The Information Commission’s Office (ICO) has secured data protection improvements from ten of the world’s largest AI foundation model developers in a new report published today.
It comes as the data protection regulator launches a call for evidence on agentic AI and confirms enquiries around recent agentic AI testing, marking the next phase in its work to regulate the technology.
Industry improvements to foundation models
From chatbots to assistants, many AI tools are powered by a relatively small number of foundation models. They are trained on large volumes of personal data and can be adapted for different purposes.
Following scrutiny from the ICO, ten of the biggest foundation model developers operating in the UK – Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI – have made, or committed to make, data protection changes.
These included clearer transparency information, stronger mechanisms for people to exercise their rights and tougher assessments of safeguards. The ICO is monitoring developers’ progress against their commitments.
The report also sets out the ICO’s regulatory positions on key issues, including how special category data can be used lawfully and whether foundation models themselves may contain personal data.
The ICO acknowledges that current foundation model training practices present technical challenges when it comes to complying with UK data protection law and data protection by design principles.
The regulator is proactively raising these boundaries of the law with Government, as addressing them will require ongoing collaboration between industry, regulators and Government as the technology continues to evolve.
The rise of AI agents
Foundation models underpin a new wave of AI agents capable of completing tasks, using tools and interacting with websites, often with limited human oversight.
As these systems become more autonomous, the data protection risks are evolving – from questions about how AI systems are trained to how they might behave independently once deployed.
Richard Nevinson, Director of Technology Regulation at the ICO, said: “AI has huge potential to benefit our society, but that depends on trust and transparency.
“Our engagement with some of the biggest developers has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area. But as AI systems operate with greater autonomy, robust data protection safeguards become even more critical.”
The ICO has today launched a six-week call for evidence, seeking views from developers, deployers and other experts on how organisations are managing the data protection risks of agentic AI.
The ICO has recently made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute around recent agentic AI testing and deployment.
In some cases, certain agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face, raising potential concerns about safeguards, accountability and oversight.
Richard Nevinson added: “These recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren’t fit for purpose.
“Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance. If people are to trust AI innovation, they rightly expect to know how their personal information is being protected.”
Recommended reading
- New Scottish Centre of Excellence For Digital Trust Launches
- Businesses Given One Month to Meet New ICO Data Protection Complaints Rules
- How Important Are Digital Trust Frameworks to Firms?
- DIGIT Expo 2025 | Is Digital Consumer Trust on The Brink?
The evidence gathered from the call will inform future ICO guidance, providing greater clarity to organisations and supporting them to innovate responsibly while protecting people’s rights. It will also support the development of the ICO’s forthcoming statutory code of practice on AI and automated decision-making.
Another priority area for the ICO is the increasing personalisation of consumer-facing AI services, such as popular general-purpose chatbots and chatbots used for role-play and companion purposes.
The regulator is conducting research with the public to understand any concerns and engaging with firms to ensure that their products meet people’s needs in a transparent and privacy-focused way.





