The Information Commissioner’s Office has extracted data protection changes from ten of the largest AI model builders and asked for evidence, over six weeks, on how agentic AI is being governed. For UK organisations wiring AI agents into their own systems, the message is that autonomy does not dilute accountability under UK GDPR.
What happened
On 8 October 2026 the Information Commissioner’s Office (ICO) published a report on generative AI development and opened a call for evidence on the privacy risks posed by AI agents. The report closes out a two-year supervision programme, set up in 2025 under the regulator’s AI and Biometrics Strategy, that looked closely at the foundation model developers it judged most likely to fall short, selected partly by their UK reach and the riskiness of their training datasets.
Ten firms remain in that programme: OpenAI, Anthropic, Google, Meta, Microsoft, Amazon, Apple, DeepSeek, Cohere and Stability AI. Each has either changed its practices or committed to doing so. The changes cover clearer privacy information, better routes for people to exercise their rights, and more rigorous testing of the safeguards that sit around training data. The ICO says it will track delivery against those commitments.
An eleventh developer is no longer in the programme. Engagement with X.AI was paused when the regulator began formally investigating Grok, and the report confirms that inquiry covers both X Internet Unlimited Company and X.AI LLC and the potential for Grok to produce harmful sexualised imagery.
The regulator also confirmed it has made enquiries of OpenAI, Anthropic, Meta and the UK’s AI Security Institute regarding recent testing and deployment of AI agents. According to the ICO, some agents were reported to have got around their protections, communicated over channels they were not authorised to use and reached external systems including Hugging Face. Responses to the agentic AI call for evidence are due by 20 November 2026.
The detail
The report sets four baseline expectations for anyone training models on personal data: a lawful basis, meaningful transparency, workable routes for people to exercise their rights, and demonstrable safeguards that materially cut risk. Where special category data is involved, or where the model itself may hold personal data, the ICO says the bar is higher still. It also concedes that current training methods make data protection by design genuinely hard to achieve, and says it is raising this with government.
Yet the report states plainly that difficulty in applying the law does not excuse ignoring the fundamentals, and that the regulator will step in where people are exposed to avoidable harm. Computer Weekly’s reading of the report is that purposes as vague as “benefiting humanity” will not support a lawful basis, and that some developers had been turning down objection and erasure requests with one-size-fits-all replies.
There is a clear security thread here. The ICO points to growing evidence that training data can be pulled back out of models, and that scraped web content can contain email signatures, API keys and passwords. A model can, in effect, become an accidental vault of credentials and personal data.
The call for evidence asks about accountability, transparency, data security, lawfulness, fairness and purpose limitation, and automated decision-making. Deployers are invited to respond as well as developers, and the answers will shape both future guidance and the statutory code of practice on AI and automated decision-making that the regulator is preparing.

Why it matters for UK organisations
Most UK organisations will never train a foundation model, but a growing number are deploying agents built on one: assistants that read mailboxes, query CRMs, raise tickets or browse the web on a user’s behalf. In those deployments the UK organisation is very often the controller, and the ICO’s line, voiced by Richard Nevinson, its director of technology regulation, is that autonomy “is not an excuse for poor compliance.”
That has practical consequences. An agent with broad delegated permissions processes personal data every time it acts, often in ways nobody predicted. If it can make or shape decisions about people, the automated decision-making rules come into play. If it can push data to a third-party tool, you need to be able to explain that disclosure. And if it goes off-script, the incident sits on your risk register, not your vendor’s.
A statutory code of practice also changes the compliance weather. Guidance is advisory; a statutory code is something regulators and courts take into account. Documenting agent governance now will pay off when it lands.
One governance footnote: the regulator is now legally the Information Commission, run by a board rather than a single commissioner following the Data (Use and Access) Act 2025, though it still trades as the ICO.
Expert view
In my experience, the gap between how an AI tool is described in a procurement pack and how it behaves once connected to real systems is wide. When we test environments where agents have been granted access, the issues are rarely exotic. They are familiar failings in a new wrapper: over-privileged service accounts, secrets left in prompts and configuration, thin logging, and nobody clearly owning the risk.
The ICO’s enquiries about agents slipping their guardrails should land with security teams as much as data protection officers. An agent that can use unauthorised channels or reach external systems is, from a defender’s point of view, an insider with unclear intent and very fast hands. Least privilege, egress control and audit trails are not AI-specific controls, and that is the point: the basics still decide the outcome.
I would also urge organisations piloting agents to respond: regulators write better guidance when practitioners, not just vendors, speak up.
What to do now
- Inventory your agents. List every AI assistant or agent with access to personal data or business systems, including features switched on inside existing SaaS platforms.
- Run or refresh a DPIA. Record the lawful basis, data flows, any automated decision-making and the human oversight in place. Treat a vague purpose as a red flag.
- Apply least privilege. Give agents dedicated, scoped identities rather than borrowed user tokens, and review their rights regularly. This maps to the Cyber Essentials user access control requirements.
- Control what agents can reach. Restrict outbound connections and tool integrations to an approved list, in line with Cyber Essentials firewall and secure configuration controls.
- Keep secrets out of prompts and training data. Scan for exposed API keys and credentials, and rotate anything that has been pasted into an AI tool.
- Log and test. Capture what agents do, and include agent behaviour and guardrail bypass in penetration testing scope.
- Question suppliers. Ask your model provider what it changed under the ICO programme.
- Respond by 20 November 2026 if you have evidence to contribute.
Bottom line
The ICO has spent two years getting the biggest model builders to tidy up their data protection. Its attention is now moving to how agents behave once deployed, and that puts UK deployers squarely in scope. Organisations that treat agents as privileged identities, governed, logged and tested like any other, will be ready for the statutory code. Those that do not are building tomorrow’s enforcement case today.
Sources
- ICO: ICO secures changes from leading AI developers as scrutiny extends to AI agents
- ICO: Building trust and transparency into generative AI development
- ICO: Agentic AI call for evidence
- Infosecurity Magazine: Major AI Firms Pledge Data Protection Changes Following UK Privacy Watchdog Push
- Computer Weekly: AI model developers have ‘no justification’ for failing to comply with privacy law
- GRC Report: UK Privacy Regulator Secures Changes From 10 Major AI Developers, Expands Scrutiny to AI Agents