Start a conversation Contact
← Research

There will be no draft of the ICO's agentic AI guidance

The ICO has agentic AI guidance in drafting for Winter 2026 and no public consultation on it, so no draft will circulate for anyone to argue with. What it will land on is already in print — the regulator has said that design and architecture determine how data protection law applies to an agentic system.

Most readiness plans for an agentic system carry the same line somewhere. It reads revisit when the ICO publishes, and it sits underneath an assistant that engineering teams are already building against. It is the reason the impact assessment is still a placeholder, and the reason nobody has yet had to decide what the assistant is allowed to reach.

The line has quietly expired, and the expiry is visible on the regulator’s own website. The ICO has agentic AI guidance in drafting, due for publication in Winter 2026, and it has decided not to consult on it. There will be no draft to read and no response window.

That does not leave a UK team without information. It means the information is already published, in a different form, and the design decisions being taken this quarter are the ones the guidance will be applied to.

There is no draft coming

The ICO maintains a public list of the guidance it has in development, showing the stage each item has reached and whether there will be a public consultation (guidance in development, technology). The entry for agentic AI guidance gives the stage as drafting, the consultation field as no, and the final version as due for publication in Winter 2026. The entry for foundation models says the same about consultation, with publication due in Summer 2026.

The contrast within the list matters: this is a choice, not a house habit. Guidance on anonymisation and pseudonymisation for research carries a consultation due to launch in August 2026. Neurotechnology guidance carries one due in October 2026. The update to the automated decision-making and profiling guidance, which is where the Data (Use and Access) Act amendments land, had a consultation and it is closed.

So the two documents that between them will determine how the UK regulator reads an agent taking decisions about people — the agentic AI guidance and the updated automated decision-making guidance — are both due in Winter 2026, and neither has a route open for arguing with a draft. One never had one. The other has shut.

This is not a complaint about process. A regulator is not obliged to consult before explaining law it already enforces. The consequence is operational: the sequence a governance function is built around — draft appears, teams read it, controls are mapped, responses are filed, design adjusts — is unavailable for the category of system this guidance is about.

What the regulator has already put in print

The substitute is not guesswork. The ICO published a Tech Futures report on agentic AI in 2026, and its central finding is unusually direct about where the answer lives:

The specific design and architecture of agentic systems impact how data protection law applies and how people exercise their data protection rights.

The same passage names the choices it means — the data and tools that a system can access, and which governance and control measures are put in place (ICO tech futures: Agentic AI). It then describes a poorly implemented system as one with no clear purposes, one connected to databases not needed for its tasks, or one with no measures in place to secure access, monitor or stop activity, or control the further sharing of information. Those are architecture defects, not policy ones.

One item on the risk list is worth reading twice, because it is the tension at the centre of the technology rather than an incidental hazard. The ICO names the risk of purposes for agentic processing being set too broadly to allow for open-ended tasks and general-purpose agents. An agent is bought for its generality. A purpose has to be narrow enough to constrain what is processed. The wider the tool surface, the harder it becomes to write a purpose that is a purpose rather than a description of the product.

The safeguards are already law, and they are a build decision

The second published source is not guidance at all. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with a new Articles 22A to 22D (section 80). Article 22A defines a decision as based solely on automated processing where there is “no meaningful human involvement in the taking of the decision”, and as significant where it produces a legal effect or a similarly significant effect for the person. Article 22B keeps a restriction, subject to stated conditions, on significant decisions built on special category data, and on decisions where the processing relies on Article 6(1)(ea). Everything else moves to Article 22C, which requires safeguards.

Every one of those four is addressed to a decision and to a person. An agent running an open-ended task produces neither by default. It produces a trajectory — instructions, tool calls, retrievals, intermediate conclusions — and somewhere inside it a step that had a legal or similarly significant effect on somebody. If the trace does not isolate that step and attach it to that person, none of the four measures can be delivered afterwards: there is nothing specific to inform anyone about and nothing specific for a human to intervene in.

What has to be true before a person can contest a decision an agent took Fig. 01
  1. Layer 01 A decision exists The trace marks which step was a decision rather than a step towards one.
  2. Layer 02 It has a subject That step is joined to the person it affected.
  3. Layer 03 Its inputs are recoverable Which tool call, which record, which retrieved passage, at which version.
  4. Layer 04 A human can change it Someone with authority to alter the outcome, not only to explain it.

Article 22A adds a clause that reads like a warning to a particular design. In considering whether there was meaningful human involvement, a person must consider, among other things, the extent to which the decision was reached by means of profiling. A reviewer at the end of a long agentic chain, approving a recommendation whose derivation they cannot reconstruct, is exactly the arrangement that clause invites a regulator to look at.

What to do before Winter 2026

Write the purpose at the level of the task, not the product. “An assistant for the operations team” is a product. What is processed, for which decision, about whom, is a purpose. If the honest answer is that the agent may reach anything the team can reach, that is a finding, and better found now than produced for a regulator later.

Treat the tool surface as a recorded decision. Which systems the agent may call is the choice the ICO named first. Record what was connected, what was not, and why — a refused connection is the cheapest evidence of data minimisation there is, and it exists only if somebody wrote it down at the time.

Mark decisions inside the trace. This is an engineering change, not a policy one. A log of every tool call is not the same artefact as a record of which calls constituted a significant decision about a named person. No later document creates the second from the first.

Run one intervention end to end. Take a decision the agent made last week and attempt all four Article 22C measures for it. It produces the only honest answer available about whether the architecture supports the safeguards.

The routes that remain open are participation rather than response. The ICO’s own next steps name industry workshops, work with partner regulators through the Digital Regulation Cooperation Forum, its innovation support services and the Regulatory Sandbox. With no consultation, those are the input routes.

What this does not tell you

It does not tell you what the guidance will say. The regulator’s published research is a reasonable basis for design and a poor basis for certainty, and anyone treating the Tech Futures report as a draft is claiming more for it than it claims for itself.

It does not tell you whether a particular decision your agent takes is “significant” for the purposes of Article 22A. That turns on the effect on the person, which is a question about your system and your users rather than about agents in general.

It does not tell you that the definitions will hold. Article 22D gives the Secretary of State power to make regulations about what is and is not to be taken as meaningful human involvement, and about which descriptions of decision have a similarly significant effect. A design built on today’s reading of those two phrases is built on something a statutory instrument can move.

None of this is legal advice, and no work of this kind produces a statement that an organisation meets the UK GDPR. The institute does not certify anyone and does not issue conformity opinions. Legal interpretation stays with your counsel. What we do is establish which obligations plausibly attach, map what already exists against them, and name the evidence that does not exist yet.

The head of engineering deciding this quarter which systems the assistant may reach, and whether its trace distinguishes a decision from a step, is not waiting for the ICO. They are writing the document the ICO will eventually be handed.

Filed under · Governance · ICO · Agentic AI · Automated decision-making Inference Institute · 23 Aug 2026

Bring us the question

Reading this because it is on your desk right now?

That is the conversation we are best at. Thirty minutes, a written summary, no obligation.