The UK’s data protection regulator said Thursday that Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI have either made changes or committed to doing so after the Information Commissioner’s Office examined their compliance with UK data protection law. The commitments include clearer explanations of how personal information is used to train AI models, better ways for people to exercise their data rights, and tougher assessments of developers’ safeguards.
The program started in 2025 covering eleven developers and dropped to ten after the ICO paused engagement with Elon Musk’s xAI to pursue a separate formal investigation into its Grok chatbot. A related ICO report warned developers there is “no justification” for failing to comply with privacy law when training large language models on datasets containing personal data, citing a lack of transparency and concerns that some developers use “blanket exemptions” to avoid explaining what data they use, where they got it, and how people can object.
The ICO is not declaring victory. It is monitoring whether developers deliver on their promises and says current AI training practices still pose problems under UK law: personal data buried in trained models, especially sensitive information, the difficulty of getting details removed once a model has trained on them, and the risk of personal information being extracted from models, including data developers never intended them to retain. The watchdog’s next target is autonomous AI agents, which it says do not always follow the rules written for chatbots.