> ## Content Index
> Fetch the complete content index at: https://bytevyte.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Convention 108+ AI privacy rules turn chatbot memory into a compliance decision
- URL: https://bytevyte.com/convention-108-ai-privacy-rules-turn-chatbot-memory-into-a-compliance-decision/
- Published: 2026-09-07T20:37:04.000Z
- Updated: 2026-09-07T20:37:04.000Z
- Description: The Council of Europe's Convention 108+ AI privacy rules would switch chatbot memory off by default and cap agent credentials. What enterprises should prepare for now.
- Author: Bytevyte Editorial
- Tags: ai-beats

The Council of Europe has drafted **Convention 108+ AI privacy rules** that would leave chatbot memory disabled by default and cap agent credentials at the minimum access each task requires, the first treaty-level rulebook to dictate product defaults for generative AI. The data protection committee published the draft agenda on September 3, 2026\. The Bureau of the Convention 108 Committee will review the guidelines in Paris on September 16-17, 2026, and formal adoption is targeted for the November plenary.

The instrument does not run through the European Union. **Convention 108+** is the modernized form of the 1981 Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, administered by the 46-member Council of Europe and binding more than 55 states, including countries outside the bloc. The Council of Europe frames the guidance as interpretation rather than legislation: it creates no new rights and imposes no obligations beyond those the treaty already carries, explaining how established data-protection principles apply to large language models, chatbots and agents.

That framing shapes scope. Because the guidelines interpret a treaty already in force, they can be applied across all parties without further national legislation once the committee adopts them.

## What the Convention 108+ AI privacy rules require

The draft sets four concrete expectations for controllers:

- Persistent chatbot memory switched off by default unless a specified purpose for continuity exists and the associated risk has been mitigated.
- Agent credentials scoped to the minimum access each assigned task requires and revocable without delay.
- A documented inventory of every model, tool, memory store and data flow within a system.
- Ability for individuals to locate, correct and delete personal data across every model layer, with attention to training-data extraction attacks.

The immediate effect is to move privacy decisions out of the product team. A vendor that wants continuity must articulate a purpose and show the risk is mitigated before memory can be switched on, and an operator running autonomous agents must be able to explain why a credential reaches any given system. Data protection authorities get a concrete yardstick for judging both calls.

The drafting rests on preparatory work begun more than a year earlier. A 34-page expert report by Isabel Barberá and Murielle Popa-Fabre, presented to the committee's 48th plenary in June 2025, traced how personal data moves through chatbots, retrieval-augmented systems and AI agents. The guidelines translate that map into requirements.

Retrieval-augmented setups show why the map matters. User content is duplicated across prompt context, vector indexes and conversation memory, so a deletion request has to reach every copy. That duplication is precisely what pushes the draft toward cross-layer erasure instead of a single delete call.

## Filling a gap the EU AI Act left open

The timing tracks a crowded regulatory year in Brussels. The EU AI Act has applied since August 2024, and its transparency duties took effect on August 2, 2026, forcing chatbots to disclose that users are dealing with software and requiring labels on deepfakes. Enforcement is shared between the European Commission's AI Office and national authorities. The act itself spent 2026 under revision: negotiations on a simplified text collapsed in April, and the Council only cleared the streamlining package in late June, leaving the timing of high-risk obligations unsettled.

Agents are the visible gap. They keep producing headline-grabbing incidents across Europe and do not fit cleanly into the AI Act's risk categories. Other instruments are circling them instead: ChatGPT became the first chatbot designated a very large online platform under EU digital-services rules, a status reserved for services above 45 million monthly users in the bloc that carries extra scrutiny duties.

The **Convention 108+ AI privacy rules** close part of that gap at treaty level. Because they are cast as interpretation, they bind every party to the Convention without waiting for new law, making them the only detailed statement of how conversational AI should handle personal data in treaty states that have no GDPR.

For multinational operators, the practical point is reach. The treaty binds states outside the EU where no GDPR applies, so a company serving those markets cannot fall back on local-law gaps. One global chatbot configuration now has to meet the treaty standard wherever it touches personal data.

There is also a spillover question for providers. Convention 108+ and the GDPR share core concepts, and in many states the same national authorities supervise both. A committee reading that treats persistent memory as a risk to be justified can therefore shape expectations well beyond the treaty's own parties.

## The design trade-offs enterprises will feel

The defaults run against convenience. Persistent memory is what lets a support assistant recall a customer's history across sessions, and agents that chain several tools need broader permissions than a single API call demands. Deployers who want those behaviors now need documented purpose and mitigation, converting a product toggle into a recorded decision a regulator can inspect.

Erasure is the harder obligation in practice. Personal data sits in prompt logs, vector databases and fine-tuning sets, and deleting across those layers is achievable with disciplined tooling. Removing information a model has absorbed into its weights is not something training pipelines support on request, so architects are likely to favor designs where personal data lives in removable stores such as retrieval indexes rather than inside model parameters.

Deployers are effectively picking among three postures. Keeping memory and agent access off delivers the simplest compliance story and the weakest user experience. Enabling them demands documented purpose, risk assessment and revocation tooling, costs that land mainly on product and security teams. Rebuilding memory as data that can be deleted on request satisfies continuity and erasure at once, at the price of reworking stateful components today.

The regime also points at a different actor than the AI Act does. Brussels concentrates on providers placing systems on the market, while the Convention 108+ AI privacy rules speak to controllers, the organizations that operate chatbots and decide how data flows through them. For most enterprises that means the deployer, not the model vendor, carries the documentation burden.

Planning can start before the text is final. The Bureau session in Paris in mid-September will shape the language, the November plenary decides on adoption, and enforcement will then run through the treaty's existing mechanisms. National authorities would have a direct route to act on memory settings and credential grants they consider out of line once the interpretation is published.

## Why this matters

For enterprises running chatbots and AI agents across Europe, memory defaults, credential scope and data-flow documentation are becoming legal settings rather than product choices. Teams that inventory their models and shrink agent access before the November plenary will be ahead of guidance that stretches a 45-year-old treaty over agentic AI while the EU's high-risk rules remain in flux.

## Sources

[Artificial Intelligence: Council gives final green light to simplify and streamline rules - Consilium](https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/?ref=bytevyte.com)

[AI Act | Shaping Europe's digital future - European Union](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=bytevyte.com)

[European approach to artificial intelligence | Shaping Europe’s digital future](https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence?ref=bytevyte.com)

[Safer and more transparent AI - European Commission](https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02%5Fen?ref=bytevyte.com)

Photo by [Enchanted Tools](https://unsplash.com/@enchantedtools?utm%5Fsource=bytevyte&utm%5Fmedium=referral) on [Unsplash](https://unsplash.com/?utm%5Fsource=bytevyte&utm%5Fmedium=referral)

## Related Articles

- [EU AI Act Enforcement Is Underway: What Enterprises Face From August 2 \[Update\]](https://bytevyte.com/eu-ai-act-enforcement-is-underway-what-enterprises-face-from-august-2-update/)
- [EU AI Act Article 50 Compliance: Six-Day Countdown to August 2 Transparency Rules](https://bytevyte.com/eu-ai-act-article-50-compliance-six-day-countdown-to-august-2-transparency-rules/)
- [EU AI Act Article 50 Compliance Deadline Narrows: 10 Days to Finalize Transparency Measures](https://bytevyte.com/eu-ai-act-article-50-compliance-deadline-narrows-10-days-to-finalize-transparency-measures/)

✔Human Verified

---

*Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.*