France France CNIL GDPR enforcement Big Tech

France's CNIL Flags GDPR Gaps in Agentic AI, But Stops Short of New Rules — Rightly So

CNIL and CIANum's July 2026 note finds agentic AI strains GDPR minimization and Article 22, but declines to prescribe fixes ahead of EU-wide guidance.

CNIL and Agentic AI: The Numbers Behind the Note People of Internet Research · France Jul 20, 2026 Joint note published CNIL and CIANum publish explorator… €325M CNIL's record Google fine September 2025 fine for unlawful G… 74M+ Google accounts affected French accounts hit by invalid coo… Dec 7, 2023 SCHUFA ruling on Article 22 CJEU Case C-634/21 held automated … peopleofinternet.com
CNIL and Agentic AI: The Numbers Behin… People of Internet Research · France Jul 20, 2026 Joint note published €325M CNIL's record Google fine 74M+ Google accounts affected Dec 7, 2023 SCHUFA ruling on Article 22 peopleofinternet.com

Key Takeaways

On July 20, 2026, France's data protection authority, the CNIL, published a joint exploratory note with the Conseil de l'IA et du Numérique (CIANum) titled "IA agentique et protection des données personnelles : équation à inconnues multiples pour les utilisateurs" — agentic AI and personal data: an equation with multiple unknowns for users. The note is not a decision, a fine, or even draft guidance. It is a diagnostic exercise, and a notably restrained one: it explicitly states that it does not suggest the existing GDPR framework is inadequate, only that its implementation needs adapting to a genuinely new architecture of software agency (CNIL).

What the regulator actually found

The note's core observation is architectural. Agentic AI systems typically run an "orchestrator" agent that delegates subtasks to specialized agents, each drawing on separate memory stores — some temporary "context," some persistent "memory" that survives across sessions. CNIL and CIANum argue this design creates three concrete points of friction with GDPR principles.

First, data minimization: because agents "ingest emails, browsing history, and files, share them with others, and store them in memory to anticipate user needs," the note found it structurally difficult to keep processing bounded to a specified purpose — the proliferation of memory instances across sub-agents was flagged as the principal source of opacity, since users cannot easily determine what is retained, by which agent, or for how long.

Second, Article 22 on automated individual decision-making. The note describes agentic systems as effecting "an implicit delegation of decision-making power from user to system," and — citing the CJEU's 2023 SCHUFA ruling (Case C-634/21, 7 December 2023), which held that credit-scoring itself constitutes automated decision-making even when a human lender formally approves the loan — argues that human oversight of agentic pipelines must be "real and effective," not a rubber-stamp review of the final output after the agent has already acted (IAPP).

Third, accountability. When an orchestrator, several specialized agents, and third-party tool integrations all touch the same task, the note acknowledges that allocating GDPR controller/processor responsibility across that chain is genuinely unresolved — a gap sharpened by the EU's 2025 withdrawal of the proposed AI Liability Directive, which would have addressed civil liability for AI harms directly.

The steelman: this is a real gap, not regulatory reflex

The substantive case for the CNIL's caution deserves to be taken seriously. Agentic AI is not a UI change to a chatbot; it is software that acts on a user's behalf with real access to a mail inbox, a calendar, a payment method, and a persistent memory of who the user is. If an agent is silently retaining browsing history to "anticipate needs," that is precisely the kind of unbounded, purpose-creeping data accumulation Article 5's minimization principle was written to prevent. And the SCHUFA precedent is a legitimate warning: regulators have already seen companies try to dodge Article 22 by inserting a token human in the loop who doesn't meaningfully review anything. A regulator naming these risks before enforcement actions pile up is doing its job.

Why the CNIL's restraint is the right call

What makes this note notable, though, is what it doesn't do. It doesn't propose a new agentic-AI liability category, doesn't set a compliance deadline, and doesn't threaten enforcement. It explicitly frames itself as exploratory, ahead of joint EDPB–European Commission guidance on the GDPR/AI Act interplay expected by the end of 2026. That sequencing is correct: agentic AI product architectures (orchestrator/sub-agent patterns, memory partitioning) are still being actively redesigned by the industry itself, and premature French-specific prescriptive rules would risk locking in one architecture over better ones still emerging, while adding a compliance burden that diverges from whatever the EU-wide guidance eventually says.

It's also worth putting this note in context of the CNIL's actual enforcement record, which has been anything but toothless. On September 1, 2025, the CNIL fined Google €325 million — €200 million against Google LLC and €125 million against Google Ireland — for inserting unlabeled ads into Gmail inboxes and manipulating cookie consent flows during account creation, a decision that affected more than 74 million French accounts (CNIL). That fine shows the CNIL is willing to move fast and hit hard once it has a concrete violation to point to. The agentic AI note is different in kind: it is the regulator thinking out loud about a technology whose failure modes it hasn't yet observed in an actual complaint or breach.

The right next step is guidance, not a French rulebook

The practical risk here is fragmentation. If CNIL moves unilaterally to prescriptive agentic-AI rules before the EDPB's cross-EU guidance lands, French-deployed agents could face compliance obligations — mandatory traceability logs, risk-tiered human-approval gates, per-agent memory expiry — that diverge from rules in Germany or the EU as a whole, raising costs for exactly the kind of cross-border AI products Europe says it wants more of. The CNIL and CIANum's own recommendations — traceability of decision chains, granular user controls over what data an agent can touch, and memory partitioned and expired per-agent — are sensible engineering defaults that responsible developers should adopt regardless of whether a regulator mandates them. Voluntary adoption now, harmonized EU guidance by year-end, and enforcement only against demonstrated harm is the sequence most likely to protect users without freezing a still-maturing product category in place.

The note's own framing is the most useful sentence in it: existing law "remains fully applicable," but its implementation modalities need adapting. That is a call for engineering discipline from AI developers, not a call for new statute.

Sources & Citations

  1. CNIL/CIANum joint note on agentic AI and GDPR
  2. CNIL: Google fined €325 million
  3. IAPP: Key takeaways from the CJEU's automated decision-making rulings
  4. Inside Privacy (Covington): French CNIL publishes note on agentic AI
  5. GDPR Article 22 text