The UK Information Commission's Office (ICO) published a report on October 8, 2026 securing data protection improvements from ten foundation model developers and setting out its regulatory positions on special category data and personal data held in foundation models. The ICO also opened a six-week call for evidence on agentic AI and confirmed enquiries with OpenAI, Anthropic, Meta and the UK AI Security Institute into reported agent testing incidents.

UK-facing foundation model developers (Amazon, Anthropic, Apple, Google, Meta, Microsoft, OpenAI, Cohere, DeepSeek and Stability AI), deployers of agentic AI systems, and providers of consumer-facing generative AI chatbots must review their training and deployment against the ICO's positions on transparency, rights mechanisms, safeguards and special category data, and respond to the call for evidence by November 20, 2026, or face escalation to formal investigation and fines of up to £17.5 million or 4% of global worldwide turnover under the Data (Use and Access) Act 2025. The ICO is monitoring the ten developers' progress against their commitments and has shown it escalates, having opened a formal investigation into X.AI's Grok system and fined TikTok £12.7 million.

What did the ICO secure from the ten developers, and what positions did it set?

Following a two-year supervision programme covering 11 priority developers, the ICO secured commitments from the ten largest foundation model developers operating in the UK to deliver clearer transparency information, stronger mechanisms for individuals to exercise their data subject rights, and tougher assessments of safeguards. The report also fixes the ICO's regulatory positions on two contested questions: how special category data can be used lawfully in training, and whether foundation models themselves may contain personal data.

The ICO acknowledges that current foundation model training practices raise technical challenges for UK data protection compliance and data protection by design, and says it is raising these boundaries with Government. Its engagement with X.AI remains paused after the ICO opened its formal Grok investigation, leaving ten developers in the supervised group.

Who must act on the report and the agentic AI call for evidence?

The report and call for evidence reach three groups by market exposure. First, the ten named foundation model developers, whose training practices and transparency obligations are measured against the published positions. Second, deployers and integrators of agentic AI systems in the UK, the focus of the call for evidence and of the ICO's confirmed enquiries into agent testing. Third, providers of consumer-facing generative AI chatbots, including role-play and companion services, where the ICO is researching personalisation risks and engaging firms on transparency.

What must developers and deployers do, and by when?

The binding date is November 20, 2026, the close of the six-week call for evidence on agentic AI. Developers and deployers should respond with evidence on how they manage the data protection risks of autonomous agents, covering security, transparency, accountability, automated decision-making, fairness and lawful data use.

In parallel, the ten supervised developers must deliver on their transparency, rights and safeguards commitments, with the ICO actively monitoring progress. The evidence gathered will inform the ICO's forthcoming statutory code of practice on AI and automated decision-making, so responses shape the binding rules that follow.

WorkstreamWhat the ICO did on October 8, 2026What exposed actors must doDeadline
Foundation model supervisionPublished report with regulatory positions on special category data and personal data in modelsDeliver transparency, rights and safeguards commitments; align training with the positionsMonitored, no fixed date
Agentic AIOpened call for evidence; confirmed enquiries into agent testingSubmit evidence on agent data protection risksNovember 20, 2026

What happens if companies fall short of the ICO's expectations?

The ICO's enforcement record under the Data (Use and Access) Act 2025 sets the stakes. Penalties reach £17.5 million or 4% of global worldwide turnover, and the regulator has shown it moves from supervision to formal action: it opened a formal investigation into X.AI's Grok system and fined TikTok £12.7 million. The ICO is contacting developers and their testing partners to establish what risk assessments and safeguards were in place during the reported agent incidents, where agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face.

Continuous, per-jurisdiction monitoring surfaces an ICO position or call for evidence the moment it publishes, before a statutory code turns guidance into hard rules.

Live
UK: AI, data-protection and cyber-resilience legislation
Track the Westminster legislative pipeline and regulatory outputs from DSIT, Ofcom, the ICO and the NCSC across online-safety, smart-data and technology-governance domains.
Email 40+ news

What to do next

  • Map your foundation model training and agentic AI deployment against the ICO's positions on transparency, rights, safeguards and special category data.
  • Draft and submit a response to the agentic AI call for evidence before November 20, 2026.
  • If you are one of the ten supervised developers, confirm your commitments are on track and document progress for ICO monitoring.
  • Brief your data protection and AI teams on the forthcoming statutory code of practice on AI and automated decision-making.

Obsidian's regulatory intelligence desk follows ICO positions, enforcement actions and the forthcoming AI code across jurisdictions, so compliance teams see the next obligation before guidance hardens into binding rules.