This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
Norton Rose Fulbright logo
  • Global
  • About
    • Our firm
      • Clients
      • Global coverage
      • Vision, culture and people
      • Governance structure
      • Risk management
      • NRF Transform
      • Alumni
    • Diversity, Equity & Inclusion
      • Strategy, goals and priorities
      • Governance and policy
      • Resource groups
    • Responsible business
      • Volunteering
      • Fundraising
      • Sustainable practice
      • Global charitable initiatives
      • Responsible use of AI
  • People
  • Services
    • Services A-Z
    • Key industries
      • Consumer markets
      • Energy, infrastructure and resources
      • Financial institutions
      • Life sciences and healthcare
      • Technology
      • Transport
    • Practices
      • Antitrust and competition
      • Banking and finance
      • Climate change and sustainability
      • Corporate, M&A and securities
      • Cybersecurity and data privacy
      • Employment and labor
      • Energy
      • Environmental, social and governance (ESG)
      • Financial services and regulation
      • Intellectual property
      • Litigation and disputes
      • Projects
      • Real estate
      • Regulation and investigations
      • Restructuring
      • Risk advisory
      • Tax
    • Practices
      • Antitrust and competition
      • Banking and finance
      • Climate change and sustainability
      • Corporate, M&A and securities
      • Cybersecurity and data privacy
      • Employment and labor
      • Energy
      • Environmental, social and governance (ESG)
      • Financial services and regulation
      • Intellectual property
      • Litigation and disputes
      • Projects
      • Real estate
      • Regulation and investigations
      • Restructuring
      • Risk advisory
      • Tax
      • Banking and finance
      • Corporate, M&A and securities
      • Employment and labor
      • Environmental, social and governance (ESG)
      • Intellectual property
      • Projects
      • Regulation and investigations
      • Risk advisory
    • NRF Transform
    • Transform image

      Find out more
  • Insights
    • Publications Podcasts Blogs
    • Webinars and events Videos
    • Professional development Resources and tools
    • colorful light particles
      Trending topics
      • Artificial intelligence
      • Data centers
      • Energy transition
      • International trade and tariffs
    • Trending topics
      • Artificial intelligence
      • Data centers
      • Energy transition
      • International trade and tariffs
  • News
    • Press releases
    • Market recognitions
    • Media information
  • Locations
  • Careers
    • Graduates and students
    • Search current vacancies
  • Careers
    • Graduates and students
    • Search current vacancies
  • Change
  • Global
    • global site
    • North America
      • Canada (English)
      • Canada (Français)
      • United States
    • Latin America
    • Europe
      • Belgium
      • Deutschland (Deutsch)
      • France
      • Germany (English)
      • Greece
      • Italy
      • Luxembourg
      • Poland
      • The Netherlands
      • Turkey
      • United Kingdom
    • Middle East
    • Africa
      • Morocco
    • Asia Pacific
      • Australia
      • China
      • Hong Kong SAR
      • Indonesia
      • Japan
      • Singapore
      • Thailand
    • Regional practices
      • India
      • Israel
      • Korea
      • Marshall Islands
      • Nordic region
      • Pakistan
      • Vietnam
Lake in the forest

Connections

Insights, perspectives and viewpoints from our lawyers on topical issues

All Posts Subscribe
print-logo
8/18/2026 1:08:31 PM | 5 minute read

The French National Data Protection Authority and the AI and Digital Council publish exploratory note on agentic AI

Agentic AI technology concept with coding and digital gears. Artificial intelligence automation, machine learning, and futuristic innovation for business solutions.
11

Get in touch

Avatar
Nadège Martin
Partner
Avatar
Geoffroy Coulouvrat
Counsel
Avatar
Laura Helloco
Associate

Get in touch

Avatar
Nadège Martin
Partner
Avatar
Geoffroy Coulouvrat
Counsel
Avatar
Laura Helloco
Associate
11

English version below

La CNIL et le Conseil de l’IA et du numérique publient une note d’exploration sur l’IA agentique et les données personnelles

 

Des traitements à une échelle différente

Avec l’IA agentique, les usages de l’intelligence artificielle changent de dimension : ces systèmes se caractérisent par une autonomie croissante et par la mise en réseau de plusieurs agents entre eux. C’est dans ce contexte que la CNIL et le Conseil de l’IA et du numérique ont publié, le 20 juillet 2026, une note intitulée « IA agentique et protection des données personnelles : équation à inconnues multiples pour les utilisateurs ».

Ces systèmes s’organisent autour d’un agent central qui pilote et dirige des agents spécialisés dédiés à des tâches précises. La gestion des données s’articule autour de deux processus distincts : d’une part, le traitement des requêtes, dont les informations sont supprimées après exécution ; d’autre part, le stockage en mémoire qui permet de conserver certaines données d’un échange à l’autre.

Ces systèmes traitent d’importants volumes de données personnelles, y compris des données sensibles, dans un contexte où la régulation n’a pas anticipé ce cas de figure précis et où les traitements demeurent particulièrement opaques. Ces caractéristiques peuvent entrer en tension avec les principes fondamentaux du RGPD et la CNIL partage des réfléxions préliminaires sur le sujet.

La perte de contrôle de l’utilisateur

Ces tensions se traduisent d’abord par un risque de perte de maîtrise des données par l’utilisateur : la note souligne que l’IA agentique peut conduire l’utilisateur à perdre le contrôle sur ses données personnelles. Ces systèmes développent une connaissance approfondie et évolutive de l’utilisateur grâce à une mémoire persistante, tout en dispersant les données au sein de multiples agents. Cette dispersion complexifie l’exercice par l’utilisateur de ses droits issus du RGPD.

La note alerte sur le risque que l’IA exécute de manière autonome l’intégralité d’une requête, ce qui peut entraîner des effets négatifs lorsque l’intention de l’utilisateur et l’interprétation de l’IA ne sont pas alignées.

Un cadre de responsabilité moins clair

Cette autonomie ne pèse pas seulement sur la maîtrise des données par l’utilisateur : elle brouille également la chaîne de responsabilité. Dans un écosystème impliquant de nombreuses interactions entre agents, il est difficile d’identifier la personne responsable vers laquelle se tourner pour faire respecter les droits en matière de protection des données.

Au-delà du RGPD, la responsabilité civile ou pénale reste également difficile à établir en raison de cette multiplicité d’acteurs. L’abandon du projet de directive européenne sur la responsabilité en matière d’IA en 2025 renforce l’importance de cette question. Par ailleurs, la multiplication des acteurs au sein de ces systèmes accroît les risques de cyberattaques.

Le cadre légal existant

Face à ces risques, le cadre juridique applicable aux IA agentiques demeure un levier essentiel de maîtrise de ces nouveaux usages. Le RGPD demeure ainsi pleinement applicable aux systèmes d’IA agentiques, de même que les autres textes en vigueur. Toutefois, la note souligne que les spécificités de ces systèmes nécessitent une adaptation des instruments de régulation existants. L’une des premières étapes en ce sens sera la publication, fin 2026, des lignes directrices du CEPD et de la Commission européenne sur l’articulation entre le RGPD et le règlement sur l’IA.

Interprétation de la note 

Au-delà de ce cadre légal, cette note témoigne avant tout de l’intérêt croissant de la CNIL, et plus largement des institutions, pour l'encadrement des systèmes d’IA agentique. Bien que dépourvue d’effet contraignant, elle invite les acteurs à prendre conscience des spécificités de ces technologies et des risques qu’elles comportent, afin de concilier innovation technologique et effectivité du cadre juridique.

À titre de recommandations, la note préconise plusieurs approches et précautions d'usage, notamment la détection et le filtrage des usages détournés, le cloisonnement de la mémoire par agent et par traitement, le maintien d’une supervision humaine pour les actions critiques, ou encore l’intégration d’un mécanisme de type « kill switch».

 

**English version**

The French National Data Protection Authority and the AI and Digital Council publish exploratory note on agentic AI 

 

Personal data processing at a different scale

With agentic AI, the uses of artificial intelligence are changing in scale: these systems are characterised by increasing autonomy and interconnections between multiple agents. It is in this context that the French National Data protection Authority and the AI and Digital Council published, on 20 July 2026, a note entitled “Agentic AI and personal data protection: an equation with multiple unknowns for users”.

These systems are organised around a central agent that directs specialised agents dedicated to specific tasks. Data management revolves around two distinct processes: on the one hand, the processing of requests, where information is deleted after execution; on the other hand, memory storage, which retains certain data from one exchange to the next.

These systems process large volumes of personal data, including sensitive data, in a context where regulation has not anticipated this specific scenario and where processing remains particularly opaque. These characteristics may conflict with the fundamental principles of the GDPR, and the CNIL is sharing preliminary reflections on the issue.

Loss of user control

These tensions surface first in a loss of user control: the note highlights that agentic AI may lead users to lose control over their personal data. These systems develop a deep and evolving knowledge of the user through persistent memory, while dispersing data across multiple agents. This dispersion complicates the exercise by users of their rights under the GDPR, such as access, rectification, or erasure.

The note warns of the risk that AI may autonomously execute an entire request, which can lead to negative effects when the user’s intention and the AI’s interpretation are not aligned.

A less clear framework of liability

This autonomy affects not only users’ control over their data, but also blurs the chain of liability. In an ecosystem involving numerous interactions between agents, it is difficult to identify the responsible person to whom one should turn to enforce data protection rights.

Beyond the GDPR, civil or criminal liability also remains difficult to establish due to this multiplicity of actors. The abandonment of the European AI liability directive project in 2025 reinforces the importance of this issue. Furthermore, the proliferation of actors within these systems increases the risks of cyberattacks.

The existing legal framework

Given these risks, the legal framework applicable to agentic AI remains an essential lever for managing these new uses. The GDPR thus remains fully applicable to agentic AI systems, as do other texts in force. However, the note emphasises that the specificities of these systems require an adaptation of existing regulatory instruments. One of the first steps in this direction will be the publication, at the end of 2026, of the EDPB and European Commission guidelines on the interplay between the GDPR and the AI Act.

Interpretation of the note

Beyond this legal framework, this note primarily reflects the growing interest of the CNIL, and more broadly of institutions, in the regulation of agentic AI systems. Although it has no binding effect, it invites stakeholders to become aware of the specificities of these technologies and the risks they entail, in order to reconcile technological innovation with the effectiveness of the legal framework.

Among its recommendations, the note advocates several approaches and precautionary measures, including the detection and filtering of misuse, the compartmentalisation of memory by agent and by processing operation, the maintenance of human oversight for critical actions, or the integration of a “kill switch” mechanism.

Subscribe to our Connections insights Sign-up now

Tags

technology, intellectual property, privacy and cyber security, artificial intelligence

Get in touch

Avatar
Nadège Martin
Partner
Avatar
Geoffroy Coulouvrat
Counsel
Avatar
Laura Helloco
Associate

Get in touch

Avatar
Nadège Martin
Partner
Avatar
Geoffroy Coulouvrat
Counsel
Avatar
Laura Helloco
Associate
Swifter, Simpler, Stricter? The DBT's Proposals for Competition Collective Actions
7/21/2026 5:00:11 PM

Swifter, Simpler, Stricter? The DBT's Proposals for Competition Collective Actions

By Caroline Thomas Susanna Rogers Nuala Canavan Emilia Radley +1 more...

Show less

On 17 July 2026, the Department for Business and Trade (DBT) published its proposals for significant reforms across three areas of the UK...
57
57

Latest Insights

CMA setback in Emma Sleep case as enforcement order refused by High Court
8/12/2026 10:57:51 AM

CMA setback in Emma Sleep case as enforcement order refused by High Court

By Jamie Cooke Nuala Canavan Matt Scott
83
83
LSE implements significant AIM Rule reforms with immediate effect: Key takeaways for AIM companies and Nomads
8/7/2026 1:27:36 PM

LSE implements significant AIM Rule reforms with immediate effect: Key takeaways for AIM companies and Nomads

By Fiona Millington Richard Sheen Clementine Hogarth Chris Pearson Deborah Wilcher +2 more...

Show less

1
52
52
Levelling the playing field? Support to football clubs under EU State aid rules
8/5/2026 9:02:40 AM

Levelling the playing field? Support to football clubs under EU State aid rules

By Alexandra Rogers Kasia Berestecka Anastasios Tsochatzidis
1
20
20

Explore our site

  • About
  • Careers
  • Diversity, Equity & Inclusion
  • People
  • Services
  • Insights
  • News

Key industries

  • Consumer markets
  • Energy, infrastructure and resources
  • Financial institutions
  • Life sciences and healthcare
  • Technology
  • Transport

Locations

  • Global coverage

Norton Rose Fulbright © 2024. All Rights Reserved.

  • Amsterdam
  • ●
  • Athens
  • ●
  • Austin
  • ●
  • Bangkok
  • ●
  • Beijing
  • ●
  • Brisbane
  • ●
  • Brussels
  • ●
  • Calgary
  • ●
  • Canberra
  • ●
  • Casablanca
  • ●
  • Chicago
  • ●
  • Dallas
  • ●
  • Denver
  • ●
  • Dubai
  • ●
  • Düsseldorf
  • ●
  • Frankfurt
  • ●
  • Hamburg
  • ●
  • Hong Kong SAR
  • ●
  • Houston
  • ●
  • Istanbul
  • ●
  • Jakarta*
  • ●
  • London
  • ●
  • Los Angeles
  • ●
  • Luxembourg
  • ●
  • Melbourne
  • ●
  • Mexico City
  • ●
  • Milan
  • ●
  • Minneapolis
  • ●
  • Montréal
  • ●
  • Munich
  • ●
  • Newcastle
  • ●
  • New York
  • ●
  • Ottawa
  • ●
  • Paris
  • ●
  • Perth
  • ●
  • Piraeus
  • ●
  • Québec
  • ●
  • Riyadh*
  • ●
  • San Antonio
  • ●
  • San Francisco
  • ●
  • São Paulo
  • ●
  • Shanghai
  • ●
  • Singapore
  • ●
  • St. Louis
  • ●
  • Sydney
  • ●
  • Tokyo
  • ●
  • Toronto
  • ●
  • Vancouver
  • ●
  • Warsaw
  • ●
  • Washington DC *associate office
  • Legal notices and disclaimers
  • Impressum
  • Standard terms
  • Blog network terms and conditions
  • Cookies policy
  • Privacy notice
  • Website access conditions
  • Fraud alerts
  • Modern Slavery Statements
  • Health plan machine readable files
  • Anti-Facilitation of Tax Evasion Statement
  • Suppliers
  • History
  • Remote access
  • Sitemap
Offices and locations

Norton Rose Fulbright © 2024. All Rights Reserved.

  • Amsterdam
  • ●
  • Athens
  • ●
  • Austin
  • ●
  • Bangkok
  • ●
  • Beijing
  • ●
  • Brisbane
  • ●
  • Brussels
  • ●
  • Calgary
  • ●
  • Canberra
  • ●
  • Casablanca
  • ●
  • Chicago
  • ●
  • Dallas
  • ●
  • Denver
  • ●
  • Dubai
  • ●
  • Düsseldorf
  • ●
  • Frankfurt
  • ●
  • Hamburg
  • ●
  • Hong Kong SAR
  • ●
  • Houston
  • ●
  • Istanbul
  • ●
  • Jakarta*
  • ●
  • London
  • ●
  • Los Angeles
  • ●
  • Luxembourg
  • ●
  • Melbourne
  • ●
  • Mexico City
  • ●
  • Milan
  • ●
  • Minneapolis
  • ●
  • Montréal
  • ●
  • Munich
  • ●
  • Newcastle
  • ●
  • New York
  • ●
  • Ottawa
  • ●
  • Paris
  • ●
  • Perth
  • ●
  • Piraeus
  • ●
  • Québec
  • ●
  • Riyadh*
  • ●
  • San Antonio
  • ●
  • San Francisco
  • ●
  • São Paulo
  • ●
  • Shanghai
  • ●
  • Singapore
  • ●
  • St. Louis
  • ●
  • Sydney
  • ●
  • Tokyo
  • ●
  • Toronto
  • ●
  • Vancouver
  • ●
  • Warsaw
  • ●
  • Washington DC *associate office
Policies and disclaimers
  • Legal notices and disclaimers
  • Impressum
  • Standard terms
  • Blog network terms and conditions
  • Cookies policy
  • Privacy notice
  • Website access conditions
  • Fraud alerts
  • Modern Slavery Statements
  • Health plan machine readable files
  • Anti-Facilitation of Tax Evasion Statement
  • Suppliers
  • History
  • Remote access
  • Sitemap
Visit our global site, or select a location
North America
  • Canada (English)
  • Canada (Français)
  • United States
Latin America
Europe
  • Belgium
  • Deutschland (Deutsch)
  • France
  • Germany (English)
  • Greece
  • Italy
  • Luxembourg
  • Poland
  • The Netherlands
  • Turkey
  • United Kingdom
Middle East
Africa
  • Morocco
Asia Pacific
  • Australia
  • China
  • Hong Kong SAR
  • Indonesia
  • Japan
  • Singapore
  • Thailand
Regional practices
  • India
  • Israel
  • Korea
  • Marshall Islands
  • Nordic region
  • Pakistan
  • Vietnam