Cybernews ranks 500 AI firms on trust, exposing gaps in data disclosure

Cybernews scored 500 AI firms. The biggest signal for agencies: unclear training and retention disclosures can turn vendor choice into a client-trust issue.

Cybernews ranks 500 AI firms on trust, exposing gaps in data disclosure

Cybernews published its AI Trustworthiness Ranking 2026 after assessing 500 AI companies across 36 countries, scoring each from 0 to 100 across security, data privacy, organizational transparency, and public perception. The details were outlined in its AI Trustworthiness Ranking 2026 write-up.

For marketing teams and agencies, the headline number is not who ranked first. It is that 63% of companies do not clearly disclose whether they train models on user data, at a time when unreleased campaigns, pricing decks, and customer details are increasingly ending up inside chat workflows.

One strategic tension sits underneath the ranking: marketers often treat “vendor approval” as a procurement box to check, while clients experience it as a trust boundary. The more AI becomes embedded in everyday work, the more “what happens to our inputs” becomes part of brand stewardship, not just IT risk.

Table of contents

Jump to each section:

What the AI Trustworthiness Ranking 2026 actually measures

The ranking evaluates companies on four pillars: security, data privacy, organizational transparency, and public perception. It spans 21 categories, from AI assistants to coding tools and music tools, and labels companies scoring 75 or higher as “AI Trustworthiness Leaders of 2026,” with an annual refresh cadence.

A key nuance: the ranking scores public documentation, not verified internal practice. Cybernews works from public sources, and public reviews carry 35% of the weighting. That makes the framework most useful as a signal of how clearly a vendor communicates, rather than a guarantee of how a system behaves under pressure.

Security is also narrowly operationalized in the scoring. It counts for 20% of the total and checks for three elements: a bug bounty, an ISO 27001 or SOC 2 certification, and a trust page. A company could have strong internal security controls, but score poorly if it does not publish those specific proofs.

Memorable observation: Trust rankings often grade the clarity of the story, not the reality of the system.

The top of the list included Google’s Gemini in the number one position, followed by Krisp, Fireflies.ai, Adobe, Magnific, Writesonic, Veryfi, Salesforce, Grammarly, and Lovable.

The top five ranked AI companies, with Google Gemini leading overall.
Marketing AI to skeptics: how to build trust
AI skepticism is rising. Learn how to position AI features with clearer boundaries, transparency, and user control to protect brand trust.

Why the training-data disclosure gap is a marketer problem

Cybernews found that 63% of companies do not clearly disclose whether they train their models on user data. Within that, 42% said nothing about it at all, and 21% used vague language. Retention disclosures were similarly unclear: around 65% do not clearly state how long they keep user data, and 56% mention retention vaguely without a timeline.

That uncertainty lands in the middle of modern marketing work. Agencies routinely handle unreleased creative, brand positioning, and pricing information. When those materials get pasted into AI tools, the question is not abstract compliance. It becomes client-facing accountability: what happened to confidential inputs after the chat window closed?

This is also where “privacy” diverges from “governance.” As advisory board member Dr. Akshika Wijesundara (senior AI advisor to the United Nations) frames it, the risk profile changes as tools shift from answering questions to taking actions, such as reading inboxes or moving money. A chatbot that mishandles data is a privacy problem; an agent with broad permissions and weak governance is a security problem, because mistakes can propagate into real systems quickly.

Memorable observation: In AI-enabled marketing, the biggest reputational risk is not what the model outputs. It is what the model remembers.

How to use a documentation-based score without over-trusting it

The ranking includes its own caveats that should shape how marketers interpret it.

First, the score is a grade on published proof. If a vendor’s security posture is real but not documented in the specific ways the ranking checks for, it can be penalized. Conversely, strong documentation can coexist with real-world failures. The write-up notes that Google has clear training, retention, and governance policies, while also having highly visible output issues in the past, including AI Overviews answers it walked back in 2024.

Second, the governance structure is not fully external: Cybernews’ publisher sits on its own board, and two of four advisory board members work for Mediatech, which owns Cybernews. That does not invalidate the work, but it is another reason to treat the ranking as a starting filter, not a final assurance.

A practical way to use this kind of ranking is as a shortlist builder for vendor due diligence, especially around disclosure quality. Then switch from reading to asking: get the training-data answer in writing, and request clarity on retention timelines rather than accepting “we may retain data to improve services” language.

Memorable observation: Procurement asks for a score; clients ask for an explanation. Your vendor choices need to survive the second question.

What this means for marketers

The ranking is a reminder that AI adoption is now a governance problem wearing a productivity costume. Once AI becomes part of campaign development, it also becomes part of how brands prove responsible handling of sensitive information.

  1. Treat AI tool choice as a client-trust decision, not a team preference
    If a client asks whether their brief could become training data, “we think it’s fine” is not an acceptable answer. The vendor’s disclosures and written commitments matter as much as feature fit.
  2. Make “training” and “retention” explicit, because silence is operational risk
    Cybernews’ data suggests many vendors do not clearly state whether they train on user data or how long they retain it. For agencies, ambiguity becomes the problem, even before any misuse occurs.
  3. Use rankings to narrow the field, then validate the specifics that matter
    A documentation-based score can highlight who communicates clearly. It cannot confirm what happened to a pasted pricing deck, or whether internal controls match public claims. Due diligence still needs direct questions and documented answers.
  4. Plan for agents, not just chatbots
    The Wijesundara point is directionally important for marketing operations: the risk escalates as tools gain permissions and start taking actions. Governance and access boundaries will increasingly sit inside marketing workflows, not outside them.

The deeper shift is that trust is becoming a product feature that marketing teams have to operationalize. As clients become more aware of how often sensitive material ends up in AI tools, “safe enough” stops being a private judgment call.

Over time, brands will likely differentiate not only by creative quality or media efficiency, but by how credibly they can say: we know where our work went, how long it persisted, and what it could train. That is not a legal footnote. It is a brand promise that will be tested in procurement reviews, security questionnaires, and client renewals.

This article is created by humans with AI assistance, powered by ContentGrow. Ready to automate your content marketing? Book a discovery call today.
Book a discovery call (for brands & publishers) - ContentGrow
Thanks for booking a call with ContentGrow. We provide scalable and tailored content creation services for B2B brands and publishers worldwide.Let’s chat a bit about your content needs and see if ContentGrow is the right solution for you!IMPORTANT: To confirm a meeting, we need you to provide your