French CNIL Publishes Note on Agentic AI and Data Protection


On July 20, 2026, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés, “CNIL”) published a joint exploratory note with the French AI and Digital Council (“CIANum”) on the data protection implications of agentic AI (the “Note”). The Note is exploratory rather than prescriptive: it does not purport to state definitive regulatory expectations, and it does not announce forthcoming guidance. However, it does provide helpful considerations for when the EU’s General Data Protection Regulation (“GDPR”) might come under strain in the course of processing personal data via autonomous systems, and identifies legal and technical measures that might help mitigate potential risks. The CNIL frames this exercise as connected to its engagement with several international counterparts, including through the G7 data protection authorities during the French G7 presidency.

The Note is the latest in a rapidly accumulating body of regulator commentary on agentic AI, including by the UK ICO, Spanish AEPD, and Singaporean IMDA. Below are some key takeaways.

1. The Note positions the change in scale of data processing associated with agentic AI systems as the key driver of amplified data protection risk.

The Note describes agentic AI as a set of computer programs built on generative AI models capable of autonomous decisions, orchestration of complex actions, and interaction with third-party services, with or without human validation. Architecturally, it identifies an “orchestrator” agent serving as the natural-language interface with the user, “specialized” agents coordinated by the orchestrator to perform discrete tasks (e.g., code generation, text processing, online payments) and connections to external applications, databases, and search tools—with interactions mediated by standardized exchange protocols (e.g., the MCP and ACP protocols).

The Note calls out two data management mechanisms that impact personal data processing: “context” retains the history of exchanges, instructions, and inter-agent interactions for the duration of a given process and is deleted at its conclusion. “Memory,” by contrast, is persistent and independent of execution processes, retaining reusable information across processes and capable of being enriched automatically through interaction. Each agent may hold its own context and memory, and multiple agents may share a common memory. Per the CNIL, it’s the proliferation of memory instances that is the principal source of opacity, because it is difficult for users to determine what data is retained, where, subject to what operations, and for how long.

2. The Note identifies potential points of friction with GDPR principles, but does not suggest the existing framework is inadequate.

The CNIL makes abundantly clear that the GDPR’s core principles remain fully applicable in the context of agentic AI. The Note nonetheless lays out the practical difficulties principle-by-principle:

  • Lawfulness (Art. 5(1)(a); Art. 6): where autonomous operations may become detached from the legal basis initially identified;
  • Transparency (Art. 5(1)(a)): where outputs are difficult to explain given agentic systems’ complex architecture and the probabilistic nature of LLMs;
  • Purpose limitation (Art. 5(1)(b)): where general-purpose agents make the scope of processing hard to limit;
  • Data minimization (Art. 5(1)(c)): where agents ingest emails, browsing history, and files, share them with others, and store them in memory to anticipate user needs;
  • Accuracy (Art. 5(1)(d)): where the probabilistic nature of generative AI produces hallucinations that may propagate across a system; and
  • Storage limitation (Art. 5(1)(e)): where diffuse memory instances complicate monitoring of retention periods.

The Note also describes the difficulty of effectuating data subject rights under Arts. 15-22. Building on the CNIL’s earlier work on the exercise of rights in the context of generative AI, it observes that a data subject may struggle to determine which agent collected information, where it was stored, whether it was transmitted onward, and which controller to approach—with the practical consequence that rectification and erasure become difficult to implement comprehensively and traceably.

3. Delegation of decision-making may implicate Art. 22 and SCHUFA.

The Note characterizes agentic AI as effecting an implicit delegation of decision-making power from user to system. Where autonomous action produces legal or similarly significant effects, Art. 22 GDPR’s prohibition and its paragraph 2 exceptions apply.

The CNIL opines that the multiplicity of agents involved in a single task may make the assessment of actual human supervision more difficult. Citing the CJEU’s judgment in SCHUFA (Case C-634/21), it emphasizes that human intervention at the output stage is not necessarily sufficient: intervention must be real and effective, and must exert influence on the final decision.

4. Accountability across the value chain remains, in the Note’s framing, unresolved.

Under the GDPR, a controller must be identifiable and capable of demonstrating compliance, but the Note acknowledges that distributed architectures complicate the allocation of roles and responsibilities. Beyond data protection, the CNIL observes that civil and even criminal liability chains across the AI value chain can be unclear, and links that difficulty to the withdrawal in 2025 of the proposed EU AI Liability Directive. It notes that the EU AI Act does apply to agentic AI, and may be helpful in identifying roles of actors involved across the agentic system. Of course, French law remains applicable (including national tort and contract law) as well as, in some circumstances, the new European regime on liability for defective products (Directive (EU) 2024/2853).

5. Design-side mitigations are critical.

The Note suggests the implementation of traceability mechanisms permitting reconstruction of an entire decision-making workflow (the personal data used, agents involved, third-party services called, exchanges, and their chronology) as a means of both improving transparency and enhancing accountability. It also calls for granular user controls over which data agents may access, particularly sensitive data, and for sector-specific clarification of when agentic processing engages Art. 22.

On the technical side, the Note recommends several potential mechanisms for limiting the consequences of excessive autonomy, including detection and filtering measures applied not only to the initial user prompt but whenever a model is invoked by any agent; partitioning of memory by agent and by process (with size limits and automated expiry); sandboxed deployment environments; risk-tiered classification of actions (with human approval required for higher-risk actions); a user-accessible “kill switch;” and extension of independent evaluation efforts to cover data protection and security properties of agentic systems.

Looking Ahead

The Note flags that guidelines on the interplay between the GDPR and the AI Act are being prepared by the European Data Protection Board (“EDPB”) and the European Commission, and are expected by the end of 2026. The Note also suggests the EDPB follow its Opinion 28/2024 on AI models and 2026 guidelines on web scraping with recommendations tailored to developers and deployers of agentic AI. As agentic AI becomes increasingly prevalent, we expect additional regulators to weigh in on how existing legal frameworks apply.



Source link

Leave a Comment