New Cybernews research covering 500 AI companies across 36 countries finds 63% do not clearly disclose whether they train their AI models on user data, and 65% do not clearly disclose how long they retain it.
The figures come from the Cybernews AI Trustworthiness Ranking 2026, which grades vendors across four pillars: data privacy, security, organisational transparency, and public perception. For the privacy pillar, the researchers read the privacy policies of every one of the 500 companies in the sample and assessed how clearly each explained data collection, sharing, use and retention.
The headline numbers hide a sharper split. Of the companies failing the training-disclosure test, 42% do not address AI training on user data in their privacy policies at all — the language is simply absent — while 21% mention it only vaguely enough to be uninformative. On data retention, 9% never mention retention or deletion, and 56% address it in language too vague to yield a specific retention period. In either case, the practical answer for a user or procurement team asking "what happens to my data?" is the same: you cannot tell.
Size turns out to matter. Larger companies had more transparent privacy policies overall, providing clearer information on collection, sharing, use and retention than smaller ones. That aligns with what one would expect — bigger vendors face more regulatory scrutiny and enterprise procurement pressure — but it also flags a risk: the long tail of smaller AI vendors, often the ones enterprises quietly onboard through a business-unit tool, is the tail where transparency drops fastest.
"People use AI tools for everything these days, and they give those tools access to their most sensitive data, sometimes sharing their deepest secrets with AI chatbots. That's why it's so important for users to clearly understand what is done with their data. People shouldn't have to interpret vague language or struggle to understand how their data is being used."
Voldemaras Kadys, Member of the AI Trustworthiness Ranking Advisory Board, Cybernews
The practical takeaway for enterprise buyers is that a vendor whose privacy policy cannot be summarised in a paragraph by a competent reviewer is a vendor to press for specifics before signing. The Cybernews study will do a service if it moves the needle on how many are willing to answer.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter