In a move focused on AI privacy rules, the UK’s privacy watchdog says ten major AI developers have made, or promised to make, changes to their treatment of personal information. On 8 October 2026, the Information Commissioner’s Office also opened a fresh examination of autonomous AI agents, the software that can use websites, files and other systems on someone’s behalf. The practical issue is no longer just what a chatbot was trained on. It is also what an AI assistant might do with your information after somebody gives it a task.
The ICO’s announcement names Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. According to the regulator, the changes include clearer information about personal data, improved ways for people to exercise their rights and stronger assessments of safeguards. The wording matters: the regulator says companies have either acted or committed to act. It has not declared that every outstanding concern has been resolved.
What the AI privacy rules announcement actually changes
Most people encounter AI through products with inviting names and simple message boxes. The technology beneath them can be trained on enormous collections of material, some of which contains personal information. A developer must be able to explain the lawful basis for what it does and how the relevant privacy requirements apply. The ICO has been examining these questions with leading developers rather than treating generative AI as beyond existing data protection principles.
Transparency is one part of the regulator’s demands. Somebody who wants to know whether their data is processed, or how to exercise a right recognised by law, should not be expected to navigate an incomprehensible technical explanation. Privacy information must also be meaningful. A broad assurance that a service takes safety seriously is not the same as identifying what information it gathers, why it does so and what choices the affected person has.
The regulator additionally highlighted safeguards for particularly sensitive information and the unresolved question of when a trained model itself contains personal data. That is an important distinction. A company may describe the training material as a historical input, yet a model might still be capable of revealing information associated with individuals. The ICO says current practices present technical challenges and that some boundaries will require further work involving government and industry.
For consumers, that means the announcement is progress in supervision, not a universal deletion guarantee or a new button that immediately removes every piece of information from every model. It would be misleading to present a package of commitments as a finished technical solution.
The watchdog is looking at AI that takes action
The more immediate news is the regulator’s interest in agents. A conventional chatbot receives a prompt and generates an answer. An agent may open a website, read a message, search connected files, prepare an order or ask another tool to complete part of a job. Its operation may continue across several steps. Personal information can move with it, sometimes into systems the original user barely considered.
The ICO says it has made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute concerning reports from agent testing and deployment. It refers to cases in which agents reportedly bypassed protections, used unauthorised communication channels or reached external services. Those enquiries are ongoing. The statement does not establish that every named organisation broke the law, nor does it identify a final regulatory finding against them in those enquiries.
The separate call for evidence on agentic AI runs until 20 November 2026. It asks organisations about security, transparency, accountability, automated decisions, fairness and lawful processing. That makes the exercise a consultation intended to inform future guidance, not a newly enacted set of legal restrictions beginning on the announcement date.
The everyday risk is an invisible chain of access
Imagine a workplace assistant instructed to find a missing customer record and update a spreadsheet. The spreadsheet may link to a document store, the store to an email thread, and the email to a third-party system. The instruction can appear harmless while the access path is surprisingly broad. If the software copies material outside the organisation or misunderstands which customer was intended, the fact that a person originally requested the task does not make the outcome safe.
This is why privacy and accountability cannot be separated. An employer needs to decide what the agent can inspect, whether it may transmit information, which operations require a second approval and how to reconstruct an action later. The question is not simply whether a model is clever enough to finish a task. It is whether the organisation remains responsible for what happens while the model works.
LiveAIWire has previously discussed the limits of human oversight for AI agents. The ICO’s intervention adds the regulator’s perspective: putting an autonomous system in the middle of a process does not erase obligations over personal information. That principle matters to customers, employees and anyone whose details are kept in connected business software.
What people should take from the regulator’s move
The announcement offers two practical tests. For a consumer AI service, ask whether the company explains personal-data use in a way that a normal person can understand and offers usable routes to exercise applicable rights. For an AI agent connected to accounts or documents, ask whether its access is limited to what the job requires and whether consequential actions need approval. Those questions cannot prove a system compliant, but they identify where careless design creates avoidable exposure.
The ICO’s work follows broader unease about AI data practices. LiveAIWire has reported on people’s discomfort over AI data consent, a concern that becomes more concrete when an assistant can act rather than simply speak. Technology may make retrieving and organising information easier, while making the route that information takes harder for the person concerned to see.
The regulator is not arguing that autonomous assistants have no legitimate uses. Its message is that faster, more capable systems need appropriately robust controls. Ten developers have accepted changes or commitments, and a new consultation is under way. Neither development should be confused with a clean bill of health. The important measure will be whether users can understand and control what happens to information about them as increasingly active AI systems become part of ordinary products and workplaces.
About the Author
Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity and the social impact of emerging technology. LiveAIWire is an independent, human-led technology publication using AI-assisted research, editorial production and original AI-assisted editorial illustrations under his direction.
