New AI law paper: Legal scope isn't determined by inferential capability
Nicola Fabiano's arXiv paper shows GDPR still applies to non-AI inference systems
A new academic paper from Nicola Fabiano, published on arXiv (2608.10601), tackles a critical blind spot in European digital regulation: the relationship between the EU AI Act and the GDPR when it comes to inference. The AI Act defines an AI system through its inferential capability (Article 3(1)), making that capability central to determining what falls under the regulation. The GDPR, by contrast, never defines inference but regulates it protectively—its obligations kick in when inference processes personal data or affects a person, irrespective of whether the system qualifies as AI. The paper argues these two legal perimeters are not concentric, and this mismatch has become operationally urgent with agentic architectures that chain multiple inference steps together.
The author proposes a two-level framework separating inference's constitutive function (defining what counts as AI) from its protective function (governing effects on individuals). The protective function operates through three pathways—identificatory, attributive, and decisional—while composition acts as a cross-cutting architectural dimension alongside reach, persistence, and reviewability. Three new concepts support the analysis: inferential threshold, inferential reach, and inferential chain, the last mapped onto the chain of legal imputation. The paper then addresses Regulation (EU) 2026/1744, which left the constitutive criterion untouched but introduced a provision on outputs influencing future inputs without any aggregation rule. To close this gap, Fabiano proposes a compositional-effects test that identifies the decision unit under Article 22 GDPR, allocates the burden of proof, and mandates documentation duties calibrated to inference chains. The core thesis: inferential capability does not determine legal scope, and its absence does not grant immunity.
- Identifies a non-coincidence between AI Act's inference-based definition and GDPR's protective governance of inference
- Proposes three legal pathways (identificatory, attributive, decisional) for inference's protective function
- Introduces a compositional-effects test for Article 22 GDPR targeting agentic AI chains, plus documentation duties
Why It Matters
For AI companies, this clarifies that GDPR obligations persist even for systems outside the AI Act's scope, especially agentic AI.