UK Privacy Regulator Turns to Agentic AI: What It Means for AI Companions and Humanoid Robots
The UK ICO opened a call for evidence on agentic AI on October 8, 2026 after securing data-protection changes from ten major model developers. Here is what companion-AI and humanoid-robot users should watch.

What changed on October 8
The UK Information Commissioner’s Office said on October 8 that ten major foundation-model developers had made, or committed to make, data-protection changes following regulatory supervision. The companies named by the regulator include Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. The changes described by the ICO cover clearer transparency information, stronger ways for people to exercise data rights and more rigorous assessments of safeguards.
At the same time, the regulator opened a six-week call for evidence focused specifically on agentic AI. The consultation asks how organisations are handling security, transparency, accountability, automated decision-making, fairness, purpose limitation and lawful processing when AI systems can take actions with limited human oversight. The consultation is scheduled to close on November 20, 2026.
An independent report from The Register framed the move as a shift from examining how models are trained toward examining what increasingly autonomous agents do after deployment. That distinction matters because a chatbot that answers a question is different from an agent that can browse websites, call tools, send information to third-party services or act on a user’s behalf.
Why agentic AI is directly relevant to companion products
AI companions are often discussed as if they were simply conversational interfaces. In practice, many companion products are moving toward persistent memory, multimodal perception, proactive reminders, tool use and connections to external services. A humanoid robot can add microphones, cameras and physical presence to that software stack. Once those capabilities are combined, the privacy surface becomes much larger than a conventional chat window.
The key issue is not whether a product calls itself an “agent.” The practical question is whether software can gather context, remember personal details, make choices about what information to use, invoke tools or send data elsewhere without the user explicitly directing each step. Those behaviours can exist inside a mobile companion app, a smart speaker, a wearable or a physical robot.
For users, this means that “does the conversation stay private?” is too narrow a question. A better checklist asks what is collected, where it is stored, which model providers process it, whether memories can be removed, what tools the system can access and whether the product can make external requests using information from previous conversations.
Persistent memory changes the risk model
Memory is one of the most attractive features in a companion system because it makes interactions feel continuous. The same feature can also turn casual conversation into a long-lived personal profile. A system may remember preferences, relationships, routines, emotional disclosures, location clues or health-related statements even when the user does not think of those messages as formal account data.
Good product design should therefore make memory visible and controllable. Users should be able to inspect stored memories, correct them and delete them. A company should explain whether deleting a conversation also deletes extracted memories, embeddings or derived profile data. If those controls are unclear, a user cannot realistically understand what “delete my data” means.
For companion robots, the issue can be even more complex because audio and visual sensors may create data before a user deliberately types or uploads anything. Products should distinguish between transient sensor processing, retained recordings, derived features and data sent to cloud services.
Tool access creates a second layer of exposure
An agent becomes more useful when it can do things: search the web, open documents, manage a calendar, make reservations or control connected devices. Each permission also creates a path through which personal information can move. An AI companion that knows a user’s schedule and preferences may not need to reveal those details outside the product unless a task genuinely requires it.
Developers therefore need explicit permission boundaries. A model should not automatically inherit access to every connected service simply because the user authenticated once. Sensitive actions should be scoped, logged and reversible where possible. The user should be able to see which tool was used, what information was sent and what result came back.
This is especially important in products designed to feel socially persuasive or emotionally engaging. A warm conversational style must not blur the difference between a suggestion and a consequential action. Human-like presentation increases the need for clear controls rather than reducing it.
Physical robots add cameras, microphones and bystanders
A humanoid or social robot can collect information about people who never created an account. Cameras may capture visitors, family members or people in a workplace. Microphones can pick up conversations involving multiple people. Even if the robot’s primary owner has accepted a privacy policy, bystanders may not have done so.
Manufacturers should therefore explain when sensors are active, whether raw audio or video leaves the device and whether visible indicators show when recording or processing is taking place. Local processing can reduce some exposure, but “runs locally” should not be treated as a magic phrase: a device may still send selected data to cloud models, telemetry services or support systems.
For buyers evaluating a companion robot, privacy should sit alongside mobility, battery life, conversational quality and warranty support. A sophisticated camera system is not automatically a benefit if the owner cannot understand or control where the images go.
What the ICO’s move does — and does not — mean
The October 8 announcement does not create a new universal law for AI companions, and it does not mean the regulator has approved the privacy practices of every company named in its report. The ICO says it is monitoring progress against commitments and is seeking evidence before producing further guidance on agentic AI.
It also does not settle every technical question around personal data inside foundation models. The regulator explicitly acknowledges difficult questions around training data, special-category data and the possibility that models themselves may contain personal information. Those issues will continue to evolve as model architectures and deployment patterns change.
For BizarreSexuality readers, the practical takeaway is narrower and more useful: privacy claims should be treated as testable product features. A company should be able to explain what it collects, why it collects it, where it goes and how a user can exercise control.
A buyer checklist for AI companions and humanoid robots
Before relying on a companion system with sensitive conversations or sensor access, check whether the privacy policy identifies the actual controller and service providers. Look for specific retention periods rather than vague statements that data is kept “as necessary.” Check whether account deletion covers chat history, memories, uploaded images and derived profile information.
Ask whether the product uses third-party model providers. If it does, identify what content is sent to them and whether the provider can retain it for abuse monitoring or model improvement. Check whether optional features such as image generation, voice cloning or web search use additional companies.
For hardware, check whether microphones and cameras can be disabled in a way that is obvious and persistent. Look for physical indicators, documented sensor behaviour and a description of what works offline. If a robot is intended for a shared home, school, care setting or workplace, bystander privacy should be part of the purchase decision.
Finally, look for an activity history for agentic actions. A useful system should make it possible to understand what it did, which tool it invoked and whether the user can revoke that permission later.
What developers should build before adding more autonomy
The temptation in companion AI is to add autonomy because it makes a product feel more alive. A proactive system can start conversations, remember anniversaries or complete tasks without being prompted line by line. But additional autonomy should arrive with additional observability.
A strong baseline includes granular consent, user-visible memory controls, least-privilege tool access, clear sensor indicators, deletion workflows, incident logging and limits on what the system can do without confirmation. High-impact actions should require a fresh confirmation rather than relying on a broad permission granted months earlier.
Developers should also test how models behave when prompts contain conflicting instructions, when external websites attempt to manipulate an agent and when a tool returns sensitive information. The privacy problem is not only “where is the database?” It is also “what decisions can the agent make with the information it already has?”
Why this matters more as companions become multimodal
The next generation of companion systems increasingly mixes text, voice, images and physical embodiment. That can improve accessibility and make interactions more natural, but it also means more categories of personal data can be combined into one profile. A voice can reveal emotion. Images can reveal a home environment. Long-term memory can reveal habits. Tool access can reveal calendars, contacts or purchases.
When those signals are combined, the result can be more sensitive than any individual data point. That is why privacy-by-design needs to be built into the product architecture rather than added as a settings page after launch.
The ICO’s new focus on agentic systems is therefore relevant well beyond enterprise automation. Any consumer product that remembers, observes and acts is moving into the same basic territory.
Bottom line
The October 8 regulatory update is a useful signal for the companion-AI and humanoid-robot market. Regulators are looking not only at how models are trained but at what increasingly autonomous systems do with personal data after deployment. For buyers, the most important response is not panic; it is better product scrutiny.
A trustworthy companion product should make privacy controls understandable, memory editable, tool permissions narrow and sensor behaviour visible. A human-like interface can make technology easier to use, but it should never make data flows harder to see.
Sources checked
- UK Information Commissioner’s Office — October 8 announcement — primary source for the ten developers, commitments and agentic-AI scrutiny.
- ICO — Agentic AI call for evidence — primary source for consultation scope and November 20 closing date.
- The Register — independent reporting, October 8 — independent context on the regulator’s move and developer commitments.
- Wikimedia Commons image record — Roboticsfan, CC BY-SA 4.0, 1600×901.