As the AI arms race accelerates, new research raises serious questions about how the world’s leading tech firms are treating data privacy in their rush to build ever-more powerful LLMs.
A study of leading AI models and their developers by data privacy firm Incogni examined the potential for unauthorised data sharing, misuse, and personal data exposure risks present in the most popular systems, highlighting issues that regulators are struggling to keep up with as AI use becomes more entwined in daily life.
To determine which LLMs and genAI platforms pose the greatest risks to user privacy, Incogni rated each against 11 key criteria, covering how user data is used in training, the transparency of platform policies, and data collection and sharing practices.
The results show that Le Chat, the AI model from Paris-based developer Mistral, offers the most privacy-friendly, or least invasive, platform, scoring well across the board.
Mistral’s LLM stood out for limiting data collection and giving users the option to opt out of having their inputs used for training. It also clearly flagged when prompts would contribute to future AI development, though, like many others, it fell short on providing a clear path for users to remove personal data from training sets.
While Le Chat is a strong European competitor, it is of course dwarfed by the global presence of OpenAI’s ChatGPT, which now boasts somewhere between 800 million and 1 billion weekly active users, according to CEO Sam Altman.
If accurate, close to 10% of the world now regularly plugs into ChatGPT, making the platform’s user privacy a critical concern.
Luckily, Incogni found that ChatGPT was one of the least privacy-invasive AI models and turned out to be among the most transparent about whether user prompts would be used for training purposes.
Despite lingering questions around model training and user data interaction, Incogni’s researchers said that ChatGPT offered clear and easily digestible privacy policies, which helped users better grasp how their data is processed.
Meanwhile, in something of a surprise given the negative attention its parent platform regularly receives, xAI’s Grok models scored well, coming in third overall, doing particularly well in allowing users to opt out of their prompts being used for training, and the ease in finding privacy policies online.
At the other end of the privacy spectrum, the study revealed that tech giants Google, Microsoft and Meta have built the most invasive platforms, with Incogni finding that some models like Gemini and Meta AI don’t seem to allow users to opt out of having their prompts used for training models.
Incogni found that these privacy issues get worse when users choose to interact with AI models via mobile apps, with Meta AI and Gemini both collecting precise location and address information, with Google’s AI model going even further in collecting user phone numbers, an attribute it shared only with Chinese-owned DeepSeek.
Many of the platforms Incogni investigated also had overly complex privacy policies, with the researchers finding that users would, on average, need at least a university-graduate level of reading to understand their intricacies.
Recommended reading
- Users Accidentally Leak Personal Data via Meta AI
- ChatGPT Search Inches Toward Strict EU Oversight as Users Surge
- AI Fuels Consumer Demand for Stronger Privacy Laws
Again, the biggest tech firms were the worst performers, with Meta, Microsoft and Google not having clearly defined AI-centric privacy policies readily available, while ‘outsiders’ like DeepSeek and the little-known Inflection AI only provided bare-bones privacy policies.
“Maintaining awareness of evolving privacy risks and data handling practices has simply become impractical for the average user,” wrote Incogni’s researchers.
“As these sophisticated models become increasingly integrated into daily workflows – from content creation to code generation – the potential for unauthorised data sharing, misuse, and personal data exposure has surged faster than privacy watchdogs or assessments can keep up with.”





