10.6% of AI-enabled mobile apps, 3,541 out of 33,396 apps found to use AI in some form, send data to a remote third-party AI endpoint, according to NowSecure's 2025 scan of 183,000 mobile apps. That means the large majority of apps marketing an AI feature keep the processing on-device or route it through a first-party service instead of an outside API. Regulators have started to notice the gap between what an app's privacy label claims and what its network traffic shows: Apple now requires apps to disclose third-party AI sharing before App Store review approval.
How many AI apps share data with third parties?
10.6% of AI-enabled apps send data to a remote third-party AI endpoint, based on NowSecure's continuous scan of the app ecosystem through its Mobile Application Risk Intelligence (MARI) service. Out of 183,000 mobile apps assessed in 2025, 33,396 (18.3%) used artificial intelligence in some form, and of those, 3,541 apps were observed sending data to an AI endpoint outside the app's own infrastructure.
That 10.6% figure comes from watching actual network traffic rather than reading privacy policy language, which is a stricter test than most earlier audits used. NowSecure's MARI service continuously assesses more than 4 million public mobile apps, and the 183,000-app figure represents the subset scanned and reported on in the September 2025 research release.
Figure 1: Of 183,000 apps scanned, 33,396 use AI and 3,541 send data to a third-party AI endpoint. Source: NowSecure, "What You Don't See Is Hurting You" (September 2025).
The count shrinks fast at each step: most apps do not use AI at all, and most that do never send data to an outside AI service. The narrow slice that does is the one worth watching closely.
Do most AI apps process data on the device instead of sending it to a third party?
Yes. 89.4% of the 33,396 AI-using apps NowSecure identified did not send data to a remote AI endpoint during testing, which means the large majority processed AI features on-device, through Apple's or Google's own machine learning frameworks, or through a first-party backend rather than an outside API.
That does not automatically mean those apps are more private. On-device processing avoids a third-party network call, but the same app can still collect the underlying data and share it elsewhere through analytics or advertising SDKs unrelated to its AI feature. The 89.4% figure only measures whether an AI call left the device for a third-party endpoint, not whether the data itself stayed private.
Figure 2: Roughly 9 in 10 AI-enabled apps kept AI processing on-device or first-party. Source: NowSecure, 2025 MARI scan of 183,000 apps.
A low remote-call rate is a reasonable sign, but it is not proof of privacy by itself.
Is third-party data sharing by apps increasing?
Yes, and the trend runs in the opposite direction of the on-device figure above. The share of third-party applications accessing sensitive data without a stated business justification climbed from 51% in 2024 to 64% in 2026, according to Reflectiz's Web Exposure 2026 Research, which tracked third-party script and application behavior across the web.
That 13-point jump in two years covers all third-party applications, not just AI-specific ones, but it is the backdrop AI features are being added against. As more apps wire AI capabilities into existing third-party SDKs and analytics pipelines, the line between an AI-specific data flow and a general third-party data flow gets harder to draw, and the overall access rate keeps climbing regardless of which feature triggered it.
The direction of that trend line matters more than any single year's number: third-party access to sensitive data is not leveling off.
Why is it hard to verify which AI apps share data with third parties?
Because the disclosures apps are supposed to publish are frequently missing or incomplete. NowSecure's 2025 research found that 97% of tested apps were missing required Privacy Manifests for their third-party SDKs, 42% were missing their main privacy manifest entirely, and 35% of iOS apps failed to disclose data that NowSecure directly observed the app collecting during testing.
Figure 3: Most of the transparency gaps sit at the SDK level, where third-party AI calls are easiest to hide. Source: NowSecure, "What You Don't See Is Hurting You" (September 2025).
These gaps are exactly what a current, accurate privacy policy is supposed to close. Naming every third-party AI processor an app actually calls, not just the ones a template assumes, is the disclosure regulators and app store reviewers check first, and a privacy policy generator built around today's data-sharing categories keeps that list from going stale as new AI features get added.
Missing manifests are not neutral paperwork gaps. They are the reason a 10.6% network-traffic figure and a 75% privacy-label figure can both be true at once, because a broken or absent disclosure hides the very data flow a checklist audit is trying to count.
What is Apple's App Store doing about third-party AI data sharing?
Apple updated App Store Review Guideline 5.1.2(i) on November 13, 2025 to explicitly name third-party AI as a regulated data-sharing category for the first time. The guideline now reads, in part: developers "must clearly disclose where personal data will be shared with third parties, including with third-party AI, and obtain explicit permission before doing so."
Figure 4: The disclosure-and-consent test Apple now applies to third-party AI data sharing. Source: Apple Developer, App Store Review Guidelines, Guideline 5.1.2(i), updated November 13, 2025.
Before this update, third-party AI sharing sat inside Apple's general data-sharing language without being named directly, which let some apps treat an AI feature as outside the scope of existing disclosure rules. Naming it explicitly closes that reading and puts app reviewers on notice to check for it.
Which AI platforms and organizations share the most data with third parties?
All 9 AI platforms Incogni analyzed in its 2025 Gen AI and LLM Privacy Ranking disclosed sharing some user data with named third parties, though the type and volume varies widely by platform. Meta AI was rated the most aggressive, sharing usernames, emails, and phone numbers and disclosing that prompts can be shared with companies inside its corporate group. Le Chat and Pi AI disclosed the least third-party sharing of the 9 platforms reviewed.
The organizational picture looks similar. 79% of organizations say their generative AI providers are willing to negotiate contract terms or tool configurations to limit data exposure, according to Cisco's 2026 Data and Privacy Benchmark Study of more than 5,200 IT, technology, and security professionals across 12 countries, the same study behind the 90% figure on expanded AI privacy programs covered in our AI and privacy statistics for 2026. Willingness to negotiate is not the same as a signed, favorable contract, but it means most vendors are not treating third-party data terms as fixed.
Figure 5: Third-party AI data sharing went from an unnamed App Store category to a named, enforced disclosure requirement in three years. Source: Security.org (2023), NowSecure (2025), Incogni (2025), Apple Developer (2025), Reflectiz (2026), Cisco (2026).
AI apps and third-party data sharing, by source
| Source | Sample analyzed | Third-party data sharing finding | Year |
|---|---|---|---|
| NowSecure MARI scan | 183,000 apps (33,396 use AI) | 10.6% of AI apps (3,541) send data to a remote AI endpoint | 2025 |
| Security.org (formerly Home Security Heroes) | 159 AI apps, Apple App Store | 75% flagged for Third-Party Advertising data sharing | 2023 |
| Incogni Gen AI and LLM Privacy Ranking | 9 leading AI platforms | All 9 share some user data with named third parties; Meta AI rated the most aggressive | 2025 |
| Reflectiz Web Exposure Research | Third-party scripts and apps across the web | 64% access sensitive data without a stated business justification, up from 51% in 2024 | 2026 |
The Bottom Line
The honest answer to how many AI apps share data with third parties depends entirely on how you measure it. NowSecure's network-traffic test puts the figure at 10.6% of AI-enabled apps, a narrow, verifiable slice that actually calls out to a remote AI endpoint. Security.org's privacy-label audit puts a similarly framed figure at 75%, because it counted a broader Third-Party Advertising disclosure category on a much smaller, older sample. Both numbers are real; they are just measuring different things, and 97% of apps missing their SDK privacy manifests is a big part of why the gap between them is so hard to close with a quick audit. The practical takeaway is the same regardless of which figure a site owner starts from: third-party access to sensitive data is trending up, not down, and Apple's App Store now treats an undisclosed third-party AI data flow as a rejection-worthy gap rather than a gray area.
Frequently Asked Questions
How many AI apps share data with third parties? 10.6% of AI-enabled apps, 3,541 of the 33,396 apps found to use AI, send data to a remote third-party AI endpoint, according to NowSecure's 2025 scan of 183,000 mobile apps. An older, smaller 2023 audit of 159 AI apps by Security.org (formerly Home Security Heroes) found a much higher 75% shared data through the App Store's Third-Party Advertising disclosure category, though that study used a narrower definition and a far smaller sample.
Do most AI apps process data on the device instead of sending it to a third party? Yes. 89.4% of the 33,396 AI-using apps NowSecure identified in 2025 did not send data to a remote AI endpoint, meaning most apps marketing an AI feature processed it on-device or through a first-party service rather than calling out to a third-party API.
Is third-party data sharing by apps increasing? Yes. The share of third-party applications accessing sensitive data without a stated business justification rose from 51% in 2024 to 64% in 2026, according to Reflectiz's Web Exposure 2026 Research.
What is Apple doing about apps that share data with third-party AI? Apple's App Store Review Guideline 5.1.2(i), updated on November 13, 2025, now requires apps to clearly disclose where personal data will be shared with third parties, including third-party AI, and to obtain explicit user permission before doing so.
Where the Numbers Come From
- NowSecure. (2025). "New NowSecure Research Targets Mobile App Privacy Risks: What You Don't See Is Hurting You." 183,000 mobile apps scanned via the MARI service; 33,396 (18.3%) use AI, 3,541 send data to a remote AI endpoint. Published September 29, 2025.
- Security.org (formerly Home Security Heroes). (2023). "Most Invasive AI Apps." 159 AI apps examined via Apple App Store privacy labels; 75% flagged for Third-Party Advertising data sharing. Published June 16, 2023.
- Incogni. (2025). "Gen AI and LLM Data Privacy Ranking 2025." 9 leading AI platforms analyzed; all disclosed sharing some user data with named third parties. Data collected May 25 to 27, 2025.
- Reflectiz. (2026). "Web Exposure 2026 Research." Third-party applications accessing sensitive data without a stated business justification rose from 51% (2024) to 64% (2026); methodology and sample of 4,700 websites over a 12-month period reported via The Hacker News, January 14, 2026.
- Apple Developer. "App Store Review Guidelines, Guideline 5.1.2(i)." Updated November 13, 2025 to require disclosure and explicit consent for personal data shared with third parties, including third-party AI.
- NowSecure. (2026). "95% of Organizations Use AI in Mobile Apps. 37% Can't See What It's Doing." Survey of 485 senior mobile application security leaders conducted by TrendCandy, April to May 2026, margin of error plus or minus 4% at 95% confidence.
- Cisco. (2026). "2026 Data and Privacy Benchmark Study." 5,200-plus IT, technology, and security professionals across 12 countries; 79% report generative AI providers are willing to negotiate contract terms to limit data exposure.
Note: All figures verified as of August 2026. The gap between NowSecure's 10.6% network-traffic figure and Security.org's 75% privacy-label figure reflects two different measurement methods, not a correction of either study, and both are called out as such in this post. Figures are refreshed at least twice a year as new scans and surveys are published.