The ICO’s latest publications signal a new phase in AI regulation, with important implications for organisations using artificial intelligence.

09/10/2026

Artificial intelligence is transforming the way organisations work. From drafting, generating posters and presentations to analysing complex documents, AI tools are becoming part of everyday business activities.

But what happens when AI stops simply answering questions and starts taking action?

Imagine asking an AI assistant to prepare for a client meeting. It searches your emails, reviews documents, accesses client records and drafts correspondence.

Convenient? Absolutely.

But what information has it accessed? Could it retrieve confidential information about another client? And what happens if it makes a mistake?

These are precisely the types of questions organisations need to consider as AI technology evolves.

The ICO Is Taking Action

On 8 October 2026, the Information Commissioner’s Office (ICO) announced that ten major AI developers had made, or committed to making, improvements to their data protection practices following regulatory scrutiny.

Its latest publication, Building Trust and Transparency into Generative AI Development, highlights the importance of lawful processing, transparency, individual rights and appropriate safeguards when developing AI systems.

The ICO has also launched a call for evidence on agentic AI, signalling increasing regulatory attention towards AI systems capable of acting with greater autonomy.

The message is clear: AI innovation does not remove existing data protection responsibilities.

What Is Agentic AI?

Traditional generative AI generally responds to instructions. You ask a question, and it produces an answer.

Agentic AI goes further.

An AI agent can potentially plan and complete tasks, interact with software, retrieve information and take actions with limited human intervention.

For example, rather than simply drafting an email, an AI agent might access customer records, prepare a response and send it automatically.

This creates exciting opportunities for efficiency, but also introduces new risks.

The more autonomy an AI system has, the more important it becomes to understand and control what it can access and do.

Who Is Responsible When AI Gets It Wrong?

Imagine an AI agent preparing a response to a customer complaint.

It retrieves relevant correspondence but accidentally includes another customer’s personal information. If the system sends that response automatically, the organisation could find itself dealing with a personal data breach.

The fact that AI was responsible for the action does not remove the organisation’s legal obligations.

Under Article 5(2) of the UK GDPR, organisations must be able to demonstrate compliance with the data protection principles.

Article 25 also requires data protection by design and by default.

This means organisations need to consider appropriate access restrictions, human oversight, security measures and monitoring before deploying AI systems.

AI may be capable of acting independently, but organisations cannot automate away their accountability.

Five Questions to Ask Before Introducing AI Agents

Before connecting AI to business systems, organisations should ask:

  1. What information can it access? Ensure access is restricted to what is necessary for the intended task.
  2. What actions can it take? Consider whether the AI should be permitted to send emails, update records or make decisions without human approval.
  3. Have we assessed the risks? Determine whether a Data Protection Impact Assessment (DPIA) is required and document appropriate safeguards.
  4. Do we understand how our supplier processes information? Consider retention, security, international transfers and whether information is used to train AI models.
  5. Can we intervene when something goes wrong? Appropriate monitoring, audit trails and the ability to suspend access are essential.

The Future of AI Requires Responsible Governance

The ICO’s latest publications are not a warning against using AI. The technology offers significant opportunities to improve productivity and transform services.

However, organisations must understand the implications of giving AI access to personal information and allowing it to act on their behalf.

The ICO’s call for evidence on agentic AI closes on 20 November 2026, but organisations should not wait for further guidance before reviewing their arrangements.

Existing UK GDPR requirements already apply.

The question is no longer simply whether employees should be allowed to use AI.

It is whether organisations understand what their AI systems can access, what actions they can take and who remains accountable when something goes wrong.

AI may be becoming more autonomous. Data protection accountability isn’t.


How JH Data Protection Can Help

At JH Data Protection Ltd, we help organisations navigate data protection requirements and introduce new technologies responsibly.

If you’re considering AI within your organisation or reviewing your existing arrangements, we can help you identify risks and implement practical safeguards.

Contact: dpo@jhdataprotection.com

Further reading: ICO – Building Trust and Transparency into Generative AI Development

Leave a Reply

  • AI Is No Longer Just Answering Questions. It’s Taking Action. Are You Ready?

    AI is no longer just answering questions – it’s taking action. Following the ICO’s latest publications on generative and agentic AI, we explore what this means for businesses, the data protection risks and how organisations can embrace AI while maintaining UK GDPR compliance.

  • With Great Power Comes Great Responsibility:

    Why AI Makes Data Protection More Important Than Ever 26/08/2026 I have always been fascinated by emerging technology. Part of working in data protection is trying to keep ahead of the game: understanding not only what technology can do now, but what it might be capable of next, and what that means for the people…

  • Cyber security is a data protection issue: lessons from the ICO’s ACRO reprimand

    14/08/2026 The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people. The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and…

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…