Plain-English Briefing
The UK data regulator is asking about AI agents. Have your answers ready.
An AI assistant reads a customer’s email, finds their order, updates the delivery date and replies. Nobody in the office touched it. If the customer later asks what happened to their details, who answers?
That question is now on the regulator’s desk. Today the Information Commissioner’s Office opened a call for evidence on how UK data protection law should apply to AI agents. For a smaller business, the useful part is not the consultation itself. It is the list of questions the ICO is asking, because they are the questions a customer, an auditor or the regulator could one day put to you.
What changed this week
On 8 October, the ICO opened a call for evidence on agentic AI: systems that carry out tasks, rather than only answering questions. It runs until 20 November 2026 and covers data security, transparency, accountability, automated decision-making, fairness and purpose limitation, and the lawful basis for processing. The ICO says the evidence will inform its thinking on the “distinctive capabilities and risks” of these systems. Read the ICO call for evidence.
It follows a structural change a week earlier. On 30 September, under the Data (Use and Access) Act 2025, the regulator moved from a single Information Commissioner to a board-led Information Commission. It is still known as the ICO. The change does not create new obligations for businesses, although the regulator also gained new investigation powers, including requiring witnesses to attend interviews.
The ICO has not yet issued its agentic AI guidance, so nothing below is a new legal requirement. It is our practical reading of where the questions are heading.
Why this reaches small firms
AI agents are no longer only a large-company project. Mainstream office and chat tools now include assistants that can work through a mailbox, a shared drive or a connected system on somebody’s behalf. Card spending data published by Capital on Tap this week suggests 12.8% of UK SME cardholders were paying AI providers in the second quarter of 2026, up from 1.1% in early 2023.
Most of that will be ordinary chat subscriptions. But the step from “it drafts the reply” to “it sends the reply and updates the record” is often a settings change, not a new purchase. That is the step the ICO is interested in.
The four questions worth answering now
The ICO’s earlier research on agentic AI picked out several concerns, including agents “processing personal information beyond what is necessary”, unclear responsibilities “through the agentic AI supply chain” and a growing amount of automated decision-making. Those translate into four plain questions for any business using an agent with customer or staff information.
1. What personal information can it reach?
An agent connected to “the mailbox” can usually reach every customer, supplier and staff email in it, not only the enquiry it was asked to handle. Write down the systems and folders it can access, then compare that with what the task actually needs. The gap between the two is the part to close first.
2. Who is responsible for what it does?
If your business decides why and how the information is used, you are likely to remain responsible for it, even when a supplier’s AI does the work. Check what the supplier’s terms say about their role, where the information is processed and whether it is used to train their models. “The AI did it” will not be a satisfactory answer to a customer or the regulator.
3. Does it make decisions about people?
Sorting enquiries is one thing. Declining a booking, setting a price for a particular customer or rejecting a job applicant is another. Where an agent’s output has a real effect on a person, a named member of staff should review it before it stands, and the person should be able to ask for that review.
4. Could you explain afterwards what it did?
If a customer asks what happened to their information, you should be able to say what the agent read, what it changed and who approved it. That means a record you can actually find, not a supplier’s assurance that “logs exist somewhere”.
We covered the permission side of this in The AI can see your business data now. Start with permissions. The ICO’s questions add the data protection layer on top.
Should you respond to the call for evidence?
Probably not, unless you have direct experience to share. The call is open to anyone, and a small firm that has deployed an agent and found something difficult has useful evidence. But the more practical response for most businesses is to make sure they could answer the four questions above if asked.
If you cannot answer them for a tool you already use, that is worth knowing now. It may mean narrowing what the agent can reach, turning off an action it does not need or adding an approval step. None of that needs to wait for the guidance.
Worth doing this week
- List every AI tool in the business that can read customer, supplier or staff information, including assistants switched on inside existing software.
- For each one, note whether it can only read, or can also send, update or delete.
- Check the supplier’s data processing terms for where information goes and whether it is used for training.
- Pick one recent task the agent handled and try to reconstruct what it did. If you cannot, fix that before giving it more to do.
If you would rather keep the data in-house
Our commercial interest: at Inferred, we build automations, business systems and private AI that runs on hardware you own. Keeping an AI system in-house can make the questions above easier to answer, because you can see what it holds and what it did. It does not remove them. A private agent with access to everything still needs limits, approvals and a record.
If you are not sure where AI is already touching personal information in your business, our operations audit maps where the work and the data actually go, including what is not worth changing.
See how the operations audit works →
Where this came from
ICO: agentic AI call for evidence, open 8 October to 20 November 2026. ICO Tech Futures: agentic AI, a research report rather than guidance. Lewis Silkin: what the ICO’s move to the Information Commission means. Intelligent SME: Capital on Tap data on SME AI spending, 6 October 2026. The opening example, the four questions and the recommendations are Inferred’s editorial interpretation; they are not ICO guidance or legal advice.