From the journal

CNIL and CIANum Publish Exploratory Note on Agentic AI and Personal Data on 20 July 2026

On 20 July 2026, France's CNIL and the Conseil de l'IA et du Numerique (CIANum) jointly published an exploratory note on the GDPR risks raised by agentic AI systems. The note identifies how AI agents' autonomous cross-service data access, persistent memory retention, and capacity to act on users' behalf create tensions with GDPR purpose limitation, data minimisation, and controller identification rules under Articles 5, 24, and 28.

3 min read

On 20 July 2026, the Commission Nationale de l'Informatique et des Libertes (CNIL) and the Conseil de l'IA et du Numerique (CIANum) jointly published an exploratory note on agentic AI and personal data. The note is analytical, not prescriptive: it does not set compliance deadlines or announce enforcement actions. It maps the data protection risks raised by AI systems that autonomously complete multi-step tasks across multiple connected services, and identifies technical and legal measures that providers and deployers can adopt ahead of formal CNIL guidance.

The note's central concern is the tension between agentic AI operations and Article 5(1)(b) and (c) of the GDPR, which impose purpose limitation and data minimisation obligations on data controllers. Agentic AI systems collect and transmit personal data across multiple connected services in volumes far beyond what a user would disclose in a single interaction. Persistent memory storage enables the creation of hyper-personalised user profiles over extended periods. In orchestration architectures where a master agent delegates tasks to multiple sub-agents, the CNIL and CIANum identify it as structurally difficult to determine the controller and processor under Articles 24 and 28, and to trace data flows for data subject access requests under Article 15.

AI agent providers, enterprise deployers using agentic systems in HR, customer service, legal, or financial processes, and platform operators connecting agentic systems to third-party services face the most direct exposure. The note recommends traceability mechanisms enabling data subjects to audit data accessed and actions taken on their behalf, partitioning of agent memory by process, sandboxed deployment environments, risk-tiered action classification with human approval required for higher-risk actions, and a user-accessible system override capability.

The note is exploratory rather than formal guidance. The CNIL signals that recommendations specifically targeting agentic AI providers and deployers are forthcoming. Organisations deploying agentic systems in France, or processing personal data of French data subjects, should treat the note's risk analysis as an indicator of the supervisory expectations that formal guidance will codify.

Licentium advises clients on GDPR compliance for AI-enabled workflows, including agentic systems in regulated environments. Contact us to discuss data mapping, controller-processor boundary analysis, and data minimisation approaches for agentic AI deployments. Work we undertake includes GDPR impact assessments for AI agents, data processing agreement reviews for multi-model orchestration architectures, data subject rights processes for agentic systems, and engagement with European data protection authorities.

Source: CNIL and CIANum, IA agentique et donnees personnelles: la CNIL et le Conseil de l'IA et du Numerique publient une note exploratoire, CNIL, 20 July 2026

More from the journal

See all

UKJT Publishes Final Legal Statement on AI Liability Under English Private Law on 7 July 2026

The UK Jurisdiction Taskforce published its final Legal Statement on Liability for AI Harms under the private law of England and Wales on 7 July 2026, providing authoritative analysis of when English common law imposes liability for non-deliberate loss caused by AI systems. The statement covers negligence, product liability, contract, and strict liability doctrines as applied to increasingly autonomous AI deployments.

EU AI Omnibus Enters Into Force on 27 July 2026, Amending AI Act Timelines and SME Obligations

Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026, amending the EU AI Act to extend compliance deadlines, expand regulatory sandbox access, and reduce administrative burdens for SMEs and small mid-cap companies. Annex III high-risk AI obligations shift to 2 December 2027; Annex I product-embedded systems to 2 August 2028. Core prohibitions and GPAI model rules are unchanged.

Senate Majority Leader Files Cloture on Digital Asset Market Clarity Act on 7 August 2026

On 7 August 2026, Senate Majority Leader John Thune filed a cloture motion on the motion to proceed to H.R. 3633, the Digital Asset Market Clarity Act (CLARITY Act), advancing the bill toward a Senate floor vote. The CLARITY Act passed the Senate Banking Committee 15-9 in May 2026 and would create a joint SEC-CFTC structure assigning CFTC jurisdiction over digital commodities and SEC jurisdiction over digital securities.