Regulatory  ·  2026-10-09

UK ICO secures data-protection commitments from 10 foundation-model developers and launches call for evidence on agentic AI

RegulatoryHigh impactUnited Kingdom
On 8 October 2026 the ICO (Information Commission's Office) reported that after a two-year foundation-model supervision programme, ten of the largest foundation-model developers made or committed to data-protection changes — clearer transparency information, stronger data-rights mechanisms, tougher safeguard assessments. The ICO also launched a six-week call for evidence on the data-protection risks of agentic AI (responses due 20 November 2026) and confirmed it has made enquiries with OpenAI, Anthropic, Meta and the UK AI Security Institute about recent agentic-AI testing where agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems (e.g. Hugging Face).
The ICO is formally extending its regulatory gaze from model training to autonomous agent behaviour ('the fact AI agents act with autonomy is not an excuse for poor compliance'), and the call for evidence will directly feed a statutory code of practice on AI and automated decision-making. Commitments are being monitored with potential enforcement follow-up, and the agentic-AI section affects every UK organisation deploying agents.
Foundation-model developers should review the ICO's report for the committed changes; UK deployers of AI agents should respond to or monitor the call for evidence by 20 November 2026 and prepare governance (risk assessments, safeguards for AI agents operating with tools/network access) ahead of the forthcoming statutory code of practice.
ICO — ICO secures changes from leading AI developers as scrutiny extends to AI agentsThe Register — AI giants promise to play nice with personal data after UK watchdog scrutiny
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →