Artificial intelligence isn’t new territory for most organisations, but the pace of development continues to accelerate, and with that comes new questions about responsibility, risk, and compliance. The UK’s data regulator, Information Commissioner’s Office (ICO), has just published a new Tech Futures report on agentic AI to help organisations think about what’s coming next and what it could mean for data protection and privacy.
This isn’t prescriptive guidance, and it isn’t legal advice but it is a useful foundation for thinking about how emerging AI capabilities may intersect with existing regulatory expectations.
What is Agentic AI?
At a high level, “agentic AI” refers to artificial intelligence systems that go beyond simply responding to prompts. These are systems that can:
- Use contextual information, plan, and act autonomously
- Carry out open-ended tasks with minimal direct instruction
- Integrate with other systems and tools to make decisions or act
This is a step beyond the generative AI many organisations are familiar with today, it’s AI that can interact with environments and processes in ways that are less predictable and more autonomous.
Why This Matters for Data Protection
The ICO’s report highlights that as agentic AI becomes more capable, and more embedded in business processes, organisations will need to think carefully about how data protection law applies:
- Controller and processor responsibilities become less clear when an AI system is acting autonomously.
- Systems that automate decision-making at scale could lead to greater volumes of personal data being processed or inferred.
- Transparency and rights management (such as data access or deletion requests) become harder if the system’s operation isn’t well documented or auditable.
- Architectures that enable broad access to datasets could unintentionally increase security risk.
Put simply: if an AI system is acting with more autonomy, the end-to-end data flows and decision logic need to be well understood, as well as how individuals’ rights will be respected.
Opportunities and Innovation: With Guardrails
The ICO isn’t just focused on risks. The report also outlines innovation opportunities where agentic AI might support better outcomes, including areas where privacy could actually benefit:
- AI agents that help with privacy management tasks
- Tools that automate certain aspects of data governance
- Mechanisms to benchmark or evaluate agentic AI systems against best practice
What makes the difference here is design and governance. Systems that build privacy and accountability in from the start, rather than as an afterthought, are much more likely to deliver positive outcomes.
Design Choices Really Do Matter
A recurring theme in the ICO’s report is that architecture and governance choices shape legal outcomes. For example:
- Limiting what data an agent can access reduces unnecessary processing.
- Clear purpose definitions mean systems don’t drift into broader or unintended use cases.
- Human oversight mechanisms help ensure accountability, especially where decisions affect rights or obligations.
- These are familiar themes for anyone used to data protection and cyber risk work, but the report underscores their importance in the context of rapidly evolving AI systems.
What This Means Practically for Organisations
For UK organisations thinking about agentic AI, whether in development procurement, or deployment, the message is clear:
- Understand where and how the system will touch personal data.
- Define responsibilities clearly across internal teams and external providers.
- Document decisions and data flows so audit and compliance processes can keep pace.
- Embed privacy by design and default into AI governance frameworks.
None of this is fundamentally new, it aligns with basic data protection principles, but agentic AI’s autonomy raises the stakes and scales up some of the traditional risks.
Next Steps for Practitioners
The ICO makes it clear that its work on agentic AI is ongoing. They’re planning workshops, updates to guidance, and cross-regulatory engagement through forums such as the Digital Regulation Cooperation Forum (DRCF).
For organisations, now is a sensible moment to:
- Refresh your AI Policies and governance frameworks
- Map out data protection risks associated with any autonomous systems
- Ensure your information governance, DPIAs, and oversight processes can handle greater complexity
If you’re already thinking about these areas in the context of other frameworks like Cyber Essentials or ISO 27001, agentic AI simply adds another layer of complexity, not an entirely new discipline.
Where Evolve North Can Help
Navigating emerging technologies alongside established compliance requirements is a recurring challenge. At Evolve North, we support organisations with:
- Practical AI governance and risk assessments
- Data protection and privacy impact reviews
- Alignment with UK GDPR and regulatory expectations
- Assurance work that connects innovation with accountability
Contact us to talk through your questions on 01748 905 002 or email info@evolvenorth.com to explore how agentic AI may interact with your data protection responsibilities.
