← Insights / Compliance

ICO rebranding to Information Commission from 30 September 2026: what changes for UK professional services data handling

On 30 September 2026, the Information Commissioner's Office will formally rebrand as the Information Commission. For most businesses, that announcement might seem like little more than a change to a letterhead. It is not. Coming at a moment when the UK's approach to AI regulation is visibly shifting

Compliance 16 September 2026 6 min read

The ICO Is Becoming the Information Commission: What UK Professional Services Firms Need to Know

On 30 September 2026, the Information Commissioner's Office will formally rebrand as the Information Commission. For most businesses, that announcement might seem like little more than a change to a letterhead. It is not. Coming at a moment when the UK's approach to AI regulation is visibly shifting, this transition deserves careful attention from any professional services firm — whether you are based in London, Toronto, Dubai, or Sydney — that handles UK personal data.

Here is what is happening, why it matters, and what you should do about it.

What the Rebrand Actually Means

The ICO announced on 15 September 2026 that it will operate under the new name Information Commission from 30 September 2026. The renaming is not purely cosmetic. It reflects an ongoing evolution in the regulator's mandate — one that extends beyond its origins as a data protection watchdog into broader questions of digital rights, AI governance, and accountability across automated systems.

For professional services firms, the practical implication is straightforward: the same regulatory authority, with the same investigatory and enforcement powers, is signalling that its remit is broadening. The enforcement record remains intact. The regulatory expectations remain in force. What changes is the direction of travel.

The Broader Regulatory Shift in the UK

The rebrand does not exist in isolation. On 14 September 2026, the UK Parliament's Joint Committee on Human Rights published a report titled Human Rights and the Regulation of AI, calling for a dedicated AI Bill and a new statutory independent AI regulator. The committee's core argument is that existing regulatory frameworks are insufficient to address the human rights risks posed by AI systems — particularly in areas such as automated decision-making, surveillance, and profiling.

The UK government has not yet committed to new legislation, but reporting from City AM on 15 September 2026 indicates ministers are now more open to tougher AI regulation than they have been in recent years. That is a meaningful shift in tone from a government that has, until recently, leaned toward a lighter-touch, sector-by-sector approach.

For professional services businesses, this is the point at which regulatory ambiguity begins to crystallise. You may not yet face a specific AI law in the UK — but the direction is clear, and firms that begin preparing now will be significantly better positioned than those that wait for legislation to force the issue.

What This Means for Data Handling Right Now

The Information Commission's investigatory work continues regardless of the name change. On 11 September 2026, the outgoing ICO issued a statement confirming its investigation into Police Scotland's compliance with Subject Access Requests under UK GDPR and the Data Protection Act. That investigation is a reminder that the regulator is actively scrutinising how organisations handle data subject rights — not just in principle, but in practice and at scale.

Subject Access Requests are a daily operational reality for accountancy firms, law firms, HR consultancies, and marketing agencies. Each of these sectors holds significant volumes of personal data: client financial records, employee files, candidate information, contact databases, and engagement histories. Mishandling a SAR — whether through delay, incomplete disclosure, or poor internal processes — remains an enforcement risk, and that risk does not diminish because the regulator has a new name.

If your SAR handling processes have not been reviewed recently, this is a practical prompt to do so.

The International Dimension

Professional services firms operating globally need to understand that UK data protection obligations apply to the data you handle, not simply to where your offices are located. If a UK-based client's employee submits a Subject Access Request to your HR consultancy in Dublin or your marketing agency in Singapore, UK GDPR applies. The Information Commission's jurisdiction follows the data.

This matters as AI tools become increasingly embedded in professional services workflows. Using AI to process, analyse, or generate outputs from personal data — client onboarding documents, HR assessments, legal research, campaign personalisation — triggers obligations under UK GDPR that many firms have not yet fully mapped. The Joint Committee's call for statutory AI regulation is a signal that these obligations are likely to become more explicit and more demanding, not less.

Firms in the EU are already navigating the EU AI Act, which introduces risk-based requirements for AI systems used in employment, education, and access to essential services. Firms in the US are contending with a patchwork of state-level AI and privacy laws. For businesses operating across jurisdictions, the UK's regulatory evolution adds another layer that requires active management rather than passive observation.

One further development from the past week is worth noting. On 14 September 2026, a student named Lyle Hopkins won a small claims court case at Oxford County Court after using AI to prepare his legal documents. The case attracted attention precisely because it illustrates how AI-assisted legal work is moving from theoretical discussion into lived practice.

For law firms and legal teams within professional services organisations, this raises genuine questions about the use of AI in document preparation, advice generation, and client-facing outputs. Where does AI assistance end and professional responsibility begin? How are AI-generated documents reviewed and quality-controlled? These are not abstract questions — they are the kinds of questions regulators, courts, and clients will increasingly ask.

Getting ahead of them requires documented policies, clear governance, and staff who understand the boundaries of appropriate AI use in professional contexts.

What You Should Be Doing Now

Across each of these developments, a consistent set of practical priorities emerges for professional services firms handling UK personal data:

Review your SAR processes. The Information Commission's investigation into Police Scotland is a reminder that SAR compliance is actively monitored. Ensure your firm can respond within statutory timeframes and that your disclosure processes are documented and auditable.

Audit your AI tool usage. Identify every AI system your firm currently uses that touches personal data. Understand what data is being processed, by whom, and under what legal basis. If you cannot answer those questions, you have a gap.

Map your cross-border data flows. If you operate across the UK, EU, US, or other jurisdictions, ensure you understand which regulatory frameworks apply to which data processing activities. A single client relationship may trigger obligations in multiple regimes simultaneously.

Document your AI governance. Even before specific AI legislation is enacted in the UK, demonstrating that your firm has considered AI risks — and has policies in place to manage them — positions you well with clients, regulators, and insurers.

Monitor the legislative pipeline. The Joint Committee's report and the government's shifting posture suggest that the UK AI regulatory landscape will look materially different within the next 12 to 24 months. Build regulatory monitoring into your compliance calendar now.

Ready to Get Ahead of What Is Coming?

The rebranding of the ICO to the Information Commission is a moment worth marking — not because it changes everything overnight, but because it reflects a regulator and a government preparing for a more demanding era of AI and data oversight. For professional services firms, the time to build the right foundations is before the legislation lands, not after.

Ops Intel works with accountants, solicitors, HR consultancies, and marketing agencies globally to navigate AI compliance with clarity and confidence. If you want to understand your obligations and build a practical compliance programme that holds up to scrutiny, visit us at opsintel.io and speak to our team.

Follow us in Google

See Ops Intel first when AI rules change

One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.

What to do about it

The news is what changed. A framework is what you do about it.

Ops Intel writes AI compliance frameworks for small and medium businesses worldwide. Before you spend anything, read a real one — the whole pack, produced by the same system that will write yours.

Call Now Claim Your Free Audit