Server

IMDEA Report on AI Privacy Analysis and Where it Matters

October 8, 2026

This October, researchers from IMDEA Networks and collaborating institutions released a privacy analysis of nine prominent conversational AI services. Our post provides a brief recap of the findings and, more importantly, what they mean for enterprises.

Report Summary

The report itself resides at Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents.

The researches found third-party advertising and tracking services across all evaluated AI services. According to the report information is processed through third-party services, such as from Google, Meta, Datadog or Intercom. Usage analytics is common for all modern applications, in particular for cloud services. It allows vendors to measure platform improvements, perform A/B testing and so on in order to constantly improve their services.

Cookie consent makes a difference. Rejecting non-essential cookies reduced some third-party interactions, although trackers remained active in several products. But, surprisingly, the researchers found no clear distinction between free and premium tiers regarding third-party data collection.

The report also explains that URLs which are brought into a chat are called via cloud infrastructure, for instance AWS or GCP. But this is understandable, as AI offerings are hosted somewhere and often at these hyperscalers.

What Does This Mean For Organizations?

First, the results should not be interpreted as evidence that cloud AI services are inherently unsuitable for enterprises. The study itself shows substantial differences between products and between the types of data transmitted. For example, it did not observe the same conversation-content exposure across every service.

But the report highlights a more fundamental consideration: With a Cloud AI service, you do not control the platform.

The vendor ultimately controls its infrastructure, telemetry mechanisms, integrations and data flows. Contractual commitments, privacy policies and enterprise agreements therefore become essential parts of the trust model.

For many use cases, this is perfectly acceptable. Copilot, Claude and other cloud AI services provide outstanding capabilities and can deliver substantial productivity gains.

But there are situations where an organization may require something different.

Comparison Cloud AI Service vs On-Premise AI Service

Sensitive Data and Strong Privacy

Highly confidential intellectual property, sensitive customer information, regulated data or internal knowledge may require the organization to retain technical control over the complete processing environment, rather than relying solely on contractual and organizational safeguards.

This is where an on-premises architecture such as the RheinInsights Retrieval Suite provides a fundamentally different proposition.

The customer can control:

  • the infrastructure,

  • the models,

  • the knowledge base,

  • the network connections,

  • the telemetry,

  • and ultimately the data flows.

Deployments can even be isolated from external networks where the use case requires it.

The distinction is therefore not simply:

Cloud AI vs. private AI.

it is

Trusting another organization to control the AI infrastructure vs. retaining that control yourself.

Both approaches have their place. The important question for organizations is knowing where that boundary should be drawn.

More insights

< Previous Post
      
Next Post >