AI Inspired Insights

The

Insights on AI automation, business intelligence, and the future of work. Written by humans, enhanced by Midas.

AI Trustworthiness Rankings: What SaaS Companies Must Know Now
📰 Midas Report Article

AI Trustworthiness Rankings: What SaaS Companies Must Know Now

63% of AI companies hide data training practices. Learn how the Cybernews AI Trustworthiness Ranking exposes compliance gaps SaaS companies must close now.

Dawn CliftonBy Dawn CliftonAug 18, 20267 min read

AI Trustworthiness Rankings: What SaaS Companies Must Know Now

0:00 / 3:04

When 63% of AI companies cannot clearly tell their users whether their data is being used to train machine learning models, that is not a product gap — it is a governance crisis. For SaaS and technology businesses operating in both B2B and B2C markets, the newly published Cybernews AI Trustworthiness Ranking is not background noise. It is a compliance alarm worth taking seriously.

Cybernews recently launched a comprehensive assessment of 500 AI companies across 36 countries, scoring each on a 0-to-100 Trustworthiness Scale. The evaluation criteria span four critical domains: security posture, data privacy practices, organizational transparency, and public perception. The findings are striking. Beyond the 63% of companies that fail to disclose AI training data usage, a parallel 65% do not clearly communicate how long they retain user data. These are not edge-case oversights — they represent the majority of the AI industry operating in a disclosure vacuum.

What Does the AI Trustworthiness Ranking Actually Measure?

The Cybernews ranking uses publicly available information only, meaning it reflects what companies voluntarily surface to the world. That framing matters enormously. A low score does not necessarily indicate malicious intent — it often signals a failure of governance infrastructure, documentation practices, or legal review cycles.

Explore MidasU and set up your Co-CEO today — free courses, certification, community

The four pillars of the ranking map directly onto established compliance frameworks. Security aligns with controls found in SOC 2 Type II and ISO 27001. Data privacy mirrors GDPR Article 13 and CCPA disclosure obligations. Organizational transparency echoes the EU AI Act's transparency requirements for high-risk AI systems. Public perception, while softer, reflects reputational risk — a category that institutional B2B buyers increasingly factor into vendor due diligence.

For SaaS companies serving enterprise clients, a poor trustworthiness score is no longer just a PR problem. It is a procurement obstacle.

Why Data Retention Disclosure Is the Hidden Compliance Landmine

The 65% non-disclosure rate on data retention timelines is the finding that deserves the most operational attention. Under GDPR's storage limitation principle, organizations must not retain personal data longer than necessary for its stated purpose. Under CCPA, consumers have the right to know how long their data will be kept. Failing to document and publish retention schedules is not just a transparency failure — it is a regulatory exposure.

For B2B SaaS vendors, this risk compounds. Enterprise clients increasingly require data processing agreements (DPAs) that specify retention windows. If your internal policy is undefined or unpublished, you cannot accurately populate those agreements. That creates downstream liability for both vendor and client.

Request our whitepaper and join with confidence — download now

"At DCMG Innovative Solutions, we treat data governance documentation as a living product — not a legal afterthought. When I look at findings like the Cybernews ranking, I see exactly where companies leave themselves exposed: not in their technology, but in their transparency. Our clients, whether they're individual users or enterprise partners, deserve to know precisely how their data is handled, retained, and protected at every stage." — Dawn Clifton, Founder, DCMG Innovative Solutions LLC

AI Voice Cloning Fraud: When Governance Gaps Become Human Harm

The stakes of poor AI governance extend far beyond enterprise compliance checklists. A vivid illustration comes from an unexpected source: entertainment. Variety reports that Stars Collective is developing Grandma, Please, a Mandarin-language remake of the Sundance breakout film Thelma. In the story, an 80-year-old grandmother is defrauded by a scammer who uses AI to clone her late husband's voice, stealing her life savings.

The fact that this storyline resonated enough to generate a major film remake — and that the original became Magnolia Pictures' highest-grossing narrative feature — signals something important about public consciousness. AI voice cloning fraud is not a hypothetical threat. The FBI and FTC have both issued consumer warnings about AI-generated voice scams targeting elderly populations. When AI companies fail to disclose how their voice synthesis tools are governed, trained, or access-controlled, they contribute — however indirectly — to an ecosystem where these harms become easier to execute.

Take the AI Readiness Survey and see how you stack up — instant results in 2 minutes

For SaaS companies building on or integrating AI APIs, vendor due diligence must now include trustworthiness assessments of upstream providers. The Cybernews ranking provides a structured starting point for that evaluation.

How SaaS Companies Should Respond to Trustworthiness Benchmarks

The emergence of third-party AI trustworthiness scoring changes the competitive landscape in measurable ways. Companies that proactively close disclosure gaps will differentiate themselves in procurement cycles. Those that ignore the benchmarks will find themselves filtered out of enterprise shortlists as AI governance due diligence becomes standard practice.

Three immediate operational priorities stand out for SaaS and technology firms:

  1. Audit your privacy policy for AI-specific disclosures. Does your documentation explicitly state whether user data trains your models? If not, that gap is now quantifiable and visible to evaluators using frameworks like the Cybernews ranking.
  2. Publish a data retention schedule. Define retention windows by data category, document the legal basis, and make it accessible in your privacy documentation. This satisfies GDPR, CCPA, and enterprise DPA requirements simultaneously.
  3. Assess your AI vendor stack. If you integrate third-party AI services, apply the same transparency standards to your upstream providers that you expect your clients to apply to you. Supply chain governance is now an AI governance issue.

The energy sector offers a useful analogy here. Research highlighted by No2NuclearPower documents how Professor Martin Green's solar innovations — now embedded in over 90% of solar panels globally — succeeded not just through technical breakthroughs but through sustained, transparent research practices that built institutional trust over decades. Trustworthiness in AI, similarly, is not achieved in a single policy update. It is built through consistent, documented, and auditable practices over time.

Free 20-minute webinar with Tom, plus a next-level-up subscription — register today

Even in competitive contexts where performance metrics dominate — much like the statistical precision governing WNBA standings analysis or the pitching probables and ERA figures that define MLB matchup reporting — the underlying data infrastructure must be reliable and consistently tracked to mean anything. AI trustworthiness scoring operates on the same principle: the metrics only hold value when the data feeding them is governed with integrity.

Frequently Asked Questions

What is the Cybernews AI Trustworthiness Ranking?

It is a scoring system that evaluates 500 AI companies across 36 countries on a 0-to-100 scale. The ranking uses publicly available information to assess security, data privacy, organizational transparency, and public perception. It was launched in August 2026 by the Cybernews research team.

Why do 63% of AI companies not disclose AI training data usage?

The Cybernews analysis attributes this to a lack of standardized disclosure requirements across jurisdictions. Many companies treat AI training data practices as proprietary information rather than a transparency obligation. Emerging regulations like the EU AI Act are expected to close this gap for high-risk AI systems.

MidasCard — connect with me

How does data retention non-disclosure create legal risk for SaaS companies?

GDPR's storage limitation principle and CCPA's consumer rights provisions both require documented retention practices. Without published retention schedules, SaaS vendors cannot accurately complete data processing agreements with enterprise clients. This creates contractual and regulatory exposure for both parties.

How should a SaaS company improve its AI trustworthiness score?

Start by auditing your privacy policy for AI-specific language covering model training, data retention, and third-party sharing. Publish a clear, accessible data retention schedule. Then extend that governance standard to any upstream AI vendors you integrate. Consistent, documented practices build measurable trustworthiness over time.

Your Next Step Toward AI Governance Readiness

The Cybernews AI Trustworthiness Ranking has introduced a new accountability layer for the entire AI industry — and SaaS companies sit squarely in its scope. If your current documentation cannot answer the two most basic questions — how do you use user data for AI training, and how long do you keep it — then closing those gaps is the most important governance task on your roadmap right now. At DCMG Innovative Solutions LLC, building transparent, auditable AI practices into every client engagement is foundational to how we operate. If your organization is working through AI governance documentation, data retention policy, or vendor due diligence frameworks, explore how a structured approach can move you from exposure to confidence.

Give Your Business the Touch of Gold with Midas!

20 business apps. 10 AI agents. One digital brain that gets smarter every day. One login. One price.

START FREE
AI Trustworthiness Rankings: What SaaS Companies Must Know Now · Midas