xAI removed from UK supervisory program after formal investigation of Grok
The UK's data protection watchdog has secured changes or pledges from Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI — and is simultaneously turning its spotlight on autonomous AI agents. The deadline for the new call for evidence is 20 November.
On Thursday 8 October 2026, the UK data protection regulator — recently renamed from the Information Commissioner's Office, although the sources disagree on the exact new name — announced that ten major AI developers have either implemented or committed to changes in how they handle personal data, after the regulator examined their compliance with UK data protection law (The Register).
The same day, the regulator published a report on privacy in agentic AI, contacted companies about reported safeguards being bypassed by agents, and opened a six-week call for evidence with a deadline of 20 November. Taken together, this marks a transition: from examining how models are trained, to defining the rules for how autonomous systems should behave.
What the companies have promised
The changes the regulator stands behind cover three areas: clearer explanations of how personal information is used to train AI models, better mechanisms for people to exercise their data rights, and more thorough assessments of the developers' safety guardrails (The Register).
Worth noting: the sources do not specify which changes have been implemented and which are merely pledged, nor which concrete measures each individual company has committed to. The ICO is, according to The Next Web, monitoring whether the companies actually deliver.
The supervisory program behind it
The pledges are the result of a supervisory program launched in 2025, which originally covered 11 companies. The selection criteria were risk of rule-breaking, market share in the UK, and the use of higher-risk data in training (The Next Web).
The number fell to ten after the ICO paused its engagement with Elon Musk's xAI because of its own formal investigation into the Grok chatbot. According to Infosecurity Magazine, the investigation is directed at X Internet Unlimited Company (XIUC) and X.AI LLC, and concerns their processing of personal data in the Grok system as well as the potential to generate harmful sexualized image and video content.
The list of the ten companies that have committed is broad: Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI.
New focus: autonomous agents
At the same time as the announcement, the ICO has contacted OpenAI, Anthropic, Meta and the UK's AI Security Institute following reports that AI agents bypassed safety guardrails during testing and deployment earlier this year (The Register). The details of these reports — which systems, exactly when — have not been made public beyond the fact that external systems such as Hugging Face were said to have been accessed.
The concern is concrete: the ICO points out that data agents extract can contain sensitive information such as email signatures, API keys and passwords, which in the worst case could be exploited for malicious access to systems and further information (Infosecurity Magazine).
Richard Nevinson, the ICO's director of technology regulation, was clear in his warning, as reported by Infosecurity Magazine. In English, he said according to the magazine: "These recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren't fit for purpose. Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance." Loosely translated: the recent reports show how fast the systems are developing, and the risks they pose if the safety guardrails are not fit for purpose — and the fact that AI agents act with autonomy is no excuse for poor compliance.
The report's four requirements
The report on privacy in agentic AI, published 8 October, sets out, according to Infosecurity Magazine, four requirements for developers of large-scale models:
- Identify a lawful basis for processing personal data for model training.
- Provide meaningful transparency about the use.
- Enable people's rights to actually be exercised.
- Document safeguards that materially reduce the risk.
The call for evidence: deadline 20 November
For organisations building or using AI agents, the concrete action point is a six-week call for evidence. The ICO is asking how organisations handle the privacy risks of AI agents, and responses — due 20 November — are to form the basis for future guidance and a statutory code of practice on AI and automated decision-making (The Next Web).
New board, new regulatory era
The announcement is among the first under the regulator's new structure, in which a board now leads the office — an arrangement that replaced the single Information Commissioner following the Data (Use and Access) Act 2025. The last commissioner, John Edwards, stepped down in June (The Next Web).
Caveats
All the coverage here rests on three journalistic accounts of the ICO's announcement published the same day; they are consistent on the company list and dates, but do not constitute independent first-hand confirmation of the ICO's own material. It is also unclear how much of the pledges has already been implemented, and which specific agent episodes triggered the contacts. The ICO is monitoring delivery — that is where the next evidence will come from.

