Ten of the world's largest AI developers — including Amazon, Anthropic, Apple, Google, Meta, Microsoft, and OpenAI — have agreed to change how they handle personal data following scrutiny by the UK's privacy regulator, which on Thursday turned its attention to a new concern: autonomous AI agents that bypass their own guardrails.

The Information Commissioner's Office (ICO) said the ten companies have either made changes or committed to doing so after the regulator examined their compliance with UK data protection law. The commitments include clearer explanations of how personal information is used to train AI models, better mechanisms for people to exercise their data rights, and more rigorous assessments of developers' safeguards.

A supervisory program bears fruit

The breadth of the list is notable. It spans US hyperscalers (Amazon, Google, Microsoft, Meta, Apple), the leading frontier labs (OpenAI, Anthropic), open-weight specialists (Cohere, Stability AI), and DeepSeek — a Chinese developer whose models are widely used by Western companies. All ten now sit under commitments covering the UK market.

The commitments flow from a supervisory program the ICO launched in 2025 covering eleven major developers. That roster dropped to ten after the regulator paused its engagement with Elon Musk's xAI in order to pursue a separate formal investigation into the company's Grok chatbot.

The intervention comes at a moment of transition for the regulator itself, which recently rebranded as the Information Commission and started over with a new board and a Manchester headquarters.

The regulator is not declaring victory. It said it will keep monitoring whether the developers deliver on their promises, and acknowledged that current AI training practices still create friction with UK data protection law. Developers still have open questions to answer about sensitive personal data embedded in trained models, about how people can get their information removed once a model has been trained on it, and about the risk that personal data — including data developers never intended to retain — can be extracted from models after the fact.

"AI has huge potential to benefit our society, but that depends on trust and transparency," said Richard Nevinson, the ICO's director of technology regulation. "Our engagement with some of the biggest developers has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area."

Next target: agents that slip their guardrails

The watchdog's attention is now shifting to AI agents — systems that browse websites, use tools, and complete tasks with limited human supervision. The ICO confirmed it has contacted OpenAI, Anthropic, Meta, and the UK's AI Security Institute following reports earlier this year of agents bypassing safeguards during testing and deployment.

"These recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren't fit for purpose," Nevinson said. "Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance."

Alongside the enforcement-adjacent engagement, the ICO has opened a six-week call for evidence on agentic AI, covering security, transparency, accountability, and the lawful use of personal data. AI policy watchers tracking the latest AI developments will want to note the timeline: responses are due by November 20 and will inform future guidance as well as the regulator's forthcoming statutory code of practice on AI and automated decision-making.

The regulator is also examining how consumer chatbots and AI companions use personal information as those products become increasingly personalized — a category that has grown rapidly as companions, character bots, and teen-oriented assistants have rolled out. That work signals that the supervisory program's scope now extends beyond model training into consumer-facing products where personalization is the core feature.

For AI companies operating in the UK, the practical effect is that the ICO has created a standing framework: named developers, documented commitments, and public follow-through. Companies that signed on will be measured against their promises, and the regulator has made clear it considers today's training practices — not just future ones — to be an ongoing compliance problem.

What it means

For AI companies operating in the UK, the message is that data protection scrutiny is moving from training data to deployed behavior. Securing commitments on training transparency was the easier phase; the harder questions — deletion from trained models, extraction risks, and agents acting outside their guardrails — remain open, and the ICO has signaled it expects industry, regulators, and government to work on them together.

The episode also illustrates the UK's post-Brexit regulatory posture: rather than a broad AI act, the country's watchdogs are applying existing data protection law to AI systems and building a statutory code of practice for automated decision-making. With a call for evidence on agentic AI now running and several of the world's largest labs formally in its sights, the ICO is positioning itself as one of the most active AI regulators among Western data protection authorities.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →