AI Policy Wiki
Dashboard

Data protection in the era of agentic artificial intelligence (Beduschi)

high confidence · updated 2026-08-02

Peer-reviewed law article (Computer Law & Security Review, May 2026) asking whether the GDPR remains adequate for agentic AI. Concludes the controller-processor model holds but data-subject rights strain, and proposes a six-level model of agentic autonomy for applying GDPR Article 22.

"Data protection in the era of agentic artificial intelligence" is a peer-reviewed article by Ana Beduschi, professor of law at the University of Exeter, published open access in Computer Law & Security Review volume 61, article 106342, on 12 May 2026 (DOI 10.1016/j.clsr.2026.106342). It asks whether the EU General Data Protection Regulation remains adequate for AI systems that pursue goals and coordinate multi-step actions with limited human input, and answers that the GDPR is not obsolete but that its limits are exposed at three specific points. Its central contribution is a six-level model of agentic autonomy for determining when GDPR Article 22 applies (Source: doi.org).

The article is the first academic treatment of the problem Three Privacy Problems AI Creates describes as data flowing across multiple AI systems with no point at which a human is notified or asked to consent. It examines the GDPR primarily, with the EU AI Act, the Data Act (Regulation (EU) 2023/2854) and the European Health Data Space Regulation (Regulation (EU) 2025/327) where relevant, and it engages the pending Omnibus IV, Digital Omnibus and Digital Omnibus on AI proposals while noting that the co-legislators had not approved the Digital Omnibus at the time of writing.

Argument

The controller-processor model holds

Beduschi frames the question through a healthcare scenario: where providers use an agentic system to analyse sensitive patient health and biometric data and to act on treatment, is the agent or its human collaborators the controller? She concludes that agentic AI does not fundamentally disrupt the GDPR's binary controller-processor model, "at least not for now," because only natural persons or legal entities can be controllers or processors. Agentic systems "regardless of their sophistication and proactive approaches to task management and problem-solving, cannot qualify as controllers (individually or jointly) under the GDPR" — even under the Court of Justice's broad reading, which has treated a Facebook fan-page administrator and a website using third-party social plugins as joint controllers, and has held that joint controllership does not require direct access to the data.

The difficulty she identifies is delegation rather than classification. The controller still defines the purpose and means of processing, but agents "may exercise some discretion in selecting methods, approaches, task sequences, and adapting strategies, thereby shaping, in practice, the means of processing personal data." Under the European Health Data Space the controller and processor concepts are unchanged, but the regulation adds a "health data holder" concept covering non-personal electronic health data as well.

Data-subject rights strain

Beduschi finds that varying degrees of agent autonomy introduce a "complex, sometimes ambiguous accountability chain." On the right of access, the duty to give meaningful information may cover not only a predefined model's logic but "the evolving manner in which a broad objective is operationalised into evaluative steps by an adaptive AI agent" — shifting the task "from explaining a single output to reconstructing a dynamic decision process, which may, in practice, prove extremely difficult." On portability, she argues that in contexts such as healthcare under the EHDS the right may reach beyond stored personal information to data about agentic operations. On erasure, she argues that personal data influences an agent's evolving decision processes in ways that "cannot simply be deleted," which she characterises as a gap between legal standards and technical realities, engaging the machine-unlearning literature.

She distinguishes agentic from generative systems on this point: both are opaque, but agentic systems "operate autonomously over time, connecting multiple decisions and pursuing goals through self-guided steps," so their workings "are not limited to a single inferential moment but develop into adaptive actions."

The six-level autonomy model

The article's framework addresses GDPR Article 22(1), under which a data subject has the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them. The controlling authority is Case C-634/21, OQ v Land Hessen (SCHUFA Holding (Scoring)) [2023] EU:C:2023:957, in which the Court held that a credit-scoring probability value used by a bank to inform a loan refusal is itself a decision based solely on automated processing, and set three cumulative conditions: a decision; based solely on automated processing including profiling; producing legal or similarly significant effects.

Beduschi argues that the existing debate "proceeds on the basis of a binary distinction between human and machine decision-making," while agentic systems "operate along a continuum of autonomy." Extending a five-level framework by Feng, McDonald and Zhang — in which the user moves from active operator to collaborator, consultant, approver and finally passive observer as agent autonomy rises — she sets out six levels:

LevelConfiguration
1Human decision
2Collaboration between a human and an AI agent, resulting in either party's decision
3AI agent's decision after seeking human approval
4AI agent's decision after consulting a human
5AI agent's decision observed by a human
6AI agent's decision with no human input or monitoring

Applying the SCHUFA conditions to a hiring scenario in which an agent selects and rejects candidates, she concludes that rejection "should activate Article 22(1) of the GDPR at all levels of the AI agent's autonomy, except at the initial level where the human recruiter maintains full control, provided that their decision does not rely heavily on the AI agent's input." At levels 2–6 the decision remains primarily automated "even if it seeks human input, advice, or approval" — so approval-in-the-loop and consultation-in-the-loop designs do not, on this reading, take a decision outside Article 22. She notes that the Digital Omnibus could expand the lawful grounds for automated decisions, particularly on contractual necessity, but would leave the definition of a decision "based solely on automated processing" governed by existing case law.

Compare Levels of Autonomy for AI Agents (Feng-McDonald-Zhang framework), which collects the other graduated-autonomy schemes; Beduschi's is distinguished by being keyed to a specific legal test rather than to capability.

Graduated safeguards

The article argues that human intervention must be calibrated to autonomy level: "As AI agents' autonomy increases, safeguards should shift from embedded human involvement and intervention to more structured, system-level, ongoing oversight that can recalibrate and, if needed, stop autonomous processes." Its overall recommendation is to combine data protection with fundamental-rights impact assessments, governance and accountability measures across the system lifecycle and across actors: developers implementing technical and organisational measures that enable compliance and oversight, and deployers verifying those capabilities are enabled, conducting DPIAs and FRIAs, auditing outputs, and reporting anomalies that could require re-adjusting the agent's initial goals.

Beduschi positions the contribution as aligning the GDPR's individual-level human-intervention right with the AI Act's system-level human-oversight obligation, alongside FRIAs, regulatory sandboxes and red teaming. See Human Oversight.

Provenance

Published open access under CC BY as the Version of Record; a copy is deposited in the University of Exeter's ORE repository (ore.exeter.ac.uk). Submitted 18 August 2025, published online 12 May 2026. The author declares no competing interest and states that no data was used in the research.

Relationships