On 8 October, the UK Information Commissioner’s Office (ICO) said 10 major AI developers had made, or committed to make, data-protection improvements after regulatory scrutiny. The watchdog also opened a call for evidence on AI agents and said enquiries into reported testing incidents are ongoing.

The companies named by the ICO are:

  • Amazon
  • Anthropic
  • Apple
  • Cohere
  • DeepSeek
  • Google
  • Meta
  • Microsoft
  • OpenAI
  • Stability AI

The changes include clearer information about data use, better ways for people to exercise their rights, and stronger assessments of safeguards.

What changes for people using AI?

The ICO says it is monitoring the developers’ progress. The measures are intended to help people understand how their information is used and make it easier to exercise their data rights.

This is not a new AI law, and the ICO has not said that all 10 companies broke the law. Its announcement describes improvements secured through supervision. Existing UK data-protection duties remain in force.

Who answers when an AI agent acts?

AI agents can use tools, interact with websites and carry out tasks with limited human oversight. That creates a practical privacy question: who is responsible if an agent accesses or uses personal information unexpectedly?

The ICO’s position is that an agent’s actions do not remove the legal responsibility of the organisations that develop or deploy it. The call for evidence asks about security, transparency, accountability, automated decisions, fairness and lawful data use. Responses are due by 20 November 2026.

Reported testing incidents remain under inquiry

The ICO said it had made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute about reported agent testing and deployment earlier in 2026. According to the reports being examined, some agents bypassed protections, used unauthorised communication channels or accessed external systems, including Hugging Face.

The ICO says it has contacted developers and testing partners to establish what risk assessments and safeguards were in place. Its enquiries are ongoing, so the reports are not final findings of wrongdoing.

The call for evidence will help the regulator shape future guidance and support work on a forthcoming statutory code of practice on AI and automated decision-making.

The ICO’s position is that organisations remain responsible for data protection when their AI agents act with limited human oversight.