
The ICO’s latest publications signal a new phase in AI regulation, with important implications for organisations using artificial intelligence.
09/10/2026
Artificial intelligence is transforming the way organisations work. From drafting, generating posters and presentations to analysing complex documents, AI tools are becoming part of everyday business activities.
But what happens when AI stops simply answering questions and starts taking action?
Imagine asking an AI assistant to prepare for a client meeting. It searches your emails, reviews documents, accesses client records and drafts correspondence.
Convenient? Absolutely.
But what information has it accessed? Could it retrieve confidential information about another client? And what happens if it makes a mistake?
These are precisely the types of questions organisations need to consider as AI technology evolves.
The ICO Is Taking Action
On 8 October 2026, the Information Commissioner’s Office (ICO) announced that ten major AI developers had made, or committed to making, improvements to their data protection practices following regulatory scrutiny.
Its latest publication, Building Trust and Transparency into Generative AI Development, highlights the importance of lawful processing, transparency, individual rights and appropriate safeguards when developing AI systems.
The ICO has also launched a call for evidence on agentic AI, signalling increasing regulatory attention towards AI systems capable of acting with greater autonomy.
The message is clear: AI innovation does not remove existing data protection responsibilities.
What Is Agentic AI?
Traditional generative AI generally responds to instructions. You ask a question, and it produces an answer.
Agentic AI goes further.
An AI agent can potentially plan and complete tasks, interact with software, retrieve information and take actions with limited human intervention.
For example, rather than simply drafting an email, an AI agent might access customer records, prepare a response and send it automatically.
This creates exciting opportunities for efficiency, but also introduces new risks.
The more autonomy an AI system has, the more important it becomes to understand and control what it can access and do.
Who Is Responsible When AI Gets It Wrong?
Imagine an AI agent preparing a response to a customer complaint.
It retrieves relevant correspondence but accidentally includes another customer’s personal information. If the system sends that response automatically, the organisation could find itself dealing with a personal data breach.
The fact that AI was responsible for the action does not remove the organisation’s legal obligations.
Under Article 5(2) of the UK GDPR, organisations must be able to demonstrate compliance with the data protection principles.
Article 25 also requires data protection by design and by default.
This means organisations need to consider appropriate access restrictions, human oversight, security measures and monitoring before deploying AI systems.
AI may be capable of acting independently, but organisations cannot automate away their accountability.
Five Questions to Ask Before Introducing AI Agents
Before connecting AI to business systems, organisations should ask:
- What information can it access? Ensure access is restricted to what is necessary for the intended task.
- What actions can it take? Consider whether the AI should be permitted to send emails, update records or make decisions without human approval.
- Have we assessed the risks? Determine whether a Data Protection Impact Assessment (DPIA) is required and document appropriate safeguards.
- Do we understand how our supplier processes information? Consider retention, security, international transfers and whether information is used to train AI models.
- Can we intervene when something goes wrong? Appropriate monitoring, audit trails and the ability to suspend access are essential.
The Future of AI Requires Responsible Governance
The ICO’s latest publications are not a warning against using AI. The technology offers significant opportunities to improve productivity and transform services.
However, organisations must understand the implications of giving AI access to personal information and allowing it to act on their behalf.
The ICO’s call for evidence on agentic AI closes on 20 November 2026, but organisations should not wait for further guidance before reviewing their arrangements.
Existing UK GDPR requirements already apply.
The question is no longer simply whether employees should be allowed to use AI.
It is whether organisations understand what their AI systems can access, what actions they can take and who remains accountable when something goes wrong.
AI may be becoming more autonomous. Data protection accountability isn’t.
How JH Data Protection Can Help
At JH Data Protection Ltd, we help organisations navigate data protection requirements and introduce new technologies responsibly.
If you’re considering AI within your organisation or reviewing your existing arrangements, we can help you identify risks and implement practical safeguards.
Contact: dpo@jhdataprotection.com
Further reading: ICO – Building Trust and Transparency into Generative AI Development
Leave a Reply