By Rafael Luque Ocaña

AI agents: what to log, and why Article 22 GDPR almost never applies

An agent that carries out actions leaves a different trail from a system that only suggests. Record-keeping under Article 26(6) of the AI Act and the right under Article 22 of the GDPR are two different things, and the second has a threshold that most actions never reach.

When an AI system suggests, the decision is still made by a person, and the relevant trail is what that person decided. When it acts — sends the email, books the appointment, approves the expense, escalates the ticket — the trail has to explain something more: why the system did that, and not something else.

That shift doesn't create new obligations. There is no separate regime for agents in the AI Act: there are obligations that apply equally with or without an agent, and practical problems that autonomy makes worse. This article deals with two that are constantly conflated.

What the AI Act asks for on records

For high-risk systems — and only for them: Article 26 reaches no other —, Article 26(6) requires the deployer to keep the logs automatically generated by the system, to the extent such logs are under its control, "for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data". It applies from 2 December 2027 for the high-risk systems of Annex III.

It's a retention obligation, and its object is the system's logs. It doesn't ask you to build a traceability system or document the model's reasoning: it asks you to keep what the tool produces.

With a system that suggests, that's usually enough to reconstruct what happened: there's a log of the suggestion and an identifiable human decision. With an agent that chains actions together, the same log may not answer the question that matters — which action triggered which, and on what basis.

That's where the practical difference lies, and it isn't a legal one: the obligation is the same; what changes is how much the record that covers it actually explains.

Article 22 GDPR, and its threshold

This is where content circulating about agents tends to overreach. The short version — "if you have agents, Article 22 applies" — is right in its direction and wrong in its scope.

The article reads:

"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."

That last clause is the article. It isn't enough for the decision to be automated: it has to produce legal effects on the person, or affect them significantly in a similar way.

An agent that reorders an inbox, drafts a message, schedules an internal meeting, or prioritises tickets doesn't reach that threshold. Nor does the fact that the action is autonomous get it there on its own: Article 22 looks at the effect on the person, not the degree of automation of the system that produces it.

What does reach it are the decisions that are recognisable as soon as they're named: rejecting an application, screening out a candidate, resolving a complaint, setting a price or a condition that affects a specific person. There, the right exists, and with it the safeguards in paragraph 3 — human intervention, expressing a point of view, contesting the decision — when the decision rests on a contract or on explicit consent.

Two different things worth not merging

They get cited together, and they don't look alike.

Article 26(6) AI ActArticle 22 GDPR
What it isan obligation to retain logsa data subject right
Who it bindsthe deployer of high-risk systemsthe controller
What triggers itthe system being high-riskthe decision producing legal or similar effects
What it coverslogs generated by the systemdecisions based solely on automated processing

They're related — if you have to respond to an Article 22 request, the Article 26(6) records are part of what lets you answer — but neither follows from the other. A system can be subject to one and not the other, and the other way round.

Merging them produces the two wrong versions that circulate: "keep logs because the GDPR requires it" — that isn't where it comes from — and "you have agents, so there's a right to human intervention" — only if the decision crosses the threshold.

What really changes when the system acts

Three things, and none of them is a new obligation.

The trail has to reconstruct a chain, not an event. With chained actions, knowing that they happened isn't enough: you need to be able to say in what order and why. It's the same retention duty, with more to retain.

"Who's accountable?" stops having an obvious answer. A system that suggests has a human at the end. One that acts needs someone designated in advance — and that designation isn't required by any specific article: it's required by needing to be able to answer when asked.

The Article 22 threshold has to be assessed action by action, not system by system. The same agent can do some things that don't cross it and one that does. The assessment isn't of the agent: it's of what it does.

And that's the uncomfortable part: these are three questions that get answered beforehand, and no automatic record answers them on its own. Who decides which actions the agent can execute without intervention, where the limit sits, who reviewed it and when — the same old difference between ticking a box and having evidence, applied to a system that no longer waits for confirmation.

A note on GPAI obligations

One aside, because it comes up every time agents are discussed: Articles 53 to 55 of the AI Act — the ones for general-purpose models — are obligations on the model's provider. For a company deploying an agent built on one of those models, they aren't its own duties: checking the provider's documentation is internal diligence, not a direct legal obligation.

It's the same distinction that separates the provider's obligations from those of the deployer: what applies to you runs through Article 26, not through the provider's chapter.

Content in accordance with Article 26 of Regulation (EU) 2024/1689 and Article 22 of Regulation (EU) 2016/679, cited from the text published in OJ L 119 of 4.5.2016 and verified against the consolidated version.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.