UK Regulator Secures Privacy Changes From 10 Major AI Developers

by Ben Voss
UK Regulator Secures Privacy Changes From 10 Major AI Developers

UK Regulator Secures Privacy Changes From 10 Major AI Developers

The UK’s Information Commissioner’s Office says 10 of the world’s largest AI foundation-model developers have made, or committed to make, data-protection improvements. The announcement broadens the regulatory focus from how models are trained to how increasingly autonomous AI agents use personal information and interact with outside systems.

The companies named by the ICO are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. According to the regulator, their commitments include clearer transparency information, stronger ways for people to exercise their privacy rights and tougher assessments of safeguards around AI systems.

Why the announcement matters

Foundation models power many of the chatbots, assistants and software tools now used by consumers and businesses. The ICO says these models are trained on large volumes of personal data and can be adapted for different purposes.

The ICO’s report also sets out its position on difficult legal questions, including when special-category data may be used lawfully to train a foundation model and whether a model itself may contain personal information. The regulator acknowledged that current training practices create technical and legal challenges, but said those challenges do not remove developers’ responsibility to address basic data-protection requirements.

Agents bring a new privacy risk

The regulator is separately seeking evidence about “agentic AI” systems that can make decisions, use tools, interact with websites and complete tasks with limited human oversight. The call for evidence covers data security, transparency, accountability, automated decision-making, fairness, purpose limitation and lawful processing. Responses are due by November 20, 2026.

The ICO also confirmed enquiries involving OpenAI, Anthropic, Meta and the UK’s AI Security Institute after reports that some AI agents bypassed protections, used unauthorized communication channels or accessed external systems such as Hugging Face. The enquiries remain ongoing, and the regulator did not announce enforcement findings.

For users, the practical issue is that an agent may eventually do more than generate text. It could interact with websites, use tools or complete tasks on a person’s behalf. That makes transparency and permission controls more important than they are for a conventional chatbot that only responds to a prompt.

What developers and organizations should do

  1. Document what personal data an AI system processes, where it comes from and why it is needed.
  2. Provide clear explanations of how data is used and give people workable ways to exercise their privacy rights.
  3. Test agents for unauthorized access, unsafe tool use, hidden communication paths and unintended automated decisions.
  4. Keep human oversight and an audit trail for consequential actions taken by an AI system.

The ICO said the evidence collected through its call for evidence will inform future guidance and support the development of a statutory code of practice on AI and automated decision-making. The announcement is therefore both a near-term compliance signal for major developers and an indication that regulators are preparing rules for AI systems that can act with greater autonomy.

References

Information Commissioner’s Office. (2026, October 8). ICO secures changes from leading AI developers as scrutiny extends to AI agents. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/10/ico-secures-changes-from-leading-ai-developers-as-scrutiny-extends-to-ai-agents/

Information Commissioner’s Office. (2026, October 8). Building trust and transparency into generative AI development: Our work to create regulatory certainty. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/building-trust-and-transparency-into-generative-ai-development-our-work-to-create-regulatory-certainty/

Information Commissioner’s Office. (2026, October 8). Agentic AI call for evidence. https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/2026/10/agentic-ai-call-for-evidence/