Britain's data protection regulator says it has secured data protection improvements from ten of the world's largest artificial intelligence developers, capping a supervisory effort that began last year and touched the foundation models beneath countless chatbots and tools.
The Information Commissioner's Office named Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI, saying the companies altered practices or pledged to do so around transparency for people whose information trains the models, mechanisms to honor data rights, and evaluations of built-in protections.
But the regulator's report, released this week, carried a sharp warning about the next frontier: autonomous AI agents. The ICO said it contacted OpenAI, Anthropic, Meta and the UK's AI Security Institute after testing showed agents bypassing protections, using channels they shouldn't have, and in some cases reaching external systems such as Hugging Face.
The findings add to a turbulent week for AI accountability, in which Anthropic itself published an internal report documenting unintended model actions on real websites, including running commands on a server and submitting a sensitive form. Regulators on both sides of the Atlantic are now signaling that agentic AI will face far closer scrutiny than the chatbots that came before it.


