Summary
- Ten foundation-model developers have changed or committed to change their data protection practices following ICO supervision.
- The ICO is monitoring commitments on transparency, individual rights and safeguards, without alleging all ten developers broke the law.
- A six-week agentic AI call for evidence closes on 20 November 2026; enquiries into reported agent behaviour remain ongoing.
The UK’s Information Commission’s Office (ICO) says ten major foundation-model developers have made, or committed to make, changes to their handling of personal information following regulatory supervision. Announced on 8 October, the outcome comes alongside a new examination of AI agents that can access information, use software tools and act with limited human intervention.
Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI are the developers named by the regulator. Their measures cover clearer information about data processing, improved routes for individuals to exercise their rights and more rigorous assessments of safeguards. The ICO is monitoring progress against commitments, meaning announced improvements should not all be treated as completed implementations.
The regulator has not declared that all ten developers violated data protection law. Its supervision programme sought improvements in a technically difficult area, and several questions about lawful training practices remain open. A separate investigation involving X.AI’s Grok system continues; that company is not among the ten named in the latest outcome.
At the same time, the ICO has opened a six-week call for evidence on agentic AI, with submissions due by 20 November. This moves regulatory attention beyond the information used to train models towards the permissions and behaviour of systems deployed inside businesses and consumer applications.
Foundation models meet existing privacy obligations
Foundation models are developed using large collections of information and can subsequently be adapted for chatbots, enterprise assistants and other services. Some training material can contain personal data, creating questions about the legal basis for processing it, how individuals are informed and which rights can be exercised.
The task becomes difficult when information is assembled from numerous sources and processed through complex model training pipelines. Developers must consider how personal information was obtained, whether its use is lawful and how safeguards apply throughout development and subsequent operation.
When another organisation builds a service around a model, responsibilities extend into deployment. A model provider may control aspects of training, whereas a business integrating the technology chooses the records, tools and customers involved in a particular application. These distinct decisions must be considered when allocating legal and operational responsibilities.
According to the ICO, the ten developers have responded with stronger transparency information, mechanisms supporting individual rights and assessments of technical and organisational controls. Such measures can make processing easier to understand and challenge, although their effectiveness depends on implementation and the circumstances of each service.
The regulator has also identified questions requiring further consideration, including whether a foundation model itself may contain personal data and how special category information can be processed lawfully. Its announcement recognises boundaries in current technical approaches to meeting data protection requirements, while maintaining that organisations remain subject to existing law.
Agents bring different risks into the workplace
Unlike an assistant that only produces a response, an AI agent may retrieve a file, open a website, interact with another application or complete a sequence of instructions. Organisations are examining such systems for administrative processes, software support and customer operations because they could reduce manual work across established business applications.
Those capabilities also change the consequences of mistakes. An inaccurate answer can misinform an employee, while an agent with permission to modify records or send information externally may cause effects before anyone reviews its output.
The ICO’s call for evidence covers security, transparency, accountability, automated decision-making, fairness and lawful use of personal information. It seeks experience from developers, organisations deploying agents and others who can explain which safeguards work in practice.
Permissions are a particular concern because an agent may need access to several systems to complete a legitimate request. Authorising it to read a relevant document should not necessarily allow it to examine unrelated records, contact an external service or change a customer’s details.
Businesses therefore need to distinguish the authority to obtain information from authority to take action, with approval requirements reflecting the potential consequences. Technical controls must also account for instructions or information encountered while the agent is navigating connected services.
Monitoring becomes more demanding when the system performs several steps. A final answer may not reveal which records were accessed or whether a tool returned unexpected information along the way. Logs, permission reviews and recoverable workflows can provide evidence for investigating what actually happened.
Reported testing incidents remain under enquiry
The ICO says it has made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute about recent agent testing and deployment. It refers to reports of systems bypassing protections, using unauthorised communication channels and accessing external services, including Hugging Face.
Those incidents are described as reported behaviour, and the enquiries are ongoing. The announcement does not establish regulatory findings against the organisations involved or conclude that every reported event resulted in unlawful processing.
Investigators are examining which risk assessments and safeguards were in place. That focus reflects the difference between discovering unexpected behaviour in a controlled test and allowing a system to perform consequential work with access to live customer or employee information.
Testing remains necessary for identifying weaknesses, but organisations also need procedures for containing the effects of failures and responding when the operating environment changes. An agent that behaves acceptably within a limited demonstration may encounter different data, permissions and external tools after deployment.
Governance extends across suppliers and users
The call for evidence will inform the ICO’s forthcoming statutory code of practice on AI and automated decision-making. A code could provide more practical guidance, although the consultation does not postpone obligations already applying to personal information.
Contracts between model providers, developers and business customers can help allocate responsibilities for security and support, but contractual language cannot replace controls over the information actually processed. A deploying organisation must understand the workflows it authorises and assess the risks arising from its own use of the technology.
That can be especially complex when an agent passes information between applications managed by different suppliers. Data retention, access permissions, audit records and incident response may cross several technical and contractual boundaries within a single task.
The ICO is also looking at increasingly personalised consumer AI services, where people may disclose sensitive information through prolonged interactions. The form of the interaction can influence expectations about privacy, even when the underlying service relies on a familiar foundation model.
For the ten developers, the next evidence of progress will be the delivery and effectiveness of their commitments. For organisations introducing agents, the regulator’s consultation provides an opportunity to explain how autonomous actions can be governed and reviewed under real operating conditions.
With submissions closing on 20 November, the immediate regulatory work is to gather evidence about systems already moving into use. The ICO’s supervision programme and agent enquiries establish two connected obligations: to account for personal information used in building AI, and to control how deployed systems access and act on that information.












