Two-thirds of AI companies fail to clearly explain what happens to your data, study finds


Artificial intelligence has rapidly evolved from a niche technology into a mainstream digital companion. People now use AI-powered chatbots and assistants to draft business reports, analyse sensitive documents, manage schedules, write computer code and even discuss personal issues. Yet a new study suggests that many users remain largely in the dark about what happens to the data they share.

According to the newly released Cybernews AI Trustworthiness Ranking 2026, nearly two-thirds of AI companies do not clearly disclose whether user information is used to train artificial intelligence models, while a similar proportion fail to provide clear information about how long user data is retained. These findings raise important questions about transparency, informed consent, and trust in the rapidly expanding AI industry.

Examining 500 AI companies

The Cybernews ranking evaluated 500 AI companies across 36 countries, assessing them across four broad categories: Data privacy, security, organizational transparency, and public perception.  Each company received an overall trustworthiness score based on publicly available information. For the data privacy component, researchers examined privacy policies to determine how clearly companies explained their data collection, sharing, usage and retention practices.

The scale of the analysis makes it one of the largest assessments of AI privacy practices conducted to date. The results suggest that despite growing public concern about AI governance, many organizations still provide only limited information about how customer data is handled.

One of the most significant findings concerns AI model training. The study found that 63% of companies do not clearly disclose whether they use user data to train their AI models. Among these organizations, 42% make no reference at all to training on user data within their privacy policies, while 21% provide only vague or incomplete explanations. Importantly, this does not necessarily mean that these companies are using customer data for AI training. Rather, it means users cannot readily determine whether such practices occur. This distinction matters because AI systems improve through exposure to large datasets. If conversations, uploaded files, emails or documents are incorporated into training processes, users may reasonably expect clear disclosure and informed choice.

From a data governance perspective, transparency is becoming a cornerstone of responsible AI deployment. Enterprises evaluating AI vendors increasingly ask whether information entered into a chatbot remains confidential, can be used for model improvement, or may ultimately influence future outputs. Without clear disclosures, obtaining definitive answers can be difficult.

How long is your data kept?

The report identified a second transparency gap surrounding data retention. According to Cybernews, 65% of AI companies do not clearly disclose how long user data is retained. Within this group, 9% fail to mention retention or deletion policies altogether, while 56% provide only broad statements without specific retention periods.  For privacy professionals, retention policies are fundamental. Regulatory frameworks such as the European Union’s General Data Protection Regulation (GDPR) emphasize data minimization and require organizations to avoid retaining personal information longer than necessary. Yet many AI privacy policies still rely on phrases such as “for as long as necessary” or “for legitimate business purposes,” language that offers little practical guidance to users attempting to understand the lifecycle of their information.

When customers provide proprietary corporate information, healthcare details, financial records or personal communications to an AI system, retention periods are often critical to risk assessment and compliance decisions. The Cybernews findings suggest that clear retention disclosures remain the exception rather than the norm.

Bigger companies appear more transparent

Not all organizations performed equally. The analysis found that larger AI companies generally maintained more transparent privacy policies than their smaller counterparts. Larger firms tended to provide clearer explanations regarding how data is collected, shared, used and retained.  There are several possible reasons for this trend, including the general tendency for large technology companies operating under intense public scrutiny and face greater regulatory oversight. They are also more likely to serve enterprise customers with dedicated procurement teams that routinely evaluate privacy and security requirements before deployment.

Smaller AI startups, by contrast, may focus primarily on rapid innovation and product development, potentially resulting in less mature privacy governance frameworks. This does not necessarily mean that smaller vendors are less secure. However, the findings indicate that they are often less explicit about explaining their practices to users.

The emergence of rankings focused on AI trustworthiness reflects a broader shift within the technology sector. Historically, software vendors competed on functionality and performance. In the AI era, organizations are beginning to compete on transparency, privacy and governance as well. Cybernews’ broader ranking found substantial differences between categories of AI products. While organizational transparency achieved a comparatively high average score, security was identified as the weakest overall area, with an average score of just 32 out of 100.

As AI systems become more capable, the stakes become higher. Modern AI tools are increasingly integrated with calendars, email systems, customer databases and financial workflows. Future generations of AI agents may be granted even greater authority to perform actions on behalf of users. In such environments, trust is no longer simply a public relations issue. It becomes an operational requirement.



Two-thirds of AI companies fail to clearly explain what happens to your data, study finds

#Twothirds #companies #fail #explain #data #study #finds

Leave a Reply

Your email address will not be published. Required fields are marked *