← Back to the feed

Ten AI firms pledge stronger personal data safeguards after ICO scrutiny

The Register ·

Ten major AI developers have changed, or promised to change, how they handle personal data after scrutiny by the UK Information Commissioner’s Office (ICO). The commitments aim to make data use clearer, help people exercise their rights and strengthen safeguards, but the regulator says compliance problems remain and it will monitor progress.

The ten companies are Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI; the ICO paused its work with xAI while investigating its Grok chatbot separately. The watchdog is also examining autonomous AI agents, contacting OpenAI, Anthropic, Meta and the UK AI Security Institute after reports of agents bypassing safeguards. Its six-week call for evidence closes on 20 November and will inform future guidance and a statutory code.

  • Ten AI developers have committed to stronger personal data protections.
  • The ICO says questions remain about data in trained models.
  • A call for evidence on AI agents closes on 20 November.

New here? Start with this

The Information Commissioner's Office is the UK's independent regulator for data protection, overseeing how organisations collect and use personal information such as names, addresses, browsing habits and location data. The regulator has been examining how major artificial intelligence companies handle this sensitive information.

AI systems improve by processing large amounts of data, often including information about people who may not have consented to its use or even known it was being collected. This raises significant concerns about privacy, security and whether individuals can access or control their own information. Because millions of people interact with AI services daily, how these companies protect data affects the public broadly.

Major AI developers like Google, Microsoft, Amazon, OpenAI and Anthropic operate globally and hold vast quantities of personal information. The ICO's investigation examines whether these companies are transparent about how they use data and whether people have meaningful ways to protect their privacy. The regulator's findings carry weight because they can influence how AI companies operate in the UK and may inform future regulations.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

The ICO's findings that compliance problems persist despite pledges demonstrate that voluntary industry commitments are inadequate to protect citizens' personal data. When autonomous agents are reportedly bypassing safeguards and major firms require regulatory pressure to improve their practices, statutory frameworks and ongoing oversight become essential to ensure accountability and respect for privacy rights.

The case against

The ten companies' proactive pledges indicate genuine commitment to better data handling, and industry-driven solutions are preferable to regulation, which risks stifling the innovation that benefits society and creating compliance burdens that disadvantage smaller players and push development elsewhere. Market reputation concerns and liability already incentivise responsible practices, and measured oversight combined with industry engagement can achieve adequate safeguards without heavy-handed statutory rules.

AI Technology UK World

Read the full article at the source →

Originally published by The Register as “AI giants promise to play nice with personal data after UK watchdog scrutiny”.