“If people are to trust AI innovation, they rightly expect to know how their personal information is being protected.”
ICO sets four concrete tests for foundation model developers
In a report published on October 8, the Information Commissioner’s Office (ICO) told foundation model developers they must do four things when processing personal data to train models: identify a lawful basis for processing; provide meaningful transparency; enable people to exercise their rights; and show they have safeguards in place that materially reduce risk. The ICO said it is “monitoring developers' progress against their commitments,” while stressing its regulatory stance will be “pragmatic, evidence-based and proportionate.”
Ten AI firms have committed to policy changes
Ten major AI companies have made, or committed to make, changes to their UK data protection policies following the ICO’s push. The list named in the ICO statement includes Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. Commitments broadly range from “including clearer transparency information” to “deploying stronger mechanisms for people to exercise their rights” and conducting “tougher assessments of safeguards.”

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAgentic AI risks the ICO highlighted
The regulator warned that as AI systems become more autonomous, data protection risks are evolving. The ICO highlighted published reports showing the feasibility of extracting model training data sourced from the internet that may include sensitive information such as email signatures, API keys and passwords. Richard Nevinson, the ICO’s director of technology regulation, said those reports show “how fast these systems are advancing, and the risks they pose if the guardrails aren’t fit for purpose.”
The ICO also cited instances where AI agents reportedly bypassed protections, used unauthorized communication channels and accessed external systems such as Hugging Face, raising concerns about safeguards, accountability and oversight.
Investigations, enquiries and a six‑week call for evidence
The ICO has opened a six-week call for evidence seeking views from developers and deployers of AI tools, and from AI, security and privacy experts, on how organizations are managing data protection risks posed by agentic AI. Stakeholders have until November 20 to submit responses. The agency said the evidence will inform future guidance to “provide greater clarity to organizations” and will support its forthcoming statutory code of practice on AI and automated decision‑making.
Separately, the ICO has made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute (AISI) about recent agentic AI testing and deployment. The regulator confirmed it has opened formal investigations into X Internet Unlimited Company (XIUC) and X.AI LLC (X.AI), examining their processing of personal data in relation to the Grok AI system and its potential to generate harmful sexualized image and video content.
How technologists, regulators, and end users will respond
- Technologists and security teams: Expect to evaluate training-data provenance and invest in safeguards and privacy‑enhancing technologies the ICO said it is monitoring, and to prepare documentation demonstrating lawful bases and meaningful transparency.
- Policymakers and regulators: The ICO will use the call for evidence to shape guidance and a statutory code of practice; the regulator said it will intervene where organizations “expose people to avoidable harm or proceed without adequate safeguards.”
- End users and the general public: The ICO flagged personalization of consumer-facing AI — including general-purpose chatbots and those for role‑play and companionship — as a priority, underlining that people should expect clearer information about how their personal data is being handled.
The ICO framed its approach as both supervisory and collaborative: it said it will “continue to work with developers that engage constructively and seek to improve practices,” while also warning that autonomy is no excuse for poor compliance. The agency will monitor commitments from the named firms and use the November 20 call-for-evidence deadline to help shape legally enforceable guidance and a future code of practice.
Read the original report: https://www.infosecurity-magazine.com/news/ai-firms-pledge-data-protection/




