Major AI Firms Pledge Data Protection Changes Following UK Privacy Watchdog Push
Ten major AI firms pledged UK data-protection changes after the ICO pushed transparency and opened a Grok probe.
The UK Information Commissioner's Office said ten AI companies — Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI — have made or committed to UK data-protection changes covering transparency, individual rights, and safeguards. An October 8 report asks foundation-model developers to identify a lawful basis, explain processing, enable data-subject rights, and show that safeguards materially reduce risk. The ICO opened a six-week call for evidence closing November 20 and has already contacted OpenAI, Anthropic, Meta, and the UK AI Security Institute. It also confirmed formal investigations into X Internet Unlimited Company and X.AI over personal-data processing for Grok, including its potential to generate harmful sexualized images and video.
- Ten AI firms, including OpenAI, Google, Meta, and Anthropic, pledged UK changes.
- ICO opened a call for evidence on agentic AI through November 20.
- ICO is formally investigating X and xAI over Grok personal-data processing.
- The regulator says agent autonomy does not excuse weak compliance.
Full article695 words · extracted from infosecurity-magazine.com · click to collapse
Ten major AI companies have made, or committed to make, changes to their UK data protection policy after the Information Commissioner's Office (ICO), the British privacy watchdog, urged them to strengthen transparency in how they process personal data.
These include Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI.
Their commitments range from including clearer transparency information to deploying stronger mechanisms for people to exercise their rights and conducting tougher assessments of safeguards.
In a new report on data privacy in agentic AI, published on October 8, the ICO said it is asking foundation model developers to ensure clear data protection policies are in place when they process personal data to train models.
Specifically, the watchdog said AI companies must:
- Identify a lawful basis for doing so
- Provide meaningful transparency
- Enable people to exercise their rights
- Show that they have safeguards in place to materially reduce risk
“We are monitoring developers' progress against their commitments,” the ICO added, while emphasizing that its approach to regulation “will remain pragmatic, evidence-based and proportionate.”
ICO Launches Call for Evidence on Agentic AI
These commitments come as the ICO has launched a six-week call for evidence, seeking views from developers and deployers of AI tools and other AI, security and privacy experts on how organizations are managing the data protection risks of agentic AI.
The agency has already made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute (AISI) around recent agentic AI testing and deployment.
Stakeholders have until November 20 to submit their responses to the ICO.
ICO Warns Data Protection Risks Grow With AI Autonomy
The regulator noted that as AI systems become more autonomous, the data protection risks they pose are evolving, from questions about how AI systems are trained to how they might behave independently once deployed.
Richard Nevinson, the ICO’s director of technology regulation, highlighted that, while AI has “huge potential to benefit our society,” realizing these benefits “depends on trust and transparency.”
This trust is endangered, said the regulator, as we are increasingly seeing reports demonstrating the feasibility of extracting model training data. Such data can be sourced from the internet and, the regulator noted, may include sensitive information such as email signatures, API keys and passwords, which could potentially be exploited to gain malicious access to systems and further information.
Nevinson also mentioned cases where AI agents reportedly bypassed protections, used unauthorized communication channels and accessed external systems such as Hugging Face, raising potential concerns about safeguards, accountability and oversight.
“These recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren’t fit for purpose. Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance. If people are to trust AI innovation, they rightly expect to know how their personal information is being protected. As AI systems operate with greater autonomy, robust data protection safeguards become even more critical,” he warned.
The evidence gathered from the call will inform the ICO’s future guidance that will aim to “provide greater clarity to organizations” and “support them to innovate responsibly” while protecting people's rights.
It will also support the development of the agency’s forthcoming statutory code of practice on AI and automated decision-making.
Read more: OpenAI: Hugging Face Incident a “Warning Shot” to the World
ICO Steps Up AI Oversight and Investigates Grok Data Practices
Beyond this specific engagement, the ICO statement stressed that it will “continue to work with developers that engage constructively and seek to improve practices”, while also monitoring developments in privacy-enhancing technologies that could help mitigate risks.
“Where organizations expose people to avoidable harm or proceed without adequate safeguards, we will intervene,” the agency warned.
Against this backdrop, the regulator confirmed that it had opened formal investigations into X Internet Unlimited Company (XIUC) and X.AI LLC (X.AI), examining their processing of personal data in relation to the Grok AI system and its potential to generate harmful sexualized image and video content.
The ICO also identified the increasing personalization of consumer-facing AI services as another priority, including popular general-purpose chatbots and those designed for role-play and companionship.