Moz Pro - Research, Refine & Rise in AI Search. Start Your FREE 7-Day Trial

Cybernews Ranks 500 AI Firms, Security Only Averages 32 of 100

63% won't disclose whether user data trains their models, leaving agencies without a clear answer.
Cybernews Ranks 500 AI Firms, Security Only Averages 32 of 100
watch video
Article by reviewed by Katherine MaclangRoberto Orosa
|

Cybernews assessed 500 AI companies across 36 countries and handed the industry an uncomfortable report card.

The AI Trustworthiness Ranking 2026 scores each company from 0 to 100.

Security averaged just 32 out of 100, the weakest of the four pillars measured.

The number that should worry agencies is that 63% of the 500 surveyed do not clearly disclose whether they train their models on user data.

When an account team pastes an unreleased campaign or a pricing deck into a chat window, two-thirds of the time, nobody can say where it goes.

Companies are ranked across security, data privacy, organizational transparency, and public perception.

The survey covers 21 categories, from AI assistants to coding and music tools.

Those scoring 75 or higher earn a spot as an AI Trustworthiness Leader of 2026, and the list will be refreshed every year.

An Advisory Board of security and artificial intelligence experts guides the project, offering outside perspective on what the scores entail.

Dr. Akshika Wijesundara, a board member and senior AI advisor to the United Nations, says the risk changes once AI tools start acting on their own.

"AI is shifting from answering questions to taking actions, reading inboxes, moving money, and making decisions on our behalf," Wijesundara explained. 

"A chatbot that mishandles data is a privacy problem.

An agent with broad permissions and weak governance is a security problem, with mistakes propagating through real systems at machine speed."

Wijesundara points to companies that spell out how they protect data, use it, and govern what their AI is allowed to do.

These firms, he says, "will have a meaningful advantage in earning long-term trust."

The top five ranked AI companies, with Google Gemini leading overall.
Google's Gemini topped the list, followed by Krisp, Fireflies.ai, Adobe, Magnific, Writesonic, Veryfi, Salesforce, Grammarly, and Lovable.

Office and productivity tools scored highest as a category at 78 out of 100, while music and audio tools scored lowest at 54.

Notably, organizational transparency was the strongest pillar overall at 90 out of 100.

The Training Data Question Goes Unanswered

Data privacy is where the ranking gets uncomfortable.

Cybernews found that 63% of the 500 companies do not clearly disclose whether they train their models on user data.

More concerningly, 42% said nothing about it at all, and 21% offered only vague language.

Retention policies fared no better.

About 65% don't clearly state how long they keep user data, while 56% mention retention in vague terms with no timeline.

This gap then becomes an agency's contractual problem.

Most client confidentiality clauses were written before anyone thought to paste a pricing deck or an unreleased campaign into a chat window.

A vague privacy policy leaves an account team with no way to confirm whether this material became training data or sat untouched.

A tool can rank well and still leave this question unanswered, and the gap is what affects brand trust more once a client asks about it.

Two caveats matter here:

  1. It scores documentation, not practice. Cybernews works only from public sources, and public reviews alone carry 35% of the weight.
  2. The publisher sits on its own board. Two of the four Advisory Board members work for Mediatech, which owns Cybernews.

Security counts for just 20% of the total and checks three boxes: a bug bounty, an ISO 27001 or SOC 2 certification, and a trust page.

A firm with tight internal security and none of these three still scores zero, so the 32 out of 100 average measures published proof of the work.

Neither caveat sinks the ranking, and both change how an agency should use it.

Any brand strategy claim gets verified before a client sees it, and a vendor's privacy page deserves the same check.

Confidential Work Is Already Inside the Chat

Roughly 77% of employees who use generative AI tools admit to pasting company information into a chatbot, according to a 2025 LayerX study.

More surprisingly, the same study found that 22% of these pastes included personally identifiable or payment information.

TELUS Digital surveyed 1,000 enterprise employees in early 2025 and found a similar outcome.

57% had entered sensitive information into public AI assistants, and 21% named customer records among what they shared.\

Agencies handle unreleased campaigns, pricing decks, and brand positioning daily.

The ranking's transparency gap lands directly in this kind of category of work.

Whether a campaign brief ended up in someone else's training run is a separate question, and it's the one clients ask.

A few lessons stand out for marketers and account teams watching where campaign work actually goes:

  • Name the tool in the contract: Confidentiality clauses that list approved platforms give legal teams something concrete to point to if client work turns up somewhere it shouldn't.
  • Keep early drafts off personal accounts: Brainstorming and outline work should stay off unmanaged AI accounts once a project touches real client material.
  • Ask vendors the training question directly: A privacy policy that stays silent on model training isn't a yes or a no, and agencies can request a written answer instead of assuming one.

A ranking can tell an agency which vendor writes the clearest privacy policy.

However, it can't tell a client whether their campaign brief made it into someone else's AI training data.

Our Take: Does a Perfect Privacy Score Mean Anything?

Google's Gemini took the top spot in a ranking where nine of the top 10 scored a perfect 100 on data privacy.

We think that the score means something real, as long as everyone reads it as a grade on what a company publishes.

Google spells out its training, retention, and governance policies clearly, which is precisely what the privacy pillar measures.

Google also has the most publicly documented output failures, including the AI Overviews answers it walked back in 2024.

Both of these facts hold, since clean documentation sits comfortably next to unpredictable output.

A client asking where their brand strategy work went after the chat window closed still needs the vendor to answer directly.

We advise you to use the ranking to narrow the shortlist, then get the training answer in writing.

Agencies choosing AI vendors will want partners who can answer disclosure questions before a client asks them first.

Explore these top AI companies in our directory.

👍👎💗🤯
Latest AI News
Receive our NewsletterJoin over 70,000 B2B decision-makers growing their brands