ComputerWeekly

When the intern has admin rights: GDPR in the agentic age


The General Data Protection Regulation (GDPR) was built for a world where personal data was easier to govern. You could map where it came from, check the lawful basis, apply the retention schedule, and reasonably expect the data to stay put until someone acted on it. AI, and agentic AI in particular, breaks that fundamental assumption. Data no longer just sits waiting to be processed under a known purpose. It moves, gets summarised, gets fed into a decision, and increasingly gets acted on without a human clicking the button that sets it in motion.

That shift is the real story. That’s not to say we need a new rulebook. What we do need to do however, is answer the very specific question of how do you apply purpose limitation, data minimisation and accountability to a system that can decide, on its own, to do something with the data you gave it?

Start with the original problem. Knowing where personal data came from and whether you’re allowed to use it is the first step of any GDPR programme, and LLMs make that more difficult to answer. Data goes in, gets transformed, and comes back out in a form that no longer looks like the original input. Subject access requests, erasure requests, and rectification all depend on being able to trace that journey.

But that is only half of the equation, and arguably the less urgent half. An AI model that summarises a document is a fairly understandable and containable risk. An agent that reads a customer record, drafts a message, sends it, and updates a CRM field is a different category of risk entirely, because now you have autonomous action taken on personal data, not just processing of it.

If AI is making decisions in real time, then a governance policy that is reviewed annually is no good. Some of the important questions to ask are: who owns the agent? What data can it touch? What systems can it access? When does it have to stop and hand control back to a person? Who has the authority, and the technical means, to pull the plug if it starts doing something it shouldn’t?

This is not a new legal category. It’s an operational one, and it’s where GDPR’s existing principles still hold up if organisations take them seriously. Purpose limitation doesn’t need a rewrite to apply to an agent, it needs someone to define, narrowly, what that agent is for and to build guardrails that keep it there. Data minimisation doesn’t need an AI amendment, it needs someone to resist giving an agent broad standing access to a customer database because it’s more convenient. Accountability doesn’t need a new article, it needs a record of what the agent did, when, and on whose authority, produced automatically because no one is going to log it by hand every time an agent fires.

This is where a lot of organisations are weakest. A slightly-too-broad purpose statement was probably within risk appetite when a human had to manually act on the data and would probably notice if something looked off. It’s far less tolerable when the acting party is an AI agent that will happily execute at scale and speed with no instinct for ‘this seems wrong’. An agent can start a task well within its lawful scope and drift outside it within the same session, well before a human reviewing outputs weekly, or even daily, would catch it. That’s not a hypothetical governance gap, it’s a description of how a lot of current agentic AI deployments work.

So, where does this leave UK and EU regulation? Don’t expect a rewrite of GDPR’s core principles, because for all intents and purposes they’re based on sound principles and technology-neutral by design. Instead, expect a steady tightening around the edges: firmer expectations on documenting AI-specific data flows and Data Protection Impact Assessments (DPIAs) that grapple with agentic behaviour rather than treating a model as a static processing step, more explicit guidance on human oversight requirements that reflects intervention capability, and growing enforcement interest in whether organisations can show control over what their AI systems did, not just what they were told to do.

The UK’s approach, alongside the evolving relationship between GDPR and the EU AI Act, will likely keep leaning on existing accountability and risk-based principles rather than duplicating them in its own AI legislation. The AI Act itself is explicit that it operates without prejudice to GDPR: the two are designed to work alongside each other, with GDPR continuing to fill the individual-rights gap that a product-safety law like the AI Act doesn’t cover.

There’s unfortunately probably not a clean regulatory fix. The gap isn’t really in GDPR. The gap is in how many organisations still treat data protection governance as a document written once and revisited at audit time, applied to AI agents that now behave less like passive software and more like a very fast intern with admin access and no judgement of their own. If we can fix that operational mismatch, GDPR will still do the job it was designed to do.

Javvad Malik is lead CISO advisor at KnowBe4



Source link