The UK's data regulator just got ten of the world's biggest AI companies to admit their data handling needed work.
The Information Commissioner's Office (ICO) said Thursday that Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI have made or committed to changes in how they handle personal data. The commitments follow two years of ICO scrutiny into how these companies collect, process and retain user information to build and run their AI systems. The regulator didn't publish a blow-by-blow account of what each company is altering, but confirmed all ten were part of the same review. With that phase closed, the ICO says its next target is AI agents: software that acts on a user's behalf, often with access to more personal data than a chatbot ever needed.
Two years is a long runway for a regulator to spend on ten companies, and it signals the ICO is treating foundation-model data practices as a systemic issue rather than one-off violations. It also sets a precedent for agentic AI: tools that book flights, manage inboxes or move money need far broader data access than a prompt-and-response chatbot, and regulators are watching before deployment, not after. The UK is positioning itself as a rule-setter here while the EU AI Act and a patchwork of US state laws still sort out their own approach to AI data handling.
Companies rarely announce privacy fixes until a regulator is standing over their shoulder; the real test is whether these changes survive once the ICO moves on to agents.