Which AI for which job · part 4 of 6

Answering on your own documents: what the model may read, and how old it is

Part 3 ended on a question: when the model can read, who decided what it may read, and when was that last true? This row is where a language model answers from your documents rather than from its training run. Three ways to do it, three different deciders, and one thing they share that the previous rows did not have: an index, which is a copy of your data with an access list and a date. The risk moves from what the model writes to what it was allowed to read.

HokonokenSeptember 2026Reading time: 16 minNot legal advice · Views are my own, not my employer's

Three things to take away

  1. Retrieval puts your documents where the training run was. The model's memory becomes two things: the weights, which are the provider's, and the index, which is yours. Everything part 3 said about content still holds. What is new is that the answer draws on a copy of your data, and the copy has an access list and a date.
  2. Three RAGs, three deciders. Classic: the retriever decides, by similarity, in one pass. Agentic: the model decides what to search, where and how many times, so retrieval has become an action and part 5 begins here. Graph: the ingest decided, before any question was asked, which entities and relations exist; the risk moved to ingest time.
  3. The index is a copy, and the law treats copies as data. Accuracy and storage limitation under GDPR Article 5, erasure under Article 17: a deletion that does not reach the index is not a deletion. And access has to be checked at query time, as the user, or the model becomes the way around the permission system.

What changed since part 3

The 2020 paper that named the technique described a model that combines "pre-trained parametric and non-parametric memory": the weights on one side, "a dense vector index" reached through a retriever on the other. That second memory is the whole point of this row. It is yours. You fill it, you can empty it, you can say what is in it and when it was put there. Nothing about the weights gives you any of that.

Four consequences, and the rest of this part is about them. The model can be right about your data without anyone retraining it. It can be confidently wrong about last quarter's policy, in the present tense, with a citation, because the index is as old as its last ingest. It can answer a user's question from a document that user was never allowed to open, because the retriever looked at similarity and not at permissions. And, for the first time in this series, the answer can point at its source: the chunk, the page, the version. The citation is not a courtesy in this row; it is the control.

Three RAGs, three deciders

Classic RAG. The question is embedded, the nearest chunks are fetched, the model writes an answer from them, a person reads it. The retriever decides what the model sees, by similarity, once. The person is still the control, as in part 3, and the system sits at level 2. What the person cannot see is what was not retrieved: a missing chunk produces a fluent answer with a gap in it, and the citation shows only what was used.

Agentic RAG. The 2025 survey that named it describes "embedding autonomous AI agents into the RAG pipeline" so that they "dynamically manage retrieval strategies, iteratively refine contextual understanding, and adapt workflows", using "reflection, planning, tool use, and multi-agent collaboration". Read that with the map: the model now decides what to search, in which store, how many times, and when to stop. Retrieval has become an action chosen by the model, and every question from the action rows applies to it: through which gateway, under whose identity, with what record. The system is at level 4 even though nothing is written anywhere, because its reads happen without a person and are read about after, and OWASP's 2025 list has an entry for the failure, "Excessive Agency". Part 5 starts exactly here; this part only asks what the retrieval action needs.

Graph RAG. The 2024 paper from Microsoft Research starts from a limitation: conventional retrieval "fails on global questions directed at an entire text corpus, such as 'What are the main themes in the dataset?'". Its answer is to build "an entity knowledge graph from the source documents" at ingest and to "pregenerate community summaries for all groups of closely related entities", so that a global question is answered from the summaries rather than from nearest chunks. What that does to the map is subtle. The decision about what the model will draw on was taken before any question, by a model, at ingest time. An extracted relation is an assertion about your data, made by a model, on a date. When it is wrong, it is wrong for every question that touches it, and the person reading the answer has no chunk to check against, only a summary of a summary. The control moved to the ingest, and so must the review.

INGEST · THE INDEX IS A COPY Sourcesfiles, mail, tickets, with their ACLsWHAT THE USER MAY SEE Parselayout, OCR, versions (Docling)PART 2 · PERCEPTION Chunk and embedvector index: Milvus, Qdrant, pgvector Extract entities and relationsgraph: GraphRAG The copychunks or nodes, each with:ACL · AS-OF DATE · SOURCE VERSION Access: the ACL travels with the chunk andis checked at query time, as the user.OWASP LLM08, LLM02. Erasure: a deletion that does not reach thecopy is not a deletion. GDPR Art. 17, 5(1)(e). Poisoning happens here: a document placed where the crawler reads it is an instruction the model will obey later. OWASP LLM04, LLM01; AI Act Art. 15(5) names "data poisoning". Freshness happens here too: the answer is as old as the last ingest, and the as-of date is the only thing that says so. S1 · PART 1 (VECTOR_IO, IDENTITY) · PART 5 (RECORDS) ASK · WHO DECIDES WHAT TO READ A questionfrom a person, as that personIDENTITY TRAVELS Classic RAGthe retriever decides: top-k by similarity, one passLEVEL 2 READ The person reads the answer and the citation. The risk is the chunk the user was not allowed to see, and how old it is. Lewis et al., 2020: parametric memory plus a dense index. Agentic RAGthe model decides: what to search, where, how oftenLEVEL 4 READ Retrieval has become an action: a tool call through the gateway, run as the user, every query recorded. OWASP LLM06. Singh et al., 2025: "dynamically manage retrieval strategies". Graph RAGthe ingest decided: entities and relations, up frontLEVEL 2 READ Global questions over a corpus. The risk moved to ingest time: who extracted the relation, from which version, when. Edge et al., 2024: entity graph and community summaries.
no language modelyour sources, a person readsthe copy, and the retrieval that became an actionLevels from part 1: 2 proposes · 4 acts, reviewed after
Top: ingest. Sources with their access lists go through a parser, then into a vector index or a graph. The copy is the hot box: every chunk or node carries an access list, an as-of date and a source version, or the four properties below cannot be met. Bottom: the question, and who decides what is read. Only agentic RAG is hot: the model chooses the retrieval, which makes it an action through the tool gateway of the first series.

The index is a copy

Four properties follow from that sentence, and each one is a requirement on the ingest pipeline, not on the model.

Access. The model has no permissions of its own; part 3 established that for the copilot and it holds here. What it inherits is the user's, and the retriever must honour them at query time: the same user, the same identity from the platform's identity provider, evaluated against the access list that travelled with each chunk. A retriever that searches the whole index and filters afterwards has already leaked; a retriever that searches an index built without access lists cannot filter at all. OWASP's 2025 list names both halves: "Sensitive Information Disclosure" and "Vector and Embedding Weaknesses", the latter written for systems "relying on semantic search and retrieval". The first series had identity at the ingress and at the tool gateway. This row needs it at the index.

Freshness. Every chunk carries the version of its source and the date it was ingested, and the answer states them. That is the whole freshness axis from part 1, made concrete. A policy replaced on Monday is answered from the Friday version until the next ingest, and nothing in the model knows. GDPR Article 5(1)(d) asks that personal data be "accurate and, where necessary, kept up to date"; the index is where that clause is met or missed for this row.

Erasure. A deletion in the source system that does not propagate to the index is not a deletion. Article 17 gives the data subject "the erasure of personal data concerning him or her without undue delay", and Article 5(1)(e) limits storage to "no longer than is necessary for the purposes". Whether an embedding of a paragraph about a person is personal data is a question I will leave to counsel; the paragraph next to it in the chunk store certainly is. The ingest pipeline needs a delete path that is as reliable as its insert path, and a record that it ran.

Integrity. The index is fed by a crawler, and a crawler reads what is placed where it reads. A document that contains instructions is, once retrieved, an instruction to the model. OWASP calls it "Prompt Injection" when it arrives through the prompt and "Data and Model Poisoning" when it arrives through the data; the AI Act's Article 15(5) names "data poisoning" among the attacks a high-risk system must resist. The defences are dull: a list of what the crawler may read, a review of what enters a graph, an input guardrail between the retrieved chunk and the model, and a record of which chunk was in the context when the answer went wrong.

What the platform owes them

Take part 3's platform and add the index and everything that feeds it.

Where the law reaches this row

Through data protection, first. This is the first row where the law's main handle is not the AI Act. GDPR Article 5(1) gives the index its five constraints in one paragraph: purpose limitation, data "collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes"; minimisation, "limited to what is necessary"; accuracy; storage limitation; and integrity, "protection against unauthorised or unlawful processing". Article 5(2) adds that the controller must "be able to demonstrate compliance", which is what the ingest records are for. Article 17 is the erasure path. The Swiss FADP carries the same principles; the first series read its Articles 7, 8 and 12, protection by design, data security and the record of processing activities, and an index of your documents is a processing activity that belongs in that record.

Through the AI Act, lightly. Article 50(1) for any assistant a person talks to. Articles 10 and 15(5) if the job is on Annex III, in which case the index is training-adjacent data and poisoning is a named attack. Article 26(6) for the logs. Nothing in Annex III says "retrieval"; the row inherits the risk class of the job it serves.

Through security law. NIS2 Article 21(2) asks for "access control policies and asset management" and "the use of cryptography". An index of everything an organisation knows is a single asset that holds all of it, at rest, in a form built to be searched; it belongs on the asset list with the encryption and the access policy that implies. The same article's supply-chain clause covers the embedding model and the store.

Through the licence. An index is a reproduction of the documents in it. For your own documents that is your decision. For licensed content, manuals, standards, market data, the licence says whether a copy built for machine retrieval is allowed, and most were written before anyone asked. Read it before the crawler does.

Three organisations, nine jobs

The same three organisations. Each job is placed by who decides what is read, and the last column is what the copy brings with it. Article 50(1) applies to every row where a person talks to the assistant and is not repeated below.

JobFamily, levelWorst actionWhat the platform must provideRegulatory line
A public agency gives caseworkers an assistant over the regulations, circulars and internal guidance they apply.Classic RAG, 2read; an outdated rule appliedIngest keyed to the official version of each text, as-of date in every answer, citation to the article; the gate reruns on every circular.Not an Annex III row by itself; if the answer feeds a benefit decision, Annex III 5(a) reaches the system it serves. Article 4 for the caseworkers. FADP Article 12: the index is in the record of processing.
The same agency answers citizens' questions on public information in a chat.Classic RAG, 2read; a wrong answer to the publicIndex limited to published texts, so there is no access question; faithfulness scored in the gate; a refusal path; conversations under a retention decision.Article 50(1): the citizen is told at the first interaction. Article 50(4) if answers are published rather than given. GDPR and FADP for what the citizen types.
The same agency lets caseworkers search across citizens' files by asking, and the assistant decides which files to open.Agentic RAG, 4read: a file the caseworker may not openEvery retrieval runs as the caseworker through the tool gateway, against the file system's own access list; each query and each file opened recorded with the caseworker's identity; a search that returns nothing is recorded too.GDPR Article 5(1)(b) and (f): purpose and access. FADP Articles 7 and 8. OWASP LLM06. Not Annex III, unless what is found feeds a decision listed there.
A bank gives advisers an assistant over product sheets, pricing and internal policies.Classic RAG, 2read; a wrong condition quoted to a clientSource version and validity date on every chunk; citation shown to the adviser; the index rebuilt from the document system, never from mail.FINMA 08/2024 §2.2 inventory entry and §2.5 documentation of data selection. Not Annex III.
The same bank analyses master agreements with a graph of clauses, parties and dependencies, and asks which contracts a change of law touches.Graph RAG, 2read; a missed dependencyThe extracted graph versioned and reviewed by a lawyer sample before use; each edge traceable to the clause and the contract version; a rebuild when a contract changes.Not Annex III. The graph is a derived record of contractual data; confidentiality and NIS2 Article 21(2) access control apply to it as to the contracts. Counsel owns the review.
The same bank's investigators use an assistant that searches transactions, alerts and prior cases on its own to build a picture.Agentic RAG, 4read: a case outside the investigator's remitRetrieval as the investigator through the tool gateway; every query and every hit recorded and kept with the case; the assistant cannot write to the case file.Anti-money-laundering rules govern the case; GDPR Article 5(1)(b) purpose limitation for the data reused; NIS2 for the systems. Annex III 5(b) excludes fraud detection; the bank should still check where the picture goes.
A manufacturer gives technicians an assistant over maintenance manuals, with several machine generations in service.Classic RAG, 2read; the wrong procedure for the machine in front of themChunks keyed to machine model and manual revision; the answer states both; a technician cannot get an answer without saying which machine.Product-safety and machinery rules for the procedure; the manual's licence for the index if it is the supplier's. Not Annex III.
The same manufacturer maps which part depends on which standard, supplier and certificate, and asks what a withdrawn certificate affects.Graph RAG, 2read; a missed part shipsGraph built from the PLM system with each edge traceable; a review of extracted relations by an engineer sample; rebuild on every bill-of-materials change.Product-compliance rules for the parts; trade-secret protection for the graph, which is the company's supply chain in one file; NIS2 Article 21(2) supply-chain security if the manufacturer is in scope.
The same manufacturer lets engineers ask an assistant that searches the PLM system, tickets and mail on its own.Agentic RAG, 4read: a project the engineer is not cleared forRetrieval as the engineer through the tool gateway against each system's own access list; export-controlled projects excluded from the index rather than filtered; every query recorded.Trade secrets and, where applicable, export-control rules that do not care whether a person or a retriever opened the file. GDPR Article 5(1)(f). NIS2.

None of the nine is high-risk under the AI Act on its own, and every one of them carries a data-protection or confidentiality obligation that already applied to the documents before anyone indexed them. That is the pattern of this row: the law did not change, the copy did. The three agentic rows are the ones where the platform column grows a gateway and an identity, and those are the columns of part 5.

What this row teaches the next

Agentic RAG is an agent that is only allowed to read. It chooses what to fetch, it goes through a tool gateway, it runs as the user, and every query is recorded; if it were not, the file the caseworker may not open would be one similarity search away. All of that machinery exists so that a read stays a read. The next row lets the same machinery write. The question that carries over is the one the reversibility axis was made for: when the worst action is no longer a disclosure but a change in a system, what has to be true before the model is allowed to make it?

Next in the series
  1. Part 1The map: who decides, who acts, and how far the system goes on its own. The reference for every part that follows.
  2. Part 2AI without a language model: prediction, recommendation, perception, optimisation. What already runs everywhere, and why it is not "less" than the rest.
  3. Part 3Generating and assisting: generative AI, integrated copilots, small specialised models. The person reads, the risk is the content.
  4. Part 5Acting within a perimeter: the AI agent with its tools, and the augmented workflow as the migration path. The risk is the action; the perimeter is outside the model.
  5. Part 6Pursuing a goal with several agents: agentic AI, delegation, intent. The most demanding regime, and the one sold first.
This article is an engineer's reading of public legal texts and public code, checked against the versions and dates given below. It is not legal advice. For a real deployment, read the texts with counsel and with your supervisor's guidance for your sector.
Read, not run. Everything in this series comes from reading public documents and public code at a stated date, not from running them in production. Treat it as a map to test, not a result to trust: the texts are amended, the projects move monthly, and a placement that is right for one organisation's wiring is wrong for another's. Place your own jobs on the map with the people who own them. When something here does not match what you find, tell me, or better, tell the project or the authority concerned: that is the only way a map like this one stays true.

Sources
  1. Patrick Lewis et al., Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks, arXiv 2005.11401, submitted 22 May 2020, v4 of 12 April 2021. Darren Edge et al., From Local to Global: A Graph RAG Approach to Query-Focused Summarization, arXiv 2404.16130, submitted 24 April 2024, latest version 19 February 2025. Aditi Singh et al., Agentic Retrieval-Augmented Generation: A Survey on Agentic RAG, arXiv 2501.09136, submitted 15 January 2025. Abstracts read 23 September 2026.
  2. OWASP Top 10 for LLM Applications 2025, entries LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM04 Data and Model Poisoning, LLM06 Excessive Agency, LLM08 Vector and Embedding Weaknesses; read 23 September 2026.
  3. Regulation (EU) 2016/679 (GDPR), Article 5 and Article 17, read on gdpr-info.eu, 23 September 2026. Federal Act on Data Protection (FADP, SR 235.1), Articles 7, 8 and 12, as read for part 3 of the first series on Fedlex, 22 September 2026; the principles article was not re-read for this part and is not quoted.
  4. Regulation (EU) 2024/1689 (AI Act), Article 4, Article 10, Article 15(5), Article 26(6), Article 50; Directive (EU) 2022/2555 (NIS2), Article 21(2); FINMA Guidance 08/2024, §2.2 and §2.5. As read for the earlier parts, 22 and 23 September 2026.
  5. Milvus, LF AI & Data, Apache-2.0, v3.0.2, 20 September 2026. Qdrant, Apache-2.0, v1.19.1, 4 September 2026. pgvector, PostgreSQL licence, v0.8.6, 22 September 2026. Weaviate, v1.39.6, 22 September 2026. GraphRAG, MIT, v3.1.2, 21 August 2026. Docling, MIT, v2.130.0, 22 September 2026. Release tags and dates from each repository's GitHub releases or tags page, 23 September 2026.
  6. OpenTelemetry semantic conventions for GenAI, the "embeddings" operation, read 23 September 2026. Model Context Protocol specification, revision 2025-06-18, server primitives: resources, prompts, tools; the current revision, 2026-07-28, keeps the three (see part 5).
  7. Agent stack blueprint, the first series, parts 1, 3 and 5, for the vector store behind the OGX server, identity, the regulatory matrix and the records.

Independent work, not affiliated with any regulator, court, standards body, foundation or vendor named. Not legal advice. Product names belong to their owners. Views are my own and do not represent the position of my employer. Text and diagrams: CC BY 4.0; quoted code and documents stay under their own licences.