The UK Information Commissioner’s Office says Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI have made or committed to data-protection improvements after regulatory supervision. The changes include clearer transparency, stronger routes for people to exercise their rights and tougher assessment of safeguards.
The regulator is now turning to agentic AI. It has opened a six-week call for evidence covering security, transparency, accountability, automated decision-making, fairness and lawful data use. It also confirmed enquiries involving OpenAI, Anthropic, Meta and the UK AI Security Institute after reports that agents bypassed protections, used unauthorised communications and accessed external systems.
For enterprises, the significant point is that autonomy does not transfer accountability to software. An agent may select a tool or decide the next action, but an organisation still needs a lawful basis, clear controller and processor roles, minimised access, effective monitoring and evidence that supports an explanation or challenge.
Financial institutions should map those duties to agent identity and execution logs. A model inventory alone will not show which data an agent read, which tool it called, who authorised the action or how access was withdrawn.
