Agentic AI and GDPR: the CNIL–CIANum note of July 20, 2026
The CNIL and CIANum say agentic AI puts GDPR principles under strain: memory, data flows between services, blurred responsibility. Their proposals, applied to an SME.
In short: on July 20, 2026, France’s data protection authority (CNIL) and the Conseil de l’IA et du Numérique (CIANum) published an exploratory note, “IA agentique et protection des données personnelles : équation à inconnues multiples pour les utilisateurs” (announcement, note in PDF, in French). It is neither a recommendation nor a new rule: it is an analysis concluding that GDPR fully applies to AI agents, but that their persistent memory, decision-making autonomy and ability to act across many services “put its principles under strain”. It proposes legal and technical ways forward. The work echoes discussions at the G7 of data protection authorities hosted by the CNIL during France’s G7 presidency.
What the note says, point by point
| What the note observes | GDPR principle under strain | Proposed way forward |
|---|---|---|
| Agents draw on large amounts of data (emails, browsing history, files), share it between agents and keep it in memory | Data minimization (art. 5(1)(c)): the need to process all of it “is not always easy to demonstrate” | Let the user choose which data the system can access; process only what the task strictly requires |
| Persistent memory and interaction history build very precise user profiles | Storage limitation, right to erasure | Memory isolated per agent and per processing purpose, capped in size, with automatic expiry |
| Data flows between many services, sometimes opaque | Transparency | Traceability: for each task, the personal data used, the agents involved, the third-party services called and the timeline |
| Decentralized chain of actors | Accountability: who is responsible for what | Strict integration protocols with third-party services; classify possible actions by risk level |
| Increased decision-making autonomy | Automated decisions (art. 22) | Human validation before critical actions; an emergency stop (“kill switch”); isolated execution environment (sandboxing) |
| Misuse and malicious use | Security | Detection and filtering of requests, real-time monitoring of agent actions, robustness testing before and during deployment |
The note also points out that the EU AI Act already applies to agentic systems without defining them as a specific category or setting rules specific to them, and that its full application is scheduled for 2027. It adds no obligation: it shows how the CNIL reads GDPR when applied to agents, and which safeguards it expects to see built in from the design stage.
What the research confirms
A 2026 survey by Bhosale, Chandre, Mehetre, Powar, Mathur and Ghandat, The dark side of autonomous intelligence: a survey on data leakage and privacy failures in agentic AI (Frontiers in Computer Science), describes the same shift: moving from stateless language models to agents with persistent memory, tool use and multi-agent collaboration creates a new class of privacy risk — unintended retention, propagation and amplification of sensitive information across tasks, users and execution cycles. The authors map leakage pathways through each component of an agent: memory modules, planning, tool calls, communication between agents and feedback loops. It is the architecture around the model, not the model alone, that creates the exposure — which is why the CNIL’s proposals target memory, access and traceability.
Applying the note in an SME: six checks
- →Access inventory: for each agent, list the mailboxes, folders, applications and categories of personal data its connectors actually reach, and remove what the task does not need.
- →Action log: keep, for each task, the data read, the tools called, the actions taken and when. It is the traceability the note describes, and your only way to answer an access request or explain a mistake.
- →Memory: one memory per agent and per use, with a written retention period; no shared memory kept “just in case”.
- →Human validation: classify actions (read, modify, delete, send outside the company) and require a person’s approval for the riskiest — a payment, a message to a customer, a deletion.
- →Emergency stop: make sure someone can cut an agent off immediately.
- →Records: add the processing to your GDPR record of processing activities and, if the agent handles sensitive data or data at scale, check whether a data protection impact assessment is required.
For customer-facing agents, the AI Act adds a transparency duty covered in our article on the AI Act in France.
Frequently asked questions
Does the CNIL’s July 20, 2026 note create new obligations for AI agents?+
No. It is an exploratory note written with the CIANum. It states that GDPR already applies to agentic AI and that the AI Act applies too, without rules specific to agents; it proposes how to implement existing rules, through transparency, user control over data and technical safeguards.
What risks does the note identify?+
A loss of control by users over their personal data, very precise profiles built through persistent memory, opaque data flows between many services, responsibilities that are hard to assign across the chain of actors, and cybersecurity risks extended to every service connected to the agent.
Which technical measures does the note propose?+
Memory isolated per agent and per processing purpose with limited size and automatic expiry, sandboxed execution, a kill switch in the user’s hands, human validation before critical actions, traceability of each task, and detection and filtering of misuse.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
Gemini can now read and write into your CRM from Gmail — who in your SMB decided that?
20 September 2026·5 min read
Business & compliance
The EU Cyber Resilience Act’s vulnerability-reporting duty is now live — and it may already apply to your software
13 September 2026·5 min read
Business & compliance
CNIL fines Extia €300,000 over botched erasure requests: what it changes for any SMB that recruits
10 September 2026·4 min read