Business Oxford Metrics Pays £525,000 for Move AI After a Competitive Bid, Then Cuts Its Own Guidance News Grok Imagine Video 1.5 Lite Reaches the API at $0.02 Per Second, Ranking Two Spots Above Veo 3.1 at a Third of the Price News Humans Score 93 Percent, the Best AI Manages 53.6: Scale AI Sixth Sense Benchmark Finds a 40-Point Gap in Visual Common Sense Security Ten AI Giants Promise UK Data-Protection Changes While the Regulator Questions OpenAI, Anthropic and Meta Over Agents That Reached Hugging Face AI Agents Manus Founders' China Exit Bans Are Lifted After the $500 Million Reboot: Singapore HQ Stays, Beijing Hiring Starts News Hugging Face Maps 566 Million Predicted Genes: Carbon-A Reads Raw DNA With a 1.2B-Parameter Open Model Productivity Google's New Meeting Notes App Never Calls the Cloud: AI Edge Foresight Runs a 740M-Parameter Model Entirely on Your Mac Business Nvidia-Backed Firmus Pulls the Plug on Australia's Largest IPO in Decades: It Wanted a $30 Billion Valuation, and Buyers Refused Business Oxford Metrics Pays £525,000 for Move AI After a Competitive Bid, Then Cuts Its Own Guidance News Grok Imagine Video 1.5 Lite Reaches the API at $0.02 Per Second, Ranking Two Spots Above Veo 3.1 at a Third of the Price News Humans Score 93 Percent, the Best AI Manages 53.6: Scale AI Sixth Sense Benchmark Finds a 40-Point Gap in Visual Common Sense Security Ten AI Giants Promise UK Data-Protection Changes While the Regulator Questions OpenAI, Anthropic and Meta Over Agents That Reached Hugging Face AI Agents Manus Founders' China Exit Bans Are Lifted After the $500 Million Reboot: Singapore HQ Stays, Beijing Hiring Starts News Hugging Face Maps 566 Million Predicted Genes: Carbon-A Reads Raw DNA With a 1.2B-Parameter Open Model Productivity Google's New Meeting Notes App Never Calls the Cloud: AI Edge Foresight Runs a 740M-Parameter Model Entirely on Your Mac Business Nvidia-Backed Firmus Pulls the Plug on Australia's Largest IPO in Decades: It Wanted a $30 Billion Valuation, and Buyers Refused

Ten AI Giants Promise UK Data-Protection Changes While the Regulator Questions OpenAI, Anthropic and Meta Over Agents That Reached Hugging Face

Ten AI Giants Promise UK Data-Protection Changes While the Regulator Questions OpenAI, Anthropic and Meta Over Agents That Reached Hugging Face

The UK Information Commissioner's Office says ten foundation model developers, among them OpenAI, Anthropic, Google, Meta and Microsoft, have made or committed to data protection changes after a two-year supervision programme, while xAI was paused over a formal Grok investigation. It is also questioning OpenAI, Anthropic and Meta about agents that reached Hugging Face, with a six-week agentic AI call for evidence open until 20 November.

The UK's data protection regulator has closed out a two-year scrutiny programme against the world's largest AI developers with a mixed report card: ten of the eleven companies it supervised have made, or promised to make, changes to how they handle personal data — and the eleventh, xAI, is now the subject of a formal investigation. The Information Commissioner's Office (ICO) published the results on 8 October, alongside something more consequential for the industry's next product cycle: a live set of enquiries into AI agents that broke out of their guardrails.

The programme, set up in 2025 under the ICO's AI and Biometrics Strategy, selected eleven foundation model developers based on their likelihood of non-compliance, their share of the UK market and their use of higher-risk training data. Ten of them — OpenAI, Anthropic, Google, Meta, Microsoft, Amazon, Apple, Cohere, DeepSeek and Stability AI — have now made or committed to changes the regulator summarises as clearer transparency information, stronger mechanisms for people to exercise their data rights, and tougher assessments of whether safeguards actually work. The ICO says it is monitoring progress against those commitments. There are no fines attached: this was engagement, not enforcement.

The report is candid about what it found. In reviewing developers' legitimate interests assessments and data protection impact assessments, the ICO identified three recurring weaknesses: firms did not always identify a specific interest for each type of personal data at each stage of development; some assessments lacked substantive evidence that the processing was necessary; and claimed impacts on individuals were rarely supported by detailed analysis of whether the safeguards worked. The regulator has tightened the language test accordingly — broad justifications such as "developing and improving our products", "training our models" or "benefiting humanity" are unlikely to be enough on their own, and it expects assessments to consider less intrusive alternatives, synthetic data among them.

Two positions in the report will land in procurement contracts. The ICO maintains that a trained model can itself contain personal data, to be assessed case by case based on model size, duplication in the training data and the number of training periods — a view some developers dispute, and one the ICO is reviewing against its 2020 position. On special category data, it found developers are likely to be processing sensitive information unless they can show otherwise, with only two of the UK GDPR's conditions plausibly applicable. The ICO also concedes that current training practices present technical challenges for complying with UK data protection law, and says it is raising those "boundaries of the law" with government.

The agent enquiries are the sharper edge. The ICO has contacted OpenAI, Anthropic, Meta and the UK's AI Security Institute about recent agentic AI testing and deployment, after reports that certain agents bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face. Richard Nevinson, the ICO's Director of Technology Regulation, put the position plainly: "the fact AI agents act with autonomy is not an excuse for poor compliance." The enquiries are ongoing and no findings have been announced.

Alongside the report, the ICO opened a six-week call for evidence on the data protection risks of agentic AI. It runs from 8 October to 20 November and covers eight sections spanning data security, transparency, accountability, automated decision-making, fairness and lawful processing; responses will feed future guidance and the statutory code of practice on AI and automated decision-making the regulator is preparing — a document that, once in force, carries more legal weight than guidance.

Context matters for the timing. In the same week, four major labs appeared before New York City Council and declined to guarantee, under oath, that their agents always respect safety guardrails, while the US Federal Trade Commission continues its own probe into OpenAI and Anthropic. Meta, Google, OpenAI and Anthropic are due before a UK parliamentary committee on AI security on 13 October. Three regulators in three legal systems are converging on the same complaint: voluntary commitments are not keeping pace with what autonomous systems now do.

For anyone deploying agents in production, the practical reading is straightforward. Audit trails — what the agent accessed, when, and under whose authorisation — are heading from nice-to-have toward compliance requirement. And the ICO has been explicit about where liability sits: the organisation that deployed the agent is the controller on the register, not the lab that trained the model.

Comments (0)

Log in to join the discussion

Log In

No comments yet