Rule of 2 (AI agents)
A design criterion for AI agents set out in the AEPD guidelines on agentic AI (section V.G, “Regla de 2”, pp. 41-42): an agent should not combine three capabilities at once — automatically processing information the organisation does not control, accessing sensitive information or personal data, and taking automatic actions with effect without human oversight. Where it combines all three, the guidelines describe a configuration that should not be allowed.
Of three risky capabilities, an agent may combine two at most, and each combination calls for its own containment.
Which obligations it carries
It is a best practice, not a legal obligation: it is proposed by the Spanish supervisory authority in guidelines that describe themselves as an introductory study, and which present it as a general minimum rule focused on cybersecurity (p. 43). What is a legal obligation is the framework in which it applies: the controller must process personal data in a manner that ensures appropriate security and be able to demonstrate that it respects the principles of Article 5 of Regulation (EU) 2016/679, an obligation applicable from 25 May 2018.
What it is not
It is not a legal threshold or a prohibition: no article of Regulation (EU) 2016/679 or of Regulation (EU) 2024/1689 sets it out. Nor does it exhaust the risk analysis: the guidelines regard it as a good starting point for the analysis and point out that, from a data protection perspective, there are other aspects to consider, such as the quality of the input information or data minimisation (p. 43). And it does not come from data protection: it was formulated in 2021 for the security of applications in browsers and later reformulated for AI agents (p. 41).
The nuance almost nobody captures
Which two capabilities are combined matters. The guidelines describe three manageable configurations (p. 42): if the agent processes uncontrolled information and accesses sensitive information, any automatic action without human oversight must be prevented; if it accesses sensitive information and acts automatically, it may only do so with safeguards for the integrity and security of the information; and if it processes uncontrolled information and acts automatically, its access to sensitive information or personal data must be prevented. Counting capabilities is not enough: what matters is which ones they are.