Council of Europe AI privacy rules target agentic systems and memorization
The Council of Europe has drafted new privacy guidelines for large language models and agentic AI systems, interpreting how the Convention 108+ treaty applies to modern AI lifecycles. The draft, scheduled for review in September 2026, addresses risks such as training data memorization, autonomous agent permissions, and the distinction between model-level and system-level privacy responsibilities.
Key Takeaways
- Guidelines require human review for agentic AI actions that produce significant or irreversible effects
- Research shows training data extraction costs as little as $200 to recover sensitive information like email signatures
- Draft rules mandate separating data read permissions from create, modify, or delete permissions in AI agents
- The Bureau of the Convention 108 Committee will review the draft in Paris on September 16-17, 2026
Why It Matters
These guidelines signal a shift from regulating static models to governing the entire AI lifecycle, specifically targeting the 'agentic' infrastructure now managing live advertising campaigns. For streaming platforms and ad tech vendors, the requirement to isolate read and write permissions may force a significant re-engineering of existing automated campaign tools. The focus on 'persistent memory' also challenges current personalization strategies, as regulators now demand that conversation histories be disabled by default unless a specific, mitigated risk case is proven. Watch for the November 2026 plenary session to see if these interpretative guidelines are formally adopted as the new standard for Convention 108+ compliance.
Additional Context
The Council of Europe's Convention 108+ framework is becoming the de facto privacy baseline for AI systems operating across its 55 member states. The treaty, which entered into force in 2018 as a modernization of the original 1981 convention, has been ratified by 24 parties including the European Union, and its consultative committee has increasingly focused on AI-specific interpretations. The Council of Europe's Convention 108+ has been cited as a model for AI governance frameworks beyond Europe, influencing regulatory approaches in Africa and Latin America where data protection authorities reference its principles when drafting national AI legislation. The September 2026 draft guidelines represent the most detailed application of Convention 108+ to generative and agentic AI systems to date, building on earlier recommendations that addressed automated decision-making but did not specifically tackle large language model training pipelines or autonomous agent architectures.
The regulatory landscape for agentic AI is tightening across multiple jurisdictions simultaneously, creating compliance complexity for companies deploying AI agents in advertising, content recommendation, and customer engagement. The European Union's AI Act, which began phased enforcement in August 2025, classifies certain AI systems by risk level and imposes transparency obligations on general-purpose AI models that overlap with Convention 108+ data protection requirements. For streaming platforms and ad tech vendors operating in Council of Europe member states, the convergence of the AI Act's transparency mandates with Convention 108+'s data minimization principles means that agentic systems handling personal data for campaign optimization or viewer profiling face dual compliance obligations. The Council of Europe's emphasis on disabling persistent memory by default aligns with the AI Act's requirement that high-risk AI systems incorporate data governance measures from the design phase.
Technical research on training data memorization, a central concern of the draft guidelines, has produced measurable benchmarks that regulators are now referencing. A 2025 study by researchers at Google DeepMind demonstrated that large language models can reproduce verbatim training sequences when prompted with specific prefixes, with extraction rates varying significantly by model size and training duration. The Council of Europe's draft explicitly distinguishes between model-level risks, where memorized data can be extracted through adversarial prompting, and system-level risks, where agentic architectures introduce new attack surfaces through tool use and multi-step reasoning. This distinction mirrors concerns raised by , a gap that privacy regulators are now attempting to address through binding interpretative guidelines rather than voluntary industry standards, such as the .
Read full article at ppc.land
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source