Here’s the scenario: in a checkout, a support queue, or an internal ops tool, an agent somewhere is filling in a UK address on someone's behalf, and it will produce an address that looks right.
Before you ship that workflow, you might think the only check you need to do is see whether the address seems okay, but you really need to ask where the address came from and whether you’re even allowed to use it.
There's no shortage of guides on wiring an address lookup into an agent, and the mechanics really are straightforward: an API key and a tool definition. The part that doesn't get covered much is the licensing question buried underneath, and in October 2025 the High Court ruled that a competing address lookup service in the UK had been built on Royal Mail's address file without the licence it needed (more on that judgement below).
A model will always give you an address
Ask any language model for a full UK address, and it will give you one because that's what generative models do. There’s no "that postcode doesn't exist" state, only a most-likely-next-token state.
UK postcodes can make matters worse because the format is trivial to imitate. SW1A 1AA and SW1A 1AZ are both structurally valid, and a regex passes both, but knowing which one is real requires the actual file.
So an agent working from a model's own knowledge produces addresses that are correctly formatted, confidently delivered, but also occasionally attached to a property that’s never existed. Once that address lands on a parcel label, a KYC record, or a policy schedule, nothing downstream will flag it because nothing downstream is checking for errors.
Three places an agent can get a UK address, and only one is the file
- The model's own internal parameters. No provenance, frozen at a training cutoff, and nothing to audit. Fine for drafting prose, not for writing to a database.
- A general geocoding or maps API. Real data, but built on a global schema that assumes a house number and a street. UK flats, sub-premises and house names are where that thins out, which we've written about before.
- A licensed source of Royal Mail's Postcode Address File. Around 32 million delivery addresses across 1.8 million postcodes, and the file on which UK delivery actually runs.
Only the third is authoritative for UK post, and it's also the only one that comes with a licence chain you can cite when somebody asks.
What the High Court said about address data in October 2025
In IDDQD Ltd v Codeberry Ltd & Smith and Royal Mail Group Ltd v Codeberry Ltd & Smith 2025, the court found that the operator of a competing address lookup service in the UK had infringed the database rights and copyright of Royal Mail and another PAF licensee.
Three findings are significant if you're building with agents.
- First, scale is not a defence. The court accepted that around 5.3% of the licensee's database had been copied and held that this still amounted to a substantial part.
- Second, and more directly relevant: downloading data temporarily, even to verify or cleanse it, was treated as extraction. The court looked at what was actually done with the data rather than the label attached to it, and the analysis published by Fieldfisher plainly makes the point that "just checking, consulting, or cleaning" is not a good enough defence.
- Third, the exposure was personal. The director was held jointly liable alongside the company, and the court awarded additional damages.
The commercial consequence arrived a few months later when service ceased operations, and every business that had integrated it into a checkout or a sign-up form lost address lookup that afternoon.
An agent touches address data in more ways than a form does
A web form makes one call, reads one result, and writes it to one record – a well-understood function, and PAF licensing was written with this in mind.
An agent offers different functions: it may hold tool results in a context window, cache responses between steps, write them into a vector store or a memory layer, fan out speculative calls it never uses, or run on a third-party platform acting on your behalf.
Royal Mail's End User Terms already have wording that bears on most of that.
- They restrict copies of PAF data.
- They define data extraction and say extracted data must not be supplied or made accessible to any third party.
- They specify when a subcontractor may use the data on your behalf, while you remain responsible for any breaches they commit.
- They define a "user" as an individual authorised to use the solution – this definition was established before any autonomous systems were making the calls.
Four questions to put to your address provider first
- Are you a Royal Mail PAF Solutions Provider, and can you say so on the record? A yes you can point to is the whole exercise.
- What do your terms say about caching or persisting responses? Agents cache by default. Find out where that sits before your framework decides for you.
- Who is the end user in the chain, and what am I agreeing to on someone's behalf? Particularly if you're building this into a product other businesses use.
- How do you handle speculative or high-volume calls? An agent exploring options can burn through a month's lookups in an afternoon.
You don't need an MCP server to do this properly
An agent doesn't need a bespoke protocol to call an address API. It needs a tool definition, and an OpenAPI spec is already one.
AddressBrain is a plain REST API with a published OpenAPI spec and a bearer token. Any agent framework that can read an OpenAPI document can register the lookup as a tool and call it, with no SDK, no OAuth handshake, and no sales call to get a key.
The fundamental architectural choice is about validation. Ensure your agent writes back the exact address returned by the API call, not a version regenerated by the LLM. You must ground the write action alongside the read; otherwise, having an agent perform a lookup only to rewrite the output completely defeats the purpose of validation.
Where AddressBrain sits
We're officially licensed via Royal Mail PAF, which means the licensing question sits with us rather than something you inherit and hope about. Lookups return structured, PAF-formatted fields, so your agent gets a real address it can write to a record rather than a string it has to parse.
If you'd like to test that inside an agent workflow, start on the free trial: 30 lookups a day for 30 days with no card required, or go straight to the developer docs.
