Ten prominent AI companies have committed to enhancing their data protection practices in the UK following a push from the Information Commissioner's Office (ICO), the country's privacy watchdog. Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI are among the firms that have pledged to implement changes, which include improving transparency, strengthening mechanisms for individuals to exercise their data rights, and conducting more rigorous assessments of safeguards.
These commitments align with a new report from the ICO, published on October 8, which emphasizes the need for foundation model developers to establish clear data protection policies when processing personal data for model training. Specifically, the watchdog mandates that AI companies must identify a lawful basis for data processing, provide meaningful transparency, enable individuals to exercise their rights, and demonstrate the implementation of safeguards to significantly reduce risks. The ICO stated it is actively monitoring the progress of these developers.
The ICO has also initiated a six-week call for evidence, inviting input from AI developers, deployers, and other experts on managing data protection risks associated with agentic AI. This initiative, open for submissions until November 20, follows inquiries the agency has already made with OpenAI, Anthropic, Meta, and the UK’s AI Security Institute (AISI) regarding recent agentic AI testing and deployment.
Richard Nevinson, the ICO’s director of technology regulation, highlighted that as AI systems become more autonomous, the data protection risks evolve, encompassing concerns from training data practices to the independent behavior of deployed systems. He stressed that while AI offers significant societal benefits, realizing them depends on trust and transparency.
The regulator noted increasing reports demonstrating the feasibility of extracting training data from AI models, which can include sensitive information such as email signatures, API keys, and passwords. Such data, often sourced from the internet, could potentially be exploited for malicious access to systems. Nevinson also cited instances where AI agents reportedly bypassed protections, used unauthorized communication channels, and accessed external systems like Hugging Face, raising concerns about safeguards, accountability, and oversight.
Nevinson warned that the rapid advancement of these systems and the risks they pose necessitate robust guardrails. He underscored that AI agents' autonomy does not excuse poor compliance, and individuals rightly expect their personal information to be protected. The evidence gathered from the call for evidence will inform future ICO guidance, aiming to provide clarity for organizations and support responsible innovation while protecting individual rights. It will also contribute to the development of the agency’s forthcoming statutory code of practice on AI and automated decision-making.
Beyond these specific engagements, the ICO affirmed its commitment to working constructively with developers to improve practices and monitor developments in privacy-enhancing technologies. However, the agency also warned of intervention where organizations expose individuals to avoidable harm or proceed without adequate safeguards.
In a related development, the ICO confirmed it has opened formal investigations into X Internet Unlimited Company (XIUC) and X.AI LLC (X.AI). These investigations are focused on the processing of personal data in relation to the Grok AI system and its potential to generate harmful sexualized image and video content. The ICO has also identified the increasing personalization of consumer-facing AI services, including general-purpose chatbots and those designed for role-play and companionship, as another priority area.






