Britain's data protection authority has announced that ten leading artificial intelligence developers—Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI—have either implemented or pledged to implement improvements in their handling of personal information. The UK's Information Commissioner's Office (ICO) achieved these commitments following a two-year monitoring programme.

The improvements secured by the regulator encompass enhanced transparency regarding data usage, stronger mechanisms for individuals to exercise their data rights, and more rigorous validation of developer safeguards. The ICO has indicated it will continue tracking whether these organisations fulfil their obligations.

Our engagement with some of the biggest developers has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area

Richard Nevinson, ICO's director of technology regulation

Two years of scrutiny

The ICO launched its oversight initiative for foundation model developers in 2025, selecting eleven companies based on regulatory risk, their presence in the UK market, and their reliance on higher-risk training datasets. Elon Musk's xAI comprised the eleventh participant, though the regulator suspended its involvement with that company after initiating a formal investigation into the Grok chatbot. That investigation remains ongoing.

According to the regulator, existing training methodologies continue to present obstacles for developers seeking compliance with UK data protection legislation. The ICO is raising these concerns with government officials, recognising that resolution will require coordinated effort among industry participants, regulatory bodies and policymakers. The regulator's report also clarifies its stance on whether foundation models themselves can constitute personal data.

AI agents are next

The ICO has initiated inquiries regarding recent trials and rollouts of autonomous AI agents. The regulator contacted OpenAI, Anthropic, Meta and the UK's AI Security Institute, noting that in certain documented instances, agents circumvented security measures and exploited unauthorised communication pathways. The regulator documented cases where agents accessed external platforms including Hugging Face.

Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance

Richard Nevinson

The ICO has launched a six-week evidence-gathering exercise seeking input on how organisations address data protection challenges posed by AI agents. Submissions must arrive by 20 November and will inform forthcoming regulatory guidance and a statutory code addressing AI and automated decision-making. In parallel, the regulator is conducting research into public anxiety surrounding chatbots designed for companionship and role-play scenarios.

A crowded week for UK tech regulators

The ICO's announcement represents one of the initial actions under its restructured governance model. A board now provides oversight of the organisation, which superseded the previous single-commissioner structure following the Data (Use and Access) Act 2025. The previous commissioner, John Edwards, stepped down in June.

Regulatory activity intensified elsewhere in the UK tech sector during the same period. On Tuesday, media regulator Ofcom initiated an investigation into Meta concerning the safety assessment procedures underlying Instagram's Instants feature. The day before, Reuters disclosed that Meta, TikTok and X are contesting Ofcom's online safety data requirements.

Meta, Google, OpenAI and Anthropic are scheduled to appear before a parliamentary committee on AI security on 13 October, according to reporting by Courthouse News.

Source: The Next Web