What was actually agreed
Three things, none of them surprising to anyone who has ever read a privacy policy. First, clearer transparency information about how personal data is used to train models. Second, stronger mechanisms for people to exercise their rights over that data. Third, tougher assessments of the safeguards developers have in place.
These are the same categories regulators have been asking about for years. The significance is not what was promised but who promised it: all ten names the ICO went after signed on.
What it does not settle
The ICO published a companion report setting out its position on generative AI and data protection, and the open questions are the interesting part. Personal data held inside trained models, especially sensitive information, remains unresolved territory. So does the practical question of how anyone gets their details removed once a model has already been trained on them; retraining a frontier model is not a process anyone runs on request. Then there is extraction risk: personal information pulled back out of a model that was supposed to have absorbed it.
The regulator says it is monitoring whether developers deliver on the promises, and that it will use its full regulatory powers where needed. That is the sentence to remember the next time nothing happens.
The lab that is not on the list
The supervisory program originally covered eleven developers. The eleventh, xAI, was quietly separated out: the ICO has opened a formal investigation into Grok's processing of personal data, including the generation of harmful manipulated imagery. Being under investigation is not the same as being found non-compliant. Still, "ten labs agreed" is partly a story about the one that didn't.
Agents are next
The ICO also launched a six-week call for evidence on agentic AI, asking how organizations manage the data risks of autonomous systems. This is not an abstract concern. The regulator says it has made enquiries with OpenAI, Anthropic, Meta, and the UK's AI Security Institute over reported incidents of agents breaching guardrails and attempting to exfiltrate data from websites. The commitments announced this week cover today's models. The next fight is over systems that act on their own.
Sources
- [1] gHacks — UK ICO Secures Data Protection Commitments From OpenAI, Google, Microsoft, and Seven Other AI Developers (Oct 9, 2026)Read source
- [2] ComputerWeekly — AI model developers have 'no justification' for failing to comply with privacy law (Oct 9, 2026)Read source
- [3] MLex — Anthropic, Google, OpenAI agree to UK privacy changes, regulator confirms (Oct 8, 2026)Read source
- [4] 15 Minute News — AI giants promise to play nice with personal data after UK watchdog scrutiny (Oct 8, 2026)Read source