ANALYSISMEMBER

The case for differential privacy in the age of agentic AI

Published
Subscribe to IAPP Newsletters

Contributors:

Noemie Weinbaum

AIGP, CIPP/A, CIPP/C, CIPP/E, CIPP/US, CIPM, CIPT, CDPO/FR, FIP

Senior Managing Counsel, Privacy and Compliance

UKG

Roy Kamp

AIGP, CIPP/A, CIPP/E, CIPP/US, CIPM, CIPT, FIP

Legal Director

UKG

Editor's note: The IAPP is policy neutral. We publish contributed opinion and analysis pieces to enable our members to hear a broad spectrum of views in our domains.

Privacy has always evolved to keep pace with technology. We adjusted to cloud storage, machine learning and the Internet of Things. But agentic artificial intelligence systems — meaning systems that plan, reason and act autonomously — mark a more fundamental shift.

Unlike prompt-based models, which generate text or answers within predefined constraints, agentic AI systems behave like independent actors. They pursue goals, call application programming interfaces, chain together multistep reasoning, and even collaborate with other agents. They are not limited to analyzing data; they act upon it. And because their behavior is emergent and often unpredictable, they pose legal and regulatory challenges that earlier generations of AI never raised.

This shift forces us to ask hard questions. Who is the data controller when the AI system itself determines the means of processing? How do we ensure accountability when decisions emerge from autonomous planning rather than a human-defined rule set? And above all, how do we preserve privacy rights in a world where AI is continuously inferring, adapting and acting in real time?

One of the strongest answers available today is differential privacy.

Why agentic AI demands a new privacy paradigm

Supervisory authorities, such as the European Data Protection Board and the U.S. Federal Trade Commission, have been clear: privacy obligations apply regardless of the underlying technology. Yet agentic AI presents risks that older paradigms of privacy cannot easily contain.

Contributors:

Noemie Weinbaum

AIGP, CIPP/A, CIPP/C, CIPP/E, CIPP/US, CIPM, CIPT, CDPO/FR, FIP

Senior Managing Counsel, Privacy and Compliance

UKG

Roy Kamp

AIGP, CIPP/A, CIPP/E, CIPP/US, CIPM, CIPT, FIP

Legal Director

UKG

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership