2026-09-02 · Cybersecurity

AI agents, GDPR and the AI Act: what to check before deploying

An agent processing personal data isn't outside GDPR's scope just because it's "just an AI tool". What the regulation actually requires.

Deploying an AI agent that touches personal data — sorting applications, qualifying leads, answering customer requests — triggers the same obligations as classic automated processing. Generative AI doesn't create an exception.

What GDPR requires

A legal basis for processing, informing the people concerned, a defined retention period, and above all: the right to human intervention for any fully automated decision with a significant effect (Article 22). An agent that rejects an application on its own, with no human recourse, is a real compliance problem.

What the EU AI Act adds

The EU's AI regulation classifies systems by risk level. An agent used for recruitment or credit scoring typically falls into the "high-risk" category, with documentation, human oversight and decision-traceability obligations far stricter than an agent that sorts support tickets.

What we check during the audit

Before any Trustagents deployment touching personal data: what's the legal basis, where is data hosted during processing (inside the EU or not), what's the AI Act risk level, and what human recourse mechanism exists for a contested decision.

What that means in practice

For higher-risk cases, a self-hosted model (Z.ai/GLM or Hermes) that sends no data to a third party significantly simplifies demonstrating compliance, compared to an API call to a proprietary model hosted outside the EU.

A question about your situation?

Request a free audit, we'll look at your specific case.