When 'agentic AI' meets data protection law: A fundamental mismatch?

Agentic AI represents a seismic shift toward autonomous, goal-directed systems that can pursue open-ended objectives, create their own workflows and adapt in real time with limited human oversight. This development poses fundamental challenges to modern privacy and data protection laws which depend on assumptions about consent, purpose limitation and the distinction between personal and nonpersonal data.

Contributors:
Mark Fenwick
Professor of International Business Law
Kyushu University, Japan
Paulius Jurcys
AIGP, CIPP/E, CIPP/US
Senior IP Counsel
Vinted
Timo Minssen
Professor
University of Copenhagen
Modern agentic artificial intelligence introduces a distinct paradigm shift in data protection. Agentic AI refers to autonomous, goal-seeking systems capable of pursuing open-ended objectives and adapting continuously without persistent human direction. From a cognitive perspective, AI agents are capable of learning dynamically from their environment, revising their own goals and making decisions with minimal human oversight and control.
Adaptive AI agents are already gaining traction across sectors as diverse as finance, healthcare, logistics and robotics. To accelerate this transition, major AI developers are providing pre-built workflow templates that automate complex sequences or empower users to build custom-designed agentic architectures.
However, the rise of agentic AI reveals a profound and growing mismatch between the realities of machine autonomy and the well-established legal frameworks designed to govern digital systems and protect personal privacy. Crucially, agentic AI defies the foundational assumptions underpinning data protection regulations like the EU General Data Protection Regulation and California Consumer Privacy Act.
This tension is best illustrated by two systemic challenges. First, the rigid dichotomy between personal and nonpersonal data — a distinction central to regulatory scope — collapses within context-hungry, AI-mediated interactions. Second, core principles governing data processing, such as consent and purpose limitation, become functionally obsolete when the fluid, indeterminate and unpredictable intent of an autonomous agent cannot be determined ex ante.
Individual consent vs. unascertainable intent of an AI agent
Contributors:
Mark Fenwick
Professor of International Business Law
Kyushu University, Japan
Paulius Jurcys
AIGP, CIPP/E, CIPP/US
Senior IP Counsel
Vinted
Timo Minssen
Professor
University of Copenhagen