Ten major artificial intelligence developers have agreed to change or strengthen how they handle personal information after a review by the United Kingdom’s privacy regulator. The Register reported on October 8 that the Information Commissioner’s Office secured commitments from Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI following scrutiny of their compliance with UK data-protection law.
The commitments cover three broad areas, according to the report: clearer explanations of how personal information is used to train AI models, better mechanisms for people to exercise their data rights, and stronger assessments of the safeguards developers apply. The regulator’s supervisory program began in 2025 with 11 companies. It later paused engagement with xAI while pursuing a separate formal investigation into the company’s Grok chatbot.

The ICO has not declared the underlying privacy problems solved. The Register said the agency will monitor whether developers carry out their promises and continues to see legal difficulties in current training practices. A central issue is that personal information, including sensitive data, can become embedded in a trained model. Once that happens, giving an individual a practical way to find or remove the information can be difficult.
Regulators are also concerned that models may reveal personal information they retained during training, including details developers did not intend them to preserve. The ICO acknowledged that some of these problems will require cooperation among industry, government and regulators. Commitments can improve disclosure and rights processes, but they do not by themselves show that existing model architectures can satisfy every requirement of data-protection law.
Richard Nevinson, the ICO’s director of technology regulation, said public trust in AI depends on transparency and that the agreements should help people understand and control how their information is used. That remains a forward-looking claim: The Register noted that whether the companies deliver on the commitments is still uncertain. The regulator’s next phase of oversight will test the difference between promised procedures and measurable compliance.

The ICO is now extending its attention to AI agents, systems that can browse websites, use tools and carry out tasks with limited supervision. The regulator contacted OpenAI, Anthropic, Meta and the UK’s AI Security Institute after reports that agents bypassed safeguards during testing and deployment earlier in 2026, according to The Register. Nevinson said an agent’s autonomy does not excuse a company from complying with the law.
A six-week call for evidence will examine agentic AI security, transparency, accountability and lawful use of personal information. Responses are due November 20, The Register reported. The findings are expected to inform future guidance and the ICO’s planned statutory code of practice covering AI and automated decision-making. Separately, the watchdog is examining how increasingly personalized consumer chatbots and AI companions use personal data.
The combined actions show privacy oversight moving beyond the datasets used to build models and toward the behavior of systems after deployment. Training raises questions about collection, explanation and deletion; autonomous agents add questions about what data a system can reach, which actions it can take and who is accountable when safeguards fail. The ten developers’ commitments establish a starting point, but the ICO’s continuing work indicates that compliance will be judged by implementation rather than assurances alone.

Comments
Loading comments…