Site navigation

New ICO Report Urges Caution on Agentic AI

Graham Turner

,

Agentic AI
The regulator warns that responsibilities around data protection compliance do not just rest with agentic AI developers but also those who are adopting the technology.

A new report from the Information Commissioner’s Office (ICO) describes the transformative ways in which agentic AI could change our lives within the next five years – including personal shopping agents that have the potential to make proactive purchases on a consumer’s behalf using their payment details.

However, the data regulator is urging both developers and adopters to be aware of the new data protection challenges that the advent of agentic AI presents: the processing of personal information beyond what is necessary; issues around determining controller and processing responsibilities throughout the agentic AI supply chain and new threats to cybersecurity.

Findings from the latest Tech Futures report go on to emphasise how the design and architecture of agentic systems are critical. Poorly implemented systems – such as those with unclear purposes, unnecessary database connections, or weak governance – could heighten risks.

The report also suggests that developers and adopters will find it useful to familiarise themselves with the differences in agentic AI compared to more traditional models – including the extent to which its capabilities and limitations meet the needs of the purpose it is being developed for.

Conversely, privacy by design offers opportunities for innovation, including data protection-compliant agents, agentic controls, privacy management agents, and benchmarking tools.

William Malcolm, Executive Director of Regulatory Risk and Innovation, ICO said:  “Agentic AI will have the capacity to make decisions and take actions independently. Our own personal AI agents could be paying for goods, booking flights and helping with household finances.

“These systems can handle vast amounts of personal information, so both developers and adopting organisations must ensure transparency, security, and compliance is built in from the start.

“While the potential benefits could be transformational, the public needs assurances their personal information is secure and well managed before placing their trust in agentic systems.

“Strong data protection foundations can help build that public trust and can help scale the fast and safe adoption of AI. Throughout 2026 the ICO will actively monitor advancements and work with AI developers and deployers to ensure they are clear on what the law requires of them.”


Recommended reading


Organisations in the process of developing products and services using personal information and agentic AI in the public interest are encouraged to explore the ICO’s range of innovation services including its Regulatory Sandbox. ICO guidance for developers of AI solutions can be found here.

The regulator will also be launching a consultation on its new draft guidance on Automated Decision Making (ADM) in 2026. The ICO continues to liaise with other regulators and government bodies, including the Digital Regulation Cooperation Forum, on issues related to data privacy and the development of AI.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data