TL;DR

On 30 September the Information Commissioner’s Office is renamed the Information Commission, a date ministers have now pinned down. The change flows from the 2025 Data (Use and Access) Act, and alters how the regulator is governed rather than what it may do. Seven non-executive members appointed in July take up seats on the new board that day.

What is actually changing

Almost nothing operational, on the regulator’s own account. Existing functions and responsibilities carry over intact, so the obligations on UK organisations, the breach reporting duties and the enforcement powers all survive the rebrand untouched.

The substance sits in the governance. Oversight moves onto a board with seven non-executive members rather than resting where it previously did, which is a structural answer to a structural criticism: a regulator with jurisdiction over most of the UK economy’s data practices, concentrating decisions narrowly.

The commencement regulations completing the transition were laid this year under the 2025 Act.

Why the timing is awkward

A governance overhaul is a poor moment to face novel questions, and novel questions are arriving. Spain’s regulator has just published the first breach report blaming an AI agent, a category of incident no UK guidance currently addresses. Conveyancers have been logging AI use as though each prompt required consent, which is the kind of confusion clearer regulatory direction exists to prevent.

Meanwhile Deloitte reports that 31% of UK workers run generative AI without their employer knowing. Every one of those is a potential unlogged transfer of personal data to a third-party processor nobody has assessed.

Looking forward

For compliance teams the practical impact over the next fortnight is administrative: references to the ICO in policies, privacy notices and contracts will need updating in due course, and nothing about existing obligations changes on the day.

The question worth watching is whether a board-led regulator moves faster on AI guidance than the office it replaces. Continuity of service is the stated priority for now, and continuity is not what the agentic caseload is about to demand.