Tel +852 5382 0328 info@safeharbour.hk WhatsApp 繁體中文
Safe Harbour Consultants · Hong Kong & Macau Get a Quote
AI governance

The PCPD's guidance on agentic AI: what it asks you to control

Published on 25 August 2026, the guidance addresses AI agents rather than chatbots — systems that take actions, reach into other tools, and hold permissions. That changes the control question.

A chatbot answers. An agent acts. Once a system can send an email, query a database, or call another service, the governance question stops being about the model's output and becomes about the permissions it holds.

What the guidance recommends

  • Grant the minimum access the agent needs, and no more.
  • Scrutinise plugins and connected tools as third-party suppliers.
  • Set retention limits on what the agent stores and logs.
  • Assess continuously, not once at deployment.
  • Keep a human in the loop for consequential actions.
  • Assign named governance responsibility.

What this means for you

Most organisations have a generative AI policy by now. Very few have an agent register: which agents exist, what tools they can call, what data they can reach, and who approved each one. That register is what the guidance is pointing at.

Where to start

Add an agent column to the AI inventory you already keep — autonomy level, tools, data scope, owner, and last review date. It is an afternoon of work and it answers the question before it is asked.

Sources
PCPD, Protecting Personal Data Privacy in the Use of Agentic AI, 25 August 2026 — pcpd.org.hk
PCPD, compliance checks on 60 organisations regarding AI and personal data, 19 May 2026 — pcpd.org.hk