The ICO turns to AI agents: ten developers change practice, and a call for evidence closes 20 November
What changed
On 8 October 2026 the Information Commissioner's Office published the outcome of a two-year supervision programme for foundation model developers. Ten of the largest developers operating in the UK have made, or committed to make, data protection changes: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. The ICO describes the changes as clearer transparency information, stronger mechanisms for people to exercise their rights and tougher assessments of safeguards, and says it is monitoring progress. The programme began with eleven priority developers; engagement with X.AI was paused when the ICO opened a formal investigation into Grok, which continues. The accompanying report tells developers that where they process personal data to train models they must identify a lawful basis, provide meaningful transparency, enable people to exercise their rights and show safeguards that materially reduce risk, and that the ICO will intervene where organisations expose people to avoidable harm.
The same day the ICO opened a six-week call for evidence on agentic AI, closing on 20 November 2026. It is addressed to developers, deployers and other experts, and it covers six themes: data security, transparency, accountability, automated decision-making, fairness and purpose limitation, and lawfulness of processing. The ICO says the evidence will inform its future guidance and its forthcoming statutory code of practice on AI and automated decision-making. No date has been given for either.
The ICO also confirmed that it has made enquiries with OpenAI, Anthropic, Meta and the UK AI Security Institute about recent agentic AI testing and deployment, in which some agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems. It has asked what risk assessments and safeguards were in place. Its Director of Technology Regulation, Richard Nevinson, put the regulator's position plainly: an agent acting autonomously is no excuse for poor compliance.
Why it matters for UK business
Most UK firms are deployers, not developers, and the announcement carries two messages for them.
The first is about what the developer commitments do and do not cover. They concern how a model is trained and how an individual can find out about, and exercise rights over, the developer's use of their data. They are not an approval of those ten companies, and they do nothing for the processing a firm carries out when it runs its own customers' or employees' data through a model. That processing has its own controller, and it is the firm. The commitments are still worth using. A DPIA that cites a vendor's assurances is stronger if it records what the vendor changed after regulatory scrutiny and where the updated transparency information now sits.
The second message is that the regulator's attention has moved from training to behaviour after deployment. Much of the ICO's published work on generative AI so far has concerned how models are built and trained. The call for evidence is about what an agent does once it has tools, credentials and limited supervision. The six themes are, in effect, the table of contents of the guidance and the code that will follow, and a firm can use them as a checklist now. The themes are the ICO's; the reading of each for a deployer is ours.
- Data security: what the agent can reach, with whose credentials, and what stops it reaching further.
- Transparency: whether the people whose data is handled know an agent is involved.
- Accountability: who is the controller when an agent calls a third-party tool, and whether the logs would let you reconstruct what it did.
- Automated decision-making: whether an agent is taking significant decisions about people without meaningful human involvement, which engages Articles 22A to 22D of the UK GDPR.
- Fairness and purpose limitation: whether an agent reuses data it came across for a purpose nobody specified.
- Lawfulness: what lawful basis covers data the agent collects on its own initiative.
The enquiries matter for a practical reason. Several of the incidents the ICO refers to arose in testing, and our August briefing on the AI Security Institute incident report set out the containment lesson for anyone deploying agents. The ICO is now asking those involved what risk assessments and safeguards were in place at the time. That is the same question it would ask a deployer after an agent mishandled personal data, and it is far easier to answer from a document written beforehand.
A statutory code also changes the weight of the eventual text. Ordinary guidance tells an organisation what the regulator expects. Existing statutory codes under the Data Protection Act 2018, such as the Children's code, must be taken into account by the regulator and by the courts, and this one should be expected to carry similar weight. The six-week window is the point at which the content of that code is most open to influence. One housekeeping note: under the Data (Use and Access) Act 2025 the legal entity is now the Information Commission, governed by a board, though the organisation is still called the ICO.
What to do, and what not to do
Do:
- Respond by 20 November 2026 if you run or are piloting agents that touch personal data. Deployers are explicitly invited, and a short factual account of what you found hard to assess is useful evidence.
- Inventory your agents. For each one, record the data it can reach, the tools it can call, the actions it can take without approval and the logs it leaves.
- Update the DPIA for each agentic deployment against the six themes, and note the date.
- Ask each foundation model vendor what it changed following ICO supervision and where its updated transparency information is. File the answer.
- Check any agent that decides or recommends outcomes for individuals against Articles 22A to 22D, including how a person would obtain human intervention.
Do not:
- Read the vendor commitments as a compliance certificate, or tell a client the ICO has approved a model.
- Wait for the code before documenting. The questions are already known, and the absence of a record is the weakness.
- Assume that an agent's autonomy moves responsibility to the vendor. The ICO has said the opposite.
Where The AI Consultancy fits
Scoping what an agent may reach and do, and evidencing it, is the governance half of our agentic AI service. Our guide to running a DPIA for an AI assistant rollout covers the document itself, and the Data (Use and Access) Act briefing explains the automated decision-making rules the fourth theme refers to.
Verified on 10 October 2026 against the ICO's news release "ICO secures changes from leading AI developers as scrutiny extends to AI agents" (8 October 2026), its call for evidence on agentic AI and consultation page (closing 20 November 2026), and the "Our message to model developers" section of its report "Building trust and transparency into generative AI development". The one-line readings of the six themes are The AI Consultancy's, not the ICO's. This briefing is general information, not legal or data-protection advice; confirm your own position with your DPO or a qualified adviser.
Frequently asked questions
- Our AI vendor is one of the ten developers. Does that mean our use of its model is compliant?
- No. The ICO's announcement concerns how developers handle personal data when building and offering foundation models: transparency, individual rights and safeguards. It is not an approval or certification of those developers, and it says nothing about how your organisation uses the model. When you put personal data through a model or an agent, you are a controller for that processing and the lawful basis, transparency, security and decision-making obligations are yours. The commitments are still useful for due diligence: ask the vendor what it changed and where its updated transparency information is, and keep the answer with your DPIA.
- Should a small firm respond to the ICO's call for evidence on agentic AI?
- If you deploy or are piloting agents that touch personal data, it is worth the time. The call is addressed to deployers as well as developers, and the ICO says the evidence will shape its guidance and its statutory code of practice. Guidance written only from the evidence of large developers tends to assume resources a small firm does not have. A short, factual response describing what you run, what you found difficult to assess and what guidance would help is the most direct way to get proportionate expectations. The closing date is 20 November 2026.
Get new briefings by email
The AI Consultancy newsletter delivers briefings and analysis for UK businesses. We use your address only to send it, and you can unsubscribe at any time.