Skip to content
Saturday, October 10, 2026
Media Rounds

The day's top stories, rounded up.

Subscribe

Technology

UK Regulator Secures Data Commitments From Ten Major AI Developers

The United Kingdom's data protection regulator, the Information Commissioner's Office, said this week that ten of the largest artificial-intelligence developers — including OpenAI, Google, Microsoft, Amazon, Anthropic and…

Share WhatsApp Facebook X LinkedIn Email
Image: Wikimedia Commons (CC BY 2.0)

The United Kingdom’s data protection regulator, the Information Commissioner’s Office, said this week that ten of the largest artificial-intelligence developers — including OpenAI, Google, Microsoft, Amazon, Anthropic and Apple — have changed how they handle personal data, or committed to doing so, following a compliance review of how AI systems are trained and deployed. The ICO announced the outcome on Thursday and said its next focus would be autonomous AI agents.

The commitments cover three areas: clearer explanations of how personal information is used to train models; better mechanisms for people to exercise their rights over their data; and tougher internal assessments of the safeguards developers maintain. The programme began in 2025 covering eleven developers; the count dropped to ten after the regulator paused its engagement with Elon Musk’s xAI to pursue a separate formal investigation into the Grok chatbot.

The ICO framed the result as evidence that supervisory engagement — regulators inside the tent, pressing for changes — can extract real concessions without litigation. Its technology regulation director said the benefits of AI depend on public trust and transparency, and that the process had secured commitments that help people understand and control how their information is used.

The regulator was equally clear that the matter is not closed. It acknowledged that current training practices still raise unresolved problems under UK data protection law, including personal data absorbed into trained models, the difficulty of removing a person’s information after training, and the risk of sensitive details being extracted from models. Those questions, it said, will require cooperation among industry, regulators and government — which is another way of saying that nobody currently knows the answers.

For users, the practical change is modest but real: better notices, clearer rights, and a regulator now publicly committed to watching whether the industry keeps its word.

The agents question, which the ICO says comes next, is thornier than the training question it is wrapping up. An agent that books, buys, writes and negotiates in a person’s name collapses distinctions data law was built on — whose data, whose consent, whose instruction — and does so at machine speed. By flagging agents now, while the products are young, the regulator is attempting the feat it missed with social media: writing expectations before practices harden. The commitments model will be tested there far more severely, because agents do not merely process personal data — they exercise it. Industry response to this week’s announcement was uniformly welcoming, which, as the ICO itself will know, costs nothing. The monitoring it promised is where the price will be set.

Recent articles by Media Rounds Business & Technology Desk