Britain's data protection regulator says ten of the world's biggest AI developers have changed, or promised to change, how they handle people's personal information when they build AI. In a report published on Oct. 8, the Information Commissioner's Office (ICO) named Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. The regulator says the models behind many chatbots and assistants are trained on large volumes of personal data, and it spent two years examining how these companies do it.
The ICO says that under UK law, a company that trains AI on personal information must have a lawful reason to use it, tell people clearly what it is doing, let them use their rights over their data, and show that its safeguards really reduce the risk. The ICO found that firms did not always spell out why they needed each type of personal data, and that some had no solid evidence it was necessary.
Some fixes are already in place. Apple, Cohere and OpenAI have changed what they tell people, including, between them, privacy notices just about how they train their models. Apple has published a page listing where its training data comes from: public web pages gathered by its Applebot crawler, data licensed or bought from other companies, open-source data, user studies and synthetic data. Apple says it does not train its models on users' private data unless they choose to help. Other changes are still promises: DeepSeek, for example, will update its privacy policy to explain what personal data from other sources goes into its training and why, and Stability AI will explain its reasons in more detail.
The regulator also says the law is hard to apply here. It says the way these models are trained today makes it technically difficult to comply with UK data protection law, and that it is raising the problem with the government.
Its next focus is AI agents: AI that can carry out tasks on its own, such as using apps and websites, instead of only answering questions. The ICO says they often work with little human oversight, and that the privacy risks are shifting from how AI is trained to how it might behave on its own once it is in use. The ICO has asked OpenAI, Anthropic, Meta and the UK's AI Security Institute about recent tests and launches, after reports that some agents got around their safeguards, used communication channels they were not allowed to use and reached outside systems such as the Hugging Face website. The ICO has not said which agents were involved. Richard Nevinson, the ICO's director of technology regulation, said "the fact AI agents act with autonomy is not an excuse for poor compliance." The ICO is also asking developers, the companies that use agents and other experts for evidence on the privacy risks, until Nov. 20. It says the answers will shape its guidance and a planned official code of practice on AI and automated decisions.
xAI, the company behind the Grok chatbot, was one of 11 companies the ICO picked for the review, but the regulator paused that work when it opened a formal investigation into how Grok handles personal data and its potential to make harmful sexual images and video. That investigation, and the enquiries into the agent incidents, are still going on. The ICO says it is monitoring the companies' progress but has not said when the promised changes must be finished. It says it will use its full legal powers where necessary, but it has announced no fines or formal findings against the ten.