Site navigation

New Study Ranks AI Models by Privacy Risk

Tom Quinn

,

Ai data privacy
New research has revealed the stark differences in how AI developers handle data privacy, with little-known players outperforming their Big Tech rivals.

As the AI arms race accelerates, new research raises serious questions about how the world’s leading tech firms are treating data privacy in their rush to build ever-more powerful LLMs.

A study of leading AI models and their developers by data privacy firm Incogni examined the potential for unauthorised data sharing, misuse, and personal data exposure risks present in the most popular systems, highlighting issues that regulators are struggling to keep up with as AI use becomes more entwined in daily life. 

To determine which LLMs and genAI platforms pose the greatest risks to user privacy, Incogni rated each against 11 key criteria, covering how user data is used in training, the transparency of platform policies, and data collection and sharing practices.

The results show that Le Chat, the AI model from Paris-based developer Mistral, offers the most privacy-friendly, or least invasive, platform, scoring well across the board. 

Mistral’s LLM stood out for limiting data collection and giving users the option to opt out of having their inputs used for training. It also clearly flagged when prompts would contribute to future AI development, though, like many others, it fell short on providing a clear path for users to remove personal data from training sets.

While Le Chat is a strong European competitor, it is of course dwarfed by the global presence of OpenAI’s ChatGPT, which now boasts somewhere between 800 million and 1 billion weekly active users, according to CEO Sam Altman.

If accurate, close to 10% of the world now regularly plugs into ChatGPT, making the platform’s user privacy a critical concern. 

Luckily, Incogni found that ChatGPT was one of the least privacy-invasive AI models and turned out to be among the most transparent about whether user prompts would be used for training purposes.

Despite lingering questions around model training and user data interaction, Incogni’s researchers said that ChatGPT offered clear and easily digestible privacy policies, which helped users better grasp how their data is processed.

Meanwhile, in something of a surprise given the negative attention its parent platform regularly receives, xAI’s Grok models scored well, coming in third overall, doing particularly well in allowing users to opt out of their prompts being used for training, and the ease in finding privacy policies online.

At the other end of the privacy spectrum, the study revealed that tech giants Google, Microsoft and Meta have built the most invasive platforms, with Incogni finding that some models like Gemini and Meta AI don’t seem to allow users to opt out of having their prompts used for training models.

Incogni found that these privacy issues get worse when users choose to interact with AI models via mobile apps, with Meta AI and Gemini both collecting precise location and address information, with Google’s AI model going even further in collecting user phone numbers, an attribute it shared only with Chinese-owned DeepSeek.

Many of the platforms Incogni investigated also had overly complex privacy policies, with the researchers finding that users would, on average, need at least a university-graduate level of reading to understand their intricacies.  


Recommended reading


Again, the biggest tech firms were the worst performers, with Meta, Microsoft and Google not having clearly defined AI-centric privacy policies readily available, while ‘outsiders’ like DeepSeek and the little-known Inflection AI only provided bare-bones privacy policies.

“Maintaining awareness of evolving privacy risks and data handling practices has simply become impractical for the average user,” wrote Incogni’s researchers.

“As these sophisticated models become increasingly integrated into daily workflows – from content creation to code generation – the potential for unauthorised data sharing, misuse, and personal data exposure has surged faster than privacy watchdogs or assessments can keep up with.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data