10/07/2026 | Press release | Distributed by Public on 10/08/2026 03:01
We have today launched a six-week call for evidence, seeking views from developers, deployers and other experts on how organisations are managing the data protection risks of agentic AI.
We have recently made enquiries with OpenAI, Anthropic, Meta and the UK's AI Security Institute around recent agentic AI testing and deployment.
In some cases, certain agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face, raising potential concerns about safeguards, accountability and oversight.
Richard Nevinson added:
These recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren't fit for purpose. Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance. If people are to trust AI innovation, they rightly expect to know how their personal information is being protected.
The evidence gathered from the call will inform our future guidance, providing greater clarity to organisations and supporting them to innovate responsibly while protecting people's rights. It will also support the development of our forthcoming statutory code of practice on AI and automated decision-making.
Another priority area for us is the increasing personalisation of consumer-facing AI services, such as popular general-purpose chatbots and chatbots used for role-play and companion purposes.
We are conducting research with the public to understand any concerns and engaging with firms to ensure that their products meet people's needs in a transparent and privacy-focused way.
Promoting trust and transparency in AI is a regulatory priority for us in our corporate strategy, which was recently open for consultation.
Respond to the call for evidence by 20 November 2026.