Search papers, labs, and topics across Lattice.
This paper analyzes the differing legal interpretations of "inference" within the EU's AI Act and GDPR, highlighting that inferential capability does not determine legal scope. It argues that while the AI Act uses inference as a defining feature for regulation, the GDPR's protective stance does not rely on the technology's classification as AI. The findings reveal that the non-coincidence of these legal frameworks becomes critical in the context of agentic architectures, necessitating a nuanced approach to regulation through a proposed compositional-effects test for decision-making units.
Legal definitions of inference in EU digital law diverge significantly, revealing a gap that could expose AI systems to unanticipated regulatory scrutiny.
Two instruments of EU digital law place inference at their centre and mean different things by it. Article 3(1) of the AI Act uses the capability to infer constitutively: it is the central feature separating the regulated category from conventional software. The GDPR never defines inference, yet governs it protectively: the consequences follow from the processing of personal data and from what the inference says about, or does to, a person, whether or not the technology that produced it qualifies as an AI system. The two perimeters are not concentric. Their non-coincidence remained invisible in single-shot systems; agentic architectures make it operationally acute. The thesis: inferential capability does not determine legal scope, and its absence does not create immunity. The framework is two-level. Inference performs two legal functions, constitutive and protective; the protective function operates through three pathways - identificatory, attributive and decisional. Composition is not a fourth pathway but a cross-cutting architectural dimension which, with reach, persistence and reviewability, is what agentic architectures modify. Three concepts support it: the inferential threshold, the inferential reach and the inferential chain, mapped onto the chain of imputation. Regulation (EU) 2026/1744 left the constitutive criterion untouched and inserted a provision contemplating outputs that influence the inputs of future operations, without supplying any rule of aggregation. The article proposes an interpretive rule, a compositional-effects test identifying the decision unit under Article 22 GDPR together with the allocation of the burden of establishing it, and documentation duties calibrated to inference chains.