The UK’s data protection watchdog is stepping up scrutiny of artificial intelligence agents amid concerns about the risks posed by increasingly autonomous technology.

The Information Commissioner’s Office (ICO) has confirmed enquiries involving OpenAI, Meta, Anthropic and the UK’s AI Security Institute as it examines how AI agents interact with external systems and handle personal information.

It also said it had secured data protection improvements from 10 of the world’s largest AI foundation model developers: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI.

These included clearer transparency information, stronger mechanisms for people to exercise their rights and tougher assessments of safeguards. It is monitoring developers’ progress against their commitments. 

AI agents can carry out tasks on behalf of users, including accessing websites, using software and communicating with other services.

However, their growing autonomy has raised concerns about whether they could bypass safeguards, access information without appropriate authorisation or take actions beyond those intended by users.

The ICO has therefore launched a six-week call for evidence, seeking views from developers, deployers and other experts on how organisations are managing the data protection risks of agentic AI. 

In some cases, certain agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face, raising potential concerns about safeguards, accountability and oversight.

Cost-cutting Oxford Metrics agrees cut-price deal for Move AI

Richard Nevinson, director of technology regulation at the ICO, said: “AI has huge potential to benefit our society, but that depends on trust and transparency. Our engagement with some of the biggest developers has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area. 

“But as AI systems operate with greater autonomy, robust data protection safeguards become even more critical.

“Recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren’t fit for purpose. Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance. 

“If people are to trust AI innovation, they rightly expect to know how their personal information is being protected.”

First ever UK-Germany tech corridor signed