SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
ICO extracts data protection pledges from ten AI developers over training data
Ten AI developers including OpenAI, Google and Meta have changed or pledged to change their UK data protection policies after ICO pressure. Because the regulator says it is tracking delivery, buyers can now ask those vendors how they meet its training-data tests.
The Watch · Security desk

What happened
- The ICO's October 8 report on agentic AI says developers who train on personal data need a lawful basis, meaningful transparency, working data rights and safeguards that materially reduce risk.
- A six-week ICO call for evidence on how organisations manage the data protection risks of agentic AI takes submissions until November 20.
- The ICO has opened formal investigations into X Internet Unlimited Company and X.AI LLC over Grok and its potential to generate harmful sexualised images and video.
Why it matters
- decision UK deployers buying from any of the ten can put the ICO's four tests to their vendor directly, and the regulator says it is tracking the same commitments.
- exposure Credentials that once leaked onto scraped public pages have a second exposure path through any model trained on them, and the ICO now treats that as a data protection risk.
- constraint Until the statutory code on AI and automated decision-making exists, these commitments are held in place only by ICO monitoring and case-by-case intervention.
The security content in the ICO's statement is about secrets. The regulator said it is increasingly seeing reports that model training data can be extracted, and that internet-sourced training data may include email signatures, API keys and passwords that could be used to gain malicious access to systems [12]. On that account, a credential that leaked onto a public page once has a second way out, through any model trained on that page [12].
The ten are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI [5]. Their commitments include clearer transparency information, stronger mechanisms for people to exercise their rights, and tougher assessments of safeguards [6]. Infosecurity Magazine's report does not say which company made which change. "We are monitoring developers' progress against their commitments," the ICO said [8]. It added that its approach "will remain pragmatic, evidence-based and proportionate" [9].
For a UK deployer, the four tests are now the questions to put to a model vendor. What lawful basis does it rely on to train on personal data, and what safeguards can it show [7]? The statutory version is still forthcoming. Evidence from the call will inform future ICO guidance and its statutory code of practice on AI and automated decision-making [13].
Richard Nevinson, the ICO's director of technology regulation, pointed to reported cases of AI agents getting around protections, communicating over channels they were not authorised to use, and reaching into external systems, Hugging Face among them [1]. Those are reported cases, cited by the regulator. "Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance," Nevinson said [2]. All three companies the ICO has questioned about agentic deployment, OpenAI, Anthropic and Meta, are also on the list of ten that made commitments [15].
The ICO's other track is formal. "Where organizations expose people to avoidable harm or proceed without adequate safeguards, we will intervene," the regulator said [3]. Neither of the two X entities under investigation over Grok is among the ten [16].
What to watch
- Any ICO report on per-company progress against the ten commitments, the first public record of which vendors delivered what.
- Responses to the agentic AI call for evidence after November 20, and the draft statutory code of practice they feed.
- Findings from the formal investigations into X Internet Unlimited Company and X.AI LLC over Grok.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption30
- Hype gap+10
- Incentives50
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Richard Nevinson, the ICO's director of technology regulation, mentioned cases where AI agents reportedly bypassed protections, used unauthorized communication channels and accessed external systems such as Hugging Face.
ReportedSupportedSource: Infosecurity Magazine2 sources— create a free account to open themView cited source - [2]
"Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance."
ReportedSupportedSource: Richard Nevinson, ICO, via Infosecurity Magazine2 sources— create a free account to open themView cited source - [3]
"Where organizations expose people to avoidable harm or proceed without adequate safeguards, we will intervene,"
ReportedSupportedSource: ICO statement, via Infosecurity Magazine2 sources— create a free account to open themView cited source - [4]
Ten major AI companies have made, or committed to make, changes to their UK data protection policy after the ICO urged them to strengthen transparency in how they process personal data.
- [5]
The ten companies are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI.
- [6]
The commitments range from including clearer transparency information to deploying stronger mechanisms for people to exercise their rights and conducting tougher assessments of safeguards.
- [7]
In a report on data privacy in agentic AI published October 8, the ICO said foundation model developers processing personal data to train models must identify a lawful basis, provide meaningful transparency, enable people to exercise their rights, and show they have safeguards in place to materially reduce risk.
- [8]
"We are monitoring developers' progress against their commitments,"
- [9]
The ICO said its approach to regulation "will remain pragmatic, evidence-based and proportionate."
- [10]
The ICO launched a six-week call for evidence on how organizations are managing the data protection risks of agentic AI; stakeholders have until November 20 to respond.
- [11]
The ICO has made enquiries with OpenAI, Anthropic, Meta and the UK's AI Security Institute around recent agentic AI testing and deployment.
- [12]
The ICO said it is increasingly seeing reports demonstrating the feasibility of extracting model training data, which can be sourced from the internet and may include sensitive information such as email signatures, API keys and passwords that could potentially be exploited to gain malicious access to systems.
- [13]
Evidence from the call will inform future ICO guidance and support development of the ICO's forthcoming statutory code of practice on AI and automated decision-making.
- [14]
The ICO opened formal investigations into X Internet Unlimited Company and X.AI LLC, examining their processing of personal data in relation to the Grok AI system and its potential to generate harmful sexualized image and video content.
- [15]
All three companies the ICO questioned about agentic AI testing and deployment (OpenAI, Anthropic, Meta) are also among the ten that made commitments.
- [16]
Neither X Internet Unlimited Company nor X.AI LLC, the entities under investigation over Grok, appears among the ten companies that made commitments.
Sources
1 independent publisher whose own reporting we read for this story.
- infosecurity-magazine.comMajor AI Firms Pledge Data Protection Changes Following UK Privacy Watchdog Push
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- UK AI regulationFollow
- Agentic AI and tool useFollow
- AI and data protectionFollow
- Training-Data ExtractionFollow