The UK ICO extracted data protection commitments from Amazon, Anthropic, Apple, and seven other AI giants — then launched a formal investigation into xAI's Grok chatbot.
UK Regulator Secures AI Data Pledges From 10 Major Firms, Opens Formal Grok Investigation
By Hector Herrera | October 9, 2026 | Government
The UK's data protection regulator has extracted formal commitments from ten of the world's largest AI developers and simultaneously launched a full investigation into Elon Musk's xAI over its Grok chatbot — the strongest coordinated regulatory action on AI data practices the UK has taken to date.
The UK Information Commissioner's Office (ICO) announced both moves on October 9, 2026. Together they mark a clear shift from voluntary engagement to enforcement posture.
What the ICO Secured
The ten companies that made or committed to data protection changes under ICO scrutiny are:
- Amazon
- Anthropic
- Apple
- Cohere
- DeepSeek
- Google
- Meta
- Microsoft
- OpenAI
- Stability AI
The ICO has not published the full terms of each company's commitments, but the agency's statement confirms that changes were made to how these systems process personal data belonging to UK residents. The ICO's leverage is the UK GDPR (General Data Protection Regulation) — the post-Brexit version of the EU's privacy law — which gives the regulator power to impose fines of up to £17.5 million or 4% of global annual turnover, whichever is higher.
Get this in your inbox.
Daily AI intelligence. Free. No spam.
The Grok Investigation
xAI's Grok chatbot is now under formal investigation. The ICO says the probe covers two distinct issues: how Grok processes personal data and the chatbot's potential to generate harmful sexualized content. xAI has also been removed from the ICO's voluntary engagement programme entirely — meaning the company is no longer treated as a cooperative participant but as a subject of regulatory scrutiny.
This is significant. The voluntary programme was the primary mechanism the ICO used to secure changes from the other ten firms. Removing xAI from that track means the regulator has concluded that voluntary engagement is not producing adequate results.
Grok is trained on posts from X (formerly Twitter), a platform with hundreds of millions of users who never consented to have their data used to train an AI model. That data pipeline has been a persistent legal concern in the EU and UK since Grok launched publicly.
Why This Matters
For businesses: If you operate in the UK and process personal data to train or operate AI systems, the ICO has made clear it is actively reviewing how that data flows. The ten firms that made commitments were almost certainly asked to change things like data retention practices, how personal data is excluded from training pipelines, or how users can exercise their rights to access or delete data that's been processed.
For AI developers: The removal of xAI from the voluntary programme is a warning. The ICO's voluntary engagement track was designed to give companies a path to compliance without immediate enforcement action. Companies that don't engage meaningfully lose that protection.
For consumers: UK residents using any of these AI products now have slightly stronger grounds to believe their personal data is being handled in a UK GDPR-compliant way — though the ICO's published statement stops short of confirming that all ten companies are fully compliant.
What to Watch
The ICO's investigation into Grok will determine whether xAI faces formal enforcement action, potentially including a fine. Watch for the ICO to also extend scrutiny to AI agents — the announcement specifically referenced "AI agents" in its scope, signaling that the next wave of regulatory attention will hit autonomous AI systems that take actions on users' behalf, not just chatbots.
Sources: UK ICO announcement, October 9, 2026
Did this help you understand AI better?
Your feedback helps us write more useful content.
Get tomorrow's AI briefing
Join readers who start their day with NexChron. Free, daily, no spam.