On 8 October 2026 the UK Information Commissioner's Office opened a call for evidence on how data protection law applies to agentic AI. It runs until the end of 20 November 2026. The call is organised around six themes: data security, transparency, accountability, automated decision-making, fairness and purpose limitation, and lawful processing. For each theme the ICO sets out its current thinking, which already describes what it expects from organisations that build or deploy agents.

What The ICO Announced

The ICO announcement describes a six-week call seeking views from developers, deployers and other experts on how organisations manage the data protection risks of agentic AI. The same release reports that ten foundation model developers have made, or committed to make, data protection changes after ICO supervision, and confirms enquiries with OpenAI, Anthropic, Meta and the UK's AI Security Institute about recent agentic AI testing and deployment. The ICO says that in some cases agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face. Those enquiries are ongoing.

Richard Nevinson, the ICO's Director of Technology Regulation, said: "the fact AI agents act with autonomy is not an excuse for poor compliance."

According to the ICO, the evidence will inform its future guidance on agentic AI and its forthcoming statutory code of practice on AI and automated decision-making. Its guidance plan lists the agentic AI guidance at the drafting stage, with the final version due in Autumn 2026.

The Six Themes

The call for evidence says it focuses on issues that are new or arise differently with agents, and that the themes are not exhaustive.

  • Data security: session isolation, how organisations decide whether an agent may reach only internal knowledge systems or third-party ones, whether guardrails and permissions change dynamically, and structured logs that record agent identity alongside its actions in a tamper-evident way.
  • Transparency: how organisations tell people when an agent reaches a new data source, uses an external tool or shares personal information; how users can limit the websites, tools, data sources and actions available to an agent; and how people can challenge, correct or reverse an agent's actions.
  • Accountability: how controller, joint controller and processor roles are allocated and written into contracts, and what information agent developers give the organisations deploying their systems.
  • Automated decision-making: how organisations decide whether the UK GDPR ADM provisions (articles 22A to 22D) apply, how they keep human involvement meaningful, and how logging and permission settings support multi-stage decisions.
  • Fairness and purpose limitation: compatibility assessments for new processing purposes, and monitoring that stops agents using personal information for purposes nobody assessed or authorised.
  • Lawful processing: which lawful bases organisations use at each stage of agent development and deployment, and how they run legitimate interests assessments, including for training or adapting orchestrator models.

A further set of questions asks about adoption: each organisation's current and expected use of agentic AI, barriers such as regulatory uncertainty, security and cost, whether plans were delayed or abandoned because of data protection uncertainty, how organisations get assurance without specific guidance, and the benefits they expect.

What It Means For Companies Running Agents

The call states the ICO's current expectations theme by theme. Several apply directly to an organisation that runs agents on personal information:

  • Agent identity: a deployer may need to register an agent, link it to an owner and purpose, and apply access policies. The ICO lists what an agent identity may need to record: owner and purpose, capabilities and tools, permissions and approval thresholds, operating context, relationships with other agents and systems, and the current task or delegated authority.
  • Permissions: the level of autonomy should be a deliberate design decision, backed by least-privilege access, scoped permissions, limits on tool use and human approval thresholds for high-risk actions.
  • Records: the ICO names agent tracing (how personal information moves between agents, tools and other components) and audit logging (which agent acted, what data and tools it used, and the outcome) among the measures organisations may need across the supply chain.
  • Timely notice: a general explanation before a task starts may not be enough when the agent reaches new data sources or proposes significant actions. The ICO suggests further information or asking the user to approve the action first.
  • Controllership: organisations that determine or sufficiently influence the purposes and means of processing through an agent can be controllers. The ICO notes that decisions about protocols, permissions and access controls may weigh more heavily on the means of processing than in generative AI.
  • Whole-workflow ADM: organisations must assess whether the ADM provisions apply across the complete workflow, and be able to reconstruct which agent was involved, under what authority, what it accessed, and whether human involvement was meaningful.
  • Lawful basis: terms of service or a user's instruction to an agent do not automatically provide a lawful basis for all the processing that follows, and different stages of one workflow may need different bases.
  • New purposes: an agent's ability to find a new use for personal information does not make that use compatible with the original purpose.

What This Does Not Settle

  • A call for evidence is not guidance. The expectations above are the ICO's current thinking as set out in the call, and the final agentic AI guidance has not been published.
  • The ICO's enquiries into reported agent testing incidents are ongoing, and the announcement reports no findings from them.
  • The call covers UK data protection law (UK GDPR and, for device storage and access, the Privacy and Electronic Communications Regulations). It says nothing about other jurisdictions.

Related: The United Kingdom jurisdiction page tracks UK AI rules and dates. The agent identity playbook and the permission outside the agent playbook cover agent registration, scoped permissions and audit logs. See also our note on UK lifecycle monitoring for AI medical devices.