The UK’s data protection regulator says ten of the largest AI developers have made, or committed to make, changes to how they handle personal data. The Information Commissioner’s Office (ICO) announced the results on October 8, 2026, alongside a new review of AI agents.

Who is named, and what changed

The ten developers are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. According to the ICO, the changes fall into three groups:

  • clearer transparency information about how personal data is used;
  • stronger mechanisms for people to exercise their data rights;
  • tougher assessments of the safeguards developers rely on.

The ICO says it is monitoring each developer’s progress against its commitments. Its announcement does not say which changes are already in place and which are still promises.

The results come from a supervision program the ICO set up in 2025. It ran for two years and covered 11 priority developers, chosen by likelihood of non-compliance, UK market share and use of higher-risk training data. The eleventh was xAI. The ICO says it paused that engagement after opening a formal investigation into the Grok AI system, which is still ongoing.

The regulator also published a report setting out its positions on how sensitive “special category” data can be used lawfully and whether foundation models themselves may contain personal data. It acknowledged that current training practices “present technical challenges” for complying with UK data protection law, and said it is raising those limits with the government.

Next: AI agents

The ICO opened a six-week call for evidence on the data protection risks of agentic AI, asking developers, deployers and other experts for views. Responses are due by November 20, 2026. The ICO says the evidence will feed future guidance and its planned statutory code of practice on AI and automated decision-making.

It also confirmed inquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute about recent agent testing and deployment. In some cases, the ICO says, agents “reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face.” Those inquiries are ongoing, and the regulator has announced no finding or penalty.

“The fact AI agents act with autonomy is not an excuse for poor compliance,” said Richard Nevinson, the ICO’s Director of Technology Regulation.

The ICO lists the personalization of consumer chatbots, including companion and role-play services, as another priority, with public research and engagement with firms under way.

What it means for users

For people in the UK, the commitments point to clearer privacy notices and easier routes to object to or ask about the use of their data. The announcement does not change any company’s settings on a set date. To see what each assistant currently does with chats, including training defaults and opt-outs, check our privacy pages for ChatGPT, Claude, Gemini, Copilot, Meta AI, DeepSeek and Grok, or the full AI privacy directory.