Skip to content

Regulation Tracker / Other

AEPD Guidance on agentic AI from a data-protection perspective (Orientaciones sobre IA agentica)

Spanish Data Protection Agency (Agencia Espanola de Proteccion de Datos)

last revised 2026-02-18last verified 2026-09-041 versioncountry page →

GuidanceIn forceRisk classificationSupervisionConfidentiality

map categories:Data protection and legal AIVendor due diligence

Guidance for controllers and processors deploying AI agents that plan and execute multi-step tasks with personal data. It identifies agent-specific risks such as autonomy, tool access and chained actions, and directs risk assessment and DPIAs, human oversight, data minimisation and clear processor arrangements. Not legal-sector specific but relied on by Spanish bars for AI use in firms.

Applies to
firms, providers, all
Effective
18 Feb 2026
Current version
18 February 2026 · 18 Feb 2026
Last verified
04 Sept 2026

What the document requires

  • Agentic systems require risk analysis beyond prompt-level supervision.
  • Human oversight and limits on autonomous actions.
  • Data minimisation and purpose limitation across tool calls.
  • Contractual allocation of controller and processor roles with providers.

Version history

VersionDateWhat changedSource
18 February 2026current2026-02-18First version recorded.official

Sources

Cite this record

SafeLegalAI Legal AI Regulation Tracker, "AEPD Guidance on agentic AI from a data-protection perspective (Orientaciones sobre IA agentica)" (Spanish Data Protection Agency (Agencia Espanola de Proteccion de Datos), 18 February 2026, 2026-02-18), safelegalai.com/regulation/other/es-aepd-orientaciones-ia-agentica-2026 (accessed 2026-09-04). Data: CC BY 4.0.

More official documents in Other