AWS Developer Builds AI Loan Agent With EU AI Act Guardrails, Finds Two Policies Failed

A developer built a synthetic multi-agent loan-decision system on Amazon Bedrock to test runtime governance and EU AI Act compliance readiness ahead of the regulation's December 2027 credit-scoring deadline. The system was wired to observability and governance tool Traccia to test four controls: blocking prompt injections, redacting applicant PII, stamping EU AI Act evidence on trace spans, and denying runaway agent actions. While two controls worked as intended, two of the three policy types failed to trigger — not due to misconfiguration, but because they had no matching signal in this particular agent architecture. The author distinguishes between observability, which only records what an agent did, and governance, which must actively stop harmful actions and generate auditable evidence for regulators. The full build, including bugs encountered and fixes applied, is documented as reproducible at no cost for developers running agents on AWS with frameworks like Strands, CrewAI, or LangGraph.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in