Ten major AI developers have changed, or promised to change, how they handle personal data after scrutiny by the UK’s Information Commissioner’s Office (ICO). The regulator is also examining whether autonomous AI agents can follow the rules when they act with less human supervision.
Watch Desk analysis
What happened
The Register reports that Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI have either made changes or committed to clearer explanations of how personal information is used in model training, better ways for people to exercise their data rights, and tougher assessments of safeguards. The ICO is monitoring whether those commitments are delivered. Read The Register’s report.
The report says the ICO has contacted OpenAI, Anthropic, Meta and the UK’s AI Security Institute following reports of agents bypassing safeguards during testing and deployment. The regulator has also opened a six-week call for evidence on agentic AI, covering security, transparency, accountability and lawful use of personal data. Responses are due by 20 November and will inform future guidance and a statutory code of practice.
What changes
- Clearer information about training data
Developers have committed to explain more plainly how personal information is used to train models. - Better routes to exercise data rights
People should have improved ways to act on their rights, though the report does not specify the promised mechanisms. - Closer scrutiny of safeguards
Developers have committed to tougher assessments, while the ICO monitors delivery. - Evidence-gathering on AI agents
The ICO’s call covers security, transparency, accountability and lawful data use, with responses due by 20 November.
Why it matters
A promise to improve data handling is not the same as resolving the awkward parts: personal information can remain embedded in trained models, including sensitive information, and removal is not straightforward. The report says the ICO also recognises the risk that information could be extracted from models, including data developers did not intend to retain.
Agents raise a further question. A system that browses, uses tools and carries out tasks with limited supervision still has to comply with data-protection rules; autonomy is not a handy exemption clause. The ICO is also examining how consumer chatbots and AI companions use personal information as they become more personalised.
Our read
This is more than a round of well-worded corporate promises: the regulator has set an evidence-gathering deadline and is turning its attention to agents’ behaviour. But the useful test is what changes for people trying to understand, control or remove their data, not how reassuring a commitment sounds. The ICO’s next guidance should turn the broad principles into practical answers.
What to watch
- Whether the developers deliver the promised changes, and how the ICO assesses them.
- What evidence the ICO receives by 20 November and what it says in response.
- Whether forthcoming guidance explains how people can address personal data embedded in trained models.
- What the ICO finds about agents’ safeguards and consumer chatbots’ use of personal information.
Discussion spark: Should AI developers have to demonstrate that people can remove personal data from trained models before a system is allowed to use it, or is that standard technically unrealistic?
Sources and evidence
- AI giants promise to play nice with personal data after UK watchdog scrutiny (8 October 2026, 12:35 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.