Find notable cyber news and cases, enriched with sources, timelines, and signals.

ICO formal investigation into Grok personal-data processing

Regulatory/Legal Action
First reported
Last updated
Happening score
H score 16
1 unique sources, 1 articles

Summary

Hide ▲

The ICO opened formal investigations into XIUC and X.AI LLC over Grok's personal-data processing, escalating UK regulatory scrutiny of the AI system. The probe centers on whether those practices can contribute to harmful sexualized image and video content. The action raises compliance pressure around data protection, safeguards, and the handling of sensitive personal information.

Related Happenings

ICO launches six-week call for evidence on agentic AI data-protection risks

Public Sector Action
H score16 First: 09.10.2026 11:00 Last: 09.10.2026 11:00 Sources 1

How related: These commitments come as the ICO has launched a six-week call for evidence, seeking views from developers and deployers of AI tools and other AI, security and privacy experts on how organizations are managing the data protection risks of agentic AI.

About this happening: The ICO launched a six-week call for evidence on agentic AI data-protection risks, drawing developers, deployers, and security/privacy experts into a public consul...

OpenAI confidential information leak

Data Leak
H score33 First: 02.10.2026 15:23 Last: 02.10.2026 15:23 Sources 1

About this happening: OpenAI parted ways with three safety researchers after confidential company information was mishandled outside approved procedures, including material tied to infras...

Irish Data Protection Commission (DPC) Fined Google €403m and required compliance changes within six months. on The order addresses unlawful location-data processing transparency

Regulatory/Legal Action
H score28 First: 21.09.2026 18:00 Last: 21.09.2026 18:00 Sources 1

About this happening: The Irish Data Protection Commission fined Google €403m ($460m) for GDPR violations involving location data. The enforcement action covers Web & App Activity...

AEPD urges stronger identity and credential controls against AI-assisted machine-speed attacks

Defensive Guidance
H score11 First: 16.09.2026 20:26 Last: 16.09.2026 20:26 Sources 1

About this happening: Spanish Data Protection Agency (AEPD) said it was notified of an alleged AI agent attack powered by a known LLM, and urged stronger digital identity and credenti...

CISA and NIST issue cloud identity token guidance

Public Sector Action
H score35 First: 16.09.2026 17:00 Last: 16.09.2026 17:00 Sources 1

About this happening: CISA and NIST issued final guidance for protecting cloud identity tokens and assertions, setting a federal cybersecurity baseline for federal agencies, cloud service...

Timeline

  1. 09.10.2026 11:00 1 articles · 1h ago

    ICO publishes agentic AI data protection report and calls for evidence

    Legal Policy Action Update

    The Information Commissioner's Office (ICO) published a report on data privacy in agentic AI and urged foundation model developers to put clear data protection policies in place when they process personal data to train models. The watchdog said AI companies must identify a lawful basis, provide meaningful transparency, enable people to exercise their rights, and show safeguards that materially reduce risk, and it also launched a six-week call for evidence on how organizations are managing the data protection risks of agentic AI.

    Show sources
  2. 09.10.2026 11:00 2 articles · 1h ago

    ICO opens formal investigations into XIUC and X.AI over Grok data processing

    Legal Policy Action Update

    The ICO confirmed that it had opened formal investigations into X Internet Unlimited Company (XIUC) and X.AI LLC (X.AI) over their processing of personal data in relation to the Grok AI system. The probe examines whether that processing could contribute to harmful sexualized image and video content, increasing UK regulatory scrutiny of Grok's handling of personal data and associated safety safeguards.

    Show sources