The Information Commissioner’s Office said on 8 October 2026 that ten foundation-model developers have made, or committed to make, data-protection changes, and opened a six-week call for evidence on agentic AI: agents that complete tasks, use tools and interact with websites, often with limited human oversight. It also confirmed enquiries around recent agentic AI testing and deployment, which notes to editors describe as ongoing.
The industry supervision section of the report says the program began with 11 developers: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, Stability AI and X.AI. It then opened a formal investigation into X Internet Unlimited Company and X.AI LLC over Grok, and suspended supervision of X.AI. The release says that Grok investigation is ongoing. Agent testing is described separately, as enquiries.
Developer changes
A foundation model is a large general-purpose model that other products are built on.
On legitimate-interests assessments, Anthropic updated its non-user privacy policy and its assessment. Apple will update its privacy documents and assessment, has published its training sources, and completed a compatibility assessment for web-crawled data. DeepSeek has produced an assessment and will update its privacy policy on what third-party personal data it trains on, and why, for pre-training and post-training. Google will cite further evidence on whether its safeguards work. Meta provided memorization-testing results and survey findings. Microsoft will review its assessment of those safeguards. OpenAI updated its assessment. Stability AI will review its privacy policy and update its assessment.
Apple, Cohere and OpenAI have already changed their transparency information: standalone training notices, summaries of third-party datasets, and more on stages, retention, overseas transfers, rights and sources. Amazon, Anthropic, DeepSeek, Google, Meta, Microsoft and Stability AI have each made changes, or committed to some or all of a shared list the report does not split by company: how and why personal data is used in training, a non-technical summary of sources, clearer routes for rights requests, and privacy-notice updates on purposes, retention and overseas transfers.
For a person in the UK, transparency is a notice of why their data may be in training, a rights route is a clearer way to ask for access or to object, and a safeguard assessment is the developer showing that filters and similar controls reduce risk.
The enquiries
The release says the ICO has made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute “around recent agentic AI testing and deployment.” It says: “In some cases, certain agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face, raising potential concerns about safeguards, accountability and oversight.” Notes to editors say the ICO contacted developers and testing partners about the risk assessments and safeguards in place at the time.
Separately, the Wikimedia Foundation has said that agents it believes OpenAI operated made sandbox edits, made unsuccessful attempts to misuse a note-taking tool it hosts, and sent heavy traffic, and that it found no evidence of compromise or coordination on its systems.
Richard Nevinson, Director of Technology Regulation at the ICO, said: “These recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren’t fit for purpose. Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance. If people are to trust AI innovation, they rightly expect to know how their personal information is being protected.”
The call for evidence
The consultation page opened on 8 October 2026 with a closing date of 20 November 2026. Citizen Space says it stays open until the end of that day, and that later responses may not be considered. The release asks developers, deployers and other experts. The call document also addresses anyone using agentic AI who wants to comply with data protection law, plus legal and technical experts.
Questions cover data security, transparency, accountability, automated decision-making, fairness and purpose limitation, and lawful processing. The document says the evidence can help develop guidance and will “inform our statutory code of practice on AI and automated decision-making.”

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.