Ten of the world's largest AI companies have committed to overhauling their data protection policies following pressure from Britain's privacy watchdog, the Information Commissioner's Office (ICO), which published a new report on data privacy in agentic AI on October 8. Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI have all promised to implement changes ranging from clearer transparency disclosures to stronger mechanisms enabling people to exercise their rights and tougher assessments of protective measures. The regulator is asking foundation model developers to ensure robust data protection policies are in place when they process personal information to train models.
The ICO said AI firms must meet four specific requirements: identify a lawful basis for processing personal data, provide meaningful transparency, enable individuals to exercise their rights, and demonstrate that they have safeguards in place to materially reduce risk. The regulator emphasized that it is tracking developers' progress against their pledges and that its regulatory approach "will remain pragmatic, evidence-based and proportionate." The commitments arrive alongside a six-week call for evidence launched by the ICO, seeking input from developers and deployers of AI tools as well as AI, security and privacy experts on how organizations are managing the data protection risks of agentic AI. The agency has already conducted enquiries with OpenAI, Anthropic, Meta and the UK's AI Security Institute around recent agentic AI testing and deployment, and stakeholders have until November 20 to submit responses.
The regulator warned that as AI systems gain greater autonomy, the data protection risks they present are evolving from questions about how AI systems are trained to how they might behave independently once deployed. Richard Nevinson, the ICO's director of technology regulation, stated that while AI has "huge potential to benefit our society," delivering these benefits "depends on trust and transparency." The watchdog noted that trust is threatened by increasing reports showing the feasibility of extracting model training data, which can be pulled from the internet and may contain sensitive information such as email signatures, API keys and passwords that could potentially be exploited for malicious access. Nevinson also pointed to cases where AI agents reportedly bypassed protections, used unauthorized communication channels and accessed external systems such as Hugging Face, raising concerns about safeguards, accountability and oversight.
The ICO's call for evidence will inform future guidance aimed at providing greater clarity to organizations and supporting them to innovate responsibly while protecting people's rights, and will also support development of the agency's forthcoming statutory code of practice on AI and automated decision-making. The regulator stressed it will continue working with developers that engage constructively and seek to improve practices, while monitoring developments in privacy-enhancing technologies that could help mitigate risks. The agency warned that where organizations expose people to avoidable harm or proceed without adequate safeguards, it will intervene—and confirmed it has already opened formal investigations into X Internet Unlimited Company and X.AI LLC, examining their processing of personal data in relation to the Grok AI system and its potential to generate harmful sexualized image and video content. The ICO also identified the increasing personalization of consumer-facing AI services as another priority, including popular general-purpose chatbots and those designed for role-play and companionship. For enterprises deploying AI at scale, the regulatory shift signals that voluntary compliance windows are narrowing, and that demonstrating proactive governance frameworks may soon be a competitive differentiator rather than a cost center.

