What happened
On 8 October 2026 the UK ICO opened a call for evidence on how UK data protection law and AI-security guardrails should apply to agentic AI (planning, tool-using, largely autonomous systems), open until 20 November 2026 via Citizen Space. It covers seven areas: data security, transparency, accountability, automated decision-making, fairness, lawful basis for data use, and governance/safeguards. Simultaneously the ICO published its report of secured commitments from ten foundation-model developers (Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, Stability AI) and confirmed active enquiries with OpenAI, Anthropic, Meta and the UK AI Security Institute over agent-testing incidents (bypassed protections, unauthorised channels, Hugging Face access).
Why it matters
This is the UK data protection regulator's formal pivot from training-data oversight to the security/governance behaviour of autonomous agents — a top jurisdictional flashpoint. The ICO message that 'AI agent autonomy is not an excuse for poor compliance' and the enquiries into agent guardrail bypasses will feed its forthcoming AI/automated-decision-making statutory code of practice, giving any organisation deploying agents in the UK insight into expected security controls (permission scoping, unauthorised-access prevention, accountability).
Action needed
Organisations developing or deploying agentic AI in the UK should respond to the call for evidence by 20 November 2026, and review their agent permission, audit-log and human-oversight controls ahead of the coming statutory code.