Ten of the biggest AI developers have made, or committed to make, changes to how they handle personal data. The UK’s Information Commissioner’s Office (ICO) secured the changes after two years of scrutiny. The data regulator named them on Thursday: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI.
The changes include clearer information on how people’s data is used. They also cover stronger ways to exercise data rights and tougher checks on developers’ safeguards. The ICO says it is monitoring whether the companies deliver.
“Our engagement with some of the biggest developers has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area,” said Richard Nevinson, the ICO’s director of technology regulation.
Two years of scrutiny
The ICO set up a programme to supervise foundation model developers in 2025. It chose 11 companies. The criteria were the risk of breaking the rules, UK market share and use of higher-risk training data.
Elon Musk’s xAI was the eleventh. The ICO paused that work after opening a formal investigation into xAI’s Grok chatbot. The investigation is still under way.
The regulator says current training practices still make it hard for developers to comply with UK data protection law. It is raising those problems with the government, because fixing them will need industry, regulators and ministers to work together. Its report also sets out its position on whether foundation models can themselves contain personal data.
AI agents are next
The ICO has made enquiries about recent tests and deployments of AI agents. It contacted OpenAI, Anthropic, Meta and the UK’s AI Security Institute. In some reported cases, agents bypassed protections and used unauthorised channels, the regulator says. Some reached external systems such as Hugging Face.
“Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance,” Nevinson said.
The ICO also opened a six-week call for evidence. It asks how organisations manage the data protection risks of AI agents. Responses are due by 20 November. They will feed into future guidance and a statutory code of practice on AI and automated decision-making. Separately, the regulator is researching public concerns about chatbots used for companionship and role-play.
A crowded week for UK tech regulators
The announcement is among the first from the ICO under its new structure. A board now oversees the office, which replaced a single Information Commissioner under the Data (Use and Access) Act 2025. The last commissioner, John Edwards, resigned in June.
On Tuesday, the media regulator Ofcom opened an investigation into Meta over the risk checks behind Instagram’s Instants feature. A day earlier, Reuters reported that Meta, TikTok and X were challenging Ofcom over online safety data.
On 13 October, Meta, Google, OpenAI and Anthropic are due before a committee of MPs on AI security. Courthouse News reported the hearing.
Get the TNW newsletter
Get the most important tech news in your inbox each week.