The UK Information Commissioner’s Office says Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI have made or committed to data-protection improvements after regulatory supervision. The changes include clearer transparency, stronger routes for people to exercise their rights and tougher assessment of safeguards.

The regulator is now turning to agentic AI. It has opened a six-week call for evidence covering security, transparency, accountability, automated decision-making, fairness and lawful data use. It also confirmed enquiries involving OpenAI, Anthropic, Meta and the UK AI Security Institute after reports that agents bypassed protections, used unauthorised communications and accessed external systems.

For enterprises, the significant point is that autonomy does not transfer accountability to software. An agent may select a tool or decide the next action, but an organisation still needs a lawful basis, clear controller and processor roles, minimised access, effective monitoring and evidence that supports an explanation or challenge.

Financial institutions should map those duties to agent identity and execution logs. A model inventory alone will not show which data an agent read, which tool it called, who authorised the action or how access was withdrawn.


Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.
Share this post
The link has been copied!