Start free trial of Lex HR →

NCSC flags agentic‑AI risks; ICO updates ADM guidance

Lexology highlights NCSC guidance on agentic AI and ICO work on automated decision‑making, urging UK employers to tighten supply‑chain and DPIA controls.

2 September 2026

Lexology has flagged fresh UK regulator activity that employers should factor into procurement and people‑tech governance: the National Cyber Security Centre has published guidance on managing the risks posed by 'agentic' AI, and the Information Commissioner’s Office has been pressing its expectations on automated decision‑making in recruitment.

The round‑up — published August 26, 2026 — highlights how the NCSC’s material frames agentic systems as a distinct class of risk, with attention to the security of autonomous agents and the software supply chain. The NCSC calls out scenarios where AI systems take actions without continuous human oversight and recommends tightening controls around deployment, credentialing and third‑party components that could be manipulated or repurposed.

Separately, the ICO’s recent engagement on automated decision‑making and hiring tools has focused on transparency and data‑protection safeguards, Lexology reports. The regulator has reiterated the centrality of data protection impact assessments (DPIAs) where AI is used to assess candidates or monitor workers, and signalled that demonstrable human review and clear disclosure to affected individuals are expected elements of compliance.

For HR and IT teams, those messages intersect in practical ways. Buyer teams should be revisiting supplier contracts to ensure vendors disclose model capabilities, update‑and‑patch processes, and incident response arrangements for autonomous behaviours, the Lexology note suggests. Meanwhile, HR leaders using screening, matching or monitoring systems will need to make sure privacy assessments capture not just personal data flows but also the operational settings that allow an AI agent to act on behalf of an employer.

The combined regulatory nudges reflect a widening regulatory focus on both the cybersecurity and rights implications of workplace AI. The NCSC’s cybersecurity framing positions agentic systems alongside other supply‑chain threats that can create cascading operational harm, while the ICO’s emphasis on transparency and DPIAs aligns with broader European data‑protection practice on automated decision‑making. Taken together, the two strands underline that AI governance is now a cross‑functional obligation spanning legal, security, procurement and people teams.

What Lexology’s summary makes clear is that the regulators are asking for evidence — not just policy statements. Organisations may therefore need to surface audit trails, supplier risk assessments and records of human oversight that show decisions about hiring or worker monitoring were subject to review. The ICO’s intervention in hiring markets is particularly likely to require HR teams to document how algorithms influence outcomes, how individuals are informed, and what mechanisms exist to challenge or escalate decisions.

Several questions remain unanswered in the public materials. Neither the NCSC nor the ICO has published a prescriptive checklist that defines the precise threshold for when an automated process becomes an ADM (automated decision‑making) risk requiring a DPIA, nor have they set out a single audit standard for bias testing or model validation in recruitment contexts. Firms looking for concrete, auditable benchmarks will still need to map regulator expectations to internal risk appetites and industry‑specific practices.

That gap leaves room for firms to move first: updating procurement terms to require vulnerability and change notifications from AI vendors, tightening operational controls for agentic features, and ensuring DPIAs specifically address autonomous behaviours and worker‑facing outcomes. As AI systems are woven deeper into talent processes, the regulators’ twin focus on security and individual rights suggests the next phase of compliance will be about demonstrable controls — not just architectural or policy statements. HR and IT leaders who treat these signals as operational imperatives, rather than theoretical risks, will be better positioned when regulators press for evidence of oversight and remediation.

Sources
  1. Lexology technology round‑up: NCSC agentic‑AI risks and ICO guidance flagged for UK organisations (Aug 26, 2026)
  2. National Cyber Security Centre
  3. Information Commissioner’s Office