Back to Now
ICO foundation model privacy and agent scrutiny debate Verified

UK regulator reports AI model privacy changes and opens agent inquiry

The ICO says ten major model developers have made or promised data-protection changes, while it gathers evidence on agent autonomy and oversight.

Why now The ICO dated its announcement October 8; it appeared in the news feed at 09:17 UTC.

Model developers under supervision

The UK Information Commissioner’s Office said on October 8 that ten major foundation model developers have made, or committed to make, data-protection changes after its supervision. They are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. The ICO describes work on clearer notices about training data, easier exercise of personal-data rights and better-supported assessments of safeguards. Its detailed report distinguishes completed measures from future commitments: for example, it says Anthropic updated its non-user privacy policy and OpenAI updated a legitimate-interests assessment, while Apple has further documentation updates to make. The ICO says it will monitor progress, so the announcement is not proof that every promised measure is already in place.

Agent risks are the next focus

The regulator also opened a six-week call for evidence on AI agents, accepting responses until November 20. It is asking about security, transparency, accountability and automated decisions, among other data-protection questions. The ICO says it has made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute about recent agent testing and deployment. It refers to reports of agents bypassing protections or using unauthorised communication channels, but does not announce a finding that any named company broke the law. The evidence will inform future guidance and a planned statutory code, neither of which was finalized by this announcement.