The UK’s data regulator has issued a strong warning that companies remain responsible for protecting personal data when they use AI systems, even when the technology acts autonomously.

The Information Commissioner’s Office (ICO) added that companies still need to ensure they have procedures and controls in place to ensure compliance with the UK General Data Protection Regulation (GDPR), the Data (Use and Access) Act 2025, and other legislation to manage the potential risks around data misuse and loss caused by agentic AI “if guardrails aren’t fit for purpose.”

Neil Hodge is a freelance business journalist and photographer based in Nottingham, United Kingdom. He writes on insurance and risk management, corporate governance, internal audit, compliance, and legal...