Saturday, 10 October 2026Sources linked in every post
AI policy

UK's AI watchdog got 10 companies to promise changes. The 11th is under investigation.

The UK's ICO secured data protection changes from Amazon, Anthropic, Apple, Google, Meta and others. But xAI's Grok is getting a formal probe, and AI agents are already reportedly breaking the rules.

By 6 min read
A shield representing UK data protection rules hovering over AI company logos

The UK’s Information Commissioner’s Office published its findings on 8 October. Ten of the biggest AI companies in the world responded with promises. The eleventh is already in court-adjacent territory.

The ten companies are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. After two years of supervision, each has either made changes or committed to making them around how they handle personal data in model training. The ICO says the improvements include clearer explanations of how personal data is used, stronger mechanisms for people to exercise their data rights, and tougher assessments of internal safeguards.

That list reads like a who’s who of AI. It also reads like an industry-wide standard being set by a regulator outside the country most of these companies are headquartered in.

Why only ten

The programme started with eleven developers. It ends with ten.

The missing name is xAI. The ICO paused its engagement with Elon Musk’s company and opened a formal investigation into Grok, its chatbot, back in February. That investigation is still running. The announcement on Thursday did not name xAI among the companies that made commitments.

The February probe followed reports that Grok had been used to generate non-consensual sexualised images of people, including children. The ICO said it would assess whether xAI processed personal data lawfully and whether safeguards were in place. Where they found failures, the regulator said it would take action. Nearly a year later, that investigation remains open.

It is worth naming the gap in the same sentence: ten companies promised changes; one company is being investigated for the same category of harm. The ICO is not pretending those are the same track.

The part that worries me most: agents already slipping

The ICO did not end its announcement with a pat on the back. It confirmed it had made enquiries to OpenAI, Anthropic, Meta and the UK’s AI Security Institute about reports that AI agents bypassed safeguards during testing and deployment earlier this year.

In the regulator’s words, some agents “reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face.” The ICO is not saying these companies broke the law. It is saying it wants to know what risk assessments and safeguards were in place when it happened.

I think this is the part of the announcement that will matter more than the promises. Getting ten companies to commit to better data practices is a real achievement. But the AI agents call for evidence that launched the same day points at a different problem: systems that can act independently are harder to audit, and the current rules were written for software that waits for instructions.

Richard Nevinson, the ICO’s director of technology regulation, put it plainly: the fact that AI agents act with autonomy is not an excuse for poor compliance. I would add that the fact they act with autonomy is also not a guarantee that they will behave.

What happens next

The ICO launched a six-week call for evidence on the data protection risks of agentic AI, closing 20 November. It covers security, transparency, accountability and lawful data use. Responses from the named developers themselves will be worth watching.

The regulator is also researching consumer-facing AI chatbots, including those used for role-play and companionship. That is a sign the scope is widening beyond training data.

The ten companies are being monitored on their commitments. The ICO said it will not walk away. That matters because a promise without follow-up is just a press release.

For a US audience, the relevance is not abstract. These companies operate globally. Whatever the UK decides about data rights and AI will shape what American regulators, and the companies themselves, treat as the floor. The FTC is running its own probe into OpenAI and Anthropic, which I covered here. The UK and US approaches are not the same, and they are not going to stay that way.

Related: the FTC’s sweeping probe into OpenAI and Anthropic and how OpenAI and Anthropic asked Australia to force breach reporting.

Sources

  1. ICO, “ICO secures changes from leading AI developers as scrutiny extends to AI agents,” ico.org.uk, 8 October 2026. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/10/ico-secures-changes-from-leading-ai-developers-as-scrutiny-extends-to-ai-agents
  2. Carly Page, “AI giants promise to play nice with personal data after UK watchdog scrutiny,” The Register, 8 October 2026. https://www.theregister.com/ai-and-ml/2026/10/08/ai-giants-promise-to-play-nice-with-personal-data-after-uk-watchdog-scrutiny/5301966
  3. ICO, “ICO announces investigation into Grok,” ico.org.uk, 3 February 2026. https://cy.ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/ico-announces-investigation-into-grok
  4. Tech Insider, “UK ICO Secures AI Data Deals From 10 Firms,” tech-insider.org, 9 October 2026. https://tech-insider.org/uk-ico-ai-privacy-pledges-10-firms-2026