
Amazon, Google, Microsoft, OpenAI and six others agree to changes, but the ICO isn't done asking questions
Ten of the world's biggest AI developers have agreed to tighten their handling of personal data following scrutiny by Britain's privacy watchdog, which is now turning its attention to autonomous AI agents that don't always play by the rules.
The recently rebranded Information Commission's Office (ICO) said Thursday that Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI have either made changes or committed to doing so after the regulator examined their compliance with UK data protection law.
These include clearer explanations of how personal information is used to train AI models, better ways for people to exercise their data rights, and tougher assessments of developers' safeguards.
The commitments follow a supervisory program launched in 2025 that initially covered 11 developers. That number dropped to ten after the ICO paused its engagement with Elon Musk's xAI to pursue a separate formal investigation into its Grok chatbot.
The watchdog isn't declaring victory just yet. It's monitoring whether developers deliver on their promises and admits that current AI training practices still pose problems under UK data protection law.
Developers still have some explaining to do over personal data buried in their models, particularly sensitive information, and how people are supposed to get their details removed once an AI has been trained on them. There's also the risk of personal information being extracted from models, including data developers never intended them to retain.
The ICO acknowledged that some of these issues will require cooperation between industry, regulators, and government. Getting companies to promise changes is one thing. Making today's AI models comply with the law is another.
"AI has huge potential to benefit our society, but that depends on trust and transparency," said Richard Nevinson, the ICO's director of technology regulation. "Our engagement with some of the biggest developers has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area."
Meanwhile, the regulator is turning its attention to AI agents, which can browse websites, use tools, and carry out tasks with limited human supervision. And some aren't sticking to the rules.
The ICO confirmed it has contacted OpenAI, Anthropic, Meta, and the UK's AI Security Institute following reports of agents bypassing safeguards during testing and deployment earlier this year.
"These recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren't fit for purpose," Nevinson said. "Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance."
The regulator has also launched a six-week call for evidence on agentic AI, covering security, transparency, accountability, and the lawful use of personal data. Responses are due by November 20 and will inform future guidance and the ICO's forthcoming statutory code of practice on AI and automated decision-making.
The watchdog is separately examining how consumer chatbots and AI companions use personal information as they become increasingly personalized.
For now, the ICO has secured promises from some of the industry's biggest names, although whether they deliver remains to be seen. And with AI agents increasingly capable of acting on their own, the watchdog may have its work cut out keeping them in line. ®