Agentic AI and personal data: what the CNIL’s July 20, 2026 note changes for your AI agents
The CNIL and the Conseil de l’IA et du Numérique published a joint note on July 20, 2026: agentic AI’s autonomy, persistent memory and ability to act across multiple services mark a genuine change of scale in the risk to personal data. No new rule was created — but the note is a clear signal on how existing ones will be checked. What it means for an SME running AI agents.
On July 20, 2026, the CNIL and the Conseil de l’IA et du Numérique (CIANum) jointly published an exploratory note on agentic AI and personal data. Its starting point is simple: an agentic AI system no longer just answers a question — it can access data across multiple connected services, chain several actions on its own, and act on a person’s behalf without a human validating each step. For the two bodies, this is not a variation on the risks already known from chatbots and generative AI — it is, in their words, “a change of scale that renews and amplifies” the risk to users’ personal data. No SME running or considering an AI agent connected to its mailbox, its CRM or its invoicing system is a bystander to this note.
What actually changes at scale
- →Decision-making autonomy: an agent chooses, within a scope it was given, which data to use and which action to take — rather than a human choosing each step, which is what most GDPR safeguards assume.
- →Persistent memory: an agent that remembers what it has seen across sessions can end up holding, and reusing, far more personal data than any single task required.
- →Action across multiple connected services: personal data can circulate between several tools an agent touches in the course of one task, in a chain that the CNIL and CIANum describe as “difficult for the user to grasp” — creating what the note calls a real risk of losing control over one’s own personal data.
- →The note is explicit that the existing legal toolkit — GDPR, the AI Act — already applies to these systems; what it says needs adapting is how that toolkit gets implemented in practice, through technical control and supervision mechanisms built into the agent itself.
A pattern the research confirms independently
The CNIL and CIANum’s note is not an isolated warning. A 2026 survey by Bhosale, Chandre, Mehetre, Powar, Mathur and Ghandat, The dark side of autonomous intelligence: a survey on data leakage and privacy failures in agentic AI, published in Frontiers in Computer Science, maps how sensitive information flows through autonomous AI systems and identifies leakage pathways that go well beyond those of a standard large language model — precisely because of the combination the CNIL note flags: standing memory across tasks, and the ability to act through several connected tools rather than answer a single prompt. Two independent sources, a regulator and a peer-reviewed survey, converge on the same diagnosis: it is the autonomy and the persistence, not the underlying model, that create the new exposure.
What it means for your SME
If you already run an agent that follows up on unpaid invoices, sorts incoming email, or drafts a report by pulling from several internal tools, the note’s scenario is not hypothetical — it is a description of how that agent already works. The risk it names most precisely is what it calls an “illusion of consent”: a customer or employee agrees once to a general use of their data, then an agent goes on to touch that data repeatedly, in ways and across services the original consent never specifically covered. For an SME, the practical question is not whether to stop using agents — it is whether you could currently produce, for any single agent, a clear answer to what data it can reach, what it does with it, and a record of what it actually did.
Before your next agent deployment: four concrete checks
- →Map, for each agent already in production, exactly which systems and which categories of personal data it can reach — not what it needs on paper, but what its actual connector permissions allow today.
- →Keep a consultable log of every action an agent takes on personal data — without one, the “technical control and supervision” the note calls for does not exist in practice, whatever the agent’s prompt says it should do.
- →Do not treat a customer’s or employee’s original consent as covering everything an agent later does with their data — if a new use case is added to an agent’s scope, check whether it still fits inside what was actually consented to.
- →Reassess memory retention specifically: an agent that keeps everything it has ever seen “just in case” is the exact pattern the note and the research both flag as the highest-exposure design choice.
This is exactly the kind of text — no new obligation created, but a clear signal of where scrutiny is heading — that a regulatory watch agent exists to catch early: reading the CNIL’s and CIANum’s publications, isolating what actually changes for an SME already running agents, and flagging it before an audit does it for you.
Frequently asked questions
Does the CNIL’s July 20, 2026 note create new legal obligations for AI agents?+
No. The note is explicit that GDPR and the AI Act already apply to agentic AI systems. What it signals is that their specific characteristics — autonomy, persistent memory, action across multiple services — require adapting how those existing rules are implemented, through technical control and supervision mechanisms, rather than through new legislation.
What is the main risk the CNIL and CIANum identify with agentic AI?+
A “change of scale” in risk to personal data compared to earlier AI tools: an agent can access and chain data across several connected services on a user’s behalf, in processing chains the note describes as difficult for the user to grasp — creating what it calls a real risk of losing control over one’s personal data.
What should an SME running AI agents check first?+
For each agent in production: which systems and data categories it can actually reach, whether a consultable log exists of what it has done, whether its scope still matches what was originally consented to, and whether it retains more data in memory than the task at hand requires.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
EU AI Act: what became mandatory on August 2, 2026 — and what it means for your SMB
19 August 2026·5 min read
Business & compliance
Claude now watermarks its text: what Anthropic’s move changes — and doesn’t — for your SMB’s AI content
18 August 2026·5 min read
Business & compliance
Computer History: ChatGPT now remembers your activity — except in France (for now)
17 August 2026·5 min read