APEX-Agents · Law
World423_DPM_02
APEX-Agents task World423_DPM_02 in AI Agents for Privacy and GDPR Compliance. Compare dual-harness agent runs across models, scores, and public traces.
Task prompt
What the agent was asked to do
Review the Controller-to-Supervisory Authority Notification Template, along with the timing set out in the V.2 Breach & Incident Response Policy, to ensure compliance with the notification requirements of the General Data Protection Regulation (GDPR). Draft a message to me here that answers Yes or No as to whether each policy is compliant. If not compliant, propose any necessary additions.
Published trajectories
Agent runs on this task
Curated dual-harness runs (parsed + original sandbox). Best scored run per model.
| Model | Harness | Score | Result | Links |
|---|---|---|---|---|
| GPT-5.4 | dual | 2/4 | Fail | Run detailsPublic trace |
| GPT-5.4 mini | dual | 2/4 | Fail | Run detailsPublic trace |
| Gemini 3.1 Pro | dual | 1/4 | Fail | Run detailsPublic trace |
| fireworks models Kimi K2 | dual | 0/4 | Fail | Run detailsPublic trace |
| Gemini 3 Flash | dual | 0/4 | Fail | Run detailsPublic trace |
| GPT-5.4 nano | dual | 0/4 | Fail | Run detailsPublic trace |
| GPT-5.5 | dual | 0/4 | Fail | Run detailsPublic trace |
Grading rubric
Rubric criteria
Runs are graded against these criteria. Open a run for model-specific verdicts.
States Yes, the Controller-to-Supervisory Authority Notification Template is compliant with the GDPR notification requirements
States Yes, the Breach & Incident Response Policy is compliant with the GDPR notification requirements
States that no additions are needed to make the Controller-to-Supervisory Authority Notification Template compliant with the GDPR’s notification requirements
States that no additions are needed to make the V.2 Breach & Incident Response Policy compliant with the GDPR’s notification requirements