Accessibility Adjustments

Use these optional tools to adjust reading and display preferences. These tools cannot resolve every accessibility barrier. Please contact the website owner if you need assistance.

  • Text adjustments
  • Content scaling 100%
  • Font size 100%
  • Line height 100%
  • Letter spacing 100%
  • Colour adjustments
  • Orientation adjustments

ICO seeks evidence on how AI agents handle personal data

Listen to this article

The UK privacy regulator has opened an evidence call on how AI agents use personal information when they choose tools and act across services. The ICO announced the consultation on October 8, alongside a report on its supervision of foundation model developers. The next policy questions concern what happens as software moves from generating answers to carrying out tasks.

The consultation is open until the end of November 20, 2026. It is an evidence gathering exercise that will inform guidance. Opening the consultation does not itself create a new law.

Six themes reach beyond model training

The six themes cover security, transparency, accountability, automated decisions, fairness and purpose limits, and lawful processing. The ICO wants evidence about isolating sessions, adjusting permissions and recording agent actions. It asks how people learn when information moves to a new tool or recipient, and how organisations allocate responsibility across suppliers. It also asks how meaningful human involvement works across an entire decision process. Further questions concern whether data collected for one task can be reused for another and how organisations select a lawful basis for each processing activity.

These are the regulator’s current questions and expectations. The ICO says existing data protection expectations continue to apply. It also seeks examples of working safeguards, barriers to adoption and the support organisations need. Its discussion of automated decisions explicitly recognises that using an agent does not automatically bring every decision within those provisions.

Tool access turns explanation into an engineering problem

The June 2025 version of the Model Context Protocol tools specification offers a concrete technical reference. MCP lets language models discover and invoke tools that interact with databases, APIs and other systems. The specification recommends interfaces that reveal available tools, show when they run and let a person deny a call. Its security section also recommends showing tool inputs before execution, validating returned results and logging tool use. It requires servers to validate inputs and implement access controls. These are protocol design provisions, and they do not establish that a particular application has implemented them or satisfies UK law.

Consider a hypothetical support agent that reads a customer message, checks an order and sends information to a delivery service. A correct final reply would tell a reviewer little about which records the agent opened along the way. A useful test would compare the intended recipient and permitted fields with the information actually sent. Repeating that test after changing the available tools could expose a different route through the same task. This is a way to examine a workflow, rather than a claim about any product’s behaviour or a legal compliance test.

The design tension already appeared in the ICO’s January 2026 agentic AI work. Its earlier privacy risk analysis described competing approaches to access. Some stakeholders favoured gradually opening more information to agents, while others emphasised the value of broader context for personalised results. The regulator linked careful tool and database selection to limiting unnecessary data use. It also warned that an inaccurate inference could travel between agents or be written into other systems. That earlier analysis helps explain why a successful task result alone leaves important questions unanswered.

The companion report records changes and commitments

The foundation model supervision report concerns a related part of the system, including training data, privacy information and routes for people to exercise their rights. According to the ICO, Apple, Cohere and OpenAI have changed the transparency information they provide. The report separately describes measures that other developers have made or committed to make. Those descriptions should be read individually. A commitment in the report does not establish that the corresponding change is already operating.

For example, the ICO says Anthropic updated its privacy information for people who do not use its services and strengthened its assessment of safeguards. It describes further changes to Apple’s privacy documentation as future work, while also recording completed Apple disclosures. The regulator’s next steps include continued scrutiny of commitments and further work on difficult questions involving sensitive training data. This is a report on supervision and regulatory positions. It provides no general certification that a named developer or its agent products comply with every applicable requirement.

Who can respond and what happens next

The ICO welcomes evidence from developers, deployers, legal and technical experts, and anyone seeking to use agentic AI while meeting data protection requirements.

Responses can be submitted through the official Citizen Space survey. The ICO warns that it may not consider submissions after the November 20 deadline. Its consultation notice says organisational responses may be published in full or summarised, depending on the respondent’s preference, with personal details removed where appropriate. Respondents should read that notice before including confidential examples or information they would not want made public.

The ICO says the evidence will feed into future agentic AI guidance and its forthcoming statutory code on AI and automated decision making. The October announcement does not supply a final publication date for either. The next useful development will be the regulator’s response to the evidence and the eventual text. The present material shows the questions being tested, while the final treatment of specific deployments remains to be worked through.

A TSUBAME 4.0 computing node in Japan, photographed in May 2026. Archive image illustrating data infrastructure. Photo by Fukumoto via Wikimedia Commons, CC BY SA 4.0. Cropped by ByteForward under CC BY SA 4.0.

Marcus Reid
Marcus Reid

Marcus Reid is focused on covering the money, rules, and institutional choices shaping AI. He runs from funding rounds and chip deals to regulation, lawsuits, leadership changes, and the business of building enormous computing systems. Marcus follows the incentives behind the announcement. Who pays, who gains leverage, and what changes for everyone else? The voice is direct, measured, and occasionally dry, especially when a grand promise arrives with very little detail.

Leave a Reply

Your email address will not be published. Required fields are marked *

Gravatar profile