AI giants promise to play nice with personal data after UK watchdog scrutiny
Amazon, Google, Microsoft, OpenAI and six others agree to changes, but the ICO isn't done asking questions
Ten leading artificial intelligence companies have pledged to improve their handling of personal data after the UK's privacy watchdog, the Information Commission's Office (ICO), conducted an investigation. The ICO, which recently rebranded, examined the compliance of Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI with UK data protection laws.
These tech giants have either implemented changes or committed to doing so in response to the regulator's findings. These changes include providing clearer explanations of how personal information is used to train AI models, enhancing ways for individuals to exercise their data rights, and implementing stricter assessments of developers' safeguards.
The ICO's scrutiny began in 2025 with 11 developers, but was later reduced to ten after the regulator paused its engagement with Elon Musk's xAI for a separate investigation. The watchdog is not satisfied yet, as it continues to monitor whether these companies live up to their promises. Developers are still struggling with issues related to personal data within their models, particularly sensitive information, and the process for individuals to have their data removed once an AI has been trained.
Additionally, there is a risk of personal information being extracted from models, even if developers did not intend them to retain it. The ICO acknowledged that some of these problems require collaboration between industry, regulators, and government. While the ICO has secured promises from some of the industry's biggest names, the effectiveness of these commitments remains to be seen.
The regulator is now turning its attention to AI agents, which can operate autonomously, browsing websites, using tools, and performing tasks with minimal human supervision. Some AI agents have been found to bypass safeguards during testing and deployment, prompting the ICO to contact OpenAI, Anthropic, Meta, and the UK's AI Security Institute.
The regulator has emphasized that the autonomy of AI agents should not be an excuse for poor compliance with data protection laws. The ICO has also launched a six-week call for evidence on agentic AI, with responses due by November 20. This information will help shape future guidance and the ICO's upcoming statutory code of practice on AI and automated decision-making.
The watchdog is also separately examining how consumer chatbots and AI companions use personal information as they become more personalized. While the ICO has secured promises from some major companies, the success of these promises and the future regulation of AI agents remain uncertain.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.