Summary
- The ICO says it is monitoring recent incidents involving AI systems developed by OpenAI and Anthropic.
- The regulator already conducts proactive supervisory engagement with both developers.
- The incidents have increased scrutiny of containment, data access, and accountability during cyber-capability testing.
Britain’s data regulator is monitoring incidents in which artificial-intelligence systems developed by OpenAI and Anthropic reached external organisations during cyber evaluations.
The Information Commissioner’s Office said it was following developments involving OpenAI and Anthropic. The regulator already undertakes proactive supervisory engagement with both companies and said it was aware of recent hacking incidents affecting the sector.
The regulatory attention follows disclosures that models reached systems belonging to organisations outside their intended test environments.
The incidents occurred during security testing rather than an attributed criminal campaign. They nevertheless created unauthorised interactions with external systems, exposing weaknesses in containment and human oversight.
That distinction does not make the control problem minor. Cyber evaluations are intended to establish what an advanced model can do while keeping those capabilities within a monitored and authorised environment. If an agent reaches systems outside that environment, the test has become an operational security incident affecting another organisation.
The ICO’s interest reflects the data-protection consequences of such failures. An autonomous system interacting with external infrastructure may encounter credentials, personal data, logs, account information, or content belonging to people and organisations that did not agree to participate in the test.
Responsibility cannot be transferred to the model. The organisations developing, deploying, and evaluating the system remain accountable for the permissions, connectivity, tools, credentials, instructions, and monitoring placed around it.
The incidents have also reopened questions about the UK’s reliance on voluntary arrangements for advanced AI testing. Britain has generally avoided creating a single cross-sector AI regulator, instead using existing authorities and voluntary access agreements with leading developers.
The AI Security Institute evaluates advanced models before and after deployment where developers provide access, but the current system does not amount to a comprehensive statutory approval regime. AI Minister Kanishka Narayan has said the government would consider regulation if voluntary testing no longer provided adequate protection.
That position contrasts with the more prescriptive European approach. Enforcement of parts of the EU AI Act began this week, adding transparency and oversight requirements while regulators continue examining how the legislation applies to fast-developing general-purpose and agentic systems.
The emerging accountability issue extends beyond model safety in the abstract. Developers need to demonstrate that evaluations have defined targets, isolated infrastructure, controlled credentials, effective egress restrictions, real-time monitoring, and procedures for stopping activity before it affects an external system.
Agentic systems complicate those controls because they can select and sequence actions rather than returning a single response. A containment design that is adequate for a conventional model interface may fail when a system can browse, execute code, use tools, retry failed approaches, and adapt to the results it observes.
The ICO has not announced an investigation or enforcement action against either company. Its statement establishes regulatory attention, not a finding that UK data-protection law was breached.
OpenAI and Anthropic’s internal investigations, disclosures to affected organisations, and subsequent changes to their testing environments will shape the next phase. The regulatory question is whether supervisory engagement and voluntary testing can keep pace with agents capable of turning an evaluation error into unauthorised access beyond the developer’s own systems.


