A New AI Privacy Framework Beyond GDPR
The Council of Europe has published draft guidelines under its Convention 108+ treaty that would establish AI privacy requirements across 55 countries, a footprint that extends well beyond the European Union's GDPR. While GDPR remains the most well-known data protection law in the world, Convention 108+ is a separate, binding international treaty that covers member states of the Council of Europe, including non-EU countries. That broader reach means the new draft guidelines could shape how AI systems handle personal data in nations that fall outside GDPR's jurisdiction entirely.
The draft addresses three specific areas of AI privacy risk: chatbot memory settings, the scope of permissions granted to AI agents, and the vulnerability of AI models to training-data extraction attacks. Each of these reflects a real and growing concern as AI tools become more embedded in everyday consumer and business use.
What the Draft Guidelines Actually Require
According to the draft, AI chatbots would need to have memory features turned off by default. This means that unless a user actively opts in, a chatbot would not retain details from previous conversations. Memory features have become popular because they let AI assistants personalize responses over time, but they also create a persistent record of potentially sensitive information shared during casual conversation. A default-off setting shifts the burden onto companies to earn user consent rather than assuming it.
The guidelines also call for AI agents, the increasingly common tools that can take actions on a user's behalf like booking appointments or managing accounts, to be scoped with the minimum credentials necessary to complete a task. This is a security principle known as least-privilege access, applied specifically to AI systems. Instead of granting an AI agent broad access to a user's data or accounts, the credentials would be limited to only what's needed for the specific job at hand, reducing the potential damage if an agent is compromised or misused.
The third area covered is training-data extraction attacks, a technique where bad actors attempt to pull sensitive or personal information out of an AI model based on how it responds to certain prompts. The draft guidelines note that these attacks can be carried out at low cost, which is part of what makes them a pressing concern for regulators. If extracting private training data doesn't require significant resources or technical sophistication, the incentive for malicious actors to attempt it grows substantially.
Why Convention 108+ Matters for Global AI Compliance
One of the more overlooked aspects of this draft is the treaty it falls under. Convention 108+ is often described as the world's first binding international instrument on data protection, and it predates GDPR. Its signatories include countries well beyond the EU's borders, which means companies operating AI products internationally may need to comply with two overlapping but distinct frameworks: GDPR for EU operations and Convention 108+ for the wider set of 55 nations.
This dual-track compliance landscape mirrors a pattern already playing out elsewhere. As covered in a recent look at how GDPR fines and AI rules are reshaping compliance, businesses are increasingly treating data protection as a core operational priority rather than a legal checkbox. Similarly, GDPR fines up to €20 million have shown that compliance and actual security posture aren't the same thing, a distinction that will matter just as much under Convention 108+'s AI-specific guidance. Other regions are moving in parallel too: POTRAZ's enforcement of data protection law in Zimbabwe starting in September 2026 is another example of data protection enforcement expanding beyond the EU's traditional regulatory reach.
What This Means For You
For everyday users of AI chatbots and agents, these draft guidelines signal a shift toward privacy-by-default design. If adopted, you may start seeing more AI products with memory features turned off unless you specifically enable them, and AI agents that ask for narrower permissions rather than broad account access. For businesses building or deploying AI tools, especially those operating in multiple countries, the draft is a reminder that AI privacy compliance Europe 2026 won't be a single unified standard. Companies will need to track requirements across both GDPR and Convention 108+ jurisdictions, and design systems that can meet the stricter of the two wherever they operate.
Key Takeaways
- Convention 108+ binds 55 nations, a footprint significantly larger than GDPR's EU-only scope, so AI compliance planning should account for both frameworks.
- Draft guidelines call for chatbot memory to default to off, giving users more control over what conversational data is retained.
- AI agents would need credentials scoped to minimum necessary access, limiting exposure if an agent is compromised.
- Training-data extraction attacks are flagged as low-cost and high-risk, underscoring why AI privacy compliance Europe 2026 is becoming a priority for regulators.
- Businesses operating internationally should start reviewing AI product settings now, rather than waiting for the guidelines to be finalized.




