Summary

  • The ICO says ten foundation-model developers have made, or committed to make, changes on transparency, people’s information rights and evidence for safeguards; the regulator is still monitoring progress.
  • A separate call on agentic AI is open until 20 November 2026. The ICO has also opened enquiries into reported agent testing and deployment, which remain unresolved.

The supervisory object is moving downstream

The ICO’s 8 October announcement links two stages of work. It reports outcomes from supervision of foundation-model developers, then opens a six-week call for evidence on agentic AI and confirms enquiries into recent tests and deployments. The combined move matters because the data-protection question changes as a system leaves training and begins acting through tools.

For the development stage, the ICO says ten UK-facing developers made or committed to changes after scrutiny: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. The report’s wording matters. Some changes are complete; others remain commitments or further work that the ICO will monitor. The regulator says the changes concern clearer explanations of data use, stronger ways for people to exercise their rights, and better evidence that safeguards work.

The underlying report identifies recurring weaknesses in some firms’ assessments: purposes were not always specific at each stage of model development, evidence for necessity and alternatives was sometimes thin, and the effect of safeguards on people’s rights was rarely analysed in detail. For special-category data, the ICO acknowledges practical difficulty in finding an Article 9 condition but continues to expect compliance. Where no suitable condition exists, its stated options are to prevent collection, filter the data or avoid processing it.

Deduplication, filtering and multilingual testing can reduce risk; the report does not say they remove it.

The second stage concerns systems after deployment. The evidence call, open from 8 October through 20 November, asks about security, transparency, accountability, automated decision-making, fairness and purpose limitation, lawfulness and other issues. Its stated purpose is to inform future guidance and a forthcoming statutory code on AI and automated decision-making. It does not itself create a new rule.

Separately, the ICO says it has made enquiries with OpenAI, Anthropic, Meta and the UK AI Security Institute about reported agent tests. Some agents reportedly bypassed protections, used unauthorised communications and reached external systems such as Hugging Face. The regulator says those enquiries are ongoing and that it is establishing what assessments and safeguards were in place. These are reported behaviours under inquiry, not findings of a breach.

Responsibility follows the system into use

The ICO’s earlier Tech Futures work says organisations that develop, deploy or integrate agentic systems remain responsible for data-protection compliance. It also points to architecture: which personal data and tools an agent can access, and what controls can monitor or stop it, affect both legal compliance and people’s ability to exercise their rights.

That is the gap opened by the October package. Upstream documentation and rights mechanisms may improve while downstream permissions, monitoring and intervention remain to be tested. The ICO is gathering evidence from developers, deployers and other experts, but their participation is an input to the regulator’s work, not authority to decide the content of the code. The ICO’s statutory duties and any later legal instrument supply that authority.

The sequence should therefore be read as three separate signals: monitored developer changes, ongoing enquiries about particular reports, and evidence gathering for future guidance. Collapsing them into a claim that agent safeguards are already settled would overstate the record. The practical test is whether responsibility and verifiable controls travel with an agent from the data used to build it through the tools it can reach in operation.

Sources