---
title: "Function creep"
description: "The gradual reuse of personal data or an AI system for purposes nobody approved, usually by configuration rather than a new release."
canonical: https://aigovernanceengineer.com/glossary/function-creep
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Function creep

The gradual reuse of personal data or an AI system for purposes nobody approved, usually by configuration rather than a new release. For personal data it breaches purpose limitation unless a compatibility assessment or new basis covers the new use [1]; negative space in the deployment record makes it detectable.

- Developed in: [ch. 19, Purpose limitation and function creep](https://aigovernanceengineer.com/bok/privacy-and-ai#purpose-limitation-and-function-creep); [ch. 15, Secondary use and downstream harm](https://aigovernanceengineer.com/bok/governing-deployment#secondary-use-and-downstream-harm); [ch. 05, Pattern: Downstream Use Register](https://aigovernanceengineer.com/patterns/downstream-use-register)
- Chapters: [ch. 05, Patterns](https://aigovernanceengineer.com/bok/patterns) · [ch. 14, Development](https://aigovernanceengineer.com/bok/governing-development) · [ch. 15, Deployment](https://aigovernanceengineer.com/bok/governing-deployment) · [ch. 19, Privacy & AI](https://aigovernanceengineer.com/bok/privacy-and-ai)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-function-creep

## Sources

[1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
