AI agent development in the United Kingdom

AI agent development for UK businesses, with the data path written down

Autonomous agents built for UK teams, deployed on infrastructure you control — and an explicit account of which component leaves that infrastructure, because under UK GDPR that is the part your DPO will ask about.

Get my free blueprint

Can a UK business run AI agents without sending data abroad?

Running the agent runtime on UK infrastructure keeps the orchestration, the logs and the memory store in the UK, but the model call is a separate decision: a hosted LLM API sends the prompt to wherever that provider processes it. Avoiding a transfer altogether requires a model hosted in the UK or EEA, or prompts that carry no personal data.

UK GDPR restricts international transfers rather than requiring UK storage — the safeguard matters more than the postcode, and the ICO regulates both.

UK buyers rarely open with "what can an agent automate". They open with where the data goes, who the processor is, and whether anything crosses a border — because the answer determines how long procurement takes. So this page is about the data path rather than the feature list.

One correction first, because it shapes everything below: UK GDPR does not require personal data to be stored in the United Kingdom. It restricts transfers out of the UK unless a safeguard applies. "Data residency" is therefore a commercial and risk-appetite term, not a statutory one, and treating it as a legal requirement leads teams to over-build in one place while ignoring the one component that actually leaves the country.

Self-hosted AI agents UK data residency

An agent deployment has four places data can rest or travel, and self-hosting only settles three of them:

If personal data must not leave the UK at all, the model has to run locally too — an open-weights model on your own GPU or a UK-hosted inference provider — and that constraint should be priced into the design at the start rather than discovered at the security review. The alternative, which is legitimate and more common, is to transfer under a safeguard: adequacy regulations where they apply, the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, backed by a transfer risk assessment. For US providers certified under it, the UK extension to the EU–US Data Privacy Framework is the other route.

A third option is frequently overlooked: keep the transfer but remove the personal data from it. Pseudonymising identifiers before the prompt is assembled, and passing record keys the model never resolves, turns a restricted transfer into an ordinary API call. It costs design effort and it constrains what the agent can say back to you — which is exactly the trade-off worth arguing about in a design review.

Which components leave the machine, on a fleet we actually run

Which components leave the machine, on a fleet we actually run — observed on Our own production host — a 19-agent Hermes fleet on one Fedora 42 VPS (4 vCPU / 15 GiB), surveyed read-only over SSH, 27 July 2026
Agent runtimesystemd units on one Fedora 42 host, no container platformself-hosted
State and logsPostgreSQL and Valkey, local to the machineon host
Operations dashboardbound to port 9119, reachable from 3 tailnet nodestailnet only
Model inferenceOpenRouter free tier plus opencode-zen — this is the hop that leavesthird-party API
Edge and hardeningno public dashboard exposureCaddy + fail2ban

Source: Our own production host — a 19-agent Hermes fleet on one Fedora 42 VPS (4 vCPU / 15 GiB), surveyed read-only over SSH. Observed .Our host is our own infrastructure, not a UK client's, and it is not offered as evidence of UK residency. The point these rows make is architectural: in a self-hosted deployment the model call is the component that crosses a border, and it is the one to design around.

What UK GDPR asks for that self-hosting will never provide

Self-hosting is an engineering control. Most of what the Information Commissioner's Office expects is documentation, and no deployment topology produces it for you:

Why hosted agent platforms complicate this

A managed platform adds at least one processor, often several, and the transfer analysis then depends on the platform's sub-processor list rather than your own architecture. That is a real trade-off, not a disqualification — it buys speed —the comparison of no-code AI agent platformssets out where that speed is worth the added data path, and where a self-hosted framework such as one of the open CrewAI alternativeskeeps the analysis inside one boundary.

The data path, component by component

What a UK deployment specifies before any code is written

Runtime location

Which machine, in which country, under whose account. Named in the scope, not implied by a marketing phrase about self-hosting.

Model and endpoint

Which model, at which endpoint, in which region, under whose API key — and whether an open-weights local model is required to avoid the transfer entirely.

Prompt contents

Exactly which fields are allowed to enter a prompt. Pseudonymisation before assembly is a design decision, and it is cheaper before the build than after.

State retention

How long memory, run logs and intermediate artefacts are kept, and the deletion path when a data subject exercises their rights.

Vendor access

Whether the studio holds credentials after handover, through which channel, and what the Article 28 terms say about it. Ours is tailnet-scoped by default.

Human approval gates

Which actions never execute unattended. Article 22 turns this from a preference into a design constraint for decisions about people.

What is identical to a build anywhere else

The jurisdiction changes the paperwork and the data path. It does not change the engineering, and claiming otherwise would be an invention:

If a supplier tells you their agent architecture is fundamentally different because you are in the UK, ask which component changed. The honest answer is the model endpoint and the contracts around it.

Questions

Does self-hosting keep UK personal data inside the UK?

It keeps the parts you host inside the UK: the agent runtime, the task queue, the logs and the memory store. It does not cover the model call. If the agent sends a prompt to a hosted LLM API, that prompt travels to wherever the provider processes it, and under UK GDPR that is a restricted transfer that needs its own safeguard.

Who is the controller and who is the processor when a vendor builds our agent?

Normally the client is the controller, because the client decides why the agent processes personal data and what it does with the results. A studio with access to the running system acts as a processor for that access, which requires an Article 28 contract covering scope, instructions, sub-processors, security and deletion. Model providers usually sit behind that as sub-processors.

Does an AI agent deployment need a DPIA?

Often, yes. Article 35 of UK GDPR requires a data protection impact assessment where processing is likely to result in a high risk to individuals, and the ICO treats innovative technology and large-scale profiling as triggers. An agent that scores people, monitors behaviour, or processes special-category data is squarely in that territory; a scheduled report-builder over internal metrics usually is not.

What does the ICO expect a business to be able to show about an AI agent?

The documentation trail, not the model weights. That means the lawful basis for the processing, the Article 30 record of processing activities, the DPIA where one is required, the Article 28 contracts covering every processor and sub-processor, the transfer safeguards for anything leaving the UK, and evidence that the security measures under Article 32 are real.

Can an AI agent make decisions about people without a human in the loop?

Only within limits. Article 22 of UK GDPR gives individuals the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, unless a listed condition applies, and even then safeguards including human intervention are required. In practice this is why high-impact steps sit behind an approval gate rather than running unattended.

Can UK clients keep an agent running on a provider that is not a US hyperscaler?

Yes. The agent runtime is ordinary server software: it runs on a UK or EEA VPS, on an on-premises machine, or inside an existing private cloud. Our own fleet runs as systemd units on a single host with no container platform underneath, which is deliberately boring infrastructure that any competent sysadmin can take over.

Get your UK agent blueprint — free.

Tell us the workflow and the data it touches. You get a written scope naming the runtime location, the model endpoint, the fields allowed into a prompt, and the retention period — before anything is built.

Goes straight to hello@iamagentman.com — we read every message ourselves. Prefer to answer three questions instead?Build your blueprint.

Talk to the studio

One message · reply within one business day