UK Privacy Regulator Secures Changes From 10 Major AI Developers, Expands Scrutiny to AI Agents
Key Takeaways
- Ten AI Developers Commit to Data Protection Improvements: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI have made or committed to changes following ICO scrutiny.
- Transparency and Privacy Safeguards Strengthened: The improvements address clearer information about personal data use, stronger mechanisms for exercising individual rights and more rigorous assessments of safeguards.
- ICO Expands Scrutiny to Autonomous AI Agents: The regulator has launched a six-week call for evidence examining how organizations manage data protection risks associated with agentic AI.
- Major AI Companies Face Regulatory Enquiries: The ICO has made enquiries involving OpenAI, Anthropic, Meta and the UK's AI Security Institute following reports of agents bypassing protections and accessing external systems.
- Further AI Guidance in Development: The findings will inform future regulatory guidance and the ICO's forthcoming statutory code of practice on AI and automated decision-making.
Deep Dive
The UK's Information Commissioner's Office (ICO) has said that Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI had agreed to improvements involving transparency, individual information rights and the assessment of data protection safeguards. Some companies have already made changes, while others have committed to doing so. The ICO said it would continue monitoring their progress.
The findings were published in a report examining the development of foundation models, the large AI systems underlying many commercial chatbots and digital assistants. These models are trained on substantial quantities of information, including personal data, raising questions about how developers comply with UK data protection law.
The ICO's report addresses several of those questions, including the circumstances in which developers can lawfully use special category data and whether foundation models themselves may contain personal information.
The regulator acknowledged that existing approaches to training foundation models present technical difficulties for compliance with data protection requirements, particularly the obligation to incorporate privacy protections into the design of systems.
It has raised these issues with the UK government and said further cooperation between industry, regulators and policymakers will be necessary as the technology develops.
Richard Nevinson, the ICO's director of technology regulation, said the regulator's engagement with developers had produced commitments intended to give individuals greater understanding and control over the use of their information.
"Our engagement with some of the biggest developers has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area," Nevinson said.
The report, Building Trust and Transparency Into Generative AI Development: Our Work to Create Regulatory Certainty, sets out the ICO's regulatory positions on several questions surrounding foundation model development. It also acknowledges that some difficulties in applying existing data protection requirements remain unresolved.
ICO Opens Examination of Autonomous AI Agents
The ICO is extending its scrutiny to AI agents, systems capable of completing tasks, operating tools and interacting with websites and other services with limited human supervision. On Thursday, the regulator launched a six-week call for evidence seeking information from developers, organizations deploying AI systems and other experts about how they manage the data protection risks associated with agentic AI.
The announcement follows enquiries involving OpenAI, Anthropic, Meta and the UK's AI Security Institute concerning AI agent testing and deployment earlier this year.
The ICO said reports that certain agents had bypassed protections, used unauthorized communication channels and accessed external systems, including Hugging Face, raised concerns about safeguards, accountability and oversight. The regulator did not announce findings of data protection violations arising from those reports or disclose the outcome of its enquiries.
The reported incidents have prompted questions about how organizations control systems capable of acting independently, particularly when those systems can communicate with external services or access information beyond their immediate operating environment. Nevinson warned that companies could not rely on the autonomy of AI agents to excuse failures to meet their legal obligations.
"These recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren't fit for purpose," he said. "Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance. If people are to trust AI innovation, they rightly expect to know how their personal information is being protected."
The ICO said evidence gathered through the consultation would inform future guidance on agentic AI and contribute to its forthcoming statutory code of practice on AI and automated decision-making. The regulator is also examining the increasing personalization of consumer-facing AI services, including general-purpose chatbots and products designed for role-play or companionship.
It is conducting research with the public to better understand concerns about these services and engaging with companies over the transparency and privacy protections incorporated into their products. The work forms part of the ICO's broader regulatory priority of promoting trust and transparency in artificial intelligence, an objective reflected in its proposed corporate strategy, which recently underwent public consultation.
The regulator has not announced additional enforcement action against the ten foundation model developers or the organizations involved in its agentic AI enquiries. Its immediate work will focus on monitoring the commitments already secured, gathering evidence about autonomous systems and developing further guidance on how existing data protection obligations apply to their use.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.


