Hong Kong's privacy regulator checked 60 organisations this year and found that 95% now use AI in daily operations. In the same review, the share with a formal AI policy fell from about 63% to 50%. Then, on 25 August 2026, the PCPD published its first guidance written specifically for AI agents. If your organisation is piloting agents that read inboxes, update CRMs or move files, this guidance now sets the standard you will be measured against.
This article explains what the guidance says, why agents are treated as a separate risk category, and how to turn nine recommendations into a governance programme your board can follow.
What is the PCPD's agentic AI guidance?
"Protecting Personal Data Privacy in the Use of Agentic AI" is guidance published by Hong Kong's Office of the Privacy Commissioner for Personal Data on 25 August 2026. It sets out nine recommendations and a five-stage security checklist for organisations whose AI agents collect, hold, process or use personal data under the PDPO.
The PCPD defines agentic AI as a system capable of autonomous perception, memory, decision-making, interaction and execution, usually built on a foundation model connected to databases, memory and operating-system tools.
The guidance supplements the PCPD's June 2024 Artificial Intelligence: Model Personal Data Protection Framework, which still applies. It was prepared with the Digital Policy Office and ASTRI as supporting organisations, and with reference to the TC260 security guidelines for AI agents published in mainland China in July 2026. You can read the official summary in the PCPD media statement.
Why does agentic AI need its own privacy guidance?
Agentic AI needs separate guidance because it acts, not just answers. A chatbot drafts a reply; an agent can open your files, read email, use stored credentials and complete multi-step tasks without a human approving each step. The PCPD says this wider access creates privacy risks that conventional chatbot governance was never designed to handle.
The PCPD names five specific risks:
--- Extensive access: agents run with higher default permissions, so one misread command can expose or delete large volumes of personal data.
--- System vulnerabilities: an agent connected to several systems turns one design flaw into a cross-system exposure.
--- Vulnerable plugins or skills: unreviewed add-ons may carry malicious code that lets attackers take over accounts or machines.
--- Function creep: agents combine data from many sources, and some systems use it to train models, which can breach the original collection purpose.
--- Multi-agent risks: inaccurate or hallucinated personal data can cascade from one agent to the next.
For an operations leader, the practical point is simple. Your existing generative AI policy probably covers what staff type into a chat window. It almost certainly does not cover what an agent is permitted to do once it holds your Microsoft 365 or ERP credentials.
What do the PCPD's 2026 compliance checks reveal about Hong Kong enterprises?
The PCPD's 2026 compliance checks show adoption racing ahead of governance. Of 60 organisations reviewed, 57 used AI and about 51% ran three or more AI systems. Yet formal AI policies fell to 50%, and board-level AI discussions dropped by roughly 25 percentage points compared with 2025.
According to Mayer Brown's analysis of the 2026 checks, half of the organisations reviewed had more than 500 employees, and the review added accounting, logistics, F&B, technology and property management to the sectors covered.
The data contains some good news. Among organisations processing personal data through AI, about 79% conducted privacy impact assessments and 92% had breach response plans. However, only about 41% of those plans specifically addressed AI-related incidents.
The PCPD found no PDPO contraventions in this round. That should not be read as comfort. The checks are a voluntary review, and the regulator has now told the market in writing what it expects for agents. The next round will be measured against that expectation.
What are the nine PCPD recommendations for agentic AI?
The nine recommendations map agentic AI onto the PDPO's six Data Protection Principles. They cover data minimisation, transparency, accuracy, retention, purpose limitation, security, data subject rights, continuous risk assessment and governance. Together they form a working control framework you can assign to named owners.
The table below groups them by the executive who would normally own each one.
Data and legal (DPO or General Counsel)
--- 1. Minimise and ring-fence: define exactly which systems and data each agent may touch for each purpose (DPP1).
--- 2. Be transparent: disclose agent use in Personal Information Collection Statements and Privacy Policy Statements (DPP1 and DPP5).
--- 5. Limit purpose: state what each agent processes data for, and when human oversight is required (DPP3).
--- 7. Uphold access and correction rights: choose systems built on privacy-by-design so data requests can still be fulfilled (DPP6).
Technology and security (CIO or CISO)
--- 3. Ensure accuracy: use human review and context-specific tuning to reduce hallucinated personal data (DPP2).
--- 4. Set retention periods: erase personal data held in conversation history, cache and long-term memory on schedule (DPP2).
--- 6. Secure the system: use official versions, vet plugins, grant least-privilege access, apply guardrails and keep audit trails (DPP4).
Risk and governance (COO or Chief Risk Officer)
--- 8. Assess continuously: test before deployment, monitor during use and keep a human in the loop for decisions with significant impact on individuals.
--- 9. Assign responsibility and train: resource a governance structure, bind vendors contractually and train every relevant employee.
How should enterprises apply the guidance across the agent lifecycle?
Enterprises should apply the guidance through its five-stage Security Checklist: evaluation, preparation, deployment, use and cessation of use. Each stage has a gate. An agent should not move to the next stage until its owner can show the controls for the current stage are in place and documented.
Consider a property management group deploying an agent to triage tenant emails and log repair tickets.
--- Evaluation: the team confirms the agent comes from an official source and checks whether the vendor trains models on customer data.
--- Preparation: the agent gets read access to one shared mailbox and write access to the ticketing system only. It has no access to the finance drive or HR files.
--- Deployment: it runs in a segregated environment with network controls, and only whitelisted plugins are installed.
--- Use: any message involving rent arrears or legal notices is routed to a human before action. Logs are reviewed weekly.
--- Cessation: when the pilot ends, credentials are revoked and memory, cache and logs containing tenant data are deleted on a documented schedule.
A financial services firm would apply the same stages with tighter thresholds. It would add HKMA and SFC expectations on outsourcing and model risk on top of the PCPD baseline.
Who is accountable when an AI agent mishandles personal data?
Your organisation is accountable. The guidance states plainly that AI agents are not legal persons. Under the PDPO, the data user that controls the collection, holding, processing or use of personal data stays responsible, however autonomous the agent is and whichever vendor supplied it.
Reed Smith's client alert recommends mapping controller and processor roles across the whole agent supply chain. That includes model providers, agent platforms, plugin developers and connected servers, with each role written into the service agreement.
Cross-boundary groups face a second layer. Mainland China's regime is more prescriptive and moving towards mandatory filing. Reed Smith advises treating the mainland standard as the baseline and adding Hong Kong PDPO requirements on top.
Accountability also has an internal dimension: someone has to know which agents exist. A September 2026 industry survey reported by GlobeNewswire found that 96.4% of IT decision-makers believed they had a complete agent inventory. Yet 66.7% of organisations with agents had experienced an agent-related operational consequence in the previous 12 months. Confidence is not the same as visibility.
What mistakes do enterprises make when governing AI agents?
The most common mistake is treating agents as another chatbot and extending the existing generative AI policy. Other frequent errors include granting broad credentials for speed, ignoring plugins, forgetting about memory and cache retention, and leaving shadow agents installed by individual staff off the register entirely.
--- Policy copy-paste: a policy that says "do not paste client data into AI tools" means nothing for an agent that reads client data directly from your systems.
--- Admin rights for convenience: pilots often run on a senior user's full account. That one shortcut fails recommendation 6 completely.
--- Unvetted skills: open-source agent tools such as OpenClaw spread quickly in Hong Kong this year. Their plugin ecosystems are where the PCPD sees the highest takeover risk.
--- No exit plan: pilots end, but credentials, memory stores and logs often remain live for months.
--- Shadow agents: without a register and a clear prohibition, employees install desktop agents that never appear in any risk assessment.
How should leaders present agentic AI governance to the board?
Present it as a short accountability report, not a technology update. Boards need four things: an inventory of agents and their access, the status of each against the nine recommendations, open risks with named owners, and a decision request. Keep it to one page and refresh it every quarter.
A workable format looks like this:
--- Inventory: number of agents in production and pilot, systems each can access, and whether personal data is involved.
--- Control status: a red, amber or green rating against each of the nine PCPD recommendations.
--- Incidents and near misses: anything an agent did that a human had to reverse.
--- Decision required: for example, approval to block unregistered agents on corporate devices.
This also answers the PCPD finding that board-level AI discussion fell by about 25 points in 2026. A director who has seen this page each quarter can show that oversight existed if a regulator ever asks.
Conclusion: governance is what lets agents scale
The PCPD has not banned anything. It has described, in nine recommendations and a five-stage checklist, what responsible agent deployment looks like in Hong Kong. Organisations that build these controls now can expand agents with confidence. Those that do not will slow down at the first incident.
If you want a starting point for the wider governance picture, our explainer on AI agent identity and access governance covers how to control what each agent can reach.
We understand the cold edges of AI and the hard parts of your work, and UD has walked with Hong Kong enterprises for twenty-eight years, making technology a partnership with warmth.
Now that you have the framework, the next step is knowing where your organisation actually stands. We'll walk you through every step, from AI readiness assessment and agent inventory to control design, deployment and ongoing review.
Reviewed by the UD enterprise AI team. This article summarises public guidance and is not legal advice. Consult qualified counsel on your specific obligations.