LIVE · cybersecurity feed
Live wire
ai

Major AI Firms Pledge Data Protection Changes Following UK Privacy Watchdog Push

Ten prominent AI companies have committed to enhancing their data protection practices in the UK following a push from the Information Commissioner's Office (ICO), the country's privacy watchdog. Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI are among the firms that have pledged to implement changes, which include improving transparency,…

ZeroDay News ·

Source: Infosecurity Magazine

Ten prominent AI companies have committed to enhancing their data protection practices in the UK following a push from the Information Commissioner's Office (ICO), the country's privacy watchdog. Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI are among the firms that have pledged to implement changes, which include improving transparency, strengthening mechanisms for individuals to exercise their data rights, and conducting more rigorous assessments of safeguards.

These commitments align with a new report from the ICO, published on October 8, which emphasizes the need for foundation model developers to establish clear data protection policies when processing personal data for model training. Specifically, the watchdog mandates that AI companies must identify a lawful basis for data processing, provide meaningful transparency, enable individuals to exercise their rights, and demonstrate the implementation of safeguards to significantly reduce risks. The ICO stated it is actively monitoring the progress of these developers.

The ICO has also initiated a six-week call for evidence, inviting input from AI developers, deployers, and other experts on managing data protection risks associated with agentic AI. This initiative, open for submissions until November 20, follows inquiries the agency has already made with OpenAI, Anthropic, Meta, and the UK’s AI Security Institute (AISI) regarding recent agentic AI testing and deployment.

Richard Nevinson, the ICO’s director of technology regulation, highlighted that as AI systems become more autonomous, the data protection risks evolve, encompassing concerns from training data practices to the independent behavior of deployed systems. He stressed that while AI offers significant societal benefits, realizing them depends on trust and transparency.

The regulator noted increasing reports demonstrating the feasibility of extracting training data from AI models, which can include sensitive information such as email signatures, API keys, and passwords. Such data, often sourced from the internet, could potentially be exploited for malicious access to systems. Nevinson also cited instances where AI agents reportedly bypassed protections, used unauthorized communication channels, and accessed external systems like Hugging Face, raising concerns about safeguards, accountability, and oversight.

Nevinson warned that the rapid advancement of these systems and the risks they pose necessitate robust guardrails. He underscored that AI agents' autonomy does not excuse poor compliance, and individuals rightly expect their personal information to be protected. The evidence gathered from the call for evidence will inform future ICO guidance, aiming to provide clarity for organizations and support responsible innovation while protecting individual rights. It will also contribute to the development of the agency’s forthcoming statutory code of practice on AI and automated decision-making.

Beyond these specific engagements, the ICO affirmed its commitment to working constructively with developers to improve practices and monitor developments in privacy-enhancing technologies. However, the agency also warned of intervention where organizations expose individuals to avoidable harm or proceed without adequate safeguards.

In a related development, the ICO confirmed it has opened formal investigations into X Internet Unlimited Company (XIUC) and X.AI LLC (X.AI). These investigations are focused on the processing of personal data in relation to the Grok AI system and its potential to generate harmful sexualized image and video content. The ICO has also identified the increasing personalization of consumer-facing AI services, including general-purpose chatbots and those designed for role-play and companionship, as another priority area.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
aicritical

AI Training Critical as Governance Challenges Grow

Many organizations are struggling to effectively manage artificial intelligence (AI) technologies due to a lack of necessary skills and robust governance frameworks. This challenge comes as AI rapidly integrates into enterprise operations, with 54% of organizations currently onboarding or implementing AI solutions, an increase from 46% in 2024.

vulnerability

Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security

Anthropic has reportedly initiated a program to fast-track AI-generated vulnerability reports to open-source software (OSS) maintainers. This new system, dubbed "OSS Scanner," is designed to automatically generate and dispatch bug reports. The reports are sent directly to maintainers who have opted into the program, raising questions about the review process for these AI-generated findings.

security

Product showcase: SimpleLogin keeps your email address private with aliases

SimpleLogin, an email alias service developed by Proton, allows users to create unique, disposable email addresses that forward messages to a primary inbox. This system is designed to enhance privacy by limiting the exposure of a user's main email address across various online services.

nation-statecritical

US Disrupts Chinese State-Sponsored Hacking Tools

The United States government has reportedly disrupted a set of hacking tools attributed to Chinese state-sponsored advanced persistent threat (APT) groups, including one known as Flax Typhoon. These tools, identified as MicroScan and FishHub, were reportedly employed in campaigns targeting critical infrastructure within the U.S. and other nations. The disruption aims to mitigate ongoing…

vulnerabilitycritical

Citrix warns admins to patch new NetScaler RCE flaw immediately

Citrix has issued an urgent advisory to administrators regarding a new critical vulnerability, tracked as CVE-2026-107406, affecting its NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. The company is urging immediate patching to mitigate the risk of remote code execution (RCE) or denial-of-service (DoS) attacks.

security

Co-creator of Empire Market dark web marketplace given 40-year sentence

Raheim Hamilton, a co-creator of the dark web marketplace Empire Market, has been sentenced to 40 years in federal prison for his role in operating the platform. The 30-year-old Virginia native pleaded guilty earlier this year to a drug conspiracy charge and was ordered by U.S. District Judge Steven Seeger to forfeit over $100 million in Bitcoin and several properties in Virginia, in addition…