OUT-LAW NEWS

Agentic AI: ICO signals its data protection priorities

Agentic AI as a wave concept_Digital - SEOSocialEditorial image

The ICO call for evidence has been opened amidst rapid development in the adoption of AI agents by businesses. Vertigo3d/iStock.


UK businesses have been given an early indication of the data protection issues the ICO expects them to address when developing or deploying agentic AI, as well as an opportunity to shape its forthcoming guidance, an expert has said.

Stephanie Lees of Pinsent Masons, who specialises in AI and data protection compliance, was commenting after the UK Information Commission’s Office (ICO) opened a call for evidence on agentic AI.

AI agents are AI systems designed to pursue objectives and complete tasks, including by using tools, accessing information and interacting with other systems. The degree of autonomy and human oversight can vary. The ICO uses “agentic AI system” to describe a computing system containing one or more AI agents.

Business adoption of AI agents is developing rapidly, although the scale, maturity and degree of autonomy of deployments vary considerably between organisations and use cases. There is evidence of their potential to disrupt established industry models in online retail, and studies have explored their potential to completely reshape how financial services are delivered and how the energy system in Britain operates. The ICO is also currently exploring the application of agentic AI in the adtech ecosystem and will publish a report on this later this year.

However, concerns about AI agents acting completely unprompted and seemingly beyond constraints imposed by those who developed or deployed them have surfaced in recent months, with OpenAI, Anthropic, the UK’s AI Security Institute, and Australia’s prime minister, Anthony Albanese, among those to have highlighted cyber incidents arising from AI agents ‘going rogue’. This has prompted some regulators globally to warn of the cyber risks posed by ‘frontier AI’, attempts to legislate to curb ‘superintelligent’ AI, and experts to warn of liability gaps in English law.

Using agentic AI tools can involve processing personal data, which is subject to data protection laws. As the UK’s data protection authority, the ICO said its call for evidence is designed to inform its thinking “on how to apply data protection law to the distinctive capabilities and risks of agentic AI”. The input it receives is expected to help shape future formal guidance for businesses.

“The ICO's call for evidence on agentic AI is a significant regulatory moment that organisations cannot afford to ignore,” said Lees. “It tackles the genuinely novel compliance challenges agentic AI presents and focuses on six key themes: data security, transparency, accountability, automated decision-making (ADM), fairness and purpose limitation, and lawful processing. It highlights how agentic AI's autonomy, ability to access multiple data sources, use tools, share information and take actions, can create novel compliance challenges under existing data protection laws.”

“While not formal guidance, it highlights the types of technical and organisational measures on which the ICO is seeking evidence, including agent identities, permissions and guardrails, audit logging, transparency measures, accountability frameworks, meaningful human oversight and robust lawful-basis assessments. Businesses that have already invested heavily in agentic AI systems should revisit their AI and data protection governance frameworks and DPIAs to ensure that they address the issues and risks highlighted in the call for evidence,” she said.

“The consultation findings will inform the ICO's statutory code of practice on AI and ADM, making this an important opportunity for organisations to assess and strengthen their governance arrangements now,” Lees added.

As well as focusing on supporting businesses that deploy agentic AI tools, the ICO has also taken steps to promote data protection in their development.

The ICO has separately confirmed that it made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute concerning recent agentic AI testing and deployment. It has also reported that, following its wider supervision of foundation-model developers, 10 developers have made or committed to data protection changes, including “clearer transparency information, stronger mechanisms for people to exercise their rights and tougher assessments of safeguards”.

The ICO’s call for evidence closes on 20 November.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.