products.

The postponement does not affect all AI Act obligations. The transparency requirements under Article 50 remain applicable from 2 August 2026.

That is not a pause on the accountability question. DORA has been fully applicable since January 2025, with its own incident-classification duties and strict reporting deadlines  obligations the Omnibus did not touch. For major ICT-related incidents, the initial notification must be submitted within four hours of classification as major and no later than 24 hours after the institution became aware of the incident. An institution running an agentic detection layer still has to decide, today, who signs off on an automated account freeze. The regulatory clock that matters here was never the AI Act’s alone.

Why agents complicate oversight

Article 14 asks for oversight commensurate with the risks, level of autonomy, and context of use of a system. That is a manageable requirement when one model produces one output for one human to review. It is harder when a case is the aggregated result of several specialised agents one scoring transaction risk, one checking sanctions exposure, and one recommending containment  coordinated by a router that resolves conflicts between their findings.

Meaningful oversight then requires explaining not just the final recommendation, but which agent contributed what, and why. Without that, the “black box” problem stops being a technical inconvenience and becomes a compliance gap.

Bounded autonomy, not binary autonomy

The practical answer taking shape across serious agentic deployments  and highly relevant to CyberAId’s architecture  is a tiered model:

  • Reversible, low-consequence actions run autonomously.
  • Cases below a confidence threshold, or touching a client relationship or a large sum, escalate automatically.
  • High-severity or hard-to-reverse actions  freezing an account or declaring a major incident  require explicit human sign-off first.

This does not remove accountability from the institution. It relocates the design question from “should a human be in the loop?” to “at what threshold does the loop close automatically, and on what evidence?”. That threshold is itself a governance decision. It needs to be documented and justified, not left as a default buried in a confidence-score parameter that nobody formally approved.

The deeper point

Faster detection and broader coverage are real gains from agentic AI in financial cybersecurity. But alongside the engineering, a project like CyberAId has to keep answering an institutional question: as autonomy increases, does accountability remain legible?

The answer is not that AI should never act alone. It is that every point where it does should be one the institution can identify, defend, and change before a regulator or a claimant asks why.

References

  1. Council of the European Union, Digital Omnibus on AI, final approval of 29 June 2026.
  2. Regulation (EU) 2024/1689 — Artificial Intelligence Act, Article 14.
  3. Regulation (EU) 2022/2554 — Digital Operational Resilience Act (DORA), applicable since 17 January 2025.