The UK Information Commissioner’s Office (ICO) has initiated formal regulatory compliance audits examining 11 major developers of artificial intelligence foundation models. The supervisory action focuses on the lawful basis of large-scale web scraping, biometric data extraction, and compliance with the newly enacted automated decision-making (ADM) provisions under the Data (Use and Access) Act 2025.
Scrutiny under enhanced UK GDPR automated decision provisions
The ICO’s enforcement drive comes as new Articles 22A through 22D of the UK GDPR establish rigorous statutory benchmarks for automated decision-making and algorithmic governance:
- Lawful basis for training data scraping: The ICO is demanding proof that developers relying on legitimate interests have conducted legitimate interest assessments (LIAs), respected digital opt-out protocols, and purged sensitive personal data before pre-training.
- Latent personal data and memorization: Regulators are auditing models for “unintentional memorization,” verifying whether sensitive personal data can be extracted through targeted adversarial prompt engineering.
- Statutory Code of Practice on AI: The investigations will directly inform the ICO’s forthcoming statutory Code of Practice on AI and Automated Decision-Making, establishing mandatory engineering safeguards for UK deployers.
Enforcement powers and liabilities for non-compliant tech firms
Information Commissioner John Edwards has warned that voluntary engagement does not preclude punitive statutory enforcement:
- Formal information notices and audits: Model developers failing to demonstrate comprehensive data governance face mandatory audit orders and binding corrective timelines.
- Substantial statutory fines: Serious breaches of UK data protection law carry maximum penalties of up to £17.5 million or 4% of total worldwide annual turnover, whichever is higher.
- Supply chain transparency for UK businesses: Commercial enterprises integrating third-party AI foundation models must independently verify vendor data provenance before deploying client-facing automated workflows.
