these AI applications operate on smartphones, they may request
access to device-level data or functions such as contacts, location
information, or stored photos. While users can technically control
each permission individually, understanding and managing a large
number of settings in a comprehensive and accurate manner is not
an easy task.
As AI systems evolve beyond “generative” functions and increasingly
operate as “agents” that act on behalf of users, the risks to personal
data protection are likely to grow significantly. When multiple
agents exchange data—such as an AI agent on a user’s smartphone
communicating with an airline’s AI agent—the flow of information
becomes far more difficult to track than it is today. Even if the user
issues instructions and intermittently monitors the process, the
detailed steps required to carry out those instructions are typically
executed autonomously by the agent. As a result, it becomes harder
to determine who has access to personal data, how long transmitted
data is retained, and whether it is being properly managed. This
increases the risk of inadequate protection or intentional misuse.
The growing number of data transfers also heightens the risk of
security breaches, and delegating account access to agents raises
the possibility that accounts may be manipulated without the data
subject’s awareness.
In this context, policy measures such as limiting data transfers to
the minimum necessary and ensuring the deletion of data once its
purpose has been fulfilled become even more critical, in line with
core personal data protection principles. In addition, AI providers,
as data controllers, should be subject to stronger obligations to
84
85