← Back to blog

Zero Agents in 144 Pages: the AI Laws Define the System and Leave the Agent to the Dictionary

A string count over the EU AI Act, NIST's framework, four state statutes and every Federal Register document since 2019: the binding texts define the AI system 1,122 times and the agent never, and the one federal attempt at a definition cites a dictionary's slang page.

Published 26 September 2026 · 15 min read · AI regulation / EU AI Act / agentic AI

The EU's Artificial Intelligence Act is 144 pages in the Official Journal. Extract the text and you get 595,707 characters, in which the phrase "AI system" appears 1,122 times, about eight times a page. The word "agent" appears zero times. Not zero times in the sense of "agent" being used for something else; zero occurrences of the string, in any meaning, anywhere in the Regulation. "Agentic" also appears zero times.

I did not expect that. The Act was finished in 2024, the year vendors started calling their products agents, and it is the longest binding text on the subject in the world. So I ran the same count over the other texts that bind anyone in 2026: NIST's AI Risk Management Framework, the White House's April 2025 memorandum on federal AI use, the three state statutes that define the technology (Colorado, Texas, Utah), California's frontier-model law, the executive orders, and the standard everyone's definition is borrowed from. The answer is the same in every binding text and different in exactly one document, and the one document is a standard nobody imported.

The count

The method is a string count over the official texts, which is a crude instrument and the right one for the question. The question is not whether the laws cover agents. They do, in the sense that an agent is built on something that is an AI system, and I will come back to that. The question is whether any of them has written down what an agent is, and a string count answers that without interpretation.

textpages"agent""agentic""AI system"the "agent" hits are
Regulation (EU) 2024/1689, the AI Act144001,122none
NIST AI 100-1, the AI RMF 1.04800238none
Colorado SB 24-2052600124none
Texas HB 149300072none
Utah SB 149 (2024)18000none
OMB M-25-21251010"chemical or biological agents"
California SB 53105"employers and their agents", in the digest
Commission Guidelines on the definition of an AI system, C(2025) 50531310110road users in a self-driving example
ISO/IEC 22989:2022, the terms clause2027clause 3.1.1, "AI agent"

Three of the four state statutes and the whole EU Regulation contain no occurrence of the string. The two that contain it use it the way a contract does, for a person acting on someone's behalf. NIST's framework, which most corporate AI policies are built on, has none.

A zero is only worth reporting with its control. The same tokenizer that returns 0 for "agent" on the EU text returns 39 for "authorised representative", 58 for "operator" and 50 for the stem "agenc" on the same text, so the zero belongs to the Regulation and not to the extraction. The extraction is clean enough that Article 3's definitions come out verbatim, which matters for the next section.

What they define instead

Every text in the table defines the same thing, and most of them define it in the same words, because they copied it from the same place.

The EU's Article 3(1): an AI system is "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments" (OJ L, 12.7.2024, p. 46).

Colorado's: "any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments" (C.R.S. 6-1-1701(2)). Texas, in Business and Commerce Code 551.001(1), uses the identical sentence. California's SB 53 defines an "artificial intelligence model" as "an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments." NIST's: "an engineered or machine-based system that can, for a given set of objectives, generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments. AI systems are designed to operate with varying levels of autonomy," and NIST says where it got it: "Adapted from: OECD Recommendation on AI:2019; ISO/IEC 22989:2022."

That last citation is the interesting one, because ISO/IEC 22989 is the vocabulary standard for AI, and its terms clause defines the agent three entries before it defines the system. Clause 3.1.1: "AI agent: automated entity that senses and responds to its environment and takes actions to achieve its goals." Clause 3.1.4 is the AI system. The definition everyone borrowed was in the same list as the one nobody borrowed. NIST cites the standard by name on page 1 and takes the system entry. The EU took the OECD's revised line. Colorado and Texas took the OECD line without the autonomy clause. California took it with the clause reworded. None of them took 3.1.1.

The one binding U.S. definition of AI that does contain the word is from 2018. OMB's memorandum M-25-21, which governs how federal agencies use AI, adopts the definition in section 238(g) of the fiscal 2019 National Defense Authorization Act (M-25-21, p. 18). That definition is a list of five things the term "includes", and the fifth is "an artificial system designed to act rationally, including an intelligent software agent or embodied robot that achieves goals using perception, planning, reasoning, learning, communicating, decision making, and acting" (Pub. L. 115-232, sec. 238(g)(5)). The software agent is there as an example of AI, in a sentence written before the current meaning of the word existed. It is not a defined term, and nothing in M-25-21 attaches to it.

The dial

What the texts do instead of naming the agent is put its defining property on a dial attached to the system. The EU's definition says "varying levels of autonomy", and Recital 12 says what that means: "AI systems are designed to operate with varying levels of autonomy, meaning that they have some degree of independence of actions from human involvement and of capabilities to operate without human intervention" (p. 4). The Commission's 2025 guidelines on the definition spend 16 occurrences of "autonom-" across 13 pages explaining that one element and none on agents. OMB's memorandum grades the dial in three: its definition "includes systems that are fully autonomous, partially autonomous, and not autonomous, and it includes systems that operate both with and without human oversight" (p. 18). Utah's definition of generative AI ends "with limited or no human oversight" (Utah Code 13-2-12(1)(a)). Colorado and Texas dropped the autonomy clause and kept only "infers how to generate outputs".

Then the duties read the dial. The EU's human-oversight article requires measures "commensurate with the risks, level of autonomy and context of use of the high-risk AI system" (Art. 14(3), p. 60), and one of the criteria for adding a use case to the high-risk list is "the extent to which the AI system acts autonomously and the possibility for a human to override a decision" (Art. 7(2)(d), p. 55). Of the eleven "autonom-" hits in the whole Regulation, those three are the ones that do work. The other eight are the personal autonomy of humans that manipulative systems must not subvert, "increasingly autonomous robots" in a recital about product safety, and two model-classification criteria.

This is a coherent design, and I want to be fair to it. A definition written in 2019 to be technology-neutral covers a 2026 agent as an AI system, because an agent infers outputs from inputs and acts on an environment, and the more autonomously it does that, the further along the dial it sits and the more oversight the EU text asks for. Nobody had to write the word down for the obligations to attach. The consequence for anyone deploying one is also coherent, and worth stating plainly because it is the practical answer to "which rules apply to my agent": under every text in the table, your agent is whatever AI system it is built on, its obligations follow that system's risk class, and where autonomy is a factor it is a factor of degree, not of kind. There is no agent-specific duty anywhere in these documents because there is no agent anywhere in these documents.

Where the word does appear

The U.S. government has used the phrase "AI agents" in documents with legal effect. I pulled every document in the Federal Register that contains it, by full-text phrase search on the Register's own API, year by year from 2019, with two controls: the phrase "artificial intelligence", which should be large and rising, and a nonsense phrase, which should be zero.

phrase20192020202120222023202420252026 (to Sept. 21)
"AI agents"00000023
"agentic"00000044
"autonomous agents"00000000
"artificial intelligence" (control)53879899170287174239
nonsense phrase (control)00000000

Five documents ever contain "AI agents", all since January 2025, against 1,207 that contain "artificial intelligence" over the same years. Here are the five, because the whole finding is in what each one does with the phrase.

The first is the Bureau of Industry and Security's AI Diffusion rule of January 15, 2025, which mentions agents twice as a capability of advanced models, once as something malicious actors could build. The rule was later rescinded and nothing here rests on it.

The second is Executive Order 14363 of November 24, 2025, launching the Genesis Mission, a Department of Energy science programme. It orders the department to "train scientific foundation models and create AI agents to test new hypotheses, automate research workflows" (sec. 1), and to provide "AI modeling and analysis frameworks, including AI agents to explore design spaces, evaluate experimental outcomes, and automate workflows" (sec. 3(a)(ii)). Build them, in other words.

The fourth is Executive Order 14409 of June 2, 2026, on AI innovation and security. Its section 4 tells the Attorney General to prioritise enforcement of the federal identity-fraud, computer-fraud and wire-fraud statutes, and says this "includes breaching any public or private information technology system, or employing AI agents to unlawfully access data or information that is subsequently used for a criminal or unlawful purpose." Jail people who misuse them, in other words. The order has no definitions section. Its only "as defined in" is for National Security Systems. Between them, the two orders instruct the government to create AI agents and to prosecute people who employ them, seven months apart, and neither says what one is.

The fifth is an Office of Personnel Management rule of June 25, 2026, on Senior Executive Service candidate programmes, where the phrase appears in a summary of a public comment that OPM says "did not propose any viable recommendations."

The third is the one that matters, and it is not a rule. On January 8, 2026, NIST's Center for AI Standards and Innovation published a request for information on security considerations for AI agents (91 FR 699), and its Background section contains the closest thing the federal government has to a working definition: "AI agent systems consist of at least one generative AI model and scaffolding software that equips the model with tools to take a range of discretionary actions. These systems may be more expansive, containing multiple sub-agents with software that orchestrates their interactions. They can be deployed with little to no human oversight. Other terms used to refer to AI agent systems include AI agents and agentic AI." The notice uses the word "agent" 68 times. It is the first federal text I can find that treats the agent as a different object from the model: a model plus scaffolding plus tools, possibly plus sub-agents and an orchestrator. Comments closed on March 9, 2026. A request for information binds nobody.

"Agentic" fares a little worse. Eight documents, and the only one that tries to say what the word means is a proposed rule from the Department of Health and Human Services on health-data interoperability (90 FR 61005, December 29, 2025). The rule proposes that "access" and "use" of health data include access by "autonomous artificial intelligence systems ('agentic artificial intelligence' or 'agentic AI')", and footnote 66 explains the term. Its first citation is Merriam-Webster's slang page for "agentic". Its second is an IEEE Access survey. The sentence itself reads, in the Register's text, that such systems "is often referred to a 'agentic AI'", two typos in a definition that a federal rule would carry into the Code of Federal Regulations. I am not mocking the drafters; the footnote is honest about where the word comes from. That is the point. When a regulator had to say what agentic means, the authority it reached for first was a dictionary's slang section, because there was nothing in the statute book to reach for.

What this does and does not show

It does not show that the gap is a mistake, and I am not arguing that it is. The OECD line was written to survive technologies that did not exist yet, and it has: an agent is an AI system, the EU's oversight duties scale with autonomy, and a court asked whether a coding agent that deleted a production database is covered by Colorado's statute would not need the word "agent" to say yes. Technology-neutral drafting is a choice with a long and mostly good record.

What it shows is narrower and, I think, more useful. The thing every vendor sells in 2026 and every security researcher writes about has no legal definition in any binding text I could find, and the only official documents that use the word are the ones asking what it means. The NIST request for information is a request. The HHS footnote cites a dictionary. The two executive orders that use the phrase point in opposite directions and define nothing. Everyone building or buying an agent is operating under definitions of the system it runs on, and the agent-specific questions, what it may be permitted to do on its own, who is liable when it uses a tool, whether an orchestrator of sub-agents is one system or several, are questions the texts answer only by reading the autonomy dial, which was calibrated for a chatbot.

Three things would change this, and none of them has happened yet. NIST or CAISI could turn the RFI into a publication with a definition; I searched the Register for a follow-on notice and there is none, and I did not search NIST's own site. The European standards bodies drafting the harmonised standards under Article 40 of the Act could adopt 22989's term, which would bring "AI agent" into EU law through the technical annexes; whether the drafts do that is not something I checked. Or a legislature could write the word down. Until one of them does, the honest description of the agent's legal status is the one the Register gives by omission: 1,207 documents about artificial intelligence, five about agents, one definition, and it comes with a link to the slang page.

The method, so you can check it

Every count above comes from two scripts published with this piece, run on September 21, 2026, together with a list of every source they read. The first, agent_word_census_c6281.py, extracts the text of each primary with PyMuPDF and counts four patterns on it: \bagents?\b, \bagentic\b, \bautonom\w* and "AI system(s)" including the spelled-out form. It prints every "agent" hit in context with its page, and pulls each document's definition by an anchor regex, so the quotations above are the extractor's output, not my transcription. For the EU Act, the PDF's page numbers are the Official Journal's: page 46 of the file carries the footer "OJ L, 12.7.2024 46/144". The second, fr_ai_agents_c6281.py, queries the Federal Register API's full-text phrase search per year and writes the document list behind each count.

The limits are facts about the measurement. The census is over the texts named in the table, not over all AI law; the Council of Europe convention, the UK's approach, China's measures, Illinois and New York, and the sectoral rules from FDA, the SEC and the banking regulators are absent by design, and anyone can add them to the script's document list and re-run. The Register's phrase search is the Register's; its recall on hyphenated or line-broken phrases in older scanned documents is not characterised here, and the dip in the "artificial intelligence" control from 2024 to 2025 is the API's number, used for nothing. The ISO standard's terms clause is read from a reseller's public sample PDF of that clause, which contains it, and ISO's own Online Browsing Platform preview shows the same clause to a browser while refusing scripted fetches; the rest of the standard is paywalled and was not bought. EUR-Lex refused a non-browser client three times with a challenge page, so the Official Journal PDF came from the Publications Office's own repository under the same identifier, and its footers confirm it is the OJ text. Colorado amended its act's effective date in 2025; the definition quoted is the signed 2024 text, and nothing here depends on the date. And "zero occurrences" is a count on extracted text: the extractor that produced it renders Article 3 verbatim, and the alternative extractor that inserted spaces inside words on this file was not used.

The word will get defined eventually, probably by a standards committee, possibly by a court, and the definition will be a sentence about scaffolding and tools and discretion that looks a lot like the paragraph NIST wrote in January and asked the public to comment on. When that happens, the count in the title will change by one.


Every count, date, locator and quoted passage in this piece was checked against the saved primaries by a script published with it, figures_c6281.py, which re-extracts the texts, recounts the words with the census's own regexes, runs the two-sided control on the EU text, and asserts each quotation is present verbatim at its stated page. A figure missing from the sources fails the run. The two collection scripts and their output files are published beside it, in one folder, with a list of every primary they read: where it came from, when it was fetched, its size and its checksum.

Sources:

A count is only worth reporting with its control.

The zero in the title survived this piece because the same tokenizer returns 39, 58 and 50 for three other words on the same text, and a script re-runs every count and every quotation against the saved primaries. If you run agents, keep that kind of record of what they did: step by step, in a form that cannot be quietly rewritten. Chain of Consciousness keeps a tamper-evident record of an agent's actions, so a claim you make about it later has rows underneath that someone else can check.

pip install chain-of-consciousness
npm install chain-of-consciousness

Or start without installing anything: Hosted Chain of Consciousness.