Announced 8 Oct 2026 · Sources checked
What did the ICO publish on 8 October?
The ICO’s news page, dated 8 October 2026, says a new report records data-protection improvements from ten of the largest foundation-model developers operating in the UK. The same day it opened a call for evidence on agentic AI and confirmed enquiries about agent testing earlier this year. Richard Nevinson, director of technology regulation, is quoted saying the engagement produced “real commitments” on transparency and control, and that autonomy is not an excuse for poor compliance.
The report is titled “Building trust and transparency into generative AI development: our work to create regulatory certainty.” A two-year programme under the 2025 AI and biometrics strategy originally covered 11 priority developers. Engagement with xAI was paused after a formal Grok investigation, leaving ten. This is a UK data-protection supervision outcome, not a healthcare-safety package. For the government’s separate 6 October response to the healthcare AI commission, see our UK AI Airlock Phase 3 story. The two documents share a regulator, not a remit.
Which developers were in the foundation-model programme?
The Industry Supervision chapter lists Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, Stability AI and X.AI. Selection used information-request responses, ICO files, public material, UK market share and usage, and training-dataset information. The ICO focused on legitimate interests (UK GDPR article 6(1)(f)), special category data (article 9), transparency (articles 13 and 14), the right of access (article 15) and the right to object (article 21).
xAI is the exception, not a listed change. On 3 February 2026 the ICO announced formal investigations into X Internet Unlimited Company and X.AI LLC over personal-data processing in Grok and reports that the system had been used to generate non-consensual sexual imagery, including of children. That statement said the office had not then decided whether there was sufficient evidence of an infringement. The 8 October pages say the investigation is still open, so xAI was suspended from this programme. The news notes call the legal entity the Information Commission, now overseen by a board created under the Data (Use and Access) Act 2025.
What data-protection changes does the ICO record?
The supervision chapter is careful with tense. Some firms “updated” documents. Others “will” update them. The news page compresses that into “made, or committed to make.” The ICO says it is monitoring progress. It does not publish a completion date, a public checklist, or an independent audit of each privacy page.
On legitimate-interest assessments, the ICO says firms did not always name a specific interest for each type of personal data at each development stage, and that necessity and impact analysis was often thin. Anthropic and OpenAI “updated” assessments. Meta provided memorisation-test results and a survey of its transparency materials. DeepSeek “produced” an assessment and “will” update its privacy policy. Apple, Google, Microsoft and Stability AI “will” update or review assessments or policies. Amazon and Cohere are not named in that list.
On transparency, Apple, Cohere and OpenAI are grouped as already having changed the information they give people, including standalone model-training notices and a summary of third-party training datasets. Amazon, Anthropic, DeepSeek, Google, Meta, Microsoft and Stability AI “have each made changes or committed to implementing some or all” of standalone notices, non-technical source summaries, clearer rights routes, retention and transfer updates, and more assessment evidence. The ICO does not say which item each of those seven has finished. Apple’s 9 September 2026 training-data page, which the ICO cites, lists Applebot crawls, licensed, open-source, user-study and synthetic sources and says Applebot respects robots.txt blocks on foundation-model training. Those are Apple’s claims.
How does the ICO treat models that may contain personal data?
The policy chapter repeats a 2020 ICO line: if training data include personal data, embeddings can still be personal data because that data can sometimes be extracted from a trained model. Some developers disagreed. The office says it has been reviewing the 2020 position. The European Data Protection Board said in December 2024 that models can embed training data in ways that mean they are not anonymous. Whether a specific model contains personal data, the ICO now says, needs a case-by-case look at architecture and the mitigations actually applied.
On special category data it says developers are likely to be processing article 9 data unless they can show their training sets do not, and that not intending to process it is not a defence. Two conditions might apply in some cases — “manifestly made public” for some first-party data, and “scientific research” where ICO research tests are met — but those conditions are unlikely to cover all special-category material in foundation-model training, especially web-scraped third-party data. The ICO is taking that boundary to government. Safeguards it has seen include deduplication, filtering, multilingual testing, hash-matching, classifiers, human curation and dedicated CSAM-detection tools. Those are categories of control, not residual-risk figures.
What is the agentic AI call for evidence?
The consultation opened on 8 October 2026 and closes at the end of 20 November 2026. The ICO wants views from developers, deployers and other experts on how organisations manage data-protection risks in agentic systems. The survey covers security, transparency, accountability, automated decision-making, fairness and purpose limitation, and lawfulness. The evidence is meant to feed future guidance and a forthcoming statutory code of practice on AI and automated decision-making. The introduction defines AI agents as large-language-model systems with tools, memory, an environment, and some autonomy. For limiting what an agent can reach, see our agent-sandboxing explainer. For a vendor proposal about how agents should announce themselves, see Meta and Sierra’s Personal Agent Protocol.
The introduction says that in summer 2026 “it was reported” that certain highly capable agents from OpenAI and Anthropic, during cyber evaluations, interacted with external systems and in some cases “bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face.” The news page adds Meta and the UK AI Security Institute to the enquiry list. Those enquiries are ongoing. The ICO is not publishing a completed incident report.
What this report does not settle
The ICO has not announced fines, enforcement notices or a finding that any named developer has finished every listed change. Several of the most specific items are still written as “will.” The office also says current foundation-model training practices present technical challenges for UK data-protection law and data-protection-by-design, and that it is raising those boundaries with government.
Annex A records commissioned memorisation research, a 2024 generative-AI consultation, reviews of assessments, and a March 2026 workshop on finding personal data in web-scraped text. The workshop showed that identifying personal data in large text sets is technically feasible at scale, but that linking a person across sources and notifying them without exposing third-party data remains hard. Treat named privacy notices as the things to re-read, not as proof that a model no longer contains someone’s data. The agentic-AI survey is open until 20 November. The Grok investigation remains a separate, unfinished case.
Common questions
Has the ICO fined any of the ten developers?
Not in this package. The 8 October news and report describe supervision, named document changes, and commitments the ICO says it will monitor. The only formal investigation discussed here is the still-open Grok case against XIUC and X.AI.
Did every named company finish the changes?
No. The ICO uses both past and future tense. Apple, Cohere and OpenAI are grouped as having already changed some transparency information. Several legitimate-interest items for Apple, DeepSeek, Google, Microsoft and Stability AI are still written as reviews that “will” happen.
Does the ICO now say every foundation model contains personal data?
No. It repeats that models can contain personal data when training data can be extracted, cites the EDPB’s December 2024 line that models are not always anonymous, and then says a specific model needs a case-by-case assessment.
What to remember
Read the ICO report as a named list of privacy-document changes and an open agentic-AI evidence call. Check the tense of each commitment before treating a lab as finished, and do not confuse the still-open Grok investigation with the ten-developer supervision list.
Sources & further reading
- ICO secures changes from leading AI developers as scrutiny extends to AI agents ↗
- Building trust and transparency into generative AI development: our work to create regulatory certainty ↗
- Building trust and transparency into generative AI development: Introduction ↗
- Building trust and transparency into generative AI development: Data protection challenges and our expectations ↗
- Building trust and transparency into generative AI development: Industry Supervision ↗
- Building trust and transparency into generative AI development: Next steps ↗
- Building trust and transparency into generative AI development: Annex A ↗
- Agentic AI call for evidence ↗
- ICO announces investigation into Grok ↗
- Datasets used for Apple's generative AI systems and services ↗
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





