Agentic Artificial Intelligence from a Data Protection Perspective

On 2 August 2026, Regulation (EU) 2024/1689 of the European Parliament and of the Council, of 13 June 2024, laying down harmonised rules on artificial intelligence (the AI Act), will become applicable. The Regulation prohibits certain uses of Artificial Intelligence (AI), classifies certain AI systems as high-risk systems and establishes demanding requirements for them, and imposes transparency obligations in relation to AI systems classified as limited-risk systems.

To the extent that personal data is processed for the training, deployment and use of AI systems, the AI Act and Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), must be applied in parallel.

In fact, the Spanish Data Protection Agency (AEPD) has already warned that the use of AI tools “would be an additional factor confirming the need to carry out” Data Protection Impact Assessments, as such use would add a further risk to the processing operations carried out “due to its nature as a novel technology”.

Therefore, compliance with the AI Act does not exempt organisations from complying with the applicable provisions of current personal data protection legislation.

In 2020, the AEPD published a Guide on GDPR compliance for processing operations involving artificial intelligence, currently under review, which identified the most relevant aspects of the AI-GDPR relationship that must be taken into account from the design stage and during the implementation of processing operations involving AI.

In February of this year, in order to address the data protection issues that may arise when controllers and processors decide to use Agentic AI systems to implement personal data processing operations, the AEPD published guidance on Agentic Artificial Intelligence from a Data Protection Perspective.

An AI agent is a system that uses language models to achieve a goal. These are autonomous systems that can operate without human intervention, carry out actions such as interacting with users, sending information or executing contracts, act proactively, and plan and reason. They do all this while perceiving their environment, meaning that they interpret dynamic contexts. In addition, they may have memory, accumulate experience and adjust their behaviour as they are used; in other words, they are adaptable.

Another defining feature is their ability to make calls to services, which may be local, such as the user’s databases, or remote, such as websites.

The document does not analyse the compliance of a specific processing operation carried out wholly or partly through AI. Instead, it explains how to manage the specific features that arise in a processing operation because it is carried out using Agentic AI.

It also provides a non-exhaustive list of the vulnerabilities and threats that may arise from the use of Agentic AI systems within organisations. The list is non-exhaustive because the rapid evolution of AI tools results in the continuous, almost real-time transformation of such vulnerabilities and threats.

However, it does emphasise a key concept for compliance with data protection regulations: knowledge.

Without knowledge of the AI’s chain of reasoning —the logical steps into which the agent breaks down a problem in order to arrive at a solution— it will not be possible to understand the data lifecycle, the source of the data, when, where, by whom, for what purpose and on what legal basis the data is processed, among other aspects.

The more complex the data lifecycle is, and the more parties involved in it —for example, through the interaction of different AI systems capable of making calls to websites— the more necessary this knowledge becomes in order to detect vulnerabilities and apply appropriate technical and organisational security measures.

The architecture of the system must be known in detail. For example, AI may involve interaction with numerous internal and external services, exposing personal data to a processing chain involving not only the controller but also multiple entities, each subject to the privacy policies, cookie policies, terms of service and contractual terms of the relevant third-party tools.

Likewise, external connections also present vulnerabilities. In order to obtain information, the system may use sources that are unsuitable, outdated, incomplete, biased or misinformed. With regard to local information sent externally, excessive freedom in invoking tools that collect internal information could result in the disclosure of unnecessary information.

With regard to data subjects’ rights, a lack of knowledge of how personal data storage and processing operations function would impair the exercise of those rights. Systems must be technically configured from the design stage to allow the management of data subjects’ rights.

It should also be noted that knowledge of the system may serve purposes beyond data protection, such as the control of trade secrets or intellectual and industrial property.

In any event, knowledge of the tools and of how they interact with their environment makes it possible to comply with all processing principles. Without such knowledge, it will not be possible to properly inform data subjects about the processing of their data and, certainly, it will not be possible to know whether the data processed is limited to the purpose for which it was collected, whether it is limited to what is necessary, whether it is accurate —especially when data is collected from sources other than the controller or processor— whether it is retained for longer than necessary, or whether appropriate technical and organisational measures have been established to ensure data security.

The AEPD states that the Record of Processing Activities once again becomes a fundamental tool for managing compliance with data protection regulations. It identifies the purposes of the processing, the categories of data subjects and personal data, the categories of recipients and any international transfers.

In addition, the AEPD recalls that the GDPR establishes only the minimum content of the Record of Processing Activities, not the maximum. Therefore, both controllers and processors must determine what additional information they may need to include in relation to the Agentic AI systems they use to implement processing operations.

Finally, as regards knowledge, the Guide includes a section recalling the importance of AI literacy for the efficiency and effectiveness of its implementation in processing operations. Knowledge of AI systems, particularly their limitations and weaknesses, enables effective data protection.

Latest news

Datax - Soluciones legales a medida para tu negocio

Barcelona 
Rambla Catalunya 66, 2ªC.
08007 Barcelona
T 93 754 06 88
info@datax.es

Mataró
Edificio Blaumar
C/ de la Bobinadora,  Nº 1-5.
Planta 1, Locales 15 y 17
08302 Mataró
T 93 754 06 88
info@datax.es

Latest Data Protection Updates

Subscribe to Our Newsletter


    PROTECCIÓN DE DATOS DATAX, SLU, as the data controller, will process your data for the purpose of managing your subscription to our newsletter and sending you informative and commercial communications regarding our services. You may access, rectify, and erase your data, as well as exercise other rights, by consulting the additional and detailed data protection information in our Privacy Policy


    Solicitar infoSolicitar info
    Call us
    Contact us
    Datax
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.