Volver a Noticias
IndustriaAI Understanding sesión informativa

Digital Journal reports widespread gaps in AI companies’ data-use disclosures

Digital Journal reports that a Cybernews ranking found 63% of 500 AI companies did not clearly explain whether user data is used for model training, while 65% did not clearly state how long data is retained.

Por 6 min read
AI-generated editorial illustration accompanying Digital Journal reports widespread gaps in AI companies’ data-use disclosures
La versión corta

Digital Journal reports that a Cybernews ranking found 63% of 500 AI companies did not clearly explain whether user data is used for model training, while 65% did not clearly state how long data is retained.

que paso

Digital Journal reported on August 24, 2026, that the Cybernews AI Trustworthiness Ranking 2026 assessed 500 AI companies across 36 countries and found widespread gaps in disclosures about data use and retention. According to Digital Journal, 63% of the companies did not clearly disclose whether user information was used to train AI models, and 65% did not clearly disclose how long user data was retained. The underlying ranking and company responses were not provided in the source text, so these findings are not independently confirmed here.

Digital Journal reported that Cybernews evaluated 500 AI companies operating across 36 countries for its AI Trustworthiness Ranking 2026. The article said the ranking examined four broad areas: data privacy, security, organizational transparency, and public perception. Companies were assessed using publicly available information, and the data-privacy analysis reviewed privacy policies for explanations of collection, sharing, use, and retention. The source described the assessment as one of the largest reviews of AI privacy practices, but it did not provide the underlying ranking, the complete company list, or the detailed scoring methodology.

Digital Journal said the largest reported gap concerned whether companies use user information to train AI models. It attributed to Cybernews the finding that 63% of companies did not clearly disclose this practice. Within that group, the article said 42% made no reference to training on user data in their privacy policies, while 21% offered explanations that were vague or incomplete. The article explicitly cautioned that this does not establish that those companies use customer data for training; it establishes, according to the report, that users cannot readily determine whether such use occurs.

A second reported gap concerned retention. Digital Journal said Cybernews found that 65% of the companies did not clearly state how long user data was kept. The article divided that group into companies that did not mention retention or deletion policies at all, reported as 9%, and companies that used broad language without specific retention periods, reported as 56%. The source cited phrases such as “for as long as necessary” and “for legitimate business purposes” as examples of language that may not tell users when information will be deleted.

The article also reported that larger AI companies generally had clearer privacy policies than smaller companies. Digital Journal presented possible explanations, including greater regulatory scrutiny, public attention, and the presence of enterprise procurement teams. It did not say that smaller companies were necessarily less secure. Separately, the article said Cybernews’s broader ranking identified security as the weakest category, with an average score of 32 out of 100. The source text does not explain how that score was calculated or how it relates to the privacy findings.

Lea la fuente principal: digitaljournal.com

Por qué es importante

The reported gaps affect whether people and organizations can make informed decisions about submitting conversations, documents, health information, financial records, or proprietary business data to AI services. Clear training-use and retention disclosures are especially important as AI tools become integrated with email, calendars, customer databases, and financial workflows. The findings also suggest that privacy-policy clarity remains uneven across the AI industry, although unclear disclosure does not by itself prove that a company misuses customer data.

The practical issue is not only whether an AI company has a privacy policy, but whether the policy lets a user understand the lifecycle of information submitted to the service. Digital Journal’s account focuses on two decisions that are difficult to make without specific disclosures: whether information may contribute to model training and how long the provider may retain it. Those questions matter for ordinary users, employers, schools, health organizations, and businesses handling confidential material. The reported findings are particularly relevant because the article describes AI systems as being used for business reports, sensitive documents, scheduling, code, and personal discussions. If users cannot determine whether such information is retained or used for model improvement, they may struggle to assess confidentiality and compliance risks before adoption.

The source does not quantify any resulting breach, misuse, financial loss, or regulatory violation, so the significance here is a transparency and governance problem rather than evidence of a specific harmful incident. Retention information can affect the controls an organization places around an AI service. A precise deletion period, a clear explanation of backups, and a distinction between service logs and training data can materially change the risk assessment. By contrast, general statements about keeping data as long as necessary may leave users unable to determine when information will disappear or whether deletion requests cover every copy. Digital Journal connected this concern to data-minimization principles associated with the European Union’s GDPR, but the article did not analyze any specific company’s legal compliance.

The reported difference between larger and smaller companies also has practical implications for procurement. A clearer policy may make a provider easier to evaluate, but clarity is not the same as secure implementation or responsible data handling. Conversely, an unclear policy does not prove that a smaller provider is unsafe. The source provides no independent audit, technical test, enforcement action, or company-by-company comparison that would allow readers to draw stronger conclusions about actual security or privacy performance.

Qué ver a continuación

The key next step is verification of the Cybernews ranking’s methodology, company sample, scoring rules, review dates, and underlying evidence. Users and enterprise buyers should look for specific answers about whether prompts and uploads are used for training, how long information is stored, what deletion means, who receives the data, and whether settings differ by product or account type. Further reporting should also establish whether companies revise their policies, whether regulators respond, and whether smaller vendors improve disclosures.

The first verification priority is the Cybernews report itself. Readers should be able to inspect the 500-company sample, the countries and product types represented, the dates when policies were reviewed, the criteria used to classify disclosures as clear or unclear, and the weighting of the four ranking categories. Without those details, the percentages provide a useful warning signal but limited evidence about the AI industry as a whole.

Companies should be pressed for concrete, product-specific answers. Important questions include whether prompts, uploaded files, conversations, and generated outputs are used for training; whether users can opt out; how long operational logs and backups are retained; what deletion covers; whether human reviewers or contractors can access data; and whether enterprise and consumer terms differ. The source does not report answers from the companies assessed, so any claim that a particular provider uses or does not use customer data for training would require separate confirmation.

Future coverage should examine whether vendors change their policies after the ranking, whether regulators or privacy authorities investigate the reported gaps, and whether procurement standards begin requiring defined retention periods and explicit training-use disclosures. The article points to growing integration of AI with calendars, email, customer databases, and financial workflows, but it does not document any new deployment or regulatory action. Those developments should therefore be treated as issues to monitor rather than established consequences of the ranking.

The underlying results should also be tested against technical and legal evidence. Policy language may not fully describe data flows, while a clear policy may still permit practices users find unexpected. Independent audits, contract terms, deletion tests, security assessments, and documented changes over time would help distinguish poor communication from harmful handling. Based on the source alone, the meaningful unknowns include whether the reported percentages remain current, whether the sample represents the wider market, and how many companies actually use customer data for training despite unclear disclosures.

Guías y cuestionarios relacionados

Ética de la IAModelos de IA explicadosAgentes de IAPon a prueba lo que sabes: prueba un cuestionario gratuito sobre IABusque un término de IA en nuestro glosario
¿Encontró esto útil?