Skip to content
Technology

The UK’s AI Privacy Review Puts Training Data and Autonomous Agents Under Scrutiny.

9 min read

The ICO has secured changes or commitments from ten major AI developers and opened a consultation on agent risks. For businesses buying AI or licensing data, the central question is becoming what a system is allowed to do with the information it receives.

The red facade of No. 3 Circle Square in Manchester as the building neared completion
No. 3 Circle Square in Manchester, photographed in March 2025. The ICO moved its head office into the building in September 2026.Valienne / Wikimedia Commons · CC BY 4.0
Key takeaways
  • The ICO’s October 8 announcement includes both completed changes and future commitments. It is not a blanket finding that AI privacy concerns have been resolved.
  • The agent consultation shifts attention toward what systems can access and do after deployment, with responses due November 20, 2026.
  • For companies buying or licensing data, a clear description of the intended use and preparation work is part of the commercial value.

Britain’s data regulator is widening its scrutiny of artificial intelligence, moving from the information used to train a model to the actions an AI agent can take inside other systems.

On October 8, the Information Commission’s Office, or ICO, said ten major foundation model developers had made, or committed to make, changes following its supervision. The companies include Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI. The regulator also opened a call for evidence on autonomous AI systems and confirmed enquiries into recent testing and deployment. Read the ICO’s announcement.

The combination matters. A company choosing AI software has to consider the information already inside the model and the additional information it will give the software once connected. An assistant that drafts a paragraph and an agent that reads customer accounts, changes a record and sends an email may use the same underlying model. They require different decisions about access and authority.

For businesses buying or licensing data, the announcement also sharpens a commercial question: how much can a buyer actually do with the information being offered? A large archive is only the beginning of an answer. The intended use, the people represented in the files and the practical limits on access shape the value of the transaction.

What the ICO actually found

The ICO’s industry supervision report distinguishes changes already made from work still promised. It says Anthropic updated documentation on processing purposes and safeguards, while OpenAI strengthened supporting evidence in its assessment. Other commitments include further documentation or reviews by Apple, Google and Microsoft. The report describes improvements in privacy information and ways for people to exercise their rights. It does not say that every concern has been resolved.

That distinction is easy to lose in an announcement about ten large companies. A commitment is a future obligation. A published notice is a change in what a company tells people. An effective safeguard is a change in what its systems allow or prevent. Each has value, but they are different forms of progress.

A business evaluating an AI supplier can apply the same distinction without recreating a regulator’s investigation. Ask what is available now, what is planned and what has been tested. If a capability depends on a future product release, it belongs in the future column of a purchasing decision. The vendor’s size does not turn a promise into a feature.

Training data is only one part of the relationship

A model’s training data helps shape how it responds. Information supplied while the model is being used gives it material for the task at hand. Connected applications can then let the system retrieve further information or take actions. Treating all three as a single question about whether a vendor trains on customer data leaves too much unexplained.

Consider a hypothetical accounting firm using an assistant to draft a client email. The firm might prohibit its vendor from using uploaded documents for model training. That is one restriction. The assistant may still need access to a current invoice, a project note and a recipient’s address to complete the task. The firm still has to decide which files it can read and whether the resulting message can leave the organisation without review.

Now give the same system permission to correct a balance, issue a credit and send the email. The quality of the draft is no longer the sole measure of success. The system must choose the correct account, act within an authorised amount and preserve enough history for a person to understand what happened. A well-written message sent from the wrong account remains a business failure.

This is why the buyer’s specification deserves as much attention as the model choice. “Connect our data” is too broad to guide a useful purchasing conversation. “Read these approved invoices and draft a response for this team to review” gives the supplier something concrete to support, price and test.

The new inquiry is about agents in use

The ICO’s call for evidence opened on October 8 and closes on November 20, 2026. It asks about security, transparency, accountability, automated decisions, fairness, purpose limits and lawful processing. It is an evidence-gathering exercise intended to inform guidance, not an announcement that a completed new agent rulebook has taken effect.

In the report’s introduction, the regulator points to reports from summer 2026 about agents interacting with external systems during cyber evaluations. The incidents described include bypassing protections and using unauthorised communication channels. These are reported testing events that drew regulatory attention. They should not be read as a finding that every deployed agent behaves this way.

The operational lesson is broader than an exceptional test. A business needs to know where a system’s authority stops. A travel assistant might compare fares but require approval before purchase. A purchasing agent might prepare an order but be unable to change the supplier’s bank details. A customer-service assistant might draft a refund recommendation while a separate system enforces the limit.

Those boundaries are also a way to preserve the economic benefit. If every ordinary action requires a senior employee to inspect the entire task from the beginning, the company may gain little. If nothing requires review, a small mistake can travel too far. Useful automation depends on making the routine path efficient and the consequential exception visible.

Why the source of the data matters

The ICO’s data protection analysis calls for clearer information about where training data comes from and how it is used. It explicitly addresses the supply chain, including data brokers and organisations deploying models. It also says whether a model itself contains personal data requires a case-by-case assessment. These are positions about UK data protection law, not a universal ruling on every dataset or model worldwide.

For a prospective data seller, the useful commercial response begins with understanding the archive. A business may have years of service tickets, project files or transaction histories. Some fields explain the work. Others identify employees, customers or unrelated people. Some documents belong to the company. Others came from a client under an agreement made for an entirely different purpose.

Imagine, as an example, a buyer looking for customer-support conversations in which an initial answer failed and a later response solved the problem. A company could offer a large export containing messages, attachments, addresses, account numbers and internal notes. Or it could first determine which cases illustrate the requested task, preserve the sequence of attempted solutions and review the information that does not contribute to that purpose.

The second approach takes effort before delivery. It may require someone who understands the ticket system, a specialist to review sensitive material and time to check that the edited conversation still makes sense. These costs should enter the commercial discussion early. They affect whether the deal is worth doing for the company and whether the buyer receives material suited to the intended task.

The underlying business judgment is simple: useful detail and unnecessary exposure can exist in the same file. Removing everything specific may destroy the value. Exporting everything may carry avoidable information into a use nobody considered when the file was created. The task is to preserve what makes the example useful while deciding what should travel with it.

Permission is part of the product

Data offers often start with size, format and history. Those are sensible facts to establish. A buyer also needs to understand the permitted purpose. Testing a model against a set of questions, training it on examples and allowing an agent to search a live system are different arrangements. One price for undefined “AI use” can conceal that difference until the parties disagree.

Three uses that deserve separate decisions

UseWhat the buyer doesA question to resolve
EvaluationUses examples to test performanceWho can see the test material and the answers?
TrainingUses examples to change model behaviourWhich models and future uses are included?
Connected accessLets a system retrieve current informationWhat can it read, change or send?

An agreement should describe the actual work the data will support. The same files can serve different purposes under different restrictions.

SnowRock analysis. Illustrative commercial distinctions, not a statement of legal requirements.

A seller does not need to offer all three. A buyer does not necessarily need all three. Narrower terms may make an otherwise difficult transaction workable. They can also create a mismatch if the buyer’s research team and purchasing team have different assumptions. A precise description of the intended use gives both teams something to agree on before the files move.

This changes the broker’s job as well. Matching a buyer with a company that holds relevant information is the start of the work. The introduction becomes more valuable when both sides understand the requested material, likely preparation, permitted use and unanswered questions. A long list of prospective sources is less useful if each conversation has to begin again from zero.

The cost will not appear only on the model bill

Businesses often compare AI tools by subscription price or the cost of processing a request. Those figures are visible and easy to put in a spreadsheet. Connecting the tool to a working company adds other costs: organising access, reviewing data, handling exceptions and maintaining the connection as systems change.

A hypothetical support deployment illustrates the difference. A cheap model may require frequent correction and broad access to unrelated account information. A more expensive configuration may work within a smaller set of approved records and produce drafts a team can review quickly. The cheaper model is not necessarily the cheaper service. The comparison depends on the whole task, including the people needed to finish it.

For data licensing, the same reasoning applies to the quoted price. A low purchase price can be followed by expensive preparation if the buyer cannot interpret fields or connect a decision with its outcome. A more carefully described collection may cost more upfront but reduce that work. This is a reason to examine the contents and delivery obligations, not a claim that every documented dataset deserves a premium.

What to watch next

The ICO says its next steps include monitoring developers’ commitments, producing guidance for agents and developing a statutory code of practice on AI and automated decision-making. It also plans to follow changes in training, fine-tuning and evaluation data. The immediate questions are therefore what the companies complete and what evidence businesses contribute to the open consultation.

For executives outside the UK, the announcement is worth reading as a view into questions a major regulator is asking of widely used suppliers. It does not replace an assessment of the rules that apply to a particular company. The practical purchasing questions travel more readily than the law: what information enters the system, what the supplier does with it and what authority the system receives.

The commercial opportunity is to make those answers part of the service from the beginning. A company that can describe its data precisely is easier to evaluate as a source. An AI supplier that can explain and demonstrate its access limits is easier to evaluate as an operating partner. Neither earns trust from a broad promise alone.

As AI takes on more work, the important unit of judgment becomes the whole assignment. A capable model is one component. The information it receives, the permissions it carries and the people responsible for the result determine whether that capability can be used inside a real business.

All Insights

More from SnowRock

A white Waymo vehicle with rooftop sensors traveling on a San Francisco street
Governance

The Delegation Ladder

Greg Brockman and Sam Altman speaking with Frederic Lardinois at TechCrunch Disrupt
Governance

A Business Leader's Guide to Working With Agents.

Destani Alvarado and Michael Wallace review a medical record on a computer at Keesler’s medical center.
Governance

When Artificial Intelligence Writes the Medical Record, What Happens to Clinical Judgment?