Skip to main content
49 days

Super Intelligence definition proposal due (60 days) · Nov 28, 2026 · See what changes

Guides

ICO AI Agents Call for Evidence: What 10 AI Developers Changed

The UK ICO named 10 AI developers that changed data practices and opened an agentic AI call for evidence closing Nov 20, 2026. Tracker and checklist.

11 min readBy Jesus A McKinney
ICO AI Agents Call for Evidence: What 10 AI Developers Changed

Image: Pexels, used under the Pexels License.

TL;DR On October 8, 2026, the UK Information Commissioner's Office (ICO) said ten foundation model developers, Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI, made or committed to data protection changes after a two-year supervision programme. The same day it confirmed enquiries with OpenAI, Anthropic, Meta and the UK AI Security Institute about agent testing, and opened a six-week call for evidence on agentic AI that closes November 20, 2026. Below: a tracker of what each developer changed, what the ICO now expects, and a checklist for teams that deploy these models.

Event date: October 8, 2026. First reported: October 8, 2026, by the ICO itself, The Register and The Next Web. This page was written on October 9, 2026.

Most small teams never deal with a foundation model developer's privacy team directly. You pick a model through an API or a SaaS tool and trust that the vendor sorted out the training data question. The ICO's report is useful because it says, in writing, what it found when it opened those vendors' paperwork, and what each of them agreed to fix. That gives you a concrete list to check your own vendors against, and a reason to look at your own agent deployments before the ICO's guidance arrives.

What the ICO announced on October 8

The ICO published three things at once: a news release, a report titled "Building trust and transparency into generative AI development", and a call for evidence on agentic AI.

Screenshot of the ICO news release dated 8 October 2026, headed ICO secures changes from leading AI developers as scrutiny extends to AI agents

Screenshot: ICO news release, 8 October 2026, ico.org.uk.

According to the release, the ten developers have "made, or committed to make, data protection changes." The ICO groups them into three kinds: "clearer transparency information, stronger mechanisms for people to exercise their rights and tougher assessments of safeguards." It says it is monitoring progress against those commitments.

The supervision programme started in 2025 under the ICO's AI and biometrics strategy. It ran over two years and covered 11 priority developers, chosen by likelihood of non-compliance, UK market share and use of higher-risk training datasets. The eleventh was X.AI. The ICO paused that engagement after it opened a formal investigation into the Grok AI system, and says that investigation is ongoing.

Richard Nevinson, the ICO's Director of Technology Regulation, said the engagement "has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area."

The ICO was also unusually frank about the limits. It said "current foundation model training practices present technical challenges when it comes to complying with UK data protection law," and that it is raising those boundaries of the law with Government. The Register put it more bluntly: "Getting companies to promise changes is one thing. Making today's AI models comply with the law is another."

One structural note: this is among the first big announcements under the ICO's new governance. Under the Data (Use and Access) Act 2025, a new Information Commission Board now oversees the office. The Next Web reported that the last commissioner, John Edwards, resigned in June.

Tracker: what each of the 10 developers changed

The report reviewed developers against five parts of the UK GDPR: legitimate interests (article 6(1)(f)), special category data (article 9), transparency (articles 13 and 14), the right of access (article 15) and the right to object (article 21). The table below lists what the ICO says each developer did on legitimate interests assessments (LIAs) and on transparency. "Made" means the ICO says the change is done. "Committed" means the ICO says the developer will make it.

Developer Legitimate interests assessment (LIA) Transparency
Amazon No developer-specific LIA item listed Made changes or committed to some or all of the ICO's listed measures
Anthropic Made: updated its non-user privacy policy and its LIA, including the efficacy of safeguards Made changes or committed to some or all of the listed measures
Apple Committed: will update privacy documentation and LIA. Made: published a page on training data sources, completed a compatibility assessment for web-crawled data Made changes to transparency information
Cohere No developer-specific LIA item listed Made changes to transparency information
DeepSeek Made: produced an LIA. Committed: will update its privacy policy on third-party personal data in training Made changes or committed to some or all of the listed measures
Google Committed: will cite further evidence in its LIA on safeguard efficacy Made changes or committed to some or all of the listed measures
Meta Made: provided memorisation testing results and survey findings on its transparency materials Made changes or committed to some or all of the listed measures
Microsoft Committed: will review its LIA for evidence-based assessment of safeguards Made changes or committed to some or all of the listed measures
OpenAI Made: updated its LIA to strengthen evidence of safeguard efficacy Made changes to transparency information
Stability AI Committed: will review its privacy policy and update its LIA Made changes or committed to some or all of the listed measures

The transparency changes at Apple, Cohere and OpenAI include standalone model training privacy notices, a summary of third-party datasets used for training, and more information on development stages, retention, international transfers and people's rights. For the other seven, the listed measures include standalone information on model development, non-technical summaries of training data sources, better routes to exercise rights, and privacy notice updates on retention and on whether training data is transferred overseas.

The ICO does not say which of the seven made which change. If one of them is your vendor, that is the first question to ask: which of the measures are live today, and where are they published?

On special category data, the ICO saw developers using deduplication, filtering and testing across multiple languages, plus hash-matching, machine learning classifiers, human curation and dedicated CSAM detection tools. Where no article 9 condition fits, the ICO says developers "should focus on implementing measures to prevent the collection of special category data, filter it out or avoid processing it."

What the ICO now expects, and why deployers should read it

A magnifying glass held over an old handwritten ledger, representing the ICO's scrutiny of legitimate interests assessments

Image: Pexels, used under the Pexels License.

The report's expectations are written for developers, but most of them apply to any company that fine-tunes a model or reuses customer data to improve an AI feature. Four points stand out.

Vague purposes will not pass. The ICO says broad interests such as "developing and improving our products and services", "training our models" or "benefitting humanity" are unlikely to meet the requirement without specification or justification. Its necessity test "should include an analysis of any less intrusive alternatives, such as synthetic data."

Safeguards need evidence. "General or unsubstantiated claims about the efficacy of safeguards are unlikely to be sufficient." Burges Salmon's reading: the regulator "has now shown, in public, what it looks for when it opens an LIA, and the answer is evidence rather than assertion."

Reusing account data for training has a checklist. If you reuse prompts, conversations or uploaded files to train or improve a model, the ICO says you should explain it clearly, assess whether the new use is compatible with the original purpose, state whether you use historical data or only data from a specific date, and tell users the categories, the period and how to opt out.

Deployers are in the chain. The ICO says developers should take responsibility for making sure everyone in the training data supply chain, "including data brokers and deployers," meets their transparency obligations. Burges Salmon expects that "to be pushed down the chain through contractual terms." In practice, expect new questionnaire items and contract clauses from your AI vendors.

The ICO also restated that "AI models themselves can contain personal data and can therefore be subject to data protection law." It criticised layered notices that created a "privacy maze" for users. If your own AI feature hides its training opt-out three clicks deep, that criticism applies to you too.

The agent enquiries: OpenAI, Anthropic, Meta and AISI

A robotic hand with exposed wires reaching toward a keyboard, representing AI agents acting with limited human oversight

Image: Unsplash.

The second half of the release matters more for teams running agents. The ICO said: "We have recently made enquiries with OpenAI, Anthropic, Meta and the UK's AI Security Institute around recent agentic AI testing and deployment." In some cases, it said, "certain agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face."

The notes to editors add that the enquiries are ongoing, and that the ICO contacted several developers and their testing partners "to establish what risk assessments and safeguards were in place at the time." No finding or penalty has been announced. We covered the reported incidents themselves in our OpenAI agent incident tracker and the Hugging Face breach report.

Nevinson's line is the one to pin above your agent rollout plan: "Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance."

The call for evidence: sections, deadline, who can answer

Screenshot of the ICO Agentic AI call for evidence page showing start date 8 October 2026, closing date 20 November 2026 and the list of survey sections

Screenshot: Agentic AI call for evidence, ICO consultations page, ico.org.uk.

The call opened on 8 October 2026 and closes at the end of 20 November 2026. The ICO wants views "from developers, deployers and other experts" on how organisations manage the data protection risks of agentic AI. Responses go through a Citizen Space survey with eight sections:

  1. About you and your organisation
  2. Data Security
  3. Transparency
  4. Accountability
  5. Automated Decision Making (ADM)
  6. Fairness and purpose limitations
  7. Lawfulness of Processing
  8. Additional questions

The evidence will feed dedicated guidance on agentic AI and the ICO's forthcoming statutory code of practice on AI and automated decision-making. Two practical notes from the consultation page: the ICO "may not consider responses received after this deadline," and it may publish organisations' responses in full or in summary. Do not put anything in a response you would not want made public.

Should a small team respond?

Respond if any of these is true:

  • You run an agent in production that touches personal data, such as an inbox triage agent, a support agent with CRM access or a coding agent with access to customer databases.
  • You have hit a practical problem the ICO could clarify, for example how to give a privacy notice for actions an agent takes on its own, or how to log agent decisions for an access request.
  • You sell an agent product to UK customers and want the guidance to reflect how small vendors actually build.

Skip it if you only use chat assistants with no tool access. Your time is better spent on the vendor checklist below.

Checklist: questions to send your AI vendor this week

Copy this into an email or your vendor review form. Each question maps to an item the ICO reviewed.

Subject: UK GDPR follow-up after the ICO foundation model report (8 Oct 2026)

1. The ICO report lists changes your company made or committed to make.
   Which are live today, and where are they published?
2. Do you publish a standalone privacy notice for model training?
   Please send the link.
3. Does that notice explain retention of training data and whether
   training data is transferred overseas?
4. Has your legitimate interests assessment been updated to include
   evidence that your safeguards work (for example memorisation testing)?
   Can you share a summary under NDA?
5. Is any of our account data (prompts, files, outputs) used to train or
   improve your models? From what date, which categories, and how do we
   opt out at the account level?
6. What filtering do you apply to special category data in training sets?
7. How do people whose data may be in your model exercise access and
   objection rights? Who do we send such a request to?
8. For agent features: what stops the agent from reaching systems or
   channels outside its assigned scope, and how are we told if it does?
9. Has your company received ICO enquiries about agent testing or
   deployment? If so, will you tell us what was asked and what you answered?

Questions 1 to 7 come straight from the report's findings. Questions 8 and 9 follow from the agent enquiries. For contract wording that backs up question 8, see our agentic AI vendor contract clauses.

Checklist: your own agent deployment, mapped to the ICO sections

Use the call-for-evidence sections as a self-review, whether or not you respond. Record the answers in your agent data controls register or your GDPR article 30 record.

ICO section Question to answer for each agent Evidence to keep
Data security Which systems, credentials and channels can the agent reach? Is access limited to the task? Permission list, credential scope, blocked domains
Transparency Do the people whose data the agent handles know an agent is acting? Privacy notice text, in-product disclosure
Accountability Who owns the agent, approves changes and reviews its logs? Named owner, change log, log review dates
Automated decision-making Does the agent make decisions with legal or similarly significant effects on people? Decision list, human review step
Fairness and purpose limitation Is the agent using data only for the purpose it was collected for? Purpose statement, data inputs list
Lawfulness of processing What lawful basis covers what the agent does with personal data? LIA or other basis record

If you rely on legitimate interests for an agent, write the interest specifically and attach evidence that your safeguards work. The ICO's comments on vague purposes and unproven safeguards were aimed at the biggest developers. There is no reason to think a smaller deployer would be held to a looser standard.

Does this reach you if you are not in the UK? Article 3(2) of the UK GDPR covers controllers outside the UK that offer goods or services to people in the UK, "irrespective of whether a payment of the data subject is required." A US or EU SaaS company with UK users is likely in scope. Check with counsel for your own case.

What practitioners are saying

We found no Reddit thread about this announcement. A thread in r/gdpr from October 3 on whether every internal AI tool needs a DPIA shows how UK teams already handle the screening step the ICO's work points toward. One commenter at a UK fintech wrote: "Each new vendor, tool and even process has short assessment, like 10 question. It's based on ICO template." A full DPIA follows only if that screening flags likely high risk (comment).

Another pushed back on doing assessments per tool: "You should not do a DPIA for tools but for processing activities that meet the high risk criteria set out in Art. 35" (comment). That distinction fits agents well. One agent can run several processing activities, and each may need its own answer.

Our take

The tracker is the useful part, and it is also where the report is weakest. For seven of the ten developers, the ICO says only that they "made changes or committed to implementing some or all" of a list of measures. That wording does not tell a customer what is actually live. A buyer can close that gap with one email, and the ICO has given you the exact items to ask about.

The agent enquiries matter more than the commitments. The ICO named three developers and a government institute, said what reportedly went wrong, and said it asked about risk assessments and safeguards "in place at the time." That is the question it will ask a deployer too. If an agent of yours reached a system it should not have, could you show what safeguards were in place that day? For most small teams the honest answer today is a permissions list nobody has reviewed. The call for evidence gives you six weeks of notice. Use it to write that record before the guidance and the code of practice turn it into an expectation.

We would not over-read the "commitments" framing either way. The ICO said it will use "the full range of our regulatory powers" where practices expose people to harm, and it has an open formal investigation into Grok. Supervision with published commitments is the soft path, not the only one.

How we checked this

This page uses 6 independent source domains: the ICO (news release, the report's supervision, expectations and next steps pages, and the call for evidence page), The Register, The Next Web, Burges Salmon, legislation.gov.uk for UK GDPR article 3, and one r/gdpr thread. We opened each source and matched a verbatim quote for every fact in our source log on October 9, 2026. Last reviewed: October 9, 2026.

What we could not verify

We did not read the MLex report, which is paywalled. We did not check The Next Web's mention of an upcoming committee hearing with MPs, so it is not on this page. We could not verify a post from the ICO's X account about the announcement because we had no working X reader, so this page has no social embed. We found no Reddit discussion of this exact announcement, which is why the quotes above come from a related thread and are labelled as such. The ICO has not published the content of its agent enquiries or any responses from OpenAI, Anthropic, Meta or the AI Security Institute.

Legal disclaimer

This article is published for informational and educational purposes only. It does not constitute legal, regulatory, or professional compliance advice and should not be relied upon as such. AI governance requirements vary by jurisdiction, industry, and organizational context. Always consult a qualified legal or compliance professional before implementing policies or making decisions with regulatory implications.

About the author

Jesus A McKinney

AI Implementation Specialist

AI implementation specialist focused on hands-on templates, step-by-step guides, and practical workflows for small teams adopting AI tools responsibly.

  • AI implementation practitioner
  • Workflow design for small teams
  • AI tool evaluation and deployment
  • Practical governance template author