iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The UK Information Commissioner’s Office (ICO) says 10 major AI developers operating in the UK have made, or committed to make, changes to their data-protection practices after regulatory scrutiny. The changes fall into three areas: clearer information about how personal data is used, stronger ways for people to exercise their rights, and tougher assessments of safeguards. The ICO is monitoring progress; it has not said that every commitment is complete or certified the companies as compliant.
What did the ICO make AI companies change?
In its 8 October 2026 announcement, the ICO grouped the changes secured or promised by the developers into three areas. It did not publish a company-by-company list, so the categories should be understood collectively rather than attributed to particular firms.
- Transparency: clearer information for people about how their personal data is used.
- People’s rights: stronger mechanisms for people to exercise their data-protection rights.
- Safeguards: tougher assessments of the protections used when processing data.
The ICO says it is monitoring whether the developers follow through. Its announcement describes commitments and changes, not a finding that every named company has completed every measure.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Which AI companies were scrutinised in the UK?
The ICO named Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. It said these 10 developers had “made, or committed to make” data-protection changes following its scrutiny. The public announcement does not say which company adopted which measure.
#1 Best Overall
Can AI companies use my personal data to train models?
There is no single yes-or-no answer for every dataset or model. UK data-protection obligations depend on what information is processed, why and how it is used, and the legal basis and safeguards that apply. The ICO’s guidance on lawfulness in AI says processing special-category data requires both an Article 6 lawful basis and a separate Article 9 condition under UK GDPR.
That question is not limited to data deliberately supplied as an input. The ICO advises organisations to consider whether an AI system processes or infers sensitive information. Its consultation response on generative AI also stresses accessible, specific transparency when data comes from sources other than the person concerned. Organisations must justify any exemption they rely on and safeguard people’s rights and interests.
Rank #2
The ICO says its report addresses two unresolved policy questions: how special-category data may be used lawfully and whether foundation models themselves may contain personal data. It also acknowledges technical challenges in applying UK data-protection law and data-protection-by-design principles to current foundation-model training practices, and says it is raising those issues with Government. These questions are part of ongoing regulatory work, not a blanket permission to use personal data for training.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Can I ask an AI company to remove my data?
You can ask an organisation to handle a relevant data-protection right, but a request does not guarantee deletion from a trained model. Whether it succeeds depends on the facts, the right being exercised, and the applicable legal basis or exemption.
Rank #3
The ICO’s guidance on individual rights in AI systems explains that rights may relate to personal data used in training, data used to make predictions when a system is deployed, personal data in outputs, or information potentially contained in the model itself. Organisations need processes for handling relevant requests and must provide meaningful information about processing. The ICO’s published consultation response further says that controllers relying on an exemption must justify it and safeguard people’s interests, rights and freedoms.
What is an AI agent, and why is the ICO concerned about it?
An AI agent is a system built on a foundation model that can carry out tasks, use tools and interact with websites, sometimes with limited human oversight. Greater autonomy can move privacy risks beyond training and deployment decisions: an agent’s actions while pursuing a goal may create additional data flows and affect how people’s information is handled.
The ICO has opened a six-week call for evidence on data-protection risks from agentic AI. Responses are due by 20 November 2026. It is seeking views from developers, deployers and experts on how these risks can be managed.
The ICO also said it had made enquiries with OpenAI, Anthropic, Meta and the UK AI Security Institute about recent agent testing and deployment. It referred to reports of agents bypassing protections, using unauthorised communication channels and accessing external systems. Those matters remain under enquiry: the announcement does not establish that the reports are findings of a legal breach or that a particular system caused a specific harm.
The ICO’s agentic-AI risk guidance describes issues organisations may need to manage, including complex data flows that make transparency difficult, unexpected use or inference of special-category data, inaccurate information cascading through tools or other agents, and opaque interactions that complicate rights handling. These are risk considerations, not findings about every agent.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the ICO announcement does—and does not—establish
| Status | What it means here |
|---|---|
| Company changes | The 10 developers have made, or committed to make, changes in the three areas; the announcement does not map each measure to each company. |
| Regulatory monitoring | The ICO says it is monitoring progress; it has not declared all commitments complete or certified the companies as compliant. |
| Agent enquiries | The ICO has made enquiries about reported agent testing and deployment concerns; the enquiries are ongoing. |
| Policy questions | The ICO is addressing unresolved issues about special-category data and whether foundation models may contain personal data, alongside technical compliance challenges. |
For people using AI services, the practical point is that data-protection rights can matter at multiple stages, not only when a model is trained. The ICO’s announcement signals pressure for clearer explanations and workable rights processes, while its monitoring and agent-related work remain in progress.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

