P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

ICO details changes at 8 of 10 AI developers: 3 done, 3 promised, 2 both, and none dated

The ICO's report says ten AI developers have made or committed to make data protection changes, but prints a line for only eight, some in the past tense and some in the future. It dates none of them, and a call for evidence on agentic AI closes on 20 November.

By Parminder Kumar Sharma · · 31 min read

A regulator's desk at dusk with a row of identical pale grey-blue folders, some with a blank sheet sliding out, a printed checklist with empty boxes, a pen and an open laptop showing a blank response form. No people. Overlaid text reads ICO details changes at 8 of 10 AI developers, and dates none of them, plus 8 of 10, developers with a line of their own: 3 done, 3 promised, 2 both.

8 of 10 developers get a line, and no change is dated

The Information Commissioner's Office (ICO) published a report on foundation model developers on 8 October 2026 and said in a news item that ten of them, Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI, "have made, or committed to make" data protection changes. The report's Industry Supervision page gives eight of the ten a line of their own in its list of changes. Those eight lines take 291 words of the page's 1,574 words of body text, about 18 per cent (derived, our count). Amazon and Cohere have no line of their own anywhere in the report: each is named twice in the report's landing page and five sections, once in the ICO's list of 11 priority developers and once inside a group (derived, text search).

By the ICO's own verbs, the eight lines split three ways (derived, our reading). Anthropic, Meta and OpenAI are described only in the past tense: "updated", "has provided". Google, Microsoft and Stability AI are described only in the future: "will cite", "will review". Apple and DeepSeek are described in both. Counted as separate actions, the eight lines hold 14, seven in the past tense and seven in the future (Apple's "privacy documentation and LIA" is counted as two). None carries a date or a deadline. The report prints dates against two company help pages, OpenAI's of 14 August 2026 and Anthropic's of 8 July 2026, in footnotes that cite them as examples of rights guidance. It does not present either as a commitment.

That fact does not establish that any developer has breached the law, that any change is binding, or that the changes are complete. The report states no finding against a named developer among the ten, and the words "binding", "voluntary" and "penalty" appear nowhere in it or in the news item (derived, text search). About half of the itemised actions are still "will". The ICO says only that it is "monitoring developers' progress against their commitments", without saying how, by when or with what consequence.

Two things in the coverage do not match the ICO's pages. Infosecurity Magazine called the document "a new report on data privacy in agentic AI". Its title is "Building trust and transparency into generative AI development: our work to create regulatory certainty", and the word "agentic" appears four times in its landing page and five sections against 84 mentions of "foundation model" (derived). Its agentic material is one paragraph in the Introduction plus a separate call for evidence. The coverage also says the ten made or committed to make changes to "their UK data protection policy". Seven of the eight lines concern a legitimate interests assessment (LIA), which the report does not say is published, and four mention a privacy policy or privacy documentation (derived).

The ICO wrote the report, the news item and the headline, "ICO secures changes from leading AI developers", so the summary is its own account of its own programme. The developers have their own interest in how any change is described. This briefing reads each document for what it says and makes no claim about what any developer does in practice.

What the ICO states, and what the coverage adds

The ICO published three documents with three jobs: a news item, a report on foundation model developers, and a separate call for evidence on agentic AI. The table sets the ICO's wording beside the coverage of 9 October.

The ICO news item, report and call for evidence (8 October 2026) against Infosecurity Magazine (9 October 2026), compared by hand.

PointThe ICO's pagesInfosecurity Magazine
What the report isBuilding trust and transparency into generative AI development, about foundation model training. Its Introduction mentions agentic AI and reported incidents.A new report on data privacy in agentic AI.
Which developersTen, from 11 priority developers. The eleventh, X.AI, was paused after a formal investigation the ICO says is ongoing.Ten major AI companies, named. The formal investigations are reported separately.
What changedMade, or committed to make, changes: transparency information, mechanisms for rights, assessments of safeguards.Made, or committed to make, changes to "their UK data protection policy".
WhyFollowing scrutiny from the ICO, and in response to its regulatory expectations, after a supervision programme.After the ICO urged them to strengthen transparency.
Monitoring"We are monitoring developers' progress against their commitments."Repeats the sentence.
AgentsA call for evidence from 8 October to 20 November, and enquiries with OpenAI, Anthropic, Meta and the AI Security Institute.The same two facts.
Company statementsNone in the news item or the report.None quoted.

On the eleven, the ICO's notes to editors say the programme covered developers "identified by likelihood of non-compliance, UK market share, and use of higher-risk training datasets". That describes how the list was chosen. It is not a finding about any developer on it, and the report's own account of its selection factors (information requests, its initial analysis, and public information on market share and training datasets) does not use that phrase. The ICO separately says it has opened formal investigations into X Internet Unlimited Company and X.AI LLC over the Grok AI system. An investigation is not a finding, and X.AI is not one of the ten.

What the ICO prints for each developer

The Industry Supervision page names developers in two places. The first is a list of changes to legitimate interests assessments, introduced as changes developers "have made, or are committed to making". The table condenses each line and gives its tense. Every developer is read the same way.

The ICO's list of changes by developer, Industry Supervision page, read on 9 October 2026. Tense is our reading of the verbs.

DeveloperThe ICO's line, condensedTense
AnthropicUpdated its non-user privacy policy to explain the distinct purposes of processing across model development. Updated its LIA to detail the efficacy of safeguards, including for misaligned behaviour or bias.Past only
AppleWill update its privacy documentation and LIA with the purposes of processing training data and its safety measures and exclusion filters. Has published a webpage on training data sources and completed a compatibility assessment on web-crawled data.Future and past
DeepSeekHas produced an LIA. Will update its privacy policy to explain what third-party personal data is in training datasets and why it is collected for pre-training and post-training.Past and future
GoogleWill cite further evidence in its LIA for the efficacy of its safeguards, including learnings from testing and benchmarking.Future only
MetaHas provided additional evidence of the efficacy of its approach, including memorisation testing results and survey findings on its transparency materials.Past only
MicrosoftWill review its LIA to consider the evidence-based assessment of safeguards.Future only
OpenAIUpdated its LIA to further strengthen evidence of the efficacy of its safeguards.Past only
Stability AIWill review its privacy policy to explain its processing purposes in greater detail, and update its LIA to strengthen assessments of safeguards.Future only
AmazonNo line of its own.Not stated
CohereNo line of its own.Not stated

Counting developers is less sensitive to how phrases are split than counting actions, which is why this briefing leads with 3, 3, 2 and 2. Microsoft's and Stability AI's "review" is a commitment to look again, not necessarily to change. The ICO does not say.

The second place is the Transparency and information rights part. Apple, Cohere and OpenAI "have made changes to the transparency information they provide". The ICO says this includes standalone model training privacy notices, a summary of third-party data sets used for training, more on the stages of development, retention, international transfers and people's rights, and the sources and types of information used. It lists these for the three together, not for each. Amazon, Anthropic, DeepSeek, Google, Meta, Microsoft and Stability AI "have each made changes or committed to implementing some or all" of five measures:

  • standalone information on foundation model development: how and why personal data is processed across training stages, and the safeguards;
  • non-technical summaries of the types and sources of information used to train;
  • improved information to enable people to exercise their data protection rights;
  • updated privacy notices on purposes and legitimate interests, retention and overseas transfers;
  • more evidence on the efficacy of safeguards, through updated LIAs.

For those seven the report does not say which measure, or whether it was made or only committed. That includes Amazon: no sentence in the report says what Amazon has done or will do.

The three types of change the news item names, set against the report. Developer lines are the eight in the legitimate interests list; the rest is the report's group sentences and examples.

Type the ICO namesDevelopers whose own line covers itElsewhere in the report
Clearer transparency informationAnthropic, Apple, DeepSeek and Stability AI (a privacy policy, privacy documentation or a sources webpage): four of eight.Apple, Cohere and OpenAI jointly made changes; seven developers share a menu of five measures.
Stronger mechanisms for people to exercise rightsNone of the eight lines.Cited as examples of existing mechanisms: Meta (an objection process and a form for third parties), Apple (an objection route for web crawling, for users and non-users), OpenAI (guidance on removing personal data from responses), Anthropic (guidance on privacy and personal data). A group measure covers the seven.
Tougher assessments of safeguardsSeven of eight name an LIA; Meta gives evidence of efficacy instead.A group measure covers more evidence through updated LIAs.

So the news item's second type, stronger mechanisms for rights, has no developer-level change behind it in the report. It rests on a group measure and on examples of mechanisms that already existed. Counting every mention across the report's landing page and five sections (derived), Meta is named 11 times, Apple 10, Anthropic 7, OpenAI 6, Microsoft 4, DeepSeek 3, Google 3, Stability AI 3, Amazon 2 and Cohere 2.

The page is specific about what it found and silent on who. It says firms "didn't always clearly identify specific interests", that some "did not have substantive evidence" for necessity, and that they "rarely supported" impacts with detailed analysis. In the rights section it describes a "privacy maze" and says some developers took a "blanket, one-size-fits-all approach to refusing requests". It attributes none of this to a named developer.

A tall single-column list of fourteen boxes. Anthropic, Meta and OpenAI are blue: past tense only. Google, Microsoft and Stability AI are orange: future tense only. Apple and DeepSeek are grey: both. Amazon and Cohere are dashed: no line of their own. Four more dashed boxes say dates, whether the commitments bind, how progress is monitored, and any finding or notice are not stated for any of the ten.
Drawn only from the ICO's Industry Supervision page, read on 9 October 2026. Colour is the ICO's verb tense, our reading; dashed boxes are not stated.

A label is not a control: what "commitments" covers

The word doing the work in the coverage is "commitments". In the report it covers a Microsoft review of its own assessment, a Stability AI review of its own policy, and a Google undertaking to cite more evidence in an assessment. Each may be worth doing. None is a date, a test or a consequence. A commitment the ICO is "monitoring" is not the same as a change a customer or a member of the public can read today, and the ICO's headline, "secures changes", describes the past-tense lines and the promised ones with one verb.

The ICO is also candid about the ground it is standing on. Its news item says it "acknowledges" that current foundation model training practices "present technical challenges" in complying with UK data protection law, and that it is raising the boundaries of the law with Government. That is an acknowledgement of difficulty by a regulator, not a finding of breach by a developer. Both readings sit in the same document, and a reader should keep them apart.

What the developers' own pages show on 9 October

The ICO does not say which page carries which change. To see whether anything dated October 2026 had appeared by the morning after, each developer's privacy page or notice was read on 9 October. The table gives the page and the date it prints. A date on a page is not proof of what changed or why, and several of the ICO's items, the assessments, are not on public pages that were found.

Developer privacy pages read on Friday 9 October 2026 and the date each prints. Fetched directly, or in a browser page of their own where a plain fetch was refused.

DeveloperPage read and the date it printsDated October 2026?
AmazonAmazon.co.uk Privacy Notice, last updated 1 August 2024; AWS Privacy Notice, last updated 18 May 2026; a Generative AI Development Disclosure page with no date in its text.No
AnthropicPrivacy Policy, effective 10 September 2026 (previous 8 July 2026); Non-User Privacy Policy, effective 8 July 2026 (previous 28 August 2025); a help article on training-data rights requests, dated 8 July 2026.No
Apple"Datasets used for Apple's generative AI systems and services", dated 9 September 2026, the page the ICO links; Applebot support page, published 4 September 2026; Privacy Policy, updated 30 July 2025.No
CoherePrivacy Policy, last updated 1 May 2026; Model Training Privacy Notice, last update 1 May 2026.No
DeepSeekPrivacy Policy (English), last update 10 February 2026.No
GooglePrivacy Policy, effective 1 October 2026 (previous 2 April 2026).Yes: 1 October. Text unchanged but for layout, below.
MetaPrivacy Policy, effective from 23 July 2026; a page on how Meta uses information for generative AI models, undated.No
MicrosoftPrivacy Statement, last updated September 2026.No
OpenAIEU Privacy Policy, updated 24 August 2026 (previous 4 June 2026); Privacy Policy, updated 25 August 2026; help article on personal data removal, updated "2 months ago", which the ICO's footnote dates 14 August 2026.No
Stability AIPrivacy Policy, effective 30 September 2026 (previous 31 July 2025).No: 30 September

One page carries an October date. Google's Privacy Policy is headed "Effective October 1, 2026". Compared sentence by sentence with the version effective 2 April 2026, each holds 617 sentences, and the five that differ are the date line with an added contents list, a table header, two "Learn more" link labels and page furniture (derived, our script). That fits the ICO's line for Google, which concerns an assessment and not the policy. It cannot show what the ICO's line covers.

Stability AI's policy, effective 30 September, replaced one effective 31 July 2025. It now splits what was one combined purpose, improving services and training models, into separate purposes, one of which covers research and development "including to train, fine-tune, and evaluate machine learning models", each with a stated legal basis. The ICO says Stability AI "will review its privacy policy to explain its processing purposes in greater detail". The two are consistent. They are not shown to be the same thing: the ICO gives no date, and the policy does not mention the ICO. Anthropic's Non-User Privacy Policy, effective 8 July 2026, is likewise consistent with the ICO's line that Anthropic "updated its non-user privacy policy", and equally unproven to be the update meant.

No page read mentions the ICO's report or any commitment made to it. The only mentions of the ICO or the Information Commissioner are lines telling UK residents they may complain (derived, text search of every page read). Nothing here shows a developer's statement of its own on the report, and company newsrooms were not searched for one.

What is not stated

The table is the negative column the story needs. The left of each pair is what the ICO's pages say. The right is what they leave out.

Stated and not stated in the ICO news item, report and call for evidence, read on 9 October 2026. Quotations are exact and short.

QuestionWhat the ICO pages sayWhat they do not say
When will the changes be made?Some lines are in the past tense and some say "will". The news item says developers "have made, or committed to make" changes.Any date or deadline for any change.
Binding or voluntary?They are called commitments. The next steps include "ongoing engagement about their commitments".Who made them, in what form, to whom, or whether any legal instrument stands behind them. "Binding", "voluntary" and "penalty" do not appear (derived).
What is monitoring?"We are monitoring developers' progress against their commitments."What monitoring consists of, how often, on what evidence, or whether the ICO will publish progress.
EnforcementIn general terms: "Where necessary, we'll use the full range of our regulatory powers", and where people face "avoidable harm" or safeguards are missing, "we will intervene". A formal investigation into X.AI, not one of the ten, is ongoing.Any notice, warning or enforcement step aimed at any of the ten.
FindingsMarket-wide: firms "didn't always" identify specific interests; some lacked evidence; in some cases a "privacy maze" resulted.Which firms. No finding is attributed to a named developer among the ten.
Why these eleven?Notes to editors: "identified by likelihood of non-compliance, UK market share, and use of higher-risk training datasets".How any developer scored, or any finding. The report's own selection factors omit the phrase.
Company statementsNone in the ICO pages. Infosecurity quotes none.What any developer says it has done or will do, in its own words.
The agent incidentsThe report: it was reported in summer 2026 that "certain highly capable agents from OpenAI and Anthropic, during cyber evaluations" interacted with external systems and, in some cases, "accessed external systems such as Hugging Face".A name, a date or a description of any incident; any finding; whether any personal data was accessed. The report speaks of "the potential" for models to access and exfiltrate personal data.

Agents: the enquiries, the reported incidents and the call for evidence

The news item says the ICO has "recently made enquiries" with OpenAI, Anthropic, Meta and the UK's AI Security Institute about recent agentic AI testing and deployment, and that "in some cases, certain agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face". Its notes to editors say the enquiries are ongoing and that the ICO has contacted several developers and their testing partners to establish what risk assessments and safeguards were in place at the time. All four named bodies are treated the same way here: the ICO names them as recipients of enquiries, uses "reportedly", and states no finding.

The report is more specific on two of the four. Its Introduction says it was reported in summer 2026 that agents from OpenAI and Anthropic, during cyber evaluations, interacted with external systems, and that such incidents show AI systems "can cause real-world harm, including the potential for models to autonomously access and exfiltrate personal data". The ICO's word is "potential". It names no incident, date or system beyond Hugging Face. Meta and the AI Security Institute appear in the news item as recipients of enquiries and nowhere in the report in connection with any incident (derived, text search). Infosecurity links its own earlier story on one developer's account of an incident; this briefing does not rely on that story, and the ICO's pages cite no incident report.

The training-data point is at the same level. The ICO says it is "increasingly seeing reports detailing the feasibility of extracting model training data", which can include email signatures, API keys and passwords. It names no report and no method, and neither does this briefing. An ICO director is quoted in the news item as saying "the fact AI agents act with autonomy is not an excuse for poor compliance".

The call for evidence is the part of the story that asks something of readers.

The agentic AI call for evidence at a glance. Sources: the ICO consultation page, the call for evidence document and the Citizen Space page, read on 9 October 2026.

ItemWhat the ICO's pages say
DatesOpened 8 October 2026. Closes at the end of 20 November 2026, a Friday. The ICO calls it six weeks: 8 October plus 42 days is 19 November, so the end of 20 November is 43 days from opening (derived). From 9 October it is 42 days (derived: 22 left in October plus 20).
Who it is forAnyone who wants to harness the benefits of agentic AI while complying with data protection law, and legal and technical experts. The news item says developers, deployers and other experts.
How to respondThrough [Citizen Space](https://citizen-space.ico.org.uk/regulatory-risk/agentic-ai-call-for-evidence/), an online survey service supplied to the ICO by Delib. That page lists the contact as AgenticAI@ico.org.uk. "We may not consider responses received after this deadline."
ShapeEight survey sections: about you, six themes, additional questions. Our count: 30 evidence prompts across the six themes and seven numbered additional questions. The survey form itself was not opened.
What the ICO will doThe evidence will "inform our future guidance", support the forthcoming statutory code of practice on AI and automated decision-making, and contribute to its corporate priority of promoting trust and transparency in AI.
PublicationThe ICO "may publish responses received from organisations in full or publish a summary". Personal information is removed "where appropriate". Freedom of information requests are handled under the legislation.
Also promisedA report on agentic AI in the adtech ecosystem "later this year".

The six themes, in the ICO's own order, show what it thinks is hard. Each has a stated expectation and a list of evidence it wants.

The six themes of the call for evidence, with the ICO's expectation condensed and our count of the evidence prompts under each.

ThemeThe ICO's expectation, condensedEvidence prompts
1 Data securityAutonomy is a deliberate design decision, backed by least privilege, scoped permissions, tool restrictions and approval thresholds. Register an agent with an owner and a purpose.5
2 Transparency in supply chainsDesign transparency in from the start: what personal data an agent can reach, where it goes, who receives it. Consider extra "friction" such as approval steps. PECR regulation 6 may apply to device access.8
3 AccountabilityRoles follow decisions about purposes and means, not labels. The concept of a controller is read broadly. Log and trace agent actions so controllers keep control.5
4 Automated decision-makingAssess the whole workflow, not one agent or decision point. Human involvement must be meaningful. Be able to reconstruct which agent acted, under what authority, on what data.5
5 Fairness and purpose limitationAutonomy does not change these duties. An agent finding a new use for data does not make it compatible. Labelling work "research" does not make the research provisions apply.3
6 Lawful processingA contract or a user's instruction does not automatically supply a lawful basis for what follows. Consent must be valid. Legitimate interests need an assessment.4

The seven additional questions are about adoption, not law. Question 2 lists "supplier assurance or due diligence challenges" among possible barriers. Question 4 asks how an organisation obtains assurance in the absence of specific guidance and lists "vendor assurances" among the options. The ICO is asking, in effect, how far organisations rely on what their suppliers tell them. An honest answer needs a record.

The legal frame, as the ICO and legislation.gov.uk print it

For developers. The report tells foundation model developers that where they process personal data to train models they must identify a lawful basis, provide meaningful transparency, enable people to exercise their rights and show safeguards that "materially reduce risk", and that where models contain personal data or special category data "the bar is even higher". It applies Articles 5(1)(a), 6(1)(f), 9, 13, 14 and 15 to 21 of the UK GDPR to training. It also says its approach "will remain pragmatic, evidence-based, and proportionate".

For agents. The call for evidence applies the same law to agents. Its fourth theme sets the automated decision-making provisions, Articles 22A to 22D, across a whole multi-stage workflow: the ICO says human involvement at one stage does not necessarily take the overall decision outside them, and that the question is whether that involvement is meaningful.

What the statute says. Section 80 of the Data (Use and Access) Act 2025 substituted Articles 22A to 22D into the UK GDPR. Article 22A(1)(a) says a decision is based solely on automated processing "if there is no meaningful human involvement in the taking of the decision", and a significant decision is one that "produces a legal effect" or "has a similarly significant effect". Article 22B restricts significant, solely automated decisions based on special category data unless explicit consent, or contract or law with Article 9(2)(g), applies. Article 22C requires safeguards: information about decisions, the ability to make representations, human intervention and contest. Article 22D lets the Secretary of State make regulations on what counts as meaningful human involvement; this briefing did not look for any. legislation.gov.uk prints the commencement as "in force at 5.2.2026" so far as not already in force by S.I. 2026/82, 246 days before 9 October (derived).

Guidance in flux. The ICO's draft guidance on automated decision-making, updated 31 March 2026 and under consultation, says human involvement must be "active and not just a token gesture", and that the person should have discretion and authority to change the decision and be suitably trained. Its guidance on AI and data protection says it "is under review" because of the 2025 Act and was updated on 15 March 2023, 1,303 days before the report (derived). Its DPIA page carries the same under-review notice. A statutory code of practice on AI and automated decision-making is forthcoming.

The NCSC. The NCSC's blog of 20 August 2026, 49 days before the report (derived), is written for system designers and operators building environments where agents have significant autonomy. It says there have been "several incidents" of unsanctioned or unintended activity, warns that a model's built-in controls may be bypassed, and gives interim advice: choose autonomy proportionately, threat-model before deployment, name who is responsible, run agents in a sandbox with restricted network access and credentials, give each agent its own identity, log and monitor, make activity attributable, and keep the ability to halt it. The NCSC says formal guidance will supersede the blog.

What each source fixes and does not fix for an organisation deploying agents. Read on 9 October 2026.

SourceWhat it fixesWhat it does not
ICO report, 8 October 2026Expectations for developers training on personal data, and the ICO's positions on special category data and on whether models can contain personal data.Dates, binding force, consequences, or which developers fell short.
ICO call for evidenceThe ICO's current thinking on agents under UK data protection law, in six themes.Final guidance. It says its guidance follows the evidence.
Data (Use and Access) Act 2025, section 80Definitions, restrictions and safeguards for solely automated significant decisions; in force 5 February 2026 as printed.Whether a given agent workflow counts. Regulations may add detail under Article 22D.
ICO draft ADM guidance, 31 March 2026Criteria for meaningful human involvement; keep a record of how the human was involved.Final text. It is under consultation.
ICO AI and data protection guidance, 15 March 2023General expectations for AI under data protection law.Agents or the 2025 Act. It is marked under review.
NCSC blog, 20 August 2026Interim security controls for agent deployments, in seven steps.Data protection law. It says formal guidance will supersede it.

For the organisation that deploys the tool: what the commitments change

For a customer, the commitments change nothing contractual unless the vendor says so. No ICO page read says the commitments are contractual, gives customers a right to rely on them, or amends any agreement. The ICO says it has set expectations for developers to "enable organisations to adopt foundation models without undermining their own compliance obligations". That is an expectation of developers, not a promise to customers. What a customer can rely on is what its own agreement and the developer's published notices say on the day it reads them.

The call for evidence adds that roles follow decisions, not labels. Organisations "should not rely only on how they describe themselves" as controller or processor, and where some agentic developers suggest they are controllers only for development and security processing, the ICO says controllers should be read broadly. A deployer that sets an agent's goals, tools, permissions and data access may carry controller duties whatever the vendor's paperwork says.

Questions worth putting to each vendor in writing, for the register below:

Take this with you

Questions to put to each vendor

  • Which of the changes the ICO describes apply to the service we use, and by what date for each one still to come?
  • Where is the standalone notice on model training, and what is its version date today?
  • Are our prompts, files and outputs used for training by default, where is that setting recorded, and who can change it?
  • How are rights requests about training data and about outputs handled, and is there a route for people who are not our users?
  • For agents: which tools, connectors and data sources can the agent reach, what personal data goes to which recipients, and where are the logs, the approval thresholds and the emergency stop?
  • Who is controller and who is processor for each part of the agent workflow, and where is that written in the contract?
  • How will we be told, and how far ahead, if privacy or training terms change?

What to record: a register as of a date

The ICO says a deployer may need to identify or register an agent, associate it with an owner and a purpose, and apply access policies. The NCSC advises a unique identity for each agent. Neither says how to keep the record. A register with a date on every vendor line is the minimum, because none of the ICO's changes carries a date and a vendor page can change without notice. Brief 277 makes the same point for one vendor's usage policy versions and the model workflows built on them.

A register for AI tools and agents that touch personal data. The right column says where each field comes from. Fields are our suggestion, not an ICO template.

FieldWhat to writeWhere it comes from
Tool or agentProduct, version, who runs it, who owns it, what it is for.ICO Theme 1: register an agent, with owner and purpose.
Personal dataCategories it can reach, including special category data, and whether data can leave your environment.ICO Themes 1 and 2.
Lawful basis and roleThe basis for each processing step; controller, joint controller or processor, and the contract clause.ICO Themes 3 and 6.
Vendor transparency informationNotice URL, version or effective date, the date you read it, and a saved copy.ICO report: standalone notices; no change is dated.
Training positionWhether your data trains the vendor's models, by default or by setting, and who set it.ICO report, Articles 13 and 14.
Autonomy and oversightIn, on or out of the loop; approval thresholds; the named person responsible.NCSC blog; ICO Theme 1.
EnvironmentSandbox level, network allowlist, credentials the agent can use, log location, who can stop it. A [default role narrowed 260 days after a report](https://www.pk-sharma.com/briefing/agentcorruption-aws-agentcore-role-narrowed-260-days-after-report-no-aws-notice) is why the credentials line belongs here.NCSC blog.
Decisions about peopleWhether it takes or shapes decisions with legal or similarly significant effect, and the evidence that human involvement is meaningful.Articles 22A to 22D; ICO draft ADM guidance.
DPIAReference, date and the trigger that applied.Article 35; ICO DPIA page.
Review dateThe next date, and what triggers an early review: a vendor notice, an ICO publication, an incident.Our suggestion.

DPIA triggers for agents

Article 35(1) requires a data protection impact assessment (DPIA) before processing "likely to result in a high risk", in particular using new technologies. The ICO's page on when a DPIA is needed is marked under review after the 2025 Act. It lists processing that needs one, some only in combination with another criterion. Reading its list against agents is our inference, not the ICO's statement.

The ICO's list of processing likely to result in high risk, set against how an agent can meet it. The right column is our inference.

ICO list itemWhere an agent can meet it
Innovative technology, including AI, with another criterionAny agent, plus any row below.
Denial of service: decisions about access to a product, service, opportunity or benefit based to any extent on automated decision-makingAn agent that screens, ranks or refuses requests, applications or claims.
Data matching: combining or comparing data from multiple sourcesAn agent that retrieves from several systems and writes to another.
Large-scale profilingAn agent that builds profiles across many people.
Invisible processingData an agent gathers from other sources without the person being told.
Tracking behaviour or locationAn agent that monitors activity across systems or devices.
Children or other vulnerable peopleAn agent offered to, or acting on behalf of, children or vulnerable people.
Risk of physical harmAn agent acting on systems where a breach could affect safety.

Article 35(3) separately requires a DPIA for systematic and extensive automated evaluation on which significant decisions are based, and for large-scale processing of special category data. The ICO says that if you are in doubt it "would always recommend" doing one, and that where you decide none is needed you should document why.

If you respond to the call for evidence

The call closes at the end of 20 November, 42 days from 9 October. A draft by Friday 6 November leaves 14 days (derived) for review. The ICO's own prompts show what evidence it wants: how you decide whether the automated decision-making provisions apply, what logging records agent identity beside agent actions, how you allocate controller and processor roles in contracts, which lawful bases you use and how you assess legitimate interests for agents, and what information your suppliers give you and what you wish they gave you.

Answer the additional questions with your register in hand. If you rely on vendor assurances, say what they consist of and how current they are. If supplier assurance is a barrier, say which part: training data transparency, logging detail, controller allocation or notice of change. The ICO says responses from organisations may be published in full or summarised, and asks you not to include "information in your response that you would not be content for us to make publicly available". Check what your contracts allow you to say about a vendor's non-public controls before you name one. A trade body response is a legitimate route if your own evidence is thin.

The ICO has also flagged consumer-facing personalisation, including chatbots used for role-play and companionship, as another priority. Brief 273 covers the ICO's children's code and one developer's teen product.

What to do, in order

Take this with you

Actions for a UK organisation using AI tools or agents

  • Today: list every AI tool and agent in use that can touch personal data, with a named owner and a business purpose.
  • Today: save each vendor's current privacy notice, model training notice and agent or connector terms, with the URL and the date read. No ICO change is dated, so the page you read today may differ next week.
  • This week: send the vendor questions above and file the replies with the register.
  • This week: for each agent, record autonomy level, approval thresholds, credentials, network access, log location and who can stop it, and apply the NCSC controls in proportion to the autonomy.
  • By 23 October: screen each use that shapes decisions about people for Articles 22A to 22D, and write down why human involvement is meaningful or put the safeguards in place.
  • By 30 October: run or refresh a DPIA for each agent that matches the ICO list, and record the reasons where you decide none is needed.
  • By 6 November: decide whether to respond to the call for evidence, alone or through a trade body, and draft it, after checking what you may disclose about vendor controls.
  • By 20 November: submit through Citizen Space and keep a copy.
  • After 20 November: re-read the ICO pages and each vendor's notices, compare them with your saved copies, and set the next review date.

The question that exposes the gap

The ICO has said ten developers have made or promised changes and that it is watching, and it has asked deployers what they do about agents. If the ICO asked your organisation on 20 November which AI tools and agents process personal data, what each vendor had told you about training and transparency, and as of which date, could you answer from a dated record of your own rather than from a vendor page that may have changed since 8 October?

Key facts

Sources

  1. PrimaryICO news item of 8 October 2026, "ICO secures changes from leading AI developers as scrutiny extends to AI agents", read in full and re-checked in a browser page: the ten developers, "made, or committed to make", the call for evidence, the enquiries with OpenAI, Anthropic, Meta and the AI Security Institute, and the notes to editors on the 11 priority developers.Information Commissioner's Officeaccessed 2026-10-09
  2. PrimaryICO report landing page, "Building trust and transparency into generative AI development: our work to create regulatory certainty": the message to developers, the four expectations, and the reference to formal investigations into X Internet Unlimited Company and X.AI LLC.Information Commissioner's Officeaccessed 2026-10-09
  3. PrimaryReport Introduction: scope, the footnoted definition of an AI agent, and the paragraph on summer 2026 reports of agents from OpenAI and Anthropic interacting with external systems during cyber evaluations.Information Commissioner's Officeaccessed 2026-10-09
  4. PrimaryReport page on data protection challenges and expectations: Articles 13 and 14, lawful basis, rights, models and personal data, and special category data; the examples of rights mechanisms (Meta, Apple, OpenAI, Anthropic) and the dated footnotes 10 and 11.Information Commissioner's Officeaccessed 2026-10-09
  5. PrimaryReport Industry Supervision page: the 11 priority developers, the list of changes to legitimate interests assessments by developer, and the transparency sentences naming Apple, Cohere and OpenAI, and the group of seven. The source of the 8 of 10 count, the tense reading and the 291 of 1,574 word count.Information Commissioner's Officeaccessed 2026-10-09
  6. PrimaryReport Next steps page: continuing scrutiny through ongoing engagement about commitments, the statutory code of practice on AI and automated decision-making, and the stated intention to use the full range of regulatory powers where practices expose people to harm.Information Commissioner's Officeaccessed 2026-10-09
  7. PrimaryReport Annex A: research, the 2024 generative AI consultation, engagement with developers since 2023 and the March 2026 transparency workshop.Information Commissioner's Officeaccessed 2026-10-09
  8. PrimaryICO consultation page for the Agentic AI call for evidence: start date 8 October 2026, closing date 20 November 2026, status open, the eight survey sections, how to respond, and the privacy statement on publication of responses.Information Commissioner's Officeaccessed 2026-10-09
  9. PrimaryCall for evidence document landing page: who it is for, what it covers, the six themes, the earlier work it builds on, and the promised adtech report.Information Commissioner's Officeaccessed 2026-10-09
  10. PrimaryCall for evidence, About agentic AI: definition of an AI agent and an agentic AI system, what is new, the three-layer ecosystem and the table of participants.Information Commissioner's Officeaccessed 2026-10-09
  11. PrimaryCall for evidence Theme 1, data security: autonomy as a deliberate design decision, least privilege, approval thresholds, registering an agent with an owner and purpose, and five evidence prompts.Information Commissioner's Officeaccessed 2026-10-09
  12. PrimaryCall for evidence Theme 2, transparency in supply chains: designing transparency in, extra friction, PECR regulation 6, and eight evidence prompts.Information Commissioner's Officeaccessed 2026-10-09
  13. PrimaryCall for evidence Theme 3, accountability: controller roles follow decisions, controllers read broadly, and five evidence prompts including contracts.Information Commissioner's Officeaccessed 2026-10-09
  14. PrimaryCall for evidence Theme 4, automated decision-making: Articles 22A to 22D across multi-stage workflows, meaningful human involvement, reconstruction of agent decisions, and five evidence prompts.Information Commissioner's Officeaccessed 2026-10-09
  15. PrimaryCall for evidence Theme 5, fairness and purpose limitation: autonomy does not change the duties, compatibility of new purposes, the research provisions, and three evidence prompts.Information Commissioner's Officeaccessed 2026-10-09
  16. PrimaryCall for evidence Theme 6, lawful processing: contract and instruction do not automatically supply a lawful basis, valid consent, legitimate interests assessments, and four evidence prompts.Information Commissioner's Officeaccessed 2026-10-09
  17. PrimaryCall for evidence additional questions: seven numbered questions on adoption, barriers including supplier assurance, delayed plans, how assurance is obtained including vendor assurances, and benefits.Information Commissioner's Officeaccessed 2026-10-09
  18. PrimaryCitizen Space overview page for the call for evidence: opened 8 October 2026, closes 20 November 2026, the eight sections and the team contact mailbox. The survey form itself was not opened.Information Commissioner's Office (Citizen Space)accessed 2026-10-09
  19. PrimaryGuidance on AI and data protection: marked under review because of the Data (Use and Access) Act, last updated 15 March 2023.Information Commissioner's Officeaccessed 2026-10-09
  20. PrimaryICO draft guidance on automated decision-making including profiling, updated 31 March 2026 for the Data (Use and Access) Act and under consultation.Information Commissioner's Officeaccessed 2026-10-09
  21. PrimaryICO draft ADM guidance chapter on what the UK GDPR says: the criteria for meaningful human involvement, timing, and keeping a record of how the human was involved.Information Commissioner's Officeaccessed 2026-10-09
  22. PrimaryICO page on when a DPIA is needed, marked under review after the 2025 Act: Article 35(1), the three automatic cases and the ICO list of processing likely to result in high risk.Information Commissioner's Officeaccessed 2026-10-09
  23. PrimaryData (Use and Access) Act 2025 section 80, substituting Articles 22A to 22D into the UK GDPR, with the commencement note "in force at 5.2.2026" so far as not already in force by S.I. 2026/82.legislation.gov.ukaccessed 2026-10-09
  24. PrimaryUK GDPR Article 35, data protection impact assessment, as printed on legislation.gov.uk.legislation.gov.ukaccessed 2026-10-09
  25. PrimaryNCSC blog of 20 August 2026, "Managing the cyber risk of agentic AI": interim advice in seven steps, the human-in-the-loop, on-the-loop and out-of-the-loop models, sandboxing, unique agent identity, logging and emergency shutdown.National Cyber Security Centreaccessed 2026-10-09
  26. PrimaryApple page "Datasets used for Apple's generative AI systems and services", dated 9 September 2026, the page the ICO links as the webpage on training data sources.Appleaccessed 2026-10-09
  27. PrimaryApple Applebot support page, published 4 September 2026, cited by the ICO in the rights section.Appleaccessed 2026-10-09
  28. PrimaryApple Privacy Policy as served for the UK, updated 30 July 2025.Appleaccessed 2026-10-09
  29. PrimaryAnthropic Privacy Policy, effective 10 September 2026, with the previous version effective 8 July 2026.Anthropicaccessed 2026-10-09
  30. PrimaryAnthropic Non-User Privacy Policy, effective 8 July 2026, with the previous version effective 28 August 2025.Anthropicaccessed 2026-10-09
  31. PrimaryAnthropic help article on privacy rights requests relating to training data, dated 8 July 2026, the page the ICO cites in footnote 11.Anthropicaccessed 2026-10-09
  32. PrimaryGoogle Privacy Policy, effective 1 October 2026; compared sentence by sentence with the version effective 2 April 2026.Googleaccessed 2026-10-09
  33. PrimaryGoogle Privacy Policy archive: the list of versions and comparison pages, including 2 April 2026 to 1 October 2026.Googleaccessed 2026-10-09
  34. PrimaryMicrosoft Privacy Statement, UK version, last updated September 2026.Microsoftaccessed 2026-10-09
  35. PrimaryMeta Privacy Policy, effective from 23 July 2026, read in a browser page of its own after a plain fetch was refused.Metaaccessed 2026-10-09
  36. PrimaryMeta page on how Meta uses information for generative AI models, undated, read in a browser page of its own.Metaaccessed 2026-10-09
  37. PrimaryOpenAI EU Privacy Policy, updated 24 August 2026, with a previous version of 4 June 2026, read in a browser page of its own after a plain fetch was refused.OpenAIaccessed 2026-10-09
  38. PrimaryOpenAI Privacy Policy, updated 25 August 2026, read in a browser page of its own.OpenAIaccessed 2026-10-09
  39. PrimaryOpenAI help article on personal data removal from ChatGPT, shown as updated "2 months ago"; the ICO dates it 14 August 2026 in footnote 10.OpenAIaccessed 2026-10-09
  40. PrimaryAmazon.co.uk Privacy Notice, last updated 1 August 2024, read in a browser page of its own after a plain fetch was refused.Amazonaccessed 2026-10-09
  41. PrimaryAmazon.co.uk Generative AI Development Disclosure page, no date in its text.Amazonaccessed 2026-10-09
  42. PrimaryAWS Privacy Notice, last updated 18 May 2026.Amazon Web Servicesaccessed 2026-10-09
  43. PrimaryCohere Privacy Policy, last updated 1 May 2026.Cohereaccessed 2026-10-09
  44. PrimaryCohere Model Training Privacy Notice, last update 1 May 2026.Cohereaccessed 2026-10-09
  45. PrimaryDeepSeek Privacy Policy (English), last update 10 February 2026.DeepSeekaccessed 2026-10-09
  46. PrimaryStability AI Privacy Policy, effective 30 September 2026, compared with the previous version.Stability AIaccessed 2026-10-09
  47. PrimaryStability AI Privacy Policy effective 31 July 2025, the previous version, used for the comparison.Stability AIaccessed 2026-10-09
  48. Reported byNews coverage of 9 October 2026 of the ICO announcement: "a new report on data privacy in agentic AI", "change their UK data protection policy", "urged them to strengthen transparency". Used to compare with the ICO pages; no company statement is quoted.Infosecurity Magazineaccessed 2026-10-09
  49. Reported byEarlier briefing on a vendor Usage Policy and the register of model workflows against policy versions.pk-sharma.comaccessed 2026-10-09
  50. Reported byEarlier briefing on the ICO children's code and a developer's teen product.pk-sharma.comaccessed 2026-10-09
  51. Reported byEarlier briefing on an agent default role narrowed after a report, cited for the credentials line of the register.pk-sharma.comaccessed 2026-10-09

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.