The Commonplace
Home Papers Evidence Explore Trends Syntheses Digests References Docs 🎲 Workforce Futures
← Papers
Direction, evidence grade, and study type are AI-generated labels (gpt-5-mini), not human-verified. Syntheses are LLM-written. "Tensions" are machine-detected candidates, not confirmed contradictions. A research-acceleration tool, not peer review. How this is built →

EU law treats 'inference' twice: the AI Act uses it to decide what counts as an AI system, while the GDPR protects the consequences of inferences regardless of whether the producing technology qualifies as AI; the paper warns that agentic architectures expose this mismatch and proposes a compositional-effects test plus documentation duties to allocate responsibility under Article 22 GDPR.

Inferential Capability Does Not Determine Legal Scope
Nicola Fabiano · August 11, 2026
arxiv theoretical n/a evidence 7/10 relevance Full text usable extracted full text Source PDF

Structured author observations

Linked only from stored provider relations; the raw author line above is never matched by name.

Arxiv

Latest observation:

  1. Nicola Fabiano unresolved corpus identity

Semantic Scholar

Latest observation:

  1. Nicola Fabiano provider ID
The paper argues that EU law uses 'inference' in two distinct legal functions — a constitutive criterion under the AI Act and a protective concept under the GDPR — and that agentic AI architectures make their non-coincidence operationally important, requiring a compositional-effects test and tailored documentation and attribution rules.

Citation observations

Cumulative provider counts captured on specific dates; providers are never combined.

Two instruments of EU digital law place inference at their centre and mean different things by it. Article 3(1) of the AI Act uses the capability to infer constitutively: it is the central feature separating the regulated category from conventional software. The GDPR never defines inference, yet governs it protectively: the consequences follow from the processing of personal data and from what the inference says about, or does to, a person, whether or not the technology that produced it qualifies as an AI system. The two perimeters are not concentric. Their non-coincidence remained invisible in single-shot systems; agentic architectures make it operationally acute. The thesis: inferential capability does not determine legal scope, and its absence does not create immunity. The framework is two-level. Inference performs two legal functions, constitutive and protective; the protective function operates through three pathways - identificatory, attributive and decisional. Composition is not a fourth pathway but a cross-cutting architectural dimension which, with reach, persistence and reviewability, is what agentic architectures modify. Three concepts support it: the inferential threshold, the inferential reach and the inferential chain, mapped onto the chain of imputation. Regulation (EU) 2026/1744 left the constitutive criterion untouched and inserted a provision contemplating outputs that influence the inputs of future operations, without supplying any rule of aggregation. The article proposes an interpretive rule, a compositional-effects test identifying the decision unit under Article 22 GDPR together with the allocation of the burden of establishing it, and documentation duties calibrated to inference chains.

Summary

Main Finding

Inferential capability — the technical capacity to “infer” as used in Article 3(1) of the AI Act — does not by itself determine whether EU law applies to a system’s outputs. EU law uses “inference” in two distinct ways: (1) constitutively in the AI Act (it helps define what counts as an AI system) and (2) protectively in data protection law (the GDPR treats the consequences of inferences as personal data/processes to be regulated regardless of whether the producing technology qualifies as an “AI system”). Agentic AI (architectures that compose, chain and autonomously invoke tools) makes this conceptual non‑coincidence operationally important: inference can be distributed across components so that a system may fall outside the AI Act’s definitional threshold yet produce legally protected inferences under the GDPR. The paper proposes an interpretive/compositional approach (a compositional‑effects test, burden allocation rule and tailored documentation duties) to map inferential chains onto legal responsibility (the chain of imputation), and to make Article 22 GDPR and AI Act obligations operational in the face of agentic composition.

Key Points

  • Two concepts of “inference”:
    • Constitutive (AI Act Article 3(1) + Recital 12): inferring capability is part of what makes something an AI system; interpretation benefits from technical gradings (Poretschkin & Naeven framework).
    • Protective (GDPR): inference is not defined but its legal consequences follow from processing personal data (three pathways: identificatory, attributive, decisional).
  • The two perimeters (AI Act vs GDPR) are not concentric; lack of AI‑Act “inference” does not imply GDPR immunity.
  • Protective pathways under GDPR:
    • Identificatory: inferences that identify or re‑identify persons.
    • Attributive: inferences that attribute traits (sensitive or not) to persons or groups.
    • Decisional: inferences used as inputs to (automated) decisions affecting individuals (Article 22 implications).
  • Composition (chaining, orchestration) is a cross‑cutting architectural dimension rather than a fourth pathway. Key composition properties: inferential reach, persistence, and reviewability.
  • Agentic architectures intensify three problems:
    • Chained inference: intermediate derivations propagate and are composed into new outputs.
    • Perimeter fragmentation: different components/providers contribute parts of an inferential pipeline.
    • Runtime composition of sensitive attributes: on‑the‑fly combinations can create novel protected inferences not anticipated at design time.
  • Legislative context: Regulation (EU) 2026/1744 acknowledges outputs that influence future inputs but supplies no aggregation rule; the AI Act’s constitutive wording remains unchanged.
  • Proposals:
    • Interpretive rule to identify the relevant decision unit for Article 22 GDPR in composed pipelines.
    • A compositional‑effects test to determine when aggregated intermediate outputs produce effects equivalent to an automated decision.
    • Allocation of burden of proof for establishing the decision unit.
    • Documentation duties proportional to inference chains (documentation of inferential threshold, reach, chain, composition points, and reviewability).
  • Practical corollary: firms cannot dodge GDPR obligations by designing systems that avoid qualifying as “AI systems”; compliance assessment must consider whole workflows and composition.

Data & Methods

  • Methodological approach: doctrinal and conceptual legal analysis, textual exegesis and normative proposal rather than empirical measurement.
  • Primary sources analysed:
    • AI Act (Regulation (EU) 2024/1689), especially Article 3(1) and Recital 12.
    • GDPR provisions (including Article 22 and doctrine from CJEU and other case law such as OT, SCHUFA, EDPS v SRB, Dun & Bradstreet Austria).
    • Regulation (EU) 2026/1744 and recent legislative amendments acknowledging recursive/feedback outputs.
  • Technical grounding: adopts and uses the Poretschkin & Naeven multi‑level technical framework for grading inferential capability (Levels 0–4) to interpret the AI Act’s constitutive usage of “infer”.
  • Analytical framework developed in the paper:
    • Two‑level legal framework: (1) constitutive vs (2) protective functions of inference.
    • Protective function decomposed into three pathways (identificatory, attributive, decisional).
    • Composition treated as cross‑cutting architectural dimension; three analytic constructs introduced — inferential threshold, inferential reach, inferential chain — mapped to the chain of imputation.
  • Output: normative interpretive rule, compositional‑effects test, burden allocation recommendation, and proposed documentation duties; no empirical validation or benchmarking.

Implications for AI Economics

  • Compliance scope uncertainty raises costs and affects adoption:
    • Firms must evaluate entire data‑processing workflows (not just models) for both AI Act and GDPR exposure. This increases compliance complexity and monitoring costs, especially for agentic systems that dynamically orchestrate tools.
    • Uncertainty around “inferential threshold” and aggregation may raise legal risk premiums, increasing insurance and legal compliance expenditures.
  • Incentives for architecture and product design:
    • Economic incentive to design systems with clear provenance, traceability and modular auditing to limit ambiguous composition effects.
    • Alternatively, firms might centralize capabilities (or vertically integrate) to internalize liability and ease compliance — potentially increasing concentration in markets where compliance burdens are high.
    • Incentives may favor design choices that reduce inferential reach or persist intermediate derivations (e.g., more explicit human checkpoints, reduced runtime composition), which could affect product functionality and competitiveness.
  • Market for compliance and provenance technologies:
    • Demand growth for tools that map inference chains, log composition points, and enable reviewability. New markets for documentation-as-a-service, traceability, explanation tech, and specialized audits.
    • Valuation premium for platforms that can demonstrably satisfy proposed documentation and compositional‑effects tests.
  • Contracting and liability allocation:
    • Increased contractual complexity between orchestrators, component/tool providers and users; firms will negotiate explicit allocations of GDPR/AI‑Act risk, indemnities and obligations to document inferential chains.
    • Smaller providers may be priced out or absorbed by larger firms able to bear compliance overhead; impacts entry and competition.
  • Data market and pricing effects:
    • Inferred data (and outputs that enable further inference) are likely to be treated as personal data in many instances — this raises transaction costs and regulatory constraints on trading inferred insights, changing valuations in data‑brokering markets.
    • Increased cost of using third‑party components that produce or contribute to protected inferences (higher due diligence and contractual requirements).
  • Enforcement and compliance asymmetries:
    • Enforcement difficulty across fragmented pipelines may create regulatory arbitrage where actors locate components across jurisdictions or cloud providers to complicate attribution.
    • Regulators’ interpretive and documentation demands (as proposed) would reduce asymmetry but generate compliance costs; enforcement focus may shift to orchestration layers and documentation sufficiency.
  • Social welfare and externalities:
    • Better documentation and compositional rules can reduce informational asymmetries and negative externalities (misattribution, wrongful automated decisions), but at the cost of innovation friction and higher entry costs.
    • Economists should weigh static loss (reduced functionality, higher costs) against dynamic gains (greater trust, lower harm, better market functioning).
  • Empirical research directions for AI economics:
    • Quantify compliance costs attributable specifically to compositional documentation, tracing, and human oversight in agentic systems.
    • Model market concentration effects from compliance economies of scale and estimate welfare impacts.
    • Study pricing and liquidity of inferred‑data markets under stricter protective interpretations.
    • Analyze optimal contract forms and insurance markets allocating chain‑of‑imputation risk among orchestrators, tool providers and end users.
    • Evaluate the cost‑benefit tradeoffs of documentation and reviewability standards (societal harm avoided vs. compliance burden).

Summary takeaway for economists: legal exposure depends on the effects and composition of inference, not only on whether a piece of software qualifies as an “AI system.” Agentic architectures amplify compliance complexity and can shift economic equilibria in product design, market structure, contracting, and the provision of compliance technologies. Quantifying those effects and designing efficient contractual and regulatory responses are actionable research and policy priorities.

Assessment

Paper Typetheoretical Evidence Strengthn/a — This is a doctrinal/legal conceptual analysis and proposal rather than an empirical study; it does not attempt causal identification or provide empirical evidence. Methods Rigorhigh — The paper deploys careful doctrinal analysis: close reading of primary EU legal texts (AI Act, GDPR, recent amendments), engagement with case law and prior literature, and development of a structured two-level analytical framework with concrete interpretive proposals and operational duties; it is rigorous for a legal-theoretical contribution though not empirically validated. SampleNo empirical sample; the paper is a doctrinal and conceptual analysis using EU primary sources (AI Act Article 3(1), Recital 12, Regulation (EU) 2026/1744, GDPR Article 22), relevant CJEU and supervisory decisions referenced (e.g., OT, SCHUFA, EDPS v SRB, Dun & Bradstreet Austria), existing academic and policy literature (Wachter & Mittelstadt, Poretschkin & Naeven, Nikiforov, etc.), and recent policy documents/guidance (e.g., Spanish DPA guidance). Themesgovernance adoption human_ai_collab GeneralizabilityLimited to EU law and the specific textual/jurisprudential context of the AI Act and the GDPR, Doctrinal/theoretical: conclusions are interpretive and not empirically tested on deployed systems, Does not offer comparative analysis with non-EU jurisdictions that define or regulate 'inference' differently, Depends on jurisprudential developments and legislative amendments after August 2026 which may alter applicability

Claims (10)

ClaimDirectionOutcomeConfidence & EvidenceDetails
Under Article 3(1) of the EU AI Act, the capability to infer is a constitutive criterion for determining whether an object qualifies as an AI system. Governance And Regulation positive Determination of AI Act material scope
Reading fidelity high
Study strength medium
not reported
0.12
A system that does not satisfy the Article 3(1) inference threshold is not subject to AI-system obligations under the AI Act in that capacity, but this does not provide immunity from the AI Act as a whole or from the GDPR. Governance And Regulation mixed Applicability of AI Act and GDPR obligations
Reading fidelity high
Study strength medium
not reported
0.12
The AI Act applies its inference criterion as a binary scope decision even though inferential capability is graded in substance. Governance And Regulation mixed Classification of systems under the AI Act
Reading fidelity high
Study strength low
not reported
0.06
Under the GDPR, legal protection can apply to inferences without asking whether the technology that produced them qualifies as an AI system. Regulatory Compliance positive GDPR protection of inferred personal information
Reading fidelity high
Study strength medium
not reported
0.12
The GDPR's protective treatment of inference operates through three pathways: identificatory, attributive, and decisional. Governance And Regulation positive Classification of GDPR-relevant effects of inference
Reading fidelity high
Study strength low
not reported
0.06
Agentic architectures make the non-coincidence between AI Act and GDPR perimeters operationally significant by chaining inferences across components, tools, and providers. Governance And Regulation negative Clarity and operability of legal scope and accountability in agentic systems
Reading fidelity high
Study strength low
not reported
0.06
For AI Act classification, assessment should consider the entire data-processing workflow rather than isolated components. Governance And Regulation positive Accuracy of AI-system classification
Reading fidelity high
Study strength low
not reported
0.06
In an agentic system, the relevant unit for assessing inferential capability is the composed pipeline rather than the individual model, tool, or orchestrator. Governance And Regulation positive Unit of legal and technical assessment for AI-system qualification
Reading fidelity high
Study strength low
not reported
0.06
The article proposes a compositional-effects test to identify the relevant decision unit under Article 22 GDPR and allocate the burden of establishing that unit. Governance And Regulation positive Attribution of automated decision-making under Article 22 GDPR
Reading fidelity high
Study strength speculative
not reported
0.02
The article proposes documentation duties calibrated to the length and structure of inference chains. Governance And Regulation positive Documentation and accountability for inferential chains
Reading fidelity high
Study strength speculative
not reported
0.02

Notes