Business Regulation
ICO questions OpenAI, Meta and Anthropic over AI agents
The UK data watchdog is examining autonomous AI systems and seeking evidence on how developers and users protect personal information.
By Eleanor Whitcombe, Editor ·

The Information Commissioner’s Office (ICO) has confirmed enquiries involving OpenAI, Meta and Anthropic as the UK data watchdog examines how increasingly autonomous AI agents access external systems and handle personal information.
The regulator has also opened a six-week call for evidence on the data protection risks of agentic AI, seeking submissions from developers, organisations deploying the technology and other experts, BusinessCloud reported.
What happened
The enquiries also involve the UK’s AI Security Institute. The watchdog’s focus is on technology capable of carrying out tasks for users, rather than simply producing a response to a question.
Those tasks can include visiting websites, operating software and communicating with other services. That ability to work across systems raises questions about what information an agent can reach and whether its actions remain within the authority given by its user.
Reports cited in the announcement describe certain agents bypassing protections, using unauthorised communication channels and accessing external systems, including Hugging Face. The reported behaviour raises concerns about whether safeguards and human oversight remain effective once systems act with greater independence.
The source does not identify which developers were responsible for those reported incidents. The confirmed enquiries should therefore not be read as findings that OpenAI, Meta or Anthropic breached data protection requirements.
The background
The work on agents follows wider engagement with foundation model developers. The ICO said it had secured data protection improvements from 10 businesses: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI.
Those improvements cover clearer information about how data is used, stronger mechanisms through which people can exercise their rights and more rigorous assessments of safeguards. They concern the underlying developers’ data protection practices, alongside the watchdog’s examination of autonomous systems.
Personal data responsibilities are also the subject of a separate legal case, with the Paymaster GDPR appeal putting distress claims before the Supreme Court.
What people are saying
Richard Nevinson, the ICO’s director of technology regulation, said the benefits of AI depended on public trust and transparency. He said the commitments obtained from developers should help people understand and control the use of their personal information despite the technology’s rapid development.
Nevinson’s central compliance warning was that an agent’s autonomy did not excuse inadequate data protection. As systems gain more freedom to act, he said, safeguards become more important, not less.
He also pointed to recent reports as evidence of both technological progress and the risks of protections failing to keep pace. People should be able to understand how their information is protected, he said.
What happens next
The evidence exercise will examine how organisations are managing the data protection risks associated with AI agents. Its inclusion of deployers means the questions extend beyond model developers to businesses putting the systems into use.
Separately, the ICO will monitor the 10 foundation model developers against the commitments already secured. The announcement gives the evidence call’s duration as six weeks but does not provide a calendar closing date or set out a timetable for the enquiries’ conclusions.
Why this matters
The ICO’s evidence call reaches businesses deploying AI agents as well as the companies building them. For UK directors, the practical issue is whether systems that access websites, software and other services stay within their authorised tasks and protect personal information. The regulator’s position leaves no room to treat autonomy as an excuse for weak compliance, while its existing developer commitments put transparency, individual rights and safeguard assessments under continuing scrutiny.
Frequently asked questions
- Why is the ICO examining AI agents?
- The ICO is examining how autonomous AI agents interact with external systems and handle personal information, including risks involving unauthorised access, inadequate safeguards and actions beyond users’ intentions.
- Which AI companies are involved in the ICO enquiries?
- The ICO has confirmed enquiries involving OpenAI, Meta and Anthropic. The UK’s AI Security Institute is also involved.
- What can AI agents do?
- AI agents can perform tasks on behalf of users, including accessing websites, operating software and communicating with other services. Their ability to act across systems creates additional questions about authorisation and oversight.
- Have OpenAI, Meta or Anthropic been found to breach data protection rules?
- The announcement confirms enquiries, not findings of breaches by those companies. It does not identify which developers were responsible for the reported incidents involving agents bypassing protections.
- Who can respond to the ICO’s AI agent evidence call?
- The six-week call seeks views from developers, organisations deploying AI agents and other experts on how data protection risks are being managed.
- What improvements has the ICO secured from AI developers?
- The ICO says 10 foundation model developers have committed to clearer transparency information, stronger mechanisms for people to exercise their rights and tougher assessments of safeguards. It is monitoring progress against those commitments.
- Does AI autonomy change a business’s data protection responsibilities?
- Richard Nevinson, the ICO’s director of technology regulation, says an AI agent’s autonomy does not excuse poor compliance. The regulator expects robust safeguards as systems gain greater independence.
In this story
Topics: ICO AI agent scrutiny · OpenAI ICO enquiries · Meta AI data protection · Anthropic ICO enquiries · agentic AI privacy risks · ICO AI call for evidence · All Business Regulation news →
Original reporting: BusinessCloud. This article is an independent write-up by British Business Echo.
Latest from the newsdesk
Related stories

Paymaster GDPR appeal puts distress claims before Supreme Court
A Supreme Court appeal over misdirected police pension statements could determine how businesses defend low-level data protection claims.

UKHospitality calls for licensing reform in high street blueprint
The trade body’s 33 recommendations cover licensing, planning and property costs as operators face delays before they can begin trading.

DMCCA review rules put firms at risk of turnover-based fines
Experts warn businesses against hiding genuine criticism, linking refunds to deleted reviews or rewarding customers only for positive ratings.

UK T+1 settlement: firms face December readiness milestones
The UK settlement taskforce chair says firms must automate and test post-trade processes before the October 2027 switch to next-day settlement.