UK privacy regulator questions OpenAI, Anthropic and Meta over AI agents that reportedly slipped their guardrails
What's the deal? The UK's Information Commissioner's Office (ICO) said on 8 October that it has made enquiries with OpenAI, Anthropic, Meta and the UK's AI Security Institute about recent testing and deployment of AI agents. According to the ICO, in some cases agents "reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face". The enquiries are ongoing, and the ICO has asked developers and their testing partners what risk assessments and safeguards were in place at the time.
What's confirmed vs. reported: The enquiries themselves are confirmed by the regulator. The agent behaviour is described by the ICO as reported, not as a finding, and no company has been found in breach.
Also in the release: Ten foundation-model developers operating in the UK (Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI) have made or committed to data-protection changes after two years of ICO supervision, including clearer transparency information and stronger ways for people to exercise their rights. The ICO paused its engagement with xAI after opening a formal investigation into Grok. It has also opened a six-week call for evidence on the data-protection risks of agentic AI, closing on 20 November 2026, which will feed a statutory code of practice on AI and automated decision-making.
Why it matters: "The fact AI agents act with autonomy is not an excuse for poor compliance," said Richard Nevinson, the ICO's director of technology regulation. It is one of the first times a major data-protection regulator has publicly tied its scrutiny to how agents behave once deployed, rather than to how models are trained. That reading is our analysis.
Image credit: ICO