What the regulator got

The Information Commissioner’s Office said on 8 October that ten foundation model developers operating in the UK have made, or committed to make, data protection changes following two years of direct supervision.

The ten are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. The changes fall into three groups: clearer transparency information, stronger mechanisms for people to exercise their rights, and tougher assessments of safeguards. The ICO says it is monitoring progress against the commitments rather than treating them as closed.

The accompanying report also sets out the regulator’s positions on two questions the industry has been arguing about for three years: how special category data can be used lawfully, and whether foundation models may themselves contain personal data.

The eleventh developer

The programme started with eleven. The ICO set it up in 2025 under its AI and Biometrics Strategy, selecting priority developers by likelihood of non-compliance, UK market share and use of higher-risk training datasets.

xAI is not in the list of ten. The ICO paused its engagement with X.AI after opening a formal investigation into Grok on 3 February, covering X Internet Unlimited Company and X.AI LLC and their processing of personal data in relation to Grok and its potential to produce harmful sexualised image and video content. The ICO said it acted after reports that Grok had been used to generate non-consensual sexual imagery of individuals, including children. That investigation is ongoing, which is why the supervision outcome covers ten companies rather than eleven.

A person working on a laptop at an office desk by a window
The commitments cover transparency, rights mechanisms and safeguard assessments. Illustrative photograph. Thirdman · pexels · Pexels License

Agents are next

The second half of the announcement is about where the ICO is going. It has opened a six-week call for evidence on agentic AI, seeking views from developers, deployers and other experts on security, transparency, accountability, automated decision-making, fairness and lawful data use. It closes on 20 November 2026, and the responses are to inform future guidance and the forthcoming statutory code of practice on AI and automated decision-making.

Richard Nevinson, the ICO’s Director of Technology Regulation, put the position in one line: “the fact AI agents act with autonomy is not an excuse for poor compliance”. He also said that “AI has huge potential to benefit our society, but that depends on trust and transparency.”

The live enquiries

The regulator is not waiting for the call for evidence to close before asking questions. It says it has contacted OpenAI, Anthropic, Meta and the UK’s AI Security Institute about recent agentic AI testing and deployment, after reports that some agents bypassed protections, used unauthorised communication channels and accessed external systems including Hugging Face. Those enquiries are ongoing.

That is a different posture from the foundation model programme. The supervision exercise ran for two years and ended in a list of commitments. The agent enquiries are running against systems that are already deployed.

An empty meeting room with a long table and chairs
The call for evidence on agentic AI closes on 20 November 2026. Illustrative photograph. cottonbro studio · pexels · Pexels License

What to watch

Three dates. The call for evidence closes on 20 November. The statutory code of practice on AI and automated decision-making follows it, and will carry obligations rather than commitments. And the Grok investigation, open since February, has produced no public finding.

The ICO says it will continue to work with developers that engage constructively. The implicit other half of that sentence is what happens to the ones that do not, and xAI is the only test case so far.