SAP Joule Agents Compliance Brief

This brief summarizes how SAP governs its AI Agents — specifically Joule Agents — and how that governance framework addresses auditability, regulatory compliance, and human oversight under the EU AI Act. Ladda ner dokumentet

SAP Joule AgentsGovernance, Auditability, and EU AI Act ComplianceCustomer EnablementVersion: 1.0Date: 2026-06-17PUBLIC
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.PUBLIC2 / 6Table of contentsDefinition of Joule Agents ......................................................................................................................................... 3How Joule Agents Are Governed .......................................................................................................................... 3The Audit Trail ....................................................................................................................................................................................... 4Regulatory Classification .............................................................................................................................................................. 4Human Oversight ................................................................................................................................................................................ 5An Important Boundary Condition ........................................................................................................................................ 5What This Briefing Does Not Address................................................................................................................. 5Resources............................................................................................................................................................................. 6
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.PUBLIC3 / 6This 1brief summarizes how SAP governs its AI Agents specifically Joule Agents and howthat governance framework addresses auditability, regulatory compliance, and human oversightunder the EU AI Act.Definition of Joule AgentsJoule Agents are AI systems integrated within SAP's enterprise cloud environment that assist userswith tasks inside governed SAP business processes. They are distinct from conventionalautomation in three important ways. Unlike rule-based automation, they reason over variable inputsusing a model. Unlike AI assistants, they pursue objectives autonomously across multiple stepswithout requiring discrete human instruction for each action. Unlike standard machine learningmodels, they perceive, decide, and execute in a loop.Under Article 3(1) of the EU AI Act, Joule Agents satisfy the definition of an AI system; they operatewith varying levels of autonomy and generate outputs that influence real environments, specificallySAP enterprise application (ERP) workflows and the business data those workflows govern.How Joule Agents Are GovernedThree principles define SAP's governance approach:Agents are not anonymous. Every Joule Agent operates under a uniquely provisioned identity,centrally managed by SAP. Agent actions are attributed to a specific governed identity, not ageneric or shared system account, and logged in the same audit infrastructure that governs humanuser activity.Agents cannot exceed human authorization. Where a Joule Agent acts on behalf of a humanuser, its permissions are bound to a subset of what that user holds. The agent cannot exceed thedelegating user's authorization scope. Authorization boundaries are explicit, documented, andenforced at the system level, not dependent on policy compliance alone.Agents operate inside existing controls, not alongside them. Joule Agents executetransactions within SAP ERP workflows and are subject to the same role-based authorizations,approval workflows, audit logging, and compliance and audit controls that govern human users.1 SAP provides this document as a high-level briefing on SAP’s AI Agents. SAP’s views are based oninformation available and reliable at the time of publication. SAP’s views may change at any time. SAPprovides this briefing only with the understanding that SAP is not providing legal or professionaladvice. This briefing should not be used as a substitute for independent legal or professional advice.Any opinion expressed in this briefing may change due to shifting regulatory requirements,technological developments, and evolving interpretations.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.PUBLIC4 / 6Human oversight is built into the system by design through these pre-existing mechanisms, it is notadded as a separate layer.The Audit TrailThe audit trail for Joule Agent actions answers four questions consistently: Who acted? Every transaction, data access, and workflow execution is logged against aspecific, provisioned agent identity. What were they authorized to do? The agent's authorization record captures the exactpermission set in effect at the time of each action. What did they actually do? Both permitted actions and blocked actions are logged. The audittrail is comprehensive. On whose behalf did they act? Where an agent acts under delegation from a human user, thedelegation chain which user authorized the agent, under what scope, and what the agent didwithin that scope is fully recorded.Agent actions that access, modify, or transmit data are subject to SAP's full cybersecurity and dataprotection controls, including AI Incident Management and regulatory notification obligations whereapplicable.Regulatory ClassificationJoule Agents are assessed against the EU AI Act's risk-based classification framework on a feature-by-feature basis. Under SAP’s EU AI Act system classification process, a Joule Agent that performsor materially influences a function falling within Annex III is classified high-risk and does not qualifyfor an exception. Within SAP SuccessFactors, agents support employment-related decisions, suchas candidate screening and ranking, performance evaluation, and task allocation, which all fallwithin Annex III, Point 4 (employment). In finance and insurance contexts, agents may influencedeterminations affecting access to essential services. Among agents assessed to date, confirmedhigh-risk classifications are concentrated in SAP SuccessFactors: SAP’s portfolio assessmentremains ongoing, and SAP anticipates that further classifications will emerge as assessmentcontinues.A narrow exception remains. Where feature performs only a procedural task, offer assistiveimprovement, for example, grammar and tone suggestions, detects patterns without decisiveinfluence, or prepares information that does not determine an outcome, and does not replacehuman judgement, it may qualify for an exception. These exceptions are feature-specific and mustbe justified individually. They do not apply to the agent product as a whole. Classification isreassessed as capabilities evolve, and a deployer’s specific use in a regulated sector can bring anotherwise-exempt feature within Annex III.Where a Joule Agent is high-risk, the full Article 9-15 lifecycle control regime applies, riskmanagement, data governance, technical documentation, record keeping (Article 12), transparencyto deployers (Article 13), human oversight (Article 14), and accuracy, robustness, and cybersecurity,together with conformity assessment and registration in the EU database of high-risk systems. SAP
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.PUBLIC5 / 6meets these requirements through its existing enterprise control framework, including establishedcontrols for security, data protection, and cloud operations. These controls are applied consistentlyto AI agents as part of SAP’s broader service delivery model, ensuring that agent functionalityremains governed within the same operational and compliance structures as other enterprisecapabilities.This includes a unified approach to logging, traceability, and auditability, aligned with enterpriselogging standards and ongoing work on agentic observability. As a result, AI agent actions areconsistently recorded, traceable across their life cycle and auditable within established securityand compliance frameworks, strengthening transparency, accountability, and trust withoutintroducing standalone governance mechanisms.These obligations are met through existing enterprise controls by design, with AI agent activitygoverned through standard application workflows and supported by established logging andmonitoring capabilities, including those used for post-market monitoring and incident management.Human OversightWhere the EU AI Act requires human oversight by design, SAP's embedded ERP approvalmechanisms enforce it. SAP's AI Ethics Policy provides three oversight models calibrated to risk andautonomy level: Human-in-the-Loop, Human-on-the-Loop, and Human-in-Command. Theappropriate model for a given deployment is determined through SAP's AI Ethics impactassessment.Users interacting with Joule Agents retain the ability to review, override, and reverse agent-executed actions. A non-AI alternative pathway for completing any task is always available.Rollback capabilities and fallback mechanisms are implemented across SAP AI systems to void orundo actions in cases of malfunction, misalignment, or safety concerns.An Important Boundary ConditionHarmonized Standards translating EU AI Act requirements into concrete technical specificationsare not expected before the end of 2026. Until those standards are published, conformityassessments cannot be conclusively finalized against the presumption-of-conformity framework.This does not, however, defer or suspend the underlying high-risk obligations, which apply to theAct’s statutory timeline regardless. Current governance positions and control designs should betreated as interim, subject to reassessment once Harmonized Standards become available. SAP’sAI governance does not operate in a vacuum in the interim. SAP holds ISO/IEC 42001 certificationfor assurance of the processes and controls that govern its AI systems.What This Briefing Does Not AddressThis brief summarizes governance principles and regulatory positioning based on informationavailable at the time of publication. It does not constitute legal or professional advice. Deployersshould seek independent legal counsel regarding their own compliance obligations, particularly inregulated sectors where sector-specific frameworks, including DORA, NIS2, and applicable nationalimplementations, overlay the EU AI Act requirements addressed here.