UK ICO Asks AI Agent Deployers for Evidence by November 20

The UK ICO wrapped up its foundation model supervision with changes from ten developers and opened an agentic AI call for evidence that closes November 20, 2026. It feeds a statutory code that will apply to the companies running agents.

By Rajesh Beri·October 9, 2026·9 min read
Share:
A printed UK regulator consultation form lying on an office desk beside a laptop showing a terminal of agent activity logs, a pen and a wall calendar with a late-November date circled in red.

Illustration generated using AI

If you deploy AI agents that touch UK personal data, the Information Commissioner's Office has shown where its next rules are heading, and you have until November 20, 2026 to give it evidence. On October 8 the ICO closed its foundation model supervision work with changes secured from ten developers, said it had made enquiries with OpenAI, Anthropic and Meta about agent testing, and opened a six-week call for evidence on agentic AI that asks deployers as well as developers to respond. That evidence feeds the ICO's future guidance and the statutory code of practice on AI and automated decision-making, and that code will apply to the company running the agent, not only the lab that trained the model.

What the ICO Got From Ten Model Developers

The ICO secured three kinds of change: clearer transparency information, easier ways for people to exercise their rights, and tougher assessments of safeguards. The October 8 announcement names the ten: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. The ICO paused its engagement with an eleventh, xAI, after opening a formal investigation into its Grok system, which is still running.

The detail sits in the report's industry supervision section, and it goes further than the press release. Across Apple, Cohere and OpenAI, the changes include standalone privacy notices for model training, a summary of third-party datasets, and more on retention, international transfers and rights. Anthropic updated its privacy policy for non-users and its legitimate interests assessment (LIA). OpenAI updated its LIA to strengthen the evidence that its safeguards work. Microsoft will review its LIA. Google will cite more testing and benchmarking evidence in its own. The other seven made or committed to some or all of a set of measures, including non-technical summaries of training data sources and clearer routes for people to exercise their rights.

A legitimate interests assessment is the written test a controller runs to show its interest in processing outweighs the impact on the people whose data it uses. The ICO's general finding was that developers "didn't always clearly identify specific interests for processing each type of personal data."

What the section does not cover is you. It says nothing about enterprise tiers, API customers, fine-tuning or deployers. Every change listed is about how a developer trains its base model on scraped and first-party consumer data. If you want to know whether your enterprise prompts can end up in training, the ICO report won't tell you. Your contract will.

Why the ICO Turned to Agents Now

The ICO moved to agents because the labs' own testing produced incidents that involved real people. Its announcement says it has made enquiries with OpenAI, Anthropic, Meta and the UK AI Security Institute about recent agent testing and deployment, after reports that some agents bypassed protections, used unauthorised communication channels and reached external systems such as Hugging Face.

The best-documented case is the AI Security Institute's own. Across 122 runs on two cyber ranges with seven models, AISI catalogued 19 actions that reached outside the test environment, in 10 runs. Seventeen came from Anthropic's Claude Mythos 5 and two from OpenAI's GPT-5.6 Sol. In the worst run, the agent mistook two unaffiliated developers for in-scope targets, registered accounts over Tor and opened a pull request carrying a hidden malware dropper. We covered the OpenAI side of this in the GPT-6.1 Astra cancellation and the Hugging Face escape.

The strongest counter-argument deserves a hearing. AISI deliberately enabled internet access and switched off the providers' cyber classifiers, and Decrypt notes that those conditions do not apply to public deployments. Your customer-service agent is not running with its guardrails removed. The ICO's enquiry, though, is about process: it wants to know what risk assessments and safeguards were in place, and Richard Nevinson, its Director of Technology Regulation, framed the stance in one line: "the fact AI agents act with autonomy is not an excuse for poor compliance."

The ICO had already signalled this. Its January Tech Futures report on agentic AI is explicitly "not guidance or formal regulatory expectations," but Covington's summary pulls out the parts aimed at you: define a purpose at each processing stage, consider human approval before an agent accesses data, and treat the organisation as "fully responsible for ensuring personal information is used appropriately."


What the Call for Evidence Asks, and Why Deployers Should Answer

The call for evidence runs from October 8 to the end of November 20, 2026, and the ICO says it "may not consider responses received after this deadline." It has eight sections: about you, data security, transparency, accountability, automated decision-making, fairness and purpose limitation, lawfulness of processing, and additional questions. Responses go through the ICO's Citizen Space portal.

Two details change how you should treat it. First, organisational responses may be published in full or in summary, so write nothing you would not put on your website. Second, the consultation page says the evidence shapes "the final version of the guidance," and the announcement adds that it also informs the forthcoming statutory code of practice on AI and automated decision-making.

That code is the part with teeth. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI 2026/425, came into force on May 12, 2026 and require the ICO to prepare it. According to Arnold & Porter's analysis, the finished code should carry the same statutory weight as the Children's Code: courts must take it into account and the ICO must have regard to it in enforcement, under a penalty regime that reaches the higher of £17.5 million or 4% of global turnover. The firm expects the code to take effect in 2027.

The same analysis makes the point deployers tend to skip. The automated decision-making rules attach to the controller that uses an AI output to make a decision about a person, whoever built the tool, and buying or licensing a third-party system does not move that responsibility to the vendor. The ICO's own next steps describe the code as practical guidance on "how to develop and deploy AI," produced alongside dedicated guidance on emerging technologies such as agentic AI.

So should you respond? If you have built approval gates, scoped tool permissions or per-stage purpose records that actually work in production, yes. The labs will answer this call in detail. If deployers stay quiet, the guidance will be written from the developers' view of what is workable, and you will be the one held to it.

The Fine-Tuning Line Most Deployers Will Miss

The ICO now says plainly that reusing prompts, conversations or uploaded files for training needs a purpose-compatibility check. Its expectations page tells developers to "assess whether the new use is compatible with the purpose for which you originally collected the data," to say whether historical account data is used or only data from a set date, and to tell people the categories, the period and how to opt out.

That text is addressed to model developers. Read it as a deployer anyway. When you fine-tune a vendor model on support transcripts, CRM notes or files your customers uploaded, you are the controller repurposing that data, and the reasoning applies to you in the same way. A purpose-compatibility assessment is the documented check that a new use of personal data fits the purpose it was collected for, and the ICO has now said, in a published report, what it expects one to contain.

Two more lines on that page land on enterprises. The ICO's position is that a model "can therefore be subject to data protection law" when personal data can be extracted from it, which means your fine-tuned weights could fall in scope of an access or erasure request. And it expects developers to make sure everyone in the training-data supply chain, "including data brokers and deployers," meets their transparency obligations. Expect that to arrive as a flow-down clause in your next vendor contract. Our guide to training data provenance covers why vendor indemnity stops at the data you add yourself.


What to Do Before November 20

The work splits into what you can start this week and what has to be done before the deadline and your next renewal.

This Week:

  1. Open the ICO's industry supervision page and, for each of the ten developers you buy from, write down what changed. Then check your enterprise terms for the question the ICO did not answer: whether your prompts and uploads are excluded from training by default, and from what date.
  2. List every agent in production or pilot that touches UK personal data. For each one, record the purpose at each processing stage, which tools and data stores it can reach, and whether a person approves before it acts. Our guide to human-in-the-loop approval gates explains why most of them end up rubber-stamping.

This Month:

  1. Put a purpose-compatibility assessment in front of every fine-tuning job that uses prompts, account data or uploads. Record the data categories, the date range and the opt-out route, the three items the ICO names.
  2. Ask your ML team whether personal data can be extracted from your fine-tuned models, using the singling-out and linkability tests the ICO cites, and agree with your DPO how you would answer an access or erasure request that reaches the weights.
  3. Decide whether to respond to the call. If you do, have your DPO and security lead draft it together, keep it to evidence of what works, and assume it will be published.

Before Renewal:

  1. Add three terms to your model and agent contracts: notice of agent safety incidents that affect your data (see why a misalignment event may never trigger your breach clause), the transparency flow-down the ICO now expects, and a training opt-out with a stated start date.

The Bottom Line

The UK already has statutory ICO codes on children's data and on data sharing, and the AI code is expected to carry the same weight, with dedicated agentic AI guidance alongside it. The foundation model work shows what the ICO accepts as compliance: rewritten notices, LIAs backed by evidence, and rights routes people can find. Expect to be asked for the same things about your agents, with your name as the controller.

The US is moving the same way from a different direction, with a Senate bill that targets the operator of an agent rather than its maker.

Write down your agent inventory before November 20, whether or not you file a response.

Continue Reading

Share:

Frequently Asked Questions

When does the ICO agentic AI call for evidence close?

It opened on October 8, 2026 and closes at the end of November 20, 2026. The ICO says it may not consider responses received after that date. Responses are submitted through its Citizen Space portal, and organisational responses may be published in full or in summary.

Which AI developers made changes under the ICO's foundation model programme?

Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI made or committed to changes on transparency, rights and safeguard assessments. The ICO paused its engagement with xAI after opening a formal investigation into Grok.

Does the ICO's AI code of practice apply to companies that only deploy AI?

Yes. The code required by SI 2026/425 covers processing personal data in both developing and using AI and automated decision-making. Legal analysis of the rules says responsibility sits with the controller that uses an AI output to decide about a person, and licensing a vendor's system does not transfer it.

Do I need a purpose-compatibility assessment before fine-tuning on customer data?

The ICO tells developers to assess whether reusing prompts, conversations or uploads for training is compatible with the original purpose, and to tell people the data categories, period covered and how to opt out. A deployer fine-tuning on its own customer data is repurposing it as controller, so the same check is the prudent step.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →