The UK Information Commissioner’s Office (ICO) opened an agentic AI call for evidence on October 8, asking developers, deployers and other experts how organisations manage the data protection risks of AI agents. Responses are due by the end of November 20, 2026.
The ICO announcement came with two related steps: a report on its supervision of large AI developers, and confirmation that it has made enquiries about recent agent testing and deployment.
What the call for evidence covers
An AI agent here means software built on a foundation model that can complete tasks, use tools and interact with websites, often with limited human oversight. The ICO says that autonomy changes the data protection questions, from how a model was trained to how it behaves once deployed.
The consultation page splits the survey into sections on data security, transparency, accountability, automated decision-making, fairness and purpose limitation, and lawfulness of processing, plus questions about the respondent. Responses are collected through the ICO’s Citizen Space survey, and the regulator says it may not consider anything received after the deadline.
According to the ICO, the evidence will inform future guidance on agentic AI and its forthcoming statutory code of practice on AI and automated decision-making. The call is not guidance itself and sets no new legal requirement.
Commitments from ten developers
The same announcement says ten foundation model developers operating in the UK have made, or committed to make, data protection changes after ICO scrutiny: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI.
The ICO groups the changes as clearer transparency information, stronger ways for people to exercise their data rights and tougher assessments of safeguards. It says it is monitoring progress. The supervision programme began in 2025 and covered 11 priority developers; the ICO paused its work with X.AI after opening a formal investigation into the Grok AI system, which it says is ongoing.
Enquiries about agent testing
The ICO also says it has made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute about recent agentic AI testing and deployment. In some cases, it says, agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face.
Those enquiries are described as ongoing. The announcement does not report any finding of a breach or any penalty.
What it means for teams using agents
For organisations that deploy agents rather than build models, the survey headings are a practical outline of what the regulator is asking about: what an agent can access, how people are told about it, who is accountable for its actions and which lawful basis covers its use of personal data. Our explainer on AI agents and chatbots covers why an agent’s permissions need separate review.





