APEX-Agents · Law
Law_World_423_DM_03
APEX-Agents task Law_World_423_DM_03 in AI Agents for Privacy and GDPR Compliance. Compare dual-harness agent runs across models, scores, and public traces.
Task prompt
What the agent was asked to do
Northstar is evaluating a situation where Bluequill had utilized the EU personal data received by its analytics module from Northstar, and utilized it for the purposes of sending out marketing emails to those data subjects. Would a CNIL investigation likely find that Northstar or Bluequill had liability under French law for not obtaining consent of the data subjects? Reply to me here with your judgement on the matter. Tell me who had liability, with a 1-2 sentence explanation.
Published trajectories
Agent runs on this task
Curated dual-harness runs (parsed + original sandbox). Best scored run per model.
| Model | Harness | Score | Result | Links |
|---|---|---|---|---|
| Gemini 3 Flash | dual | 3/3 | Pass | Run detailsPublic trace |
| Gemini 3.1 Pro | dual | 3/3 | Pass | Run detailsPublic trace |
| GPT-5.4 mini | dual | 3/3 | Pass | Run detailsPublic trace |
| fireworks models Kimi K2 | dual | 2/3 | Fail | Run detailsPublic trace |
| GPT-5.4 | dual | 2/3 | Fail | Run detailsPublic trace |
| GPT-5.4 nano | dual | 2/3 | Fail | Run detailsPublic trace |
| GPT-5.5 | dual | 2/3 | Fail | Run detailsPublic trace |
Grading rubric
Rubric criteria
Runs are graded against these criteria. Open a run for model-specific verdicts.
States that Bluequill would have, or likely have, liability under French law for not obtaining consent of the data subjects
States that Bluequill has the responsibility to obtain valid consent because it is the entity carrying out the commercial prospecting operations under the CPCE
States that Bluequill has the responsibility to obtain valid consent regardless of the fact that it received the data indirectly from Northstar