Skip to main content
1 min readExecutive Guide

Executive Guide

Research Summary: Inferential Capability Does Not Determine Legal Scope

Original authors
Attribution requires verification
Original source
arXiv — Computers and Society
Summary & Analysis prepared by
Aziz Shuaib Ausi
Resource type
Research Summary / Knowledge Resource
Resource published on AZIZ OS
13 August 2026
Last updated
22 September 2026
Reading time
1 min
Publication type
Executive Guide
Availability
Open access
About this Summary & Analysis

AZIZ OS provides independently prepared summaries and analytical interpretations of externally published research and knowledge sources. The underlying works remain attributable to their original authors and rights holders. This resource is intended to improve accessibility and understanding and does not replace the original publication.

Checking access…

Recent research from arXiv highlights a critical divergence in how 'inference' is defined and applied within EU digital law, specifically between the AI Act and the GDPR. The AI Act uses inferential capability to define regulated AI systems, while the GDPR governs inference protectively based on its impact on individuals, regardless of whether the technology is classified as AI. This creates non-concentric regulatory perimeters, which become operationally acute with agentic architectures, suggesting that mere inferential capability does not solely determine legal scope.

Why it matters

The divergence in legal definitions and regulatory approaches to 'inference' across critical digital laws creates significant operational and compliance complexities for organisations developing and deploying advanced technologies. Understanding these differing regulatory perimeters is essential for strategic planning, risk management, and ensuring legal compliance in the evolving landscape of AI and data protection.

Key insights

  • The EU AI Act uses 'inferential capability' as a foundational criterion to distinguish regulated AI systems from conventional software.
  • The GDPR, while not defining 'inference', regulates its outcomes protectively, focusing on the processing of personal data and its effects on individuals, irrespective of AI classification.
  • The regulatory scopes of the AI Act and the GDPR concerning inference are not aligned or concentric.
  • This non-alignment was less apparent in single-shot systems but becomes operationally critical with the rise of agentic architectures.
  • The core thesis is that inferential capability itself does not determine the full legal scope of a technology or system.

Source

arXiv — Computers and Society — https://arxiv.org/abs/2608.10601

Citation

Cite the original work (APA 7)

The original source is authoritative for this citation. Cite the source publication directly — this attribution is pending verification. Open the original source.

Verification

This is an authenticated AZIZ OS resource record.

Verification ID
ASA-EXG-2026-00243
Version
v1.0 · r0
Issued
13 August 2026
Resource prepared by
Aziz Shuaib Ausi
Resource status
Research Summary / Knowledge Resource
Underlying work
Inferential Capability Does Not Determine Legal Scope
Original authors
Attribution requires verification
Original source
arXiv — Computers and Society
Provenance status
Attribution requires verification
Rights
Underlying publication rights remain with the respective copyright holder(s). Refer to the original source for authoritative publication and licensing information.

This verification confirms the AZIZ OS resource record and its documented provenance. It does not establish authorship of the underlying external work.

Verify this resource