Inferential Capability Does Not Determine Legal Scope
Nicola Fabiano
Studio Legale Fabiano
cs.CY, cs.AI
Submitted: 2026-08-12
Updated: 2026-08-13
Code: https://github.com/fraunhofer-iais/inference-fra
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
Importance score: 75/100
The gist: The paper argues that the term "inference" performs two distinct legal functions in EU digital law, and that these functions are not aligned.
Terminology
Summary
The paper argues that the term inference
performs two distinct legal functions in EU digital law, and that these functions are not aligned. The thesis is that inferential capability does not determine legal scope, and its absence does not create immunity.
The paper identifies two concepts of inference:
-
Constitutive function (AI Act): Article 3(1) of the AI Act uses the
capability to infer
as a definitional criterion that separates AI systems from conventional software. The paper notes thatArticle 3(1) provides only that the system, for explicit or implicit objectives, infers from the input it receives how to generate outputs.
This criterion isconstitutive of material scope,
binary in application but graded in substance,
andworkflow-dependent, not component-dependent.
The paper notes that Regulation (EU) 2026/1744left the constitutive criterion untouched
in its 2026 amendment. -
Protective function (GDPR): The GDPR
governs inference without naming it.
It attaches obligations based on what an inference is (personal data), what it concerns (potentially special categories), and what it does (potentially a decision). The paper states:The Regulation does not define inference, does not use the term in its operative provisions, and does not condition protection on any technological qualification.
The protective function operates through three pathways:
-
Identificatory (Article 4(1) GDPR): Whether derived information reaches an identifiable person, given
means reasonably likely to be used
by the entity holding it. Authority: Breyer, EDPS v SRB. -
Attributive (Article 9(1) GDPR): Whether derived information is
liable to reveal a protected attribute,
subject to a proposedderivability threshold.
Authority: OT, Meta Platforms. -
Decisional (Article 22 GDPR): Whether a derived value
determines an outcome producing legal effects or similarly significant effects.
Authority: SCHUFA, with the explanatory corollary in Dun & Bradstreet Austria.
The paper proposes a two-level analytical framework distinguishing these functions and pathways. It argues that composition
is not a fourth pathway but a cross-cutting architectural dimension
along with reach, persistence and reviewability
that agentic architectures modify. The paper states: agenticity does not create new legal categories of inference; it modifies the reach, composition, persistence and reviewability of inferences already legally relevant.
The paper identifies an aggregation gap
: the pathways apply to sequences but supply no rule for determining when several intermediate derivations should be assessed as one legally relevant unit.
To address this, the paper proposes a compositional-effects test
to identify the decision unit under Article 22 GDPR, with criteria including cumulative determination,
effective foreclosure,
and composition of the unit, by state dependency.
It also proposes allocating the burden of establishing the unit to the controller, supported by Article 5(2) GDPR, Article 15(1)(h) as construed in Dun & Bradstreet Austria, and Articles 12 and 19 of the AI Act.
The paper also proposes documentation duties calibrated to inference chains,
including recording sources consulted, derivations made, state transitions, and constraints in force. It distinguishes between the inferential chain
(descriptive and technical) and the chain of imputation
(normative and organisational), arguing that the legally significant object is the mapping between them.
The paper concludes: "Inferential capability does not determine legal scope, and its absence does not create immunity. A system below the Article 3(1) threshold may travel the identificatory, attributive and decisional pathways in full; a system above it does not thereby discharge any data protection obligation."
Improvements for AI systems
Improvements to AI systems based on this paper:
-
Implement inference-chain auditing – The AI system will maintain a structured log of every intermediate derivation it performs (e.g., from raw input → feature → score → decision), recording sources consulted, state transitions, and constraints in force. This enables the system to expose its full
inferential chain
on demand, satisfying documentation duties under GDPR Articles 5(2), 15(1)(h), and AI Act Articles 12 and 19. -
Add a compositional-effects test module – The AI system will evaluate whether multiple intermediate inferences, when aggregated, produce a
cumulative determination
oreffective foreclosure
of a user's outcome. It will automatically flag when a sequence of derivations should be treated as a single legally relevant unit under Article 22 GDPR, rather than as isolated steps. -
Provide dual-scope reporting – The system will generate two parallel reports: (a) a technical
inferential chain
(descriptive, component-level) and (b) a normativechain of imputation
(organisational, responsibility-level). It will explicitly map the correspondence between the two, so legal reviewers can see which technical steps are attributed to which legal obligations. -
Decouple capability from legal scope – The AI system will not assume that being below the AI Act's Article 3(1)
inference capability
threshold grants immunity from GDPR obligations. Instead, it will run a pathway-specific check: identificatory (reach to an identifiable person), attributive (liability to reveal protected attributes), and decisional (determination of legal/significant effects). This ensures full compliance even for conventional software. -
Implement derivability-threshold warnings – The system will estimate whether a derived inference is
liable to reveal
a special category of data (e.g., health, political opinion) under Article 9(1) GDPR, using a probabilistic derivability threshold. It will issue a compliance alert before the inference is used in any downstream decision. -
Support controller-side burden allocation – The AI system will automatically document the
composition of the unit
(e.g., state dependency between steps) and provide evidence that the controller has established the decision unit, shifting the burden of proof appropriately as proposed by the paper. -
Enable agentic-architecture impact assessment – When the AI system operates in a multi-agent or autonomous configuration, it will assess how
reach, composition, persistence, and reviewability
of inferences are modified by the architecture. It will report whether agenticity changes the legal character of any inference (e.g., from a mere intermediate step to a decisive one).
What the improved AI system can do:
It can operate in high-stakes domains (credit scoring, hiring, healthcare triage) while automatically producing legally defensible inference logs, detecting when aggregated inferences cross into decisional
territory, and generating dual-chain documentation that satisfies both GDPR and AI Act obligations—without conflating technical capability with legal immunity.
Abstract
Two instruments of EU digital law place inference at their centre and mean different things by it. Article 3(1) of the AI Act uses the capability to infer constitutively: it is the central feature separating the regulated category from conventional software. The GDPR never defines inference, yet governs it protectively: the consequences follow from the processing of personal data and from what the inference says about, or does to, a person, whether or not the technology that produced it qualifies as an AI system. The two perimeters are not concentric. Their non-coincidence remained invisible in single-shot systems; agentic architectures make it operationally acute. The thesis: inferential capability does not determine legal scope, and its absence does not create immunity. The framework is two-level. Inference performs two legal functions, constitutive and protective; the protective function operates through three pathways - identificatory, attributive and decisional. Composition is not a fourth pathway but a cross-cutting architectural dimension which, with reach, persistence and reviewability, is what agentic architectures modify. Three concepts support it: the inferential threshold, the inferential reach and the inferential chain, mapped onto the chain of imputation. Regulation (EU) 2026/1744 left the constitutive criterion untouched and inserted a provision contemplating outputs that influence the inputs of future operations, without supplying any rule of aggregation. The article proposes an interpretive rule, a compositional-effects test identifying the decision unit under Article 22 GDPR together with the allocation of the burden of establishing it, and documentation duties calibrated to inference chains.
Sources
- Regulating AI Agents
- A pragmatic approach to regulating AI agents
- AI Agents Under EU Law
- When Do Data-Driven Systems Exhibit the Capability to Infer?
Related papers
- Reasoning Enhances Robustness to Prompt Injection in LLM-Based Consensus
- Generative AI Purpose-built for Social and Mental Health: A Real-World Pilot
- PersonaMem-v3: Toward Omni-Platform Personal Intelligence for Holistic User Understanding, Recommendation, and Agentic Tasks
- What is an intelligent system?
- AI University: An LLM-Powered Learning Assistant for Engineering---A Finite Element Method Case Study
- Generative AI Use in Entrepreneurship: An Integrative Review and an Empowerment-Entrapment Framework