The 60-second summary
On 8 October 2026, the ICO published the outcome of its foundation-model supervision programme. Ten developers—Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI—have made or committed to changes involving legitimate-interest assessments, transparency, information-rights mechanisms and evidence for safeguards. The ICO also opened a call for evidence on agentic AI, covering security, transparency, accountability, automated decision-making, fairness, purpose limitation and lawful processing. Responses close at the end of 20 November 2026. The report states regulatory expectations under existing data-protection law; it is not a new statute or a finding that every named developer infringed the law.
Timeline that matters
8 October 2026
20 November 2026
After consultation
What changed
The ICO published the results of targeted supervision of ten priority foundation-model developers after suspending X.AI from that programme when a separate formal investigation began.Apple, Cohere and OpenAI changed transparency information, including standalone model-training notices and clearer information about datasets, development stages, retention, transfers and rights.Amazon, Anthropic, DeepSeek, Google, Meta, Microsoft and Stability AI made or committed to measures including dedicated foundation-model information, clearer dataset-source summaries, improved rights routes and stronger evidence in legitimate-interest assessments.The ICO set out positions on lawful basis, special-category data, information rights and when a trained model may itself contain personal data.A separate six-week call for evidence seeks operational evidence about agentic-AI security, transparency, accountability, automated decision-making, fairness, purpose limitation and lawful processing.
Who should care
Foundation-model developers and providersOrganisations developing or deploying AI agentsPrivacy, AI governance, security and product leadersTeams responsible for training data, model evaluation and red-teamingProcurement and vendor-risk teams buying foundation-model or agentic-AI servicesLegal and compliance teams managing rights requests and legitimate-interest assessments
Why this matters for global organisations.
Regulatory scrutiny is moving from policy statements to operational evidence. Training-data governance, rights handling, safeguard testing and agent permissions need accountable owners, measurable controls and retained proof.
15 actions to start now
- Map every personal-data source used for pre-training, post-training, fine-tuning, evaluation and product personalisation, including brokered, scraped and user-provided data.
- Separate first-party and third-party transparency information and test whether people can find and understand it without navigating a privacy maze.
- Record the specific purpose and lawful basis for each data category and model-development stage; avoid generic interests such as merely improving products.
- Refresh legitimate-interest assessments with necessity analysis, less-intrusive alternatives and independently supportable evidence that safeguards work.
- Identify special-category data risks by source and category; document the Article 9 condition or controls that prevent, filter or avoid the processing.
- Test model memorisation, extraction, singling-out and linkability risks across languages and realistic adversarial prompts.
- Provide accessible routes for access, erasure, restriction and objection requests covering datasets, models and outputs, including requests from non-users.
- Document how technical limitations affect rights outcomes and require case-specific reasoning before refusing a request.
- Review retention, deletion, overseas-transfer and downstream-recipient disclosures for training and evaluation data.
- For agentic AI, inventory tools, permissions, credentials, communication channels, external systems and actions available to each agent.
- Set least-privilege permissions, approval gates, containment controls and kill switches for high-impact agent actions.
- Log prompts, tool calls, data access, overrides, outputs and human approvals in a form suitable for incident investigation and rights handling.
- Run pre-deployment and continuous tests for unauthorised communications, protection bypass, excessive data access, unfair outcomes and purpose drift.
- Assign accountable owners across privacy, security, product and legal teams, with escalation criteria for agent behaviour and data incidents.
- Decide whether to respond to the ICO call for evidence and preserve supporting examples, testing results and proposed practical safeguards.
Evidence worth retaining
- Training-data inventory and provenance records by lifecycle stage
- Privacy notices, just-in-time notices and user-testing results
- Legitimate-interest assessments and DPIAs with dated approvals
- Special-category data assessments and filtering test results
- Model memorisation, extraction, singling-out and linkability test reports
- Rights-request workflows, request logs, search records and refusal rationales
- Retention schedules, deletion records and transfer assessments
- Agent tool and permission inventories, approval matrices and kill-switch tests
- Security and red-team results covering protection bypass and unauthorised channels
- Audit logs for prompts, tool calls, external access and human intervention
- Vendor commitments, remediation plans and progress evidence
- Consultation response and source materials, if submitted
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which entities are controllers or processors at each model-development and deployment stage?
- Is the stated purpose and lawful basis sufficiently specific for each source and category of personal data?
- Which Article 9 conditions could apply, and what processing must be prevented if none applies?
- When could the model or its embeddings remain personal data after training?
- What reasonable and proportionate search is required before refusing an information-rights request?
- Which agent actions require human approval, and when could automated-decision rules apply?
- Do contracts provide enough information and audit rights to validate provider safeguards?
- Could a consultation response disclose confidential, security-sensitive or third-party information?
Official sources
- ICO — announcement, 8 October 2026
- ICO — foundation-model supervision report
- ICO — industry supervision findings and commitments
- ICO — agentic AI call for evidence, closes 20 November 2026
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.