What does the AI Act ask of developers who build software with AI agents?
Deep dive into the AI Disclosure project
I'm Giorgio Pagano, a freelance Drupal developer: I use AI agents across my whole development workflow, and I created AI Disclosure, the Drupal AI Initiative module for declaring AI use in content. Here I answer a question I get often: what the European regulation on artificial intelligence asks of developers who work with an agent. The answers follow the text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026.
What are you under the AI Act when you write code with an AI agent?
Someone who uses an AI agent to write code at work is a deployer of that agent. Article 3, point 4, defines a deployer as anyone "using an AI system under its authority". The only exception is use in a personal non-professional activity, which Article 2, paragraph 10, keeps outside the obligations. A freelancer building software for a client is therefore a deployer of Claude Code, of Copilot, or of whichever agent they use.
The provider is a different role: under Article 3, point 3, it is whoever develops an AI system or model and places it on the market under its own name. For the agent I use, the provider is the company that distributes it.
What does the AI Act ask of you today, as a deployer of the agent?
As a deployer of a coding agent, the main obligation is AI literacy. Article 4, as rewritten by the Digital Omnibus, asks providers and deployers to take "measures to support the development of AI literacy" among their staff and anyone using the systems on their behalf, and leaves each of them to choose the right level. For a freelancer, that means knowing the tool: how it works, where it gets things wrong, what it can be trusted with.
The obligations on the model sit with the model provider. Article 53 asks providers of general-purpose AI models for technical documentation, information for those who integrate the model, and a copyright policy, and Chapter V has applied since 2 August 2025.
When does a developer become a provider?
A developer who delivers a site or an application that integrates an AI model becomes the provider of that system. Article 3, point 68, calls "downstream provider" anyone who integrates an AI model into their own system, even when the model comes from another company. That covers a chatbot on a client's site, or a Drupal module that generates text and images with an external model.
As a provider, the transparency obligations of Article 50 apply, from 2 August 2026:
| Obligation | Article | Who carries it |
|---|---|---|
| People talking to an AI system must know it | 50, paragraph 1 | provider of the system |
| Generated audio, images, video and text must be marked in a machine-readable way | 50, paragraph 2 | provider of the system |
| Deep fakes and text published to inform the public must be disclosed | 50, paragraph 4 | deployer, meaning the client who publishes |
For systems placed on the market before 2 August 2026, the marking in paragraph 2 has to be in place by 2 December 2026, as set by the Digital Omnibus. If the system is one of the high-risk uses in Annex III, recruitment for example, the obligations of Chapter III apply from 2 December 2027.
Does code written by an agent need a label?
The labels in Article 50 cover people talking to an AI system, generated audio, image, video and text content, and text published to inform the public. For code that an agent writes on a developer's behalf, the responsibility lies with whoever delivers it: the contract with the client, the rules on software security and the quality of the work.
Open source projects already have a rule for this. The drupal.org policy on the use of AI says each person is responsible for the code they post, asks contributors to verify the dependencies, logic and security of generated code, and to disclose AI use even when the output was reviewed, in the issue or merge request template section designed for it.
How do I declare and govern AI use in my projects?
In my projects every use of AI comes with a declaration or a check, and each practice rests on a specific reference:
| Practice | How I apply it | Reference |
|---|---|---|
| AI label on published content | Every article and every translation carries the level of AI involvement, visible to readers and readable by machines, with AI Disclosure | Article 50, paragraph 4 |
| Disclosure in issues and merge requests | Every AI Disclosure issue and merge request on git.drupalcode.org ends with an "AI Compliance" section | drupal.org policy on the use of AI |
| Code review | I read every change line by line and do a security review before merging | drupal.org policy, responsibility of whoever delivers |
| End-to-end tests | On top of the automated tests, I walk through every step by hand on a test site | good development practice |
| Knowing the tool | I know the limits of the agents I use and choose what to hand to each of them | Article 4 |
On my articles the label is a transparency choice: Article 50, paragraph 4, exempts text that went through human review with a person holding editorial responsibility, and I add the declaration anyway. How the label works is in how I apply Article 50(4) to a Drupal site, and the rest of the method in how I work with AI in development. AI is one more tool: the specification, the decisions and the responsibility for the work stay mine.
For a concrete case, with a contract or a high-risk system, the right reading comes from a lawyer who knows the AI Act. If the project involves Drupal, tell me what it is about.
Sources
All sources were checked on 11 October 2026.
- Regulation (EU) 2024/1689, EUR-Lex: Articles 2 (paragraph 10), 3 (points 3, 4 and 68), 50, 53 and 113. Primary source.
- Regulation (EU) 2026/1744, Digital Omnibus on AI, EUR-Lex, OJ L of 24 July 2026: new Article 4, 2 December 2026 deadline for Article 50(2), new dates for Chapter III. Primary source.
- Policy on the use of AI when contributing to Drupal, drupal.org, updated 11 October 2026. Primary source.
- The "AI Compliance" section of AI Disclosure issues, for example #106 on git.drupalcode.org. The author's own experience.
This text was translated by AI.
How was AI used?
Translated from the Italian original with AI assistance, then read and corrected by a person, who holds editorial responsibility.