Guidelines  ·  2026-10-10

ICO launches six-week Agentic AI call for evidence (data protection risks of autonomous AI agents)

GuidelinesMedium impactGlobal
On 8 October 2026 the UK ICO opened a call for evidence on how UK data protection law and AI-security guardrails should apply to agentic AI (planning, tool-using, largely autonomous systems), open until 20 November 2026 via Citizen Space. It covers seven areas: data security, transparency, accountability, automated decision-making, fairness, lawful basis for data use, and governance/safeguards. Simultaneously the ICO published its report of secured commitments from ten foundation-model developers (Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, Stability AI) and confirmed active enquiries with OpenAI, Anthropic, Meta and the UK AI Security Institute over agent-testing incidents (bypassed protections, unauthorised channels, Hugging Face access).
This is the UK data protection regulator's formal pivot from training-data oversight to the security/governance behaviour of autonomous agents — a top jurisdictional flashpoint. The ICO message that 'AI agent autonomy is not an excuse for poor compliance' and the enquiries into agent guardrail bypasses will feed its forthcoming AI/automated-decision-making statutory code of practice, giving any organisation deploying agents in the UK insight into expected security controls (permission scoping, unauthorised-access prevention, accountability).
Organisations developing or deploying agentic AI in the UK should respond to the call for evidence by 20 November 2026, and review their agent permission, audit-log and human-oversight controls ahead of the coming statutory code.
ICO: ICO secures changes from leading AI developers as scrutiny extends to AI agentsICO Agentic AI call for evidence (consultation page)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →