Most AI companies do not explain how they use data

The growing use of AI in businesses is outpacing supplier transparency: most suppliers still do not clearly explain what happens to the data entrusted to their tools.

2 Min Read
Cyber security, cyber attack
Adobe Stock

More than six out of ten companies developing AI tools do not clearly explain whether users’ data is used in the model training process, according to the latest Cybernews study.

Cybernews analysed 500 companies from 36 countries, assessing, amongst other things, their privacy policies, security and organisational transparency. In the case of 42 per cent of the organisations surveyed, their documents did not address the question of whether user data was used to train AI at all, whilst a further 21 per cent provided vague answers. A similar issue concerned data retention: 65 per cent of companies did not clearly state how long data remains in their systems.

This is particularly important given the growing use of generative AI in businesses. Chatbots and virtual assistants process documents, code snippets, customer data and internal analyses. If a provider does not clearly define the rules governing their use, a company using such a tool must take additional risks into account when selecting it and negotiating the contract.

Security is also a cause for concern. In this category, the average score for all surveyed companies was just 32 out of 100 points. At the same time, the ranking primarily measures publicly available statements and security measures, so a lack of information does not automatically imply misuse of data. Cybernews itself points out that the methodology does not allow for the verification of companies’ actual practices.

However, the importance of transparency will continue to grow. In the EU, the Commission began enforcing further provisions of the AI Act on 2 August 2026, whilst providers of general-purpose models had already been subject to, amongst other things, the obligation to publish information on the content used for training. Unclear data policies are therefore increasingly becoming not only a reputational issue, but also a business and regulatory one.

Share This Article