On 8 October 2026, the Information Commissioner's Office (ICO), the UK data protection authority, published the outcome of its supervision programme for foundation models. Ten developers, Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI, have changed or committed to changing their practices, according to the regulator's press release. The same day, the ICO launched a six-week call for evidence on agentic AI, open until 20 November 2026, and confirmed it had questioned OpenAI, Anthropic, Meta and the AI Security Institute about trials and deployments of agents.

Eleven developers targeted, X.AI out of the programme

Created in 2025, the programme covered eleven developers deemed a priority over two years, notably based on their UK market share. The eleventh, X.AI, is no longer included. The ICO suspended its exchanges with it after opening formal investigations on 3 February 2026 into X Internet Unlimited Company and X.AI LLC, regarding the processing of personal data by Grok and its ability to produce sexualised images and videos. This investigation is still ongoing.

Legitimate interest assessments to be redone

The supervision covered five points of the UK GDPR, including legitimate interest as a legal basis, sensitive data and the right to object. According to the report, companies did not always identify a specific interest for each type of data at each stage of development, some had no serious evidence of the necessity of the processing, and the impact on individuals' rights was rarely supported by a detailed analysis. Phrases such as "training our models" or "benefiting humanity" are, for the ICO, unlikely to suffice without precision and justification.

The supervision report details the revisions of these documents, as well as technical safeguards. Some of the commitments remain to be fulfilled. Anthropic has updated its privacy policy for non-users and its legitimate interest assessment (LIA). OpenAI has strengthened in its LIA the evidence of the effectiveness of its safeguards. DeepSeek has produced an LIA and must explain in its policy which third-party personal data are included in its training datasets, and why. Google will cite more evidence, Microsoft will "re-examine" its LIA, Stability AI will detail its purposes. Apple will update its documentation and has published a page on the sources of its training data. Meta has provided results of memorisation tests and surveys on the effectiveness of its information.

On public information, Apple, Cohere and OpenAI have already changed what they publish, with in particular dedicated notices on training, a summary of third-party datasets and details on retention and transfers. Amazon, Anthropic, DeepSeek, Google, Meta, Microsoft and Stability AI have changed or committed to implementing "all or part" of a list of measures: dedicated training information, non-technical summaries of sources, better ways to exercise one's rights, details on retention and transfers outside the country. The report does not say which company has adopted which measure, nor with what deadline. The ICO only says it is monitoring the progress of commitments.

For individuals, some concrete mechanisms

The report cites a few mechanisms usable now. Meta offers a separate form for non-users whose data may have been used for training, which asks for the prompt that produced the response in question and a screenshot. Apple allows both users and non-users to report web pages to be excluded from training, and documents the blocking of its indexing robot. OpenAI has published instructions for requesting the removal of personal data from ChatGPT responses, Anthropic instructions on privacy and personal data in AI systems.

The regulator also notes a "maze" of information scattered across notices and help pages, and recalls that deleting data from an already trained model may require retraining it entirely.

Article 9, a limit accepted by the regulator

On sensitive data (health, political opinions, religion), the ICO considers that developers probably process them, intentionally or not, unless they prove otherwise. It identifies only two exceptions of Article 9 potentially available: the exception relating to data "manifestly made public" by the person, deemed hardly applicable to data scraped from the web, and scientific research, which will not cover everything. The regulator writes that these conditions "limit" the possibility of lawfully training models on such data and says it is raising the issue with the government. This does not exempt developers from their obligations: in the absence of an applicable condition under Article 9, the ICO asks them to prevent the collection of such data, filter them or avoid processing them.

A line close to that of the CNIL and the EDPB

On the question of whether a model itself contains personal data, the ICO says it has put its 2020 position (yes, if the training data can be extracted from it) back under review and refers to a case-by-case examination. This is also the line of Opinion 28/2024 adopted in December 2024 by the European Data Protection Board, at the request of the Irish authority. On 19 June 2025, the CNIL (France's data protection authority) published recommendations according to which legitimate interest is a possible legal basis for developing an AI system, "provided strong safeguards are taken". The ICO goes in the same direction. As it had set out in its series of consultations on generative AI, legitimate interest is, realistically, the only conceivable legal basis for data scraped from the web, provided evidence is provided.

Transparency remains the weak point. According to research commissioned by the ICO, the sector's transparency has even "continued to decline". On the European side, ActuIA noted at the end of September that 21 out of 24 AI Act summaries named no scraped site in the relevant section.

Agents, the next area of work

In its introduction, the report mentions that in summer 2026, according to published information, agents from OpenAI and Anthropic, during cybersecurity evaluations and in some cases, bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face. The ICO says it has contacted several developers and their testing partners to find out what risk assessments and safeguards were in place. These steps are ongoing and the ICO has announced no conclusions.

The call for evidence is aimed at developers, deployers and experts. Its results will feed into future guidelines on agentic AI and the statutory code of practice on AI and automated decision-making that the ICO is preparing. "The fact that AI agents act autonomously does not excuse poor compliance," said Richard Nevinson, ICO Director of Technology Regulation.

Commitments whose implementation the ICO must still monitor

This supervision report mentions no sanctions. It lists changes already made and commitments whose implementation remains to be monitored, on notices and legal analyses as well as technical safeguards. For a European company integrating these models, this report provides concrete points to examine with a provider: the purposes of training, documented safeguards and the means to exercise individuals' rights. The commitments listed do not, however, by themselves establish the compliance of a deployment. The ICO announces it will continue to monitor them and work with the UK government on difficulties related to sensitive data. On AI agents, its call for evidence remains open until 20 November 2026.

Our articles will then appear first in Google Top Stories.