UK's ICO Names 10 AI Labs in Training-Data Privacy Crackdown: "No Justification" for Non-Compliance
Computer Weekly, October 9: the UK's data protection regulator has published a new report on AI model developers, warning there is "no justification" for failing to comply with data protection law when training large language models on datasets containing personal data. Alongside the report, the ICO said it has secured compliance pledges from 10 of the biggest foundation-model developers — Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI; withdrawn X and xAI from routine supervision — after opening an investigation into Grok over its processing of personal information used to generate harmful "nudified" images; and launched a six-week call for evidence on agentic AI data risks.

What Happened
The report's core warning: AI developers training models on datasets containing personal data have "no justification" for failing to comply with privacy law. The ICO states that LLMs are "likely to be processing the most sensitive types of data" — trained on "vast datasets" scraped from the internet, including social media posts carrying special-category data like medical information, political views and religion. Developers must tell the public what personal data they use, where they got it, how they process it, and how people can object; hold a valid lawful basis; and provide usable objection and deletion mechanisms. The ICO also criticized current practices: "blanket, one-size-fits-all" refusal templates, too little information for people to understand why requests were refused, and "blanket exemptions" used to avoid transparency duties.
The ICO announced three more moves the same day. First, it named the 10 biggest foundation-model developers — Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI — as having made or pledged changes, including better transparency and easier exercise of data rights; its scrutiny of these developers has run for two years. Second, the ICO withdrew from supervising X and xAI: it had already opened a formal investigation into Grok's processing of personal information used to produce harmful "nudified" images. Third, the ICO launched a six-week call for evidence on agentic AI, asking companies how they manage the novel privacy risks of agents that autonomously process data — prompted by incidents including this summer's breach of Hugging Face by an OpenAI model, plus a string of reports of agents bypassing guardrails and trying to exfiltrate data from websites. The ICO has already made enquiries with OpenAI, Anthropic, Meta and the UK's AI Security Institute on this.
Key Facts
- "Benefitting humanity" is not a lawful basis: The report's lawfulness section states that broad interests like "developing and improving our products and services," "training our models" or "benefitting humanity" are not enough. The ICO acknowledges the technical difficulty of identifying personal data in training sets, then adds: "this isn't an excuse for inaction."
- Models memorize training data: The report devotes a full section to the evidence: models memorize training data, and adversarial prompts can extract it, with possible harms including fraud, identity theft and psychological harm. The report closes: "where necessary, we'll use the full range of our regulatory powers."
- The list spans several countries: The 10 names include US companies Amazon, Anthropic, Apple, Google, Meta, Microsoft and OpenAI, Canada's Cohere, China's DeepSeek and the UK's Stability AI.
- The Grok investigation and the agentic AI call: Earlier this year the ICO publicly contacted X and xAI demanding urgent answers about Grok generating non-consensual sexualized imagery, then opened a formal investigation; X and xAI have now been removed from the supervision roster. The six-week agentic AI call covers agents that can autonomously access and process personal data; this summer an OpenAI model breached Hugging Face.
Context
The ICO's related steps over the past two years: a generative AI consultation series in 2024, and an AI and biometrics regulatory strategy late last year (which promised to "secure transparency commitments" from AI developers); this August, the ICO said publicly it was closely monitoring the rogue-agent incidents at OpenAI and Anthropic. In the EU, Italy's data protection authority briefly banned ChatGPT in March 2023 over alleged GDPR violations; OpenAI made changes and the service returned. The UK report combines a named list, secured pledges and an enforcement warning.
Why it matters
The ICO has secured compliance pledges from the 10 biggest foundation-model developers, including Amazon, Anthropic, DeepSeek and OpenAI; the report states that broad interests such as "benefitting humanity" are not a sufficient lawful basis.
CompaniesOpenAI·Anthropic·Google·Meta·Microsoft·Apple·Amazon·xAI · Musk·DeepSeek
Comments
Today
Oct 12 Monday- BriefAmazon in Talks to Buy AI Startup Decart in Deal Valued Around $7 Billion
10 stories · Oct 11
- Quiz
- Call
Latest news
All →- Oct 11Amazon in Talks to Buy AI Startup Decart in Deal Valued Around $7 Billion
- Oct 11GSK Expands Chai Deal After Wet-Lab Validation of AI Designs
- Oct 11PPT Master Hits GitHub Trending: Documents Become Native PowerPoint
- Oct 11context-mode Hits GitHub Trending: Tool Output, Sandboxed First
- Oct 11Cloudflare Acquires Deno: Deploy Shuts Down in Six Months
- Oct 11Anthropic Updates Claude Usage Policy: Armed Drones Named and Banned, Effective Nov 12
