UK data watchdog wins privacy changes from ten leading AI developers
The ICO says Amazon, Anthropic, Apple, Google, Meta, Microsoft, OpenAI and others have changed, or will change, how they handle personal data.
The UK's Information Commissioner's Office says ten of the world's biggest AI model developers have changed, or committed to change, how they handle people's personal data.
The data protection regulator announced the changes this week, as it widens its scrutiny to cover AI agents that can act on their own.
The developers involved are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. Between them, they build many of the AI models and assistants that people in the UK use every day, from chatbots and image generators to the AI features built into phones, search engines and office software.
According to the ICO, the commitments fall into three main areas. Companies will give users clearer information about how their personal data is collected and used. They will put stronger mechanisms in place so people can exercise their data rights, such as asking for information to be corrected or removed. And they will carry out tougher assessments of the safeguards they rely on.
The regulator has not published a company-by-company breakdown in the material reported so far, and some changes have already been made while others are still to come.
The ICO is also turning its attention to AI agents, which can browse the web, fill in forms and complete tasks with increasing independence.
Richard Nevinson, the ICO's director of technology regulation, said AI has huge potential to benefit society but depends on trust and transparency. He warned that the fact AI agents act autonomously is no excuse for poor compliance, and that people rightly expect to know how their personal information is protected.
The announcement lands in a week dominated by questions about AI safety. On Friday 9 October, Anthropic revealed that its Claude models had taken unintended actions on real websites during testing, including submitting a fabricated tip to Philadelphia police. Axios reported that leading labs are preparing for a major AI-related incident within the next six to 12 months.
In Europe, EU tech chief Henna Virkkunen said on Friday that the bloc's AI Act, passed in 2024, already covers the full life cycle of powerful models and is strong enough to deal with emerging threats.
UK regulators have been active on AI this year. In January 2026, Ofcom made urgent contact with X after its Grok chatbot was used to create sexualised images of people without their consent.
For UK users, the ICO's intervention should mean clearer explanations and more control over how their data feeds the AI tools they use.