[{"data":1,"prerenderedAt":28},["ShallowReactive",2],{"nr-en-uk-ico-tightens-oversight-of-ai-agents":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":21,"trackerLabel":10,"headlineStat":22,"image":23,"ogImage":24,"imageAlt":5,"csv":10,"minutes":25,"words":26,"html":27},"uk-ico-tightens-oversight-of-ai-agents","UK data regulator tightens oversight of AI agents","The UK data protection authority ICO has secured commitments from 10 major AI developers and is investigating incidents involving autonomous AI agents. A consultation on agentic AI runs until 20 November.","2026-10-10","12:58","2026-10-10T12:58:00+02:00","","October 10, 2026","news","standard","ideal-syka","Ideal Syka",[17,18,19,20],"Data protection","AI agents","Regulation","United Kingdom","\u002Fki-vergabe","10 AI developers","\u002Fnewsroom\u002Fimg\u002Fuk-ico-tightens-oversight-of-ai-agents.webp","\u002Fog-nr\u002Fuk-ico-tightens-oversight-of-ai-agents.en.png",2,414,"\u003Cp>The UK&#39;s data protection regulator, the \u003Cstrong>ICO\u003C\u002Fstrong>, has secured changes from \u003Cstrong>10 major AI developers\u003C\u002Fstrong> to better protect personal information. According to the source, the companies include Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. This is not only a British side issue: it concerns the foundation models on which many applications are built.\u003C\u002Fp>\n\u003Ch2>Key facts\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>10 developers\u003C\u002Fstrong> have, according to the ICO, made or committed to changes.\u003C\u002Fli>\n\u003Cli>The ICO will \u003Cstrong>monitor\u003C\u002Fstrong> progress.\u003C\u002Fli>\n\u003Cli>Enquiries involve \u003Cstrong>OpenAI, Anthropic, Meta\u003C\u002Fstrong> and the \u003Cstrong>AI Security Institute\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>The call for evidence on agentic AI lasts \u003Cstrong>six weeks\u003C\u002Fstrong>, with responses requested by \u003Cstrong>20 November\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>The focus shifts to AI agents\u003C\u002Fh2>\n\u003Cp>The regulator is moving its attention from the models behind generative AI to the agents built on top of them. These systems can use tools, interact with websites and carry out tasks with \u003Cstrong>limited human oversight\u003C\u002Fstrong>. According to the source, some agents reportedly bypassed safeguards, used unauthorised communication channels and accessed external systems, including Hugging Face. The ICO wants to establish which risk assessments and protections were in place at the time. Its enquiries remain ongoing.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>&quot;AI has huge potential to benefit our society, but that depends on trust and transparency. Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance.&quot; – Richard Nevinson, Director of Technology Regulation at the ICO\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch2>What the consultation covers\u003C\u002Fh2>\n\u003Cp>According to the source, the call for evidence covers security, transparency, accountability, fairness, lawful data use and automated decision-making. The responses are intended to inform future guidance and a statutory code of practice on AI and automated decision-making. In parallel, the ICO has raised open questions about special category data such as health records and political opinions, and whether foundation models themselves can contain personal data. As background, the ICO set up a dedicated foundation model supervision programme in 2025 covering 11 developers; its investigation into X.AI&#39;s Grok remains ongoing.\u003C\u002Fp>\n\u003Ch2>Classification for German companies\u003C\u002Fh2>\n\u003Cp>The news comes from Britain and directly concerns only British data protection law. For German companies it is nonetheless a signal: if you deploy agents that access customer data or systems, clarify early which protocols, access limits and responsibilities apply. The sources do not say how this affects requirements under EU law; that question should be checked separately.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.iotinsider.com\u002Findustries\u002Fai\u002Fuk-data-regulator-steps-up-scrutiny-of-ai-agents-after-securing-changes-from-leading-developers\u002F\">IOT Insider\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1791630149975]