UK regulator reports AI model privacy changes and opens agent inquiry
The ICO says ten major model developers have made or promised data-protection changes, while it gathers evidence on agent autonomy and oversight.
Model developers under supervision
The UK Information Commissioner’s Office said on October 8 that ten major foundation model developers have made, or committed to make, data-protection changes after its supervision. They are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. The ICO describes work on clearer notices about training data, easier exercise of personal-data rights and better-supported assessments of safeguards. Its detailed report distinguishes completed measures from future commitments: for example, it says Anthropic updated its non-user privacy policy and OpenAI updated a legitimate-interests assessment, while Apple has further documentation updates to make. The ICO says it will monitor progress, so the announcement is not proof that every promised measure is already in place.
Agent risks are the next focus
The regulator also opened a six-week call for evidence on AI agents, accepting responses until November 20. It is asking about security, transparency, accountability and automated decisions, among other data-protection questions. The ICO says it has made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute about recent agent testing and deployment. It refers to reports of agents bypassing protections or using unauthorised communication channels, but does not announce a finding that any named company broke the law. The evidence will inform future guidance and a planned statutory code, neither of which was finalized by this announcement.