Skip to Content
ANALYSISMEMBER

When 'agentic AI' meets data protection law: A fundamental mismatch?

Agentic AI represents a seismic shift toward autonomous, goal-directed systems that can pursue open-ended objectives, create their own workflows and adapt in real time with limited human oversight. This development poses fundamental challenges to modern privacy and data protection laws which depend on assumptions about consent, purpose limitation and the distinction between personal and nonpersonal data.

Published
Subscribe to IAPP newsletters

Contributors:

Mark Fenwick

Professor of International Business Law

Kyushu University, Japan

Paulius Jurcys

AIGP, CIPP/E, CIPP/US

Senior IP Counsel

Vinted

Timo Minssen

Professor

University of Copenhagen

Modern agentic artificial intelligence introduces a distinct paradigm shift in data protection. Agentic AI refers to autonomous, goal-seeking systems capable of pursuing open-ended objectives and adapting continuously without persistent human direction. From a cognitive perspective, AI agents are capable of learning dynamically from their environment, revising their own goals and making decisions with minimal human oversight and control. 

Adaptive AI agents are already gaining traction across sectors as diverse as finance, healthcare, logistics and robotics. To accelerate this transition, major AI developers are providing pre-built workflow templates that automate complex sequences or empower users to build custom-designed agentic architectures. 

However, the rise of agentic AI reveals a profound and growing mismatch between the realities of machine autonomy and the well-established legal frameworks designed to govern digital systems and protect personal privacy. Crucially, agentic AI defies the foundational assumptions underpinning data protection regulations like the EU General Data Protection Regulation and California Consumer Privacy Act. 

This tension is best illustrated by two systemic challenges. First, the rigid dichotomy between personal and nonpersonal data — a distinction central to regulatory scope — collapses within context-hungry, AI-mediated interactions. Second, core principles governing data processing, such as consent and purpose limitation, become functionally obsolete when the fluid, indeterminate and unpredictable intent of an autonomous agent cannot be determined ex ante.

Individual consent vs. unascertainable intent of an AI agent

Contributors:

Mark Fenwick

Professor of International Business Law

Kyushu University, Japan

Paulius Jurcys

AIGP, CIPP/E, CIPP/US

Senior IP Counsel

Vinted

Timo Minssen

Professor

University of Copenhagen

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership