This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.

Search the website
Thought Leadership

Ten AI Giants, One Regulator and a Lesson for Everyone Else: What the ICO’s Foundation Model Report Really Tells Us

Passle image

On 8 October 2026, the ICO published a report setting out the results of its supervision of the largest foundation model developers operating in the UK, alongside a six-week call for evidence on agentic AI. Taken together, they give the clearest picture yet of how the regulator thinks about the models underpinning so many business tools, and of where its attention is heading next.

What actually happened

Ten developers, namely Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI, have made, or committed to make, data protection changes following ICO scrutiny. The programme originally covered 11 developers, but the ICO paused its engagement with X.AI after opening a formal investigation into the Grok AI system, which is ongoing. The changes include clearer transparency information, stronger mechanisms for people to exercise their rights and tougher assessments of safeguards, and the ICO says it is monitoring progress against those commitments. 

The detail is more revealing than the headline. When the ICO reviewed developers' legitimate interests assessments (LIAs) and DPIAs, it found that firms did not always identify specific interests for each type of personal data at each stage of development, that some lacked substantive evidence of necessity, and that impacts on individuals were rarely backed by detailed analysis of how well safeguards actually worked. Several developers have since updated their LIAs to strengthen the evidence on the efficacy of their safeguards. 

The bar for a legitimate interests assessment just went up

This is the part of the report I would expect to travel furthest beyond the AI sector. The ICO says that broad interests such as "developing and improving our products and services", "training our models" or "benefitting humanity" are unlikely to be enough without specification or justification. It expects a robust, impartial necessity assessment that considers less intrusive alternatives such as synthetic data, and it says general or unsubstantiated claims about safeguards are unlikely to be sufficient. 

None of this is a new legal test. But the regulator has now shown, in public, what it looks for when it opens an LIA, and the answer is evidence rather than assertion. Any organisation using its own customer or employee data to fine-tune or improve a model should expect the same scrutiny. An LIA that says "we have appropriate safeguards" without showing they work now looks exposed.

"May incidentally include personal data" is no longer a safe phrase

On transparency, the ICO criticised vague language such as statements that training data "may incidentally include personal data", and privacy information scattered across multiple notices, help pages and interfaces. It also describes a "privacy maze" in which overly layered approaches made it hard for people to understand their rights. Describing training data simply as "publicly accessible information" is unlikely to be sufficient. 

There is a practical lesson here for anyone repurposing existing data. Where account data such as prompts, conversations or uploaded files is reused for training, the ICO says organisations should explain this clearly, assess compatibility with the original purpose, state whether historical data is being used and explain opt-out options. It also suggests leaving a reasonable period between notifying people and using their data for training, so that they can object. Anyone who has watched a product team want to switch on a "use data to improve our AI" setting overnight will recognise why that matters.

Your vendor's model may itself be personal data

The ICO maintains its position that models can contain personal data, noting that some developers disagreed and that it is reviewing its 2020 position to ensure it remains justified. Its view is that whether a specific model contains personal data requires a case-by-case assessment, influenced by factors such as model size, duplication in the training data and the number of training periods.

This has real consequences in contracts. If a model can contain personal data, then questions about where the model is hosted, who can access it, what happens to fine-tuned versions at the end of a contract and how rights requests are handled stop being theoretical. The ICO also says developers should take responsibility for ensuring that everyone in the training data supply chain, including data brokers and deployers, meets their transparency obligations. We should anticipate that expectation to be pushed down the chain through contractual terms, and expect suppliers to ask what deployers are doing on their side.

Special category data: the regulator admits the problem

The most candid part of the report concerns Article 9. The ICO found that developers are likely to be processing special category data, intentionally or not, unless they can show otherwise. It identifies only two potentially applicable conditions, "manifestly made public" and scientific research, and accepts that these are unlikely to cover all such processing. Where no condition is available, developers should focus on preventing collection, filtering it out or avoiding processing it. 

The ICO goes further and acknowledges that current training practices present technical challenges for compliance, and that it is raising these "boundaries of the law" with Government. It is unusual for a regulator to say quite so plainly that the law and the technology are pulling in different directions. For organisations, the sensible reading is that sensitive data in AI training will remain an area where the regulator expects visible effort and documented filtering, not silence.

Agents are next, and autonomy is not a defence

The second half of the announcement is arguably more important for the coming year. The ICO has made enquiries with OpenAI, Anthropic, Meta and the UK's AI Security Institute about recent agentic AI testing and deployment, after reports that certain agents bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face. The report notes that such incidents show the potential for models to autonomously access and exfiltrate personal data. 

Richard Nevinson, Director of Technology Regulation at the ICO, put it bluntly: "the fact AI agents act with autonomy is not an excuse for poor compliance", which is worth remembering. Organisations deploying agents that can browse, send messages or act across systems are the ones whose names will appear on the controller line. The questions to ask now are familiar ones applied to a new context – what can the agent access, what can it do without a human signing off, how is its activity logged, and who has assessed the risk before it went live?

The call for evidence covers security, transparency, accountability, automated decision-making, fairness and lawful data use, and closes on 20 November 2026. Its findings will feed into future guidance and the ICO's forthcoming statutory code of practice on AI and automated decision-making. Organisations with live or planned agent deployments have a genuine opportunity to shape that code, and a code of practice is a document regulators and courts tend to take seriously.

The takeaway

The ICO has chosen supervision and public commitments over enforcement for the largest developers, at least for now. But the report reads as a template; the standards it applies to Amazon, Google and OpenAI on LIAs, notices, rights handling and special category data are the same standards it will apply to anyone else using personal data to build, train or tune AI. The difference is that the big developers have now had a detailed private briefing on what the regulator expects and have been publicly named as having responded. Everyone else has the report.

If you would like to discuss how current or future regulations impact what you do with AI, please contact Olivia Ward, Tom Whittaker, Lucy Pegler, Martin Cook or any other member in our Technology team. 

See more from Burges Salmon

Want more Burges Salmon content? Add us as a preferred source on Google to your favourites list for content and news you can trust.

Update your preferred sources

Follow us on LinkedIn

Be sure to follow us on LinkedIn and stay up to date with all the latest from Burges Salmon.

Follow us