Britain's data protection regulator used its foundation-model supervision programme to extract concrete changes from ten of the world's largest AI developers — and turned its attention to the next problem the same day: AI agents acting on people's behalf.

The Information Commissioner's Office published its findings on 8 October. Ten developers, reported to include OpenAI, Google, Anthropic, Microsoft, Amazon, Apple, Cohere, Meta and DeepSeek, have made or committed to make changes to how they handle UK personal data. An eleventh, Elon Musk's xAI, was dropped from the programme after the ICO opened a formal investigation into the Grok chatbot, covering X Internet Unlimited Company and X.AI LLC.

What the ICO found

The regulator's central complaint is transparency. Developers were not clear enough about how personal data is used to train models, and the ICO raised questions about the lawful basis for that processing. It also rejected the argument that building capable AI excuses weak compliance: in the regulator's framing, "benefiting humanity" is no justification for failing to meet the law.

The commitments obtained centre on two things: clearer explanations to users about AI training data, and making it easier for people to exercise their existing data rights — access, objection and, in some cases, erasure.

From models to agents

The same day, the ICO opened a six-week call for evidence on agentic AI, running until 20 November. It covers security, transparency, accountability, automated decision-making, fairness and lawful use of data, and is aimed at both developers and the organisations that deploy agents.

That is the harder question. When an agent reads your email, books your travel and spends your money, the accountability chain can be genuinely murky: is the developer the controller, the deployer, or the user? Regulators have spent two years mapping model training. The next two look likely to be spent mapping delegation.

Why it matters

Two things distinguish this from a press release. First, pledges made under supervision tend to reappear as expectations in enforcement — the ICO says it will keep monitoring delivery, and the call for evidence is explicitly framed as feeding a statutory code. Second, the UK is deliberately positioning itself as the regulator that extracts concrete operational changes rather than fines, at a moment when AI companies are trying to set the pace of rulemaking themselves.

What to watch

Whether the promised transparency materialises in products rather than policy documents; how the Grok investigation concludes; and how many organisations outside the eleven respond to the agentic AI consultation before it closes on 20 November.