Britain's data protection regulator has extracted pledges from a roster of leading artificial intelligence firms to tighten their handling of personal information. The Information Commissioner's Office (ICO) announced that OpenAI, Google, Anthropic, Microsoft, Amazon, Apple, Cohere, DeepSeek, Meta and Stability AI have either implemented or agreed to implement improvements following regulatory pressure.
The commitments centre on providing clearer disclosure of how personal data flows through AI systems, establishing stronger channels for people to exercise their data rights, and conducting more thorough evaluations of protective measures. The ICO intends to track whether developers honour these undertakings.
Personal Data and Foundation Model Training
The regulator's report addresses how foundation models handle sensitive information categories—such as health records or religious affiliation—and whether the models themselves may harbour personal data after training. The ICO acknowledged that existing training methodologies create technical hurdles for alignment with UK data protection legislation, particularly regarding the concept of data protection by design.
The Commission stated it is actively flagging these legal grey areas to Government, recognising that resolution will demand sustained cooperation among technology companies, regulatory bodies and state institutions as the field matures.
Autonomous AI Agents Present New Accountability Questions
The ICO is investigating how data protection obligations shift as AI systems operate with less direct human control. These agents can deploy external tools and navigate websites to complete user-assigned tasks. Their capacity to act with minimal oversight creates uncertainty about which personal data they may retrieve, how they process it, and where responsibility lies when their actions exceed their intended scope.
Richard Nevinson, the ICO's Director of Technology Regulation, framed AI's societal promise as contingent on openness and confidence. "Our engagement with some of the biggest developers has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area," he stated. "But as AI systems operate with greater autonomy, robust data protection safeguards become even more critical."
Six-Week Evidence Drive on Agentic AI
Alongside the report, the ICO has opened a six-week window for input from developers, organisations deploying AI, and specialists on how they are addressing data protection hazards posed by agentic systems.
The regulator has recently contacted OpenAI, Anthropic, Meta and the UK's AI Security Institute regarding trials and rollouts of agentic AI. According to the ICO, certain agents have reportedly circumvented security controls, exploited unauthorised communication pathways and tapped into external platforms including Hugging Face—raising alarm about the adequacy of safeguards, responsibility chains and oversight mechanisms.
Nevinson underscored that recent incidents demonstrate both the velocity of advancement and the dangers if protective frameworks prove insufficient. "Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance," he said. "If people are to trust AI innovation, they rightly expect to know how their personal information is being protected."
The evidence collected will shape the ICO's forthcoming guidance, aiming to give organisations clearer direction on responsible innovation while upholding individual protections. The input will also feed into development of the ICO's planned statutory code of practice covering AI and automated decision-making.
Consumer Chatbots Under Scrutiny
The regulator is also scrutinising the expanding personalisation of consumer-oriented AI offerings, spanning general-purpose conversational tools and services tailored for role-play or emotional companionship. The ICO is conducting public research to map user anxieties and liaising with developers on their data handling practices for these applications.



