SAP Joule Agents Compliance Brief
This brief summarizes how SAP governs its AI Agents — specifically Joule Agents — and how that governance framework addresses auditability, regulatory compliance, and human oversight under the EU AI Act. Ladda ner dokumentet
SAP Joule Agents
Governance, Auditability, and EU AI Act Compliance
Customer Enablement
Version: 1.0
Date: 2026-06-17
PUBLIC
Governance, Auditability, and EU AI Act Compliance
Customer Enablement
Version: 1.0
Date: 2026-06-17
PUBLIC
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
PUBLIC
2 / 6
Table of contents
Definition of Joule Agents ......................................................................................................................................... 3
How Joule Agents Are Governed .......................................................................................................................... 3
The Audit Trail ....................................................................................................................................................................................... 4
Regulatory Classification .............................................................................................................................................................. 4
Human Oversight ................................................................................................................................................................................ 5
An Important Boundary Condition ........................................................................................................................................ 5
What This Briefing Does Not Address................................................................................................................. 5
Resources............................................................................................................................................................................. 6
PUBLIC
2 / 6
Table of contents
Definition of Joule Agents ......................................................................................................................................... 3
How Joule Agents Are Governed .......................................................................................................................... 3
The Audit Trail ....................................................................................................................................................................................... 4
Regulatory Classification .............................................................................................................................................................. 4
Human Oversight ................................................................................................................................................................................ 5
An Important Boundary Condition ........................................................................................................................................ 5
What This Briefing Does Not Address................................................................................................................. 5
Resources............................................................................................................................................................................. 6
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
PUBLIC
3 / 6
This 1brief summarizes how SAP governs its AI Agents — specifically Joule Agents — and how
that governance framework addresses auditability, regulatory compliance, and human oversight
under the EU AI Act.
Definition of Joule Agents
Joule Agents are AI systems integrated within SAP's enterprise cloud environment that assist users
with tasks inside governed SAP business processes. They are distinct from conventional
automation in three important ways. Unlike rule-based automation, they reason over variable inputs
using a model. Unlike AI assistants, they pursue objectives autonomously across multiple steps
without requiring discrete human instruction for each action. Unlike standard machine learning
models, they perceive, decide, and execute in a loop.
Under Article 3(1) of the EU AI Act, Joule Agents satisfy the definition of an AI system; they operate
with varying levels of autonomy and generate outputs that influence real environments, specifically
SAP enterprise application (ERP) workflows and the business data those workflows govern.
How Joule Agents Are Governed
Three principles define SAP's governance approach:
Agents are not anonymous. Every Joule Agent operates under a uniquely provisioned identity,
centrally managed by SAP. Agent actions are attributed to a specific governed identity, not a
generic or shared system account, and logged in the same audit infrastructure that governs human
user activity.
Agents cannot exceed human authorization. Where a Joule Agent acts on behalf of a human
user, its permissions are bound to a subset of what that user holds. The agent cannot exceed the
delegating user's authorization scope. Authorization boundaries are explicit, documented, and
enforced at the system level, not dependent on policy compliance alone.
Agents operate inside existing controls, not alongside them. Joule Agents execute
transactions within SAP ERP workflows and are subject to the same role-based authorizations,
approval workflows, audit logging, and compliance and audit controls that govern human users.
1 SAP provides this document as a high-level briefing on SAP’s AI Agents. SAP’s views are based on
information available and reliable at the time of publication. SAP’s views may change at any time. SAP
provides this briefing only with the understanding that SAP is not providing legal or professional
advice. This briefing should not be used as a substitute for independent legal or professional advice.
Any opinion expressed in this briefing may change due to shifting regulatory requirements,
technological developments, and evolving interpretations.
PUBLIC
3 / 6
This 1brief summarizes how SAP governs its AI Agents — specifically Joule Agents — and how
that governance framework addresses auditability, regulatory compliance, and human oversight
under the EU AI Act.
Definition of Joule Agents
Joule Agents are AI systems integrated within SAP's enterprise cloud environment that assist users
with tasks inside governed SAP business processes. They are distinct from conventional
automation in three important ways. Unlike rule-based automation, they reason over variable inputs
using a model. Unlike AI assistants, they pursue objectives autonomously across multiple steps
without requiring discrete human instruction for each action. Unlike standard machine learning
models, they perceive, decide, and execute in a loop.
Under Article 3(1) of the EU AI Act, Joule Agents satisfy the definition of an AI system; they operate
with varying levels of autonomy and generate outputs that influence real environments, specifically
SAP enterprise application (ERP) workflows and the business data those workflows govern.
How Joule Agents Are Governed
Three principles define SAP's governance approach:
Agents are not anonymous. Every Joule Agent operates under a uniquely provisioned identity,
centrally managed by SAP. Agent actions are attributed to a specific governed identity, not a
generic or shared system account, and logged in the same audit infrastructure that governs human
user activity.
Agents cannot exceed human authorization. Where a Joule Agent acts on behalf of a human
user, its permissions are bound to a subset of what that user holds. The agent cannot exceed the
delegating user's authorization scope. Authorization boundaries are explicit, documented, and
enforced at the system level, not dependent on policy compliance alone.
Agents operate inside existing controls, not alongside them. Joule Agents execute
transactions within SAP ERP workflows and are subject to the same role-based authorizations,
approval workflows, audit logging, and compliance and audit controls that govern human users.
1 SAP provides this document as a high-level briefing on SAP’s AI Agents. SAP’s views are based on
information available and reliable at the time of publication. SAP’s views may change at any time. SAP
provides this briefing only with the understanding that SAP is not providing legal or professional
advice. This briefing should not be used as a substitute for independent legal or professional advice.
Any opinion expressed in this briefing may change due to shifting regulatory requirements,
technological developments, and evolving interpretations.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
PUBLIC
4 / 6
Human oversight is built into the system by design through these pre-existing mechanisms, it is not
added as a separate layer.
The Audit Trail
The audit trail for Joule Agent actions answers four questions consistently:
• Who acted? Every transaction, data access, and workflow execution is logged against a
specific, provisioned agent identity.
• What were they authorized to do? The agent's authorization record captures the exact
permission set in effect at the time of each action.
• What did they actually do? Both permitted actions and blocked actions are logged. The audit
trail is comprehensive.
• On whose behalf did they act? Where an agent acts under delegation from a human user, the
delegation chain — which user authorized the agent, under what scope, and what the agent did
within that scope — is fully recorded.
Agent actions that access, modify, or transmit data are subject to SAP's full cybersecurity and data
protection controls, including AI Incident Management and regulatory notification obligations where
applicable.
Regulatory Classification
Joule Agents are assessed against the EU AI Act's risk-based classification framework on a feature-
by-feature basis. Under SAP’s EU AI Act system classification process, a Joule Agent that performs
or materially influences a function falling within Annex III is classified high-risk and does not qualify
for an exception. Within SAP SuccessFactors, agents support employment-related decisions, such
as candidate screening and ranking, performance evaluation, and task allocation, which all fall
within Annex III, Point 4 (employment). In finance and insurance contexts, agents may influence
determinations affecting access to essential services. Among agents assessed to date, confirmed
high-risk classifications are concentrated in SAP SuccessFactors: SAP’s portfolio assessment
remains ongoing, and SAP anticipates that further classifications will emerge as assessment
continues.
A narrow exception remains. Where feature performs only a procedural task, offer assistive
improvement, for example, grammar and tone suggestions, detects patterns without decisive
influence, or prepares information that does not determine an outcome, and does not replace
human judgement, it may qualify for an exception. These exceptions are feature-specific and must
be justified individually. They do not apply to the agent product as a whole. Classification is
reassessed as capabilities evolve, and a deployer’s specific use in a regulated sector can bring an
otherwise-exempt feature within Annex III.
Where a Joule Agent is high-risk, the full Article 9-15 lifecycle control regime applies, risk
management, data governance, technical documentation, record keeping (Article 12), transparency
to deployers (Article 13), human oversight (Article 14), and accuracy, robustness, and cybersecurity,
together with conformity assessment and registration in the EU database of high-risk systems. SAP
PUBLIC
4 / 6
Human oversight is built into the system by design through these pre-existing mechanisms, it is not
added as a separate layer.
The Audit Trail
The audit trail for Joule Agent actions answers four questions consistently:
• Who acted? Every transaction, data access, and workflow execution is logged against a
specific, provisioned agent identity.
• What were they authorized to do? The agent's authorization record captures the exact
permission set in effect at the time of each action.
• What did they actually do? Both permitted actions and blocked actions are logged. The audit
trail is comprehensive.
• On whose behalf did they act? Where an agent acts under delegation from a human user, the
delegation chain — which user authorized the agent, under what scope, and what the agent did
within that scope — is fully recorded.
Agent actions that access, modify, or transmit data are subject to SAP's full cybersecurity and data
protection controls, including AI Incident Management and regulatory notification obligations where
applicable.
Regulatory Classification
Joule Agents are assessed against the EU AI Act's risk-based classification framework on a feature-
by-feature basis. Under SAP’s EU AI Act system classification process, a Joule Agent that performs
or materially influences a function falling within Annex III is classified high-risk and does not qualify
for an exception. Within SAP SuccessFactors, agents support employment-related decisions, such
as candidate screening and ranking, performance evaluation, and task allocation, which all fall
within Annex III, Point 4 (employment). In finance and insurance contexts, agents may influence
determinations affecting access to essential services. Among agents assessed to date, confirmed
high-risk classifications are concentrated in SAP SuccessFactors: SAP’s portfolio assessment
remains ongoing, and SAP anticipates that further classifications will emerge as assessment
continues.
A narrow exception remains. Where feature performs only a procedural task, offer assistive
improvement, for example, grammar and tone suggestions, detects patterns without decisive
influence, or prepares information that does not determine an outcome, and does not replace
human judgement, it may qualify for an exception. These exceptions are feature-specific and must
be justified individually. They do not apply to the agent product as a whole. Classification is
reassessed as capabilities evolve, and a deployer’s specific use in a regulated sector can bring an
otherwise-exempt feature within Annex III.
Where a Joule Agent is high-risk, the full Article 9-15 lifecycle control regime applies, risk
management, data governance, technical documentation, record keeping (Article 12), transparency
to deployers (Article 13), human oversight (Article 14), and accuracy, robustness, and cybersecurity,
together with conformity assessment and registration in the EU database of high-risk systems. SAP
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
PUBLIC
5 / 6
meets these requirements through its existing enterprise control framework, including established
controls for security, data protection, and cloud operations. These controls are applied consistently
to AI agents as part of SAP’s broader service delivery model, ensuring that agent functionality
remains governed within the same operational and compliance structures as other enterprise
capabilities.
This includes a unified approach to logging, traceability, and auditability, aligned with enterprise
logging standards and ongoing work on agentic observability. As a result, AI agent actions are
consistently recorded, traceable across their life cycle and auditable within established security
and compliance frameworks, strengthening transparency, accountability, and trust without
introducing standalone governance mechanisms.
These obligations are met through existing enterprise controls by design, with AI agent activity
governed through standard application workflows and supported by established logging and
monitoring capabilities, including those used for post-market monitoring and incident management.
Human Oversight
Where the EU AI Act requires human oversight by design, SAP's embedded ERP approval
mechanisms enforce it. SAP's AI Ethics Policy provides three oversight models calibrated to risk and
autonomy level: Human-in-the-Loop, Human-on-the-Loop, and Human-in-Command. The
appropriate model for a given deployment is determined through SAP's AI Ethics impact
assessment.
Users interacting with Joule Agents retain the ability to review, override, and reverse agent-
executed actions. A non-AI alternative pathway for completing any task is always available.
Rollback capabilities and fallback mechanisms are implemented across SAP AI systems to void or
undo actions in cases of malfunction, misalignment, or safety concerns.
An Important Boundary Condition
Harmonized Standards translating EU AI Act requirements into concrete technical specifications
are not expected before the end of 2026. Until those standards are published, conformity
assessments cannot be conclusively finalized against the presumption-of-conformity framework.
This does not, however, defer or suspend the underlying high-risk obligations, which apply to the
Act’s statutory timeline regardless. Current governance positions and control designs should be
treated as interim, subject to reassessment once Harmonized Standards become available. SAP’s
AI governance does not operate in a vacuum in the interim. SAP holds ISO/IEC 42001 certification
for assurance of the processes and controls that govern its AI systems.
What This Briefing Does Not Address
This brief summarizes governance principles and regulatory positioning based on information
available at the time of publication. It does not constitute legal or professional advice. Deployers
should seek independent legal counsel regarding their own compliance obligations, particularly in
regulated sectors where sector-specific frameworks, including DORA, NIS2, and applicable national
implementations, overlay the EU AI Act requirements addressed here.
PUBLIC
5 / 6
meets these requirements through its existing enterprise control framework, including established
controls for security, data protection, and cloud operations. These controls are applied consistently
to AI agents as part of SAP’s broader service delivery model, ensuring that agent functionality
remains governed within the same operational and compliance structures as other enterprise
capabilities.
This includes a unified approach to logging, traceability, and auditability, aligned with enterprise
logging standards and ongoing work on agentic observability. As a result, AI agent actions are
consistently recorded, traceable across their life cycle and auditable within established security
and compliance frameworks, strengthening transparency, accountability, and trust without
introducing standalone governance mechanisms.
These obligations are met through existing enterprise controls by design, with AI agent activity
governed through standard application workflows and supported by established logging and
monitoring capabilities, including those used for post-market monitoring and incident management.
Human Oversight
Where the EU AI Act requires human oversight by design, SAP's embedded ERP approval
mechanisms enforce it. SAP's AI Ethics Policy provides three oversight models calibrated to risk and
autonomy level: Human-in-the-Loop, Human-on-the-Loop, and Human-in-Command. The
appropriate model for a given deployment is determined through SAP's AI Ethics impact
assessment.
Users interacting with Joule Agents retain the ability to review, override, and reverse agent-
executed actions. A non-AI alternative pathway for completing any task is always available.
Rollback capabilities and fallback mechanisms are implemented across SAP AI systems to void or
undo actions in cases of malfunction, misalignment, or safety concerns.
An Important Boundary Condition
Harmonized Standards translating EU AI Act requirements into concrete technical specifications
are not expected before the end of 2026. Until those standards are published, conformity
assessments cannot be conclusively finalized against the presumption-of-conformity framework.
This does not, however, defer or suspend the underlying high-risk obligations, which apply to the
Act’s statutory timeline regardless. Current governance positions and control designs should be
treated as interim, subject to reassessment once Harmonized Standards become available. SAP’s
AI governance does not operate in a vacuum in the interim. SAP holds ISO/IEC 42001 certification
for assurance of the processes and controls that govern its AI systems.
What This Briefing Does Not Address
This brief summarizes governance principles and regulatory positioning based on information
available at the time of publication. It does not constitute legal or professional advice. Deployers
should seek independent legal counsel regarding their own compliance obligations, particularly in
regulated sectors where sector-specific frameworks, including DORA, NIS2, and applicable national
implementations, overlay the EU AI Act requirements addressed here.